GDPR & Compliance

Effective: August 18, 2026

Global Compliance Commitment: Scanterity is designed from the ground up to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the ePrivacy Directive, the UK Data Protection Act 2018, and applicable international data protection laws.

1. Your Rights Under GDPR (EU/EEA Residents)

If you are a resident of the European Economic Area (EEA) or the United Kingdom, you have the following rights under Articles 13–22 of the General Data Protection Regulation (EU) 2016/679:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you, including processing purposes, data categories, recipients, and retention periods. We will respond within 30 days.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data or completion of incomplete data without undue delay.
  • Right to Erasure (Art. 17): Request deletion of your personal data when the data is no longer necessary, you withdraw consent, or you object to processing. Also known as the “right to be forgotten.”
  • Right to Restriction (Art. 18): Request restriction of processing while we verify accuracy of your data, while we assess an objection, or if processing is unlawful but you prefer restriction over erasure.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV) and transmit it to another controller.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right Against Automated Decision-Making (Art. 22): Not be subject to decisions based solely on automated processing that produce legal effects. Our plagiarism scores are analytical tools — not automated legal decisions.

To exercise any of these rights, contact our Data Protection Officer at hello@scanterity.com. We will respond within 30 calendar days. You also have the right to lodge a complaint with your local supervisory authority.

2. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources of collection, the business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions (legal obligations, security, etc.).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do NOT sell or share your personal information for cross-context behavioral advertising. There is no data to opt out of.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will receive equal service and pricing.
  • Right to Limit Use of Sensitive Data: You can direct us to limit use of sensitive personal information to purposes necessary to provide the Service.

To submit a verifiable consumer request, contact us at hello@scanterity.com. We will verify your identity and respond within 45 calendar days.

3. Legal Basis for Processing (GDPR Art. 6)

We process personal data on the following legal bases:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the plagiarism detection service you requested — including scanning submitted text and generating reports.
  • Legitimate Interests (Art. 6(1)(f)): Processing for platform security (rate limiting, abuse prevention, DDoS protection), service improvement, and aggregate analytics. We have conducted a Legitimate Interest Assessment (LIA) confirming these interests do not override your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, including tax reporting, fraud prevention, and responses to valid legal process.
  • Consent (Art. 6(1)(a)): Where specifically requested, such as for marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. Data Processing & Retention

Scanterity implements a strict data minimization policy. Below are our data categories and retention periods:

  • Scanned Document Content: Processed in volatile memory (RAM) only. Retention: 0 seconds after scan completion. Content is never written to disk, indexed, or stored in any database.
  • Scan Results/Reports: Generated client-side in your browser. We do not store copies of your reports on our servers.
  • Technical Logs (IP, User Agent): Retained for a maximum of 90 days for security monitoring and abuse prevention. Automatically purged thereafter.
  • Account Data (if registered): Retained for the duration of your active account plus 30 days after account deletion request.
  • Payment Records: Retained for 7 years as required by tax and financial regulation. Processed by PCI DSS-compliant third-party payment processors — we never store full payment card details.
  • Cookie Data: Session cookies expire when you close your browser. Functional cookies expire after 30 days maximum.

5. Cookie & ePrivacy Compliance

In compliance with the ePrivacy Directive (2002/58/EC) and its national implementations, we provide full transparency about our cookie usage:

  • Strictly Necessary Cookies: Required for the service to function (session management, CSRF protection). These do not require consent under Art. 5(3) of the ePrivacy Directive.
  • Functional Cookies: Store user preferences such as scan settings. These are set only with your consent.
  • Analytics Cookies: We do NOT use third-party analytics trackers (Google Analytics, Facebook Pixel, etc.). We use privacy-preserving, first-party aggregate analytics only.
  • Advertising Cookies: We do NOT use any advertising or tracking cookies. We do not participate in ad networks or retargeting programs.

You can manage cookies through your browser settings at any time. Disabling strictly necessary cookies may affect the functionality of the Service.

6. International Data Transfers

If your personal data is transferred outside the EEA/UK, we ensure adequate protection through one or more of the following safeguards, in compliance with GDPR Chapter V:

  • EU-U.S. Data Privacy Framework (DPF): Where applicable, we rely on the adequacy decision for the EU-U.S. Data Privacy Framework.
  • Standard Contractual Clauses (SCCs): We use the European Commission’s approved Standard Contractual Clauses (Decision 2021/914) with all sub-processors.
  • UK International Data Transfer Agreement (IDTA): For UK transfers, we use the UK Addendum to the EU SCCs or the UK IDTA as appropriate.
  • Supplementary Measures: Including encryption in transit (TLS 1.3) and at rest (AES-256), pseudonymization, and access controls.

7. Data Processing Agreement (DPA)

For enterprise and institutional customers where Scanterity acts as a Data Processor under Article 28 of the GDPR, we offer a comprehensive Data Processing Agreement that includes:

  • Detailed description of processing activities, purposes, and data categories
  • Technical and organizational security measures (Art. 32 GDPR)
  • Sub-processor disclosure and change notification procedures
  • Data breach notification obligations (within 48 hours)
  • Audit rights and compliance verification procedures
  • Data return and deletion obligations upon contract termination

To request a signed DPA, contact hello@scanterity.com.

8. Security Measures (Art. 32 GDPR)

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption: All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
  • Access Controls: Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication for all administrative access.
  • Ephemeral Processing: Submitted documents are processed in volatile memory and never written to persistent storage.
  • Rate Limiting: Per-IP rate limiting to prevent abuse and ensure fair resource allocation.
  • Input Validation: Comprehensive server-side input validation and sanitization to prevent injection attacks.
  • Content Security Policy: Strict CSP headers to prevent XSS and code injection attacks.
  • Regular Audits: Periodic security assessments and vulnerability scanning.

9. Data Breach Notification

In compliance with GDPR Articles 33–34 and applicable breach notification laws:

  • Supervisory Authority Notification: We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individual rights and freedoms.
  • Data Subject Notification: Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay via email and a prominent notice on the Service.
  • Documentation: All breaches are documented in our internal breach register, including the nature of the breach, categories and approximate number of individuals affected, likely consequences, and remedial measures taken.

10. Children’s Privacy

The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact our DPO immediately.

11. Supervisory Authorities & Contact

You have the right to lodge a complaint with your local data protection supervisory authority. Key authorities include:

Data Protection Officer
Email: hello@scanterity.com
General Privacy: hello@scanterity.com
DPA Requests: hello@scanterity.com