In short: we use the details you submit to create your monitor, produce recurring visibility snapshots, send those updates and relevant Rotgar insights, secure the service and improve its reliability. We do not sell your personal data.
1. Who is responsible
The controller is Evgeniy Yudin, operator of Rotgar.com (“Rotgar”, “we”, “us”). For privacy questions or requests, email evgeniy.yudin@rotgar.com. Rotgar operates this service from Spain and applies the EU General Data Protection Regulation (“GDPR”) where it applies.
2. Information we process
- Contact information: email address.
- Monitoring brief: submitted domain, brand names, services, city and language.
- Consent records: the notice and agreement versions accepted, timestamps, IP-derived security records and unsubscribe history.
- Service and device data: request timestamps, basic browser and security logs, monitor state, failures and interactions with private report links.
- Analysis data: prompts generated from your brief, publicly available web information, model outputs, cited sources, extracted observations and recurring reports.
Please submit only business information you are authorised to use. Do not submit health data, patient information, account passwords, confidential records or other sensitive personal data.
3. Why and on what basis we process it
Operating the requested monitoring service
We process your submitted information to validate the website, configure the monitoring brief, run snapshots and show your private status and report pages. The lawful basis is taking steps at your request and performing the ongoing monitoring service (Article 6(1)(b) GDPR).
Rotgar insights included with monitoring updates
You expressly subscribe to emails that may combine your visibility updates with relevant Rotgar articles, analysis and service information. The lawful basis is your consent. Frequency may vary. You may withdraw consent at any time through the unsubscribe action in a report or email.
Security, abuse prevention and legal compliance
We process limited technical records to protect the service, detect fraud and defend legal claims, based on our legitimate interests (Article 6(1)(f)) and legal obligations where applicable.
Service improvement
We may use aggregated or de-identified operational information to understand reliability and improve the monitoring method. We do not use submitted email addresses to train third-party foundation models.
4. Service providers and international transfers
We use selected infrastructure and AI service providers to host the intake, store monitor data, send communications and execute analysis. This MVP uses Cloudflare infrastructure and an automated OpenAI Codex workflow. Providers may process data outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism.
We send only the monitoring context needed for the analysis. Your contact email does not need to be included in model prompts.
5. How long we keep information
We retain an active monitor’s data while you remain subscribed and for a limited period afterwards to handle support, audit consent and protect legal rights. Raw operational logs and intermediate outputs may have shorter retention periods. Consent and suppression records may be retained as necessary to demonstrate compliance and ensure we do not resume emails after an unsubscribe request.
When information is no longer needed, we delete or irreversibly anonymise it, subject to backup cycles and legal retention obligations.
6. Security and private links
Monitor and report URLs contain a hard-to-guess access token. Anyone who receives that URL may be able to view the associated report or unsubscribe the monitor. Keep it private and contact us if you believe it has been exposed. We use access controls, encrypted transport, audit records and operational safeguards proportionate to this MVP, but no online system is risk-free.
7. Your choices and GDPR rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time without affecting processing already carried out. Use the unsubscribe action on your monitor page or email evgeniy.yudin@rotgar.com.
You may also complain to the Spanish Data Protection Agency (AEPD) or the competent authority where you live or work.
8. Email verification during the MVP
The initial MVP may create a monitor without requiring you to click an email verification link. This does not mean the address has been independently verified. We may manually review, reject, pause or request verification of any submission. Verification may become mandatory for new monitors later.
9. Changes
We may update this notice as the service evolves. Material changes will be reflected by a new effective date and, where required, a new consent request.