loader image

Privacy Policy

How SitePrimed, an ITML product, collects, uses and protects personal data when you use our website and platform.

Who we are

SitePrimed is a product of ITML, an EU-based software company. For the personal data described in this policy, the data controller is https://itml.gr. You can reach our privacy team using the details in the Contact section.

What data we collect

We collect the following categories of personal data:

    • Account data — your name, work email and organisation, provided when you create an account or contact us.
    • Authentication data — we use passwordless magic-link sign-in, so we do not store passwords; we process the email address the link is sent to.
    • Usage & technical data — how you use the platform, plus standard technical data such as IP address, device and browser, and diagnostic logs.
    • Scan data — the URLs you ask us to scan and the results we produce. This concerns your website content; any personal data within scanned pages is covered under When we are a processor.
    • Billing data — for paid plans, billing details and VAT information handled via our payment provider.

Why we process it & legal bases

We process personal data to provide and secure the service, to communicate with you, and to meet legal obligations. Our legal bases under the GDPR are:

    • Contract — to deliver the service you sign up for (account, scans, fixes, billing).
    • Legitimate interests — to secure, maintain and improve the service, balanced against your rights. 
    • Consent — for non-essential cookies and optional marketing emails, where you have opted in.
    • Legal obligation — to comply with tax, accounting and other legal duties.

AI processing

SitePrimed uses AI models to generate remediation suggestions (for example, proposed meta descriptions or alt text) from your scan data. Suggestions are always reviewed and approved by a person before anything is applied — the AI proposes, you decide. AI processing is EU-based, and customer data is not used to train third-party models.

Sub-processors

We use a limited set of vetted sub-processors (for hosting, email delivery, payments and AI processing) to run the service. Each is bound by a data-processing agreement. 

Data location & transfers

Your content and scan data are processed and stored in the EU. We do not route this data through US cloud infrastructure. Where any limited transfer is unavoidable, it is governed by an appropriate safeguard. 

Retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Indicative periods:

    • Account data — for the life of your account and then 3 months after closure.
    • Scan data — 12 months from the scan date, or until the customer deletes it, whichever is sooner.
    • Billing records — as required by law ( 5 years).

Your rights

Subject to the GDPR, you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You can also withdraw consent at any time and lodge a complaint with a supervisory authority. To exercise any right, contact us using the details below; we respond within the timeframes the law requires.

When we are a processor

When we scan your site and apply approved fixes, any personal data contained in your pages is processed on your behalf — you are the controller and we are the processor. That relationship is governed by our Data Processing Agreement (DPA), which sets out our obligations, sub-processors, security measures and international-transfer terms.

Cookies

We use a small number of cookies and similar technologies. Essential cookies keep the service working; non-essential (for example analytics) are set only with your consent. Full details, including a table of the cookies we use, are in our Cookie Policy.

Security

We protect personal data with encryption in transit and at rest, least-privilege access controls, and logging. More detail is on our Security page. No system is perfectly secure, but we work to industry-standard practices and review them regularly.

Changes

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date; where changes are significant we will take reasonable steps to notify you. 

Contact

For any privacy question or to exercise your rights, contact our privacy team at privacy@siteprimed.eu or write to info@itml.gr.