Last updated: 30 July 2026.
This is an interim policy. It is written to be accurate about how this site behaves today rather than to be complete. It is pending review by legal counsel. Our registered company details, the safeguards covering international data transfers, and a direct contact address will be published here when that review completes. Where we do not yet have a confirmed answer, this policy says so instead of guessing.
Who is responsible
Forgera operates this website at forgera.eu and is the controller for the personal data described below. Until the registered company details are published here, you can reach us using the routes listed on our contact page.
What we collect, and why
When you ask for a website audit. The tool on our audit page runs its first set of checks without asking you for anything. One thing is recorded at that stage, and it is there to protect other people's websites rather than to learn anything about you: a short one-way fingerprint of your IP address, together with the address of the site being checked, so that nobody can point the tool at someone else's website hundreds of times over. Those records expire within the hour and are deleted automatically. If you then ask for the full report, we ask for your email address and store five things: that address, the address of the site you asked us to check, the resulting score, the fact that you agreed together with the wording you agreed to, and the report itself.
This is stored in a database on our side: Cloudflare D1, in the same infrastructure that serves this website. We keep the report so that we can show it to you on a page of its own rather than trapping it inside an email. That page sits at a long, randomly generated address that cannot be guessed and is published nowhere; search engines are told not to index it; it carries the date on which it was measured; and it stops working 90 days after the audit ran. Asking us to delete your data removes the stored report along with everything else we hold. The link to it is sent through Resend, an email delivery provider acting as our processor.
When you message us on WhatsApp. Our contact page offers a WhatsApp link. If you choose to use it, the conversation takes place inside WhatsApp and is processed by Meta on its own terms from the moment you send the first message. If you would rather not involve Meta, the same page publishes an email address that reaches us directly.
When you simply visit. This site is hosted on Cloudflare, which records standard technical request data such as IP address, timestamp, and the page requested, in order to serve and secure the site.
The legal basis we rely on
For sending you an audit report you asked for: your consent, which you give with the tick box next to the request and can withdraw at any time by asking us to delete your data. For replying to a message you send us: taking steps at your request before entering into a contract, and our legitimate interest in responding to people who contact us. For anything in the analytics or marketing cookie categories: your consent, which you give or refuse in the banner and can change at any time.
Cookies and consent
Nothing in the analytics or marketing categories runs before you accept it. When you first arrive, a consent banner asks you to choose between three categories:
- Necessary — required for the site to function. These cannot be switched off.
- Analytics — measuring how the site is used. Denied until you accept.
- Marketing — advertising and retargeting. Denied until you accept.
Google Consent Mode is set to denied by default on every page load, so consent-gated tools stay inactive until you allow them. One cookie records the choice you made, so the banner does not ask you again.
Changing your mind. Every page carries a cookie settings control. Opening it lets you change or withdraw any consent you have given, at any time, without contacting us.
How long we keep things
We keep audit records — your email address, the site you asked about, the score and your consent — for 24 months from the day you asked, after which we delete them. The report itself is kept for a shorter period: 90 days from the day it was produced, after which the stored copy is erased and its link stops working. We keep messages you send us for as long as we need them to deal with your enquiry and to keep ordinary business records of work we have quoted or carried out. We do not use your contact details for marketing unless you have asked us to.
Who else sees your data
Three providers process data on our behalf. Cloudflare hosts and delivers this site, and stores the audit records described above in its D1 database. Resend delivers the audit report email. Meta Platforms Ireland processes any WhatsApp conversation you start with us, from the moment you send the first message — that one is your choice, and the email address on the contact page avoids it entirely. We do not sell personal data, and we do not share it with anyone else for their own purposes. The detail of our agreements with these providers, and of any transfers outside the European Economic Area, is part of the legal review noted at the top of this page.
Your rights
Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it or delete it, ask us to restrict how we use it, object to our use of it, and ask for it in a portable format. Where we rely on your consent, you can withdraw it at any time. You also have the right to complain to your national data protection authority.
To exercise any of these, get in touch using the routes on our contact page and tell us what you need. If it is about an audit you asked for, giving us the email address you used is enough for us to find and delete everything we hold against it.
Changes to this policy
When this policy changes we update the date at the top. The interim status above will be removed once the legal review is complete and the outstanding details are filled in.