Summary: TrustCtrl is hosted in the EU, GDPR aligned, and we do not sell your data. We collect only what is needed to operate the service, and web analytics run only with your consent.
1. Who we are
TrustCtrl is a digital trust monitoring platform built and operated in Denmark by Certiva ApS (CVR: 46450965). References to "we", "us" or "our" in this policy refer to Certiva ApS, which acts as the data controller for the data described below.
For the monitoring data that customers add to the platform, we act as a data processor on the customer's behalf — this is governed by our Data Processing Agreement (DPA).
For questions about this policy, contact us at mail@trustctrl.com.
2. What data we collect
- Account data: company name, your name, email address, and password (stored bcrypt-hashed — we never store or see your plain-text password)
- Monitoring data: the domains and hostnames you add, and technical observations about them collected during scans — certificate metadata, DNS records, HTTP responses, page content, email-authentication records and scan results
- Technical and log data: IP addresses, session identifiers and security-relevant logs needed to operate and protect the platform
- Web analytics: first-party, anonymous visit statistics on this website — collected only if you consent via the cookie banner (see the Cookie Policy)
- Communication data: messages you send us by email
The Service is not yet open for public sign-up, and we do not collect any payment details.
3. How we use your data
- To provide and operate the TrustCtrl platform
- To send service-related notifications — for example down/up alerts, certificate expiry reminders and the weekly digest
- To respond to support requests and enquiries
- To keep the platform secure and improve how it works
- To comply with legal obligations
We do not use your data for advertising, and we do not sell it or share it with third parties for marketing purposes.
4. Legal basis (GDPR)
Our processing is based on:
- Contract performance (Art. 6(1)(b)) — to deliver the service you signed up for
- Legitimate interest (Art. 6(1)(f)) — to keep the platform secure and improve it
- Legal obligation (Art. 6(1)(c)) — where required by applicable law
- Consent (Art. 6(1)(a)) — for web analytics, which you can withdraw at any time via the Cookie settings link in the page footer
5. Where your data is stored
All data is stored on infrastructure located within the European Union. We do not transfer personal data to countries outside the EU/EEA without adequate safeguards in place.
6. Google user data (Search Console and Analytics integrations)
Google Search Console
SiteControl offers an optional integration with Google Search Console. If you choose to connect it, you grant TrustCtrl read-only access to your Search Console data via Google's official API, using the webmasters.readonly scope.
What we access: search performance statistics (queries, clicks, impressions, positions), sitemap status and index-coverage information for the website properties you explicitly connect — nothing else from your Google account.
What we use it for: exclusively to show your own search visibility and indexing status inside your TrustCtrl dashboard and reports, next to the rest of your website's monitoring data. We do not use this data for advertising, we do not sell it, and we do not share it with third parties.
Storage and retention: retrieved Search Console data is stored on our EU infrastructure, is visible only to users in your own organisation, and is deleted when you disconnect the integration or delete the related website from the platform.
Human access: no human at TrustCtrl reads your Google data, except with your explicit permission (e.g. a support request), where required for security investigations, or where required by law.
Revoking access: you can disconnect the integration at any time inside TrustCtrl, or revoke TrustCtrl's access from your Google account at myaccount.google.com/permissions.
Google Analytics (BusinessValue)
SiteControl offers a second, separate optional integration with Google Analytics 4. If you choose to connect it, you grant TrustCtrl read-only access to your Analytics data via Google's official API, using the analytics.readonly scope. This is a distinct connection from the Search Console one above: it uses its own consent screen, and connecting or disconnecting one has no effect on the other.
What we access: for the GA4 property you explicitly select, aggregated organic search statistics per landing page and per day — sessions, conversions and revenue — plus the list of property names on the account, so you can choose which one to use. We request only organic-search traffic; data about your paid, email, social and direct traffic is filtered out by Google before it reaches us. We do not access individual user records, user identifiers, demographic or device-level data, audiences, or any other report.
What we use it for: exclusively to show, inside your own TrustCtrl dashboard and reports, what your website's search traffic produced — which pages and which search terms led to conversions or revenue. We do not use this data for advertising, we do not sell it, we do not share it with third parties, and we do not use it to train machine-learning or AI models.
Storage and retention: retrieved Analytics data is stored on our EU infrastructure, is visible only to users in your own organisation, and is deleted when you disconnect the integration or delete the related website from the platform.
Human access: as above — no human at TrustCtrl reads your Google data except with your explicit permission, where required for security investigations, or where required by law.
Revoking access: you can disconnect the Analytics integration on its own at any time inside TrustCtrl, or revoke TrustCtrl's access from your Google account at myaccount.google.com/permissions.
TrustCtrl's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Data retention
We retain account data for as long as your account is active, plus a reasonable period thereafter to fulfil legal obligations. Monitoring data is retained while the related domain is being monitored, so the platform can show trends and history. Data that is no longer needed is deleted or anonymised.
You may request deletion of your data at any time by contacting us.
8. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent, where processing is based on consent
- Lodge a complaint with a supervisory authority — in Denmark, Datatilsynet
To exercise any of these rights, contact us at mail@trustctrl.com.
9. Security
TrustCtrl is built with security as a core requirement. Passwords are bcrypt-hashed, traffic is encrypted in transit with TLS, and stored secrets are encrypted at rest with AES-256-GCM. Two-factor authentication (TOTP) is available and can be enforced organisation-wide, and access within an organisation is governed by fine-grained role-based access control.
10. Cookies
We use necessary cookies for login and security on the application pages, and optional first-party analytics that only run with your consent. The full overview — including every cookie and storage key we use — is in the Cookie Policy. You can change your choice at any time via the Cookie settings link in the page footer.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to registered account holders by email. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related questions or requests:
Certiva ApS (CVR: 46450965)
Denmark
Email: mail@trustctrl.com
Web: trustctrl.com/contact