NIS2-Check / Privacy

Privacy notice

What personal data NIS2-Check processes, why, who receives it, how long we keep it and what your rights are (GDPR Art. 13).

Deutsche Fassung: Datenschutzerklärung auf Deutsch. Last updated: 27 September 2026. If the two versions differ, the German one applies.

1. Who is responsible for your data

NIS2-Check is part of the ComplyFort family of compliance tools and is run by InnoDigital, the trading name of a sole proprietorship registered in Poland. The controller of your personal data under the GDPR is:

Adam Szydło (sole proprietorship, trading as InnoDigital)
Kościuszki 40/11, 46-320 Praszka, Poland
NIP 5761448946, REGON 524963224
Email: hello@innodigital.io

Write to that address about anything in this notice. We have not appointed a data protection officer; at our size the law does not require one, so the address above reaches the person who decides.

2. Data every ComplyFort tool handles

2.1 Free use and fair-use limits

To keep the free tier fair we count uses per day against a one-way hash of your IP address, the date and a secret salt. The hash cannot be turned back into your address and changes every day.

Legal basis: carrying out the service you asked for (GDPR Art. 6(1)(b)) and our legitimate interest in preventing abuse (Art. 6(1)(f)).

2.2 When you give us your email address

When you enter your email address (to receive a report, to buy, or to join a waiting list) we store it with what you asked for in the tool's own records and in our internal customer records (a CRM we host on our own servers), so we know who used which tool and can honour an opt-out or deletion request across all our products at once. Our logs never contain your address in readable form: they hold a one-way hash of the part before the @, next to the domain.

Legal basis: carrying out what you asked for (Art. 6(1)(b)) and our legitimate interest in keeping a record of who contacted us (Art. 6(1)(f)). You can object at any time.

2.3 Product news, only if you tick the box

Where a form offers product news, the checkbox is unticked by default. We add your address to that tool's mailing list at Brevo, our email provider, only when you tick it. When you tick the box we store a consent record in our own database: your email address, the time, the form you used and the wording of the checkbox you saw, so we can show later that you agreed. We keep it while you stay subscribed and for 3 years after you withdraw consent. If you leave it unticked you get only the messages needed for what you asked for. Every product-news email has an unsubscribe link, and one unsubscribe covers all our products.

Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time without affecting what happened before.

2.4 Paying

Paid features are sold through Stripe Managed Payments. For each purchase Link, LLC, a Stripe company, is the merchant of record: Link is the seller on your receipt and card statement, collects and pays the VAT or sales tax, sends the receipt and handles refunds and payment disputes. Stripe collects your card details, billing address and, where relevant, your tax id on its hosted checkout page; we never see or store the card. Stripe and Link process that data as independent controllers under their own privacy policies.

After a successful payment Stripe tells us your email address, what you bought and the purchase reference. We keep these, together with a one-way hash of your report code (never the code itself), to know what you are entitled to, to send you your code and as evidence if a payment is disputed.

Legal basis: the contract with you (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).

2.5 Our internal copy of outgoing email

We send email through Brevo. A hidden copy (BCC) of every email we send goes to an internal company mailbox on Google Workspace, so we can check that our emails went out and handle replies and bounces. The copy contains what you received, including any report code. It is not used for marketing.

Legal basis: our legitimate interest in running and checking our own email delivery (Art. 6(1)(f)).

2.6 Security logs

Our edge server keeps a standard access log (IP address, the requested address including any query string, and the time) on our host in Finland. It is size-capped, so old entries are overwritten; in practice that is about a week. The application itself keeps no access log. Visitors from countries under EU or US sanctions (Iran, North Korea, Syria, Cuba, Russia, Belarus) are blocked at the edge based on their IP address.

Legal basis: our legitimate interest in keeping the service secure and in complying with sanctions law (Art. 6(1)(f)).

2.7 Analytics and session replay

Two things happen when you view a page:

  • Our self-hosted analytics (Rybbit, at analytics.complyfort.com, run by us on our own servers; nothing goes to a third-party analytics company) receives the page you viewed including its query string, the referring page, your screen size, language and the page title. It uses your IP address at the moment of the visit to work out a rough location and does not store the address itself. Session replay is switched on. It records the page as it is displayed to you, with mouse movement, scrolling, clicks and page changes, so we can see where a form confuses people. Text you type into a field is masked. The parts of the page that show your answers or your results (the special-role boxes of the check, the result, the report and the contact form) are blocked from the recording entirely, so the recording shows an empty box there.
  • Our own server counts the page view as a one-way daily hash of your IP address and browser string, with the page path, in our data warehouse. The raw address is not stored there and the hash cannot be linked across days.

Replay recordings are deleted after 30 days. Page-view statistics are kept for 10 years. The analytics script sets no cookies; it writes one random identifier into your browser's local storage and, while replay runs, one flag into session storage. There is no opt-out switch on the site yet; a browser content blocker that blocks analytics.complyfort.com stops the script, and the check works without it.

Legal basis: our legitimate interest in understanding how the tools are used and improving them (Art. 6(1)(f)). You can object at any time by writing to us.

3. What NIS2-Check does with your data

3.1 The free check

Your answers on sector, size (employees, turnover, balance sheet) and special roles are processed only to compute the result. As long as you do not request the report, they are neither stored nor linked to you. Only the daily limit from section 2.1 is counted.

3.2 When you request the report

When you request the report we store your email address, the optional company name, the sector you chose and the result of the check, even if the report is not issued, for example because payment is still missing or a report code was invalid or already used. Section 2.2 applies to the address.

3.3 The evidence pack

After purchase your report code arrives by email. The code travels only in the body of the request to our server, never in the address bar, and the page also hands your email address to checkout in a form rather than in the address. When you redeem the code we store the full report with the figures you entered (employees, turnover, balance sheet), your email address, the company name and the issue date as evidence of what we issued to you, together with the hash of your code and the purchase reference. We show you the report on the page; we do not email it.

3.4 Compliance-Watch waiting list

If you join the waiting list we store your email address and the date and note your interest in the planned plan in our customer records. Sections 2.2 and 2.3 apply.

3.5 The contact form

If you write to us through the contact form, we process your name (optional), your email address and your message to forward them by email through Brevo to our mailbox hello@innodigital.io and to answer you. The application does not store the message; the log only records that a message was forwarded, with the one-way hash from section 2.2. The form's daily limit is counted as in section 2.1.

Legal basis for section 3: carrying out the service you asked for and the contract (Art. 6(1)(b)), the obligation to keep purchase records (Art. 6(1)(c)) and our legitimate interest in evidence of what we issued (Art. 6(1)(f)).

4. Who receives your data

We do not sell your data and we do not share it with advertisers. These service providers process it for us, or receive it as independent controllers where noted:

RecipientRoleWhatWhere
Hetzner Online GmbHhosting (processor)all application data, databases, analytics and logsHelsinki, Finland
Amazon Web Services EMEA SARLbackup storage (processor)encrypted daily backups, kept 30 days (35 days for the customer-records database)Frankfurt, Germany
Link, LLC and Stripe (Stripe Managed Payments)merchant of record and payment processor (independent controllers)card details, billing address, tax id, email, payment historyUS (Link, LLC) and Ireland (Stripe Technology Europe, Limited), with Stripe group companies in the US
Sendinblue SAS (Brevo)email delivery and mailing lists (processor)email address, email content, delivery eventsFrance
Google Ireland Ltd (Google Workspace)internal mailbox for the copy of outgoing email (processor)copies of the emails we sendEU, with Google group companies in the US
Cloudflare, Inc.DNS only; our pages are not proxied through CloudflareDNS lookups for complyfort.com made by your resolverglobal

Where a provider transfers data outside the European Economic Area (Link, Stripe and Google group companies in the US), the transfer relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.

5. How long we keep it

DataKept for
Answers in the free checknot stored
Report requests without a purchase (email, company, sector, result)24 months after your last contact with us
Issued evidence reports, code hash and purchase referencethe life of the purchase, then 5 years for Polish accounting rules
Free-use counters (hashed IP address)the hash changes every day; the daily files are cleared when the service restarts, at the latest after the quarterly review
Email address and lead record24 months after your last contact with us
Product-news subscriptionuntil you unsubscribe or withdraw consent
Consent record (email, time, form, checkbox wording)while you stay subscribed, then 3 years
Messages sent through the contact formnot stored by the application; they sit as email in our mailbox for as long as we need them to handle your request, at most 24 months
Purchase and entitlement recordsthe life of your purchase or subscription, then 5 years for Polish accounting rules
Edge access logsize-capped, in practice about a week
Analytics page views10 years
Session replay recordings30 days
Backups of the databases above30 days (35 days for the customer-records database)

We delete replay recordings and backups automatically. The other periods in this table are applied by a manual review we run at least once a quarter.

6. Your rights

You can ask us for access to your data, to correct it, to delete it, to restrict or object to its use, and to receive it in a portable format. You can withdraw the product-news consent at any time. Write to hello@innodigital.io; we may ask you to confirm the email address the request concerns.

We handle requests manually and answer within one month, as the GDPR requires. Deleting your data means removing your records from the tool and from our internal customer records and taking you off any mailing list, except records the law requires us to keep. Backups expire on their own within 35 days. To delete what Stripe and Link hold, contact them as well; they will tell us.

You can also complain to a data protection authority. Ours is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl; you can also contact the authority where you live or work (in Germany, the data protection authority of your federal state).

Giving us your data is voluntary. Without an email address we cannot issue you a report or a code; the free check needs no account.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

7. Cookies and browser storage

NIS2-Check sets no cookies of its own. The site stores your language choice (German or English) in your browser's local storage (key nis2_lang). The analytics script writes one random identifier into local storage and, while replay runs, one flag into session storage, as described in section 2.7. Stripe sets its own cookies on its checkout pages under Stripe's cookie policy.

8. Changes

We will post any change on this page with a new "last updated" date. The terms cover the rest of how the service works; the provider details are in the Impressum.