Privacy Policy
Last updated: 31 July 2026
1. Data controller
Rubén Benítez Pérez (self-employed), DNI 52598426W, with address at Calle Pau VI, 6, 08173 Sant Cugat del Vallès (Barcelona), Spain. Contact for privacy matters: info@protramit.com.
2. What data we collect and why
- Email address you provide when requesting an audit — used to send you the report and, if you purchase the full report, the payment confirmation. Legal basis: performance of the requested service (contract) / your consent.
- The URL you submit for analysis and the pages we crawl from it — used to generate the audit itself. Legal basis: performance of the requested service.
- Your IP address — stored only as an irreversible hash, used for basic abuse prevention (rate limiting) and security logging. Legal basis: legitimate interest (protecting the service from abuse).
- Payment data, if you purchase the full report — processed entirely by Stripe; we never receive or store your card details. Legal basis: performance of a contract.
If you request a cybersecurity audit, which is always a paid service, we additionally collect:
- The domain audited and the security findings detected (configuration issues, known vulnerabilities, results of the active tests) — used to generate your report. This data can be more sensitive than a SEO report's, since it describes real weaknesses in a website; it is protected with the same access controls as the rest of the service and is never shared publicly. Legal basis: performance of the requested service.
- Your declaration of ownership or authorisation for the audited domain, together with your IP address and the date/time it was given — kept as evidence that you confirmed being authorised to request the active tests before they ran. Legal basis: legitimate interest / compliance with our duty to demonstrate lawful authorisation before running active tests against a website.
- A one-time access token sent to your email to log in to your audits panel without a password — it expires after 30 minutes or after first use, whichever comes first, and is not reusable. Legal basis: performance of the requested service.
3. Who we share data with
Some data is necessarily processed by service providers acting as data processors on our behalf, strictly to deliver the service:
- Anthropic (Claude API) — processes audit findings to generate the report's written explanations. For the cybersecurity audit, this can include a web search limited to public, official vulnerability databases (to correlate known CVEs for the software versions detected) — no personal data of yours is sent for that search, only the software version strings found. The website's own content is never invented; Anthropic does not receive your email or payment data.
- Google (PageSpeed Insights API) — receives the URL being analysed to measure loading performance (SEO analysis only).
- Stripe — processes payment for the full SEO report and for the cybersecurity audit; receives your email and payment details directly, we do not.
We never sell your data, and we never disclose the identity of competing businesses used internally for sector comparison — that data is for internal analysis only and never appears in any report.
4. Data retention
Audit data (the analysed URL, email, findings and reports) is kept for 12 months from the audit date, after which it is deleted or anonymised. Anonymised, aggregated statistics that no longer identify you or your website may be kept longer.
5. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to info@protramit.com, identifying yourself and specifying your request. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es) if you believe your rights have not been respected.
6. Security
We apply reasonable technical and organisational measures to protect your data, including restricting analysis to publicly reachable websites only (private/internal networks are always rejected) and encrypting connections to third-party services.