Privacy policy

DustOff looks through the publicly reachable pages of your website and emails you where content has gathered dust. Here is what data comes up, why we need it and how you get rid of it.

1. Controller

DustOff is a project by hantha GmbH, Dick 48/B, 39058 Sarntal (BZ), South Tyrol — Italy. Email: info@getdustoff.com, phone: +39 0471 623 721. Full details are in the imprint.

A data protection officer is not legally required and has not been appointed. The address above answers every privacy question.

2. Website check

When you enter an address, we fetch publicly reachable pages of that website and look through the text for statements that have aged out. We process the address you entered, the page content we fetched and technical metadata of the request.

Legal basis is Art. 6(1)(b) GDPR (performing the check you asked for) and Art. 6(1)(f) GDPR (operating the service).

3. Email notifications

We store your email address only if you enter it and explicitly agree to be notified. Legal basis is your consent under Art. 6(1)(a) GDPR. As proof we log the time and wording of that consent plus the confirmation via the link in the first email (double opt-in).

You can withdraw consent at any time with future effect — via the unsubscribe link in every email or the unsubscribe page. After withdrawal your address stays on a suppression list so nobody writes to you again by accident (Art. 6(1)(c)/(f) GDPR).

4. Payments

If you book a paid plan, payment runs through Stripe. Stripe processes name, email address, payment method, billing address and tax details under its own responsibility; we never see full card data.

We store only the email address, customer and subscription id, plan, status and period end — that is what unlocks your plan. Legal basis is Art. 6(1)(b) GDPR (contract) and, for invoice data, Art. 6(1)(c) GDPR (tax retention).

5. Referral programme

If you refer DustOff, we store your personal referral link, the address of the referred person, the confirmation time and whether a credit was granted. Each side only ever sees the other side shortened (e.g. a***@example.com).

To see how well referrals work, we also count anonymously how often a referral link is shared, clicked and confirmed. We store no address and no IP — only a non-reversible short code of the link and the channel used (e.g. WhatsApp). Legal basis is Art. 6(1)(f) GDPR (evaluating our own programme); these counts are deleted after 6 months.

To prevent abuse we keep a review log: it records when a referral was rejected, why and when. Legal basis is Art. 6(1)(b) GDPR (running the programme) and Art. 6(1)(f) GDPR (protection against duplicate and self-referrals).

6. Email delivery log

For every message sent we store recipient address, type, subject, time, delivery status and the sending service's id. We need this to spot delivery problems and to prove withdrawals. Legal basis is Art. 6(1)(f) GDPR.

7. Recipients and processors

We use the following processors under Art. 28 GDPR: Lovable (application hosting), Supabase (database, hosted in the EU), Firecrawl (fetching publicly reachable pages), Anthropic (language model that assesses text passages), Resend (email delivery) and Stripe Payments Europe (payments, controller for payment data).

Where data is transferred to third countries, this happens on the basis of the EU standard contractual clauses and additional safeguards. Beyond that we pass on no data unless legally obliged.

8. Use of artificial intelligence

The check runs in two stages. First DustOff looks for dates, years, seasonal wording and deadlines using rules. Only when a passage is concretely suspicious does the excerpt around it go to an AI service that assesses whether the content looks out of date.

Only publicly reachable text excerpts of the checked website are transmitted — no screenshots, no usage data about your visitors and no email addresses. The content is not used to train AI models. There is no automated decision with legal effect under Art. 22 GDPR: the AI produces a hint, you decide.

9. Server logs and abuse protection

Visiting this website creates technically necessary server logs (IP address, time, requested resource, user agent). They serve operation and defence against automated requests and are deleted after 7 days at the latest. Legal basis is Art. 6(1)(f) GDPR.

Against bots we use hidden form fields plus timing and frequency checks. No profiles are built and no third-party captchas are loaded.

The frequency check counts requests per sender. We never store an IP address in clear text, only a non-reversible hash with a secret pepper; these counters are deleted after 24 hours at the latest. Legal basis: Art. 6(1)(f) GDPR.

10. Ideas and feedback

If you request an offer via the enterprise page, we store company, name, email address, number of websites, preferred cadence and your message — solely to prepare an offer. The legal basis is your consent under Art. 6(1)(a) GDPR and Art. 6(1)(b) GDPR for pre-contractual steps; we delete the enquiry after 24 months at the latest.

If you write to us via the contact form, we store name, email address, subject, message and language — solely to reply to you. The legal basis is your consent under Art. 6(1)(a) GDPR; we delete the message after 24 months at the latest.

If you send us a message through the ideas page, we store the text, the chosen type (idea, friction, question), the language, the page you came from and — only if you provide it — your email address. The address is optional and used solely to reply.

The legal basis is your consent under Art. 6(1)(a) GDPR; we store the wording of that consent alongside it. Messages are deleted after 24 months at the latest, earlier on request.

11. Cookies and tracking

We set no marketing cookies and embed no tracking pixels. Strictly necessary cookies run without consent; measurement only if you agree in the notice at the bottom of the page:

NamePurposeLifetime
dustoff_langRemembers your chosen language.12 months
dustoff_refRemembers the referral link you arrived through.30 days
dustoff_couponLinks a referral credit to your later order.30 days
_ga, _ga_*Anonymous usage statistics (Google Analytics) — only after your consent.up to 14 months

The first three cookies are required for the features you asked for and need no consent. Google Analytics cookies are only set once you agree in the notice at the bottom of the page (Art. 6(1)(a) GDPR); until then no Google script is loaded. You can withdraw consent at any time by clearing this site's browser storage. The provider is Google Ireland Limited, Dublin; IP addresses are truncated, advertising features are off, and a transfer to the US under the EU standard contractual clauses and the EU-US Data Privacy Framework cannot be ruled out. We additionally use local browser storage for bot protection; that data never leaves your device.

12. Retention

We delete automatically after these periods:

DataPeriod
Check results and checked pageswhile monitoring is active, at most 24 months
Email address and preferencesuntil withdrawal or deletion
Suppression entry after withdrawalindefinite, as proof of withdrawal
Email delivery log12 months
Referral review log12 months
Anonymous referral counts6 months
Plan change audit trail24 months
Unconfirmed referrals6 months
Ideas and feedback24 months
Enterprise enquiries24 months
Contact messages24 months
Your take on reported spotswhile monitoring is active
Invoice and payment datastatutory retention period (up to 10 years)

13. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw consent at any time; processing until then stays lawful.

A short email to info@getdustoff.com is enough. We answer within one month.

14. Delete at the push of a button

You do not have to write to us to disappear: in your settings you delete everything tied to your address yourself — monitoring, results, preferences and referrals. Only the suppression entry stays so nobody writes to you again by accident.

Go to settings

15. Right to complain

You can complain to a supervisory authority. Ours is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy (garanteprivacy.it). You may also contact the authority of your country of residence.

Last updated: August 2026