Skip to content
TOLMENA

Privacy Notice

Version 1.0 · 4 October 2026 · binding language: English

We do not ask who you are. To scan a page we need its address — nothing else. No account, no email, no cookies, no tracking scripts. Everything the scan produces is deleted automatically after 24 hours.

1 · Who is responsible

The controller for the processing described here is:

Cemil Ceyhan, sole proprietor, trading as TOLMENA
Tekirdağ, Türkiye · Tax ID (VKN) 2070228557

Email: [email protected]

We have not appointed a Data Protection Officer; we are not required to under Article 37 GDPR. Write to the address above with any question about this notice.

2 · What we process, and why

Everything the service touches. There is nothing else.
DataWhyKept for
The address you submit, and the page content fetched from it To run the accessibility checks and build your report 24 hours, then deleted automatically
Scan results: rule failures, counts, the generated report So you can open the report after the scan finishes 24 hours, then deleted automatically
Your IP address Only to count scans per day and stop abuse Held in memory only, never written to disk, reset daily
Server access log Fault diagnosis and security IP is truncated before it is written (last block zeroed); rotated after 14 days

The legal basis is our legitimate interest under Article 6(1)(f) GDPR: providing the service you asked for and protecting it from abuse. Where you submit an address in order to receive a report, the processing is also necessary to perform that request under Article 6(1)(b).

3 · What we do not do

4 · Where the processing happens

Scans run on a server we rent from Hetzner Online GmbH in Nuremberg, Germany. The data stays inside the European Union. Hetzner acts as a processor on our behalf under Article 28 GDPR. There is no transfer to a third country.

5 · Scanning a site you do not own

A scan reads a page the same way any visitor's browser does: it requests the public address and measures what comes back. We do not log in, do not submit forms, do not follow links beyond the page you gave us, and do not store the page itself after the report is built.

If you submit an address, you confirm you are entitled to have that page scanned — because you own it, operate it, or have the owner's permission. This is set out in section 3 of the Terms of Use.

6 · Your rights

Under the GDPR you may ask us to confirm what we hold about you, to give you a copy, to correct it, to delete it, to restrict or stop the processing, and to receive it in a portable form. You may also object to processing based on legitimate interest.

In practice there is usually nothing to act on: after 24 hours a scan and its report no longer exist, and we never hold your identity. If you want a scan removed before that, send us its report link at [email protected] and we will delete it.

If you believe we have handled your data unlawfully you may complain to a supervisory authority in the EU or EEA country where you live or work, or to the authority with jurisdiction over us.

7 · Security

Traffic to the site and to the scanning service is encrypted with TLS. The scanner runs with no privileges beyond fetching a public page, cannot reach internal or private network addresses, and discards the browser profile it used when the scan ends.

8 · Changes

If this notice changes we will raise the version number and the date at the top of this page. Material changes will be announced on the site before they take effect.