agentreadycheck

Also available as Markdown

Privacy policy

Last updated: 26. August 2026

Controller

Sascha Hoffmann
Einzelunternehmen
Matternstraße 19
10249 Berlin
Deutschland

Email: [email protected]

What this site does — and what that produces

AgentReady Check checks a domain you enter for technical agent-readiness. Four kinds of data arise in the process.

1. Scanned domains and results

We store the scanned domain, the score achieved and the check results. This data is not personal and is published in aggregate as market data at /api/v1/stats. No link to the person who started the scan is stored.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in aggregated market data), to the extent any personal reference exists at all.

2. Email address when unlocking the report

If you enter your email address to unlock the remaining checks, we store that address together with the scanned domain and the timestamp. We use it to send you the full report.

Legal basis: Art. 6 (1) (b) GDPR (fulfilling your request) and Art. 6 (1) (a) GDPR insofar as you consent to receiving further information.

You can object to further use informally by email at any time; we then delete the address.

3. Server logs

When the site is accessed, our host processes technically necessary data (IP address, timestamp, requested URL, user agent). We additionally keep IP-based counters in memory to limit abuse (rate limits). These counters are not stored persistently and expire automatically.

Legal basis: Art. 6 (1) (f) GDPR (operational security).

4. Reach measurement

We measure how the site is used with Datafast in its cookieless configuration. No cookie is set for this and no cross-site profile is built. Datafast derives a pseudonymous visitor identifier server-side from a salted hash of signals such as IP address and browser user agent; the salt rotates roughly every 24 hours, so visits cannot be linked across days. Your IP address is not stored in plain text.

We use this to see which channels bring people to the scanner — including whether AI assistants refer visitors to us.

Separately from this, we record requests from automated crawlers (for example GPTBot, ClaudeBot, PerplexityBot or Googlebot) server-side: the requested URL, the user agent and the source IP address. This concerns machine traffic, not visitors; requests from ordinary browsers are filtered out before anything is sent.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in reach measurement). Because the configuration is cookieless and non-identifying, no consent banner is required for it under § 25 (2) TDDDG.

Cookies

We set strictly necessary cookies only, and no tracking:

Cookie Purpose Lifetime
arc_unlocked remembers that you unlocked the full report 1 year
arc_scans remembers which scans you started yourself, so only you can change their visibility 1 year

Both are HttpOnly and are never evaluated for analytics. No consent banner is required for them (§ 25 (2) no. 2 TDDDG).

Beyond the cookieless reach measurement described above we use no advertising, remarketing or social media services, and we build no cross-site profiles. Datafast may use browser session storage, which is cleared when you close the session.

Processors

We work with the following processors; data processing agreements pursuant to Art. 28 GDPR are in place with all of them:

Service Purpose Place of processing
Vercel Inc. hosting and delivery of the application Frankfurt region (eu-central)
Supabase Inc. database (scans, leads) Frankfurt region (eu-central-1)
Cloudflare, Inc. DNS and upstream proxy worldwide, anycast
Resend (Plus Five Five, Inc.) sending the report email USA
Datafast (datafa.st) cookieless reach measurement and crawler traffic see the provider's data processing agreement

Where data is transferred to the USA, this is based on the EU standard contractual clauses or a certification under the EU-US Data Privacy Framework.

Retention

Scan results are stored permanently as anonymous market data. Email addresses are stored until you object or request deletion.

Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw consent at any time with effect for the future.

Contact us informally at [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority.


See also: Legal notice