01.Data Controller & Architectural Principles
This Privacy Policy explains how BOSS STUDIO S.R.L. (“we”, “us”, or “Data Controller”) processes personal data through the SlopCheckr platform, API, and associated services, in full compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Romanian Law no. 190/2018.
We build with a strict Data Minimization and Zero-PII Forensics principle: our diagnostic engine parses public frontend markup without tracking end-users across third-party websites or storing sensitive private data.
02.Nature of Processing: Public DOM & Forensic Audit Telemetry
When a user or automated CI/CD pipeline submits a publicly accessible URL for analysis:
Our automated crawler emits a single standard HTTP GET request to retrieve publicly rendered HTML, CSS stylesheets, Tailwind utility classes, and declared web fonts.
The crawler never bypasses firewalls, never fills in forms, does not execute authenticated sessions, and never accesses internal databases or personal records belonging to visitors of audited domains.
The computed-style extraction engine computes heuristic metrics in temporary volatile memory to generate the report cards, conversion audits, and code diffs.
03.Legal Bases for Processing (GDPR Article 6)
Account creation, email verification, API token issuance, subscription management, and crediting scan balances.
Aggregating benchmark telemetry, computing industry design rankings, detecting fraud, and enforcing API rate limits.
Saving optional performance diagnostic cookies and user interface preferences (e.g. preferred code snippet formats).
04.Your Statutory Rights under GDPR (Articles 15–22)
As a data subject located in the European Union or accessing our services globally, you are entitled to exercise the following rights:
To exercise any of these rights, email our Data Protection Officer at [email protected]. We respond to all verified requests within 30 calendar days.
05.Authorized Sub-Processors, Security & Infrastructure (Cloudflare & Vercel)
We partner exclusively with verified service providers maintaining strict GDPR Data Processing Addendums (DPAs), Standard Contractual Clauses (SCCs), and ISO 27001 / SOC 2 certifications:
- TikTok Information Technologies UK Limited & TikTok Technology Limited (ByteDance Ltd): We deploy the TikTok Pixel (Pixel ID:
DA6V4CBC77UDHRK42RUG) and TikTok Server-Side Events API (CAPI) to measure advertising effectiveness, attribute sales conversions (such as Pro memberships and audit credit purchases), and prevent bot-induced ad spend fraud. Where user identifiers (such as email addresses) are transmitted for conversion matching, they are irreversibly pseudonymized via one-way cryptographic SHA-256 hashing prior to dispatch. Data processing is governed by TikTok's GDPR-compliant Business Products Terms, Controller-to-Controller Data Processing Agreements, and European Commission Standard Contractual Clauses (SCCs). - Google Analytics & Google Identity (Google LLC / Google Ireland Ltd): Provides aggregated, pseudonymized web traffic measurement, performance telemetry, and event analytics (Measurement ID:
G-SLNBYQY772) to understand feature engagement and optimize platform load times under GDPR compliant Data Processing Terms and standard EU SCCs. - Cloudflare, Inc. (Global / EU Edge): Provides DNS resolution, Web Application Firewall (WAF), DDoS mitigation, and Cloudflare Turnstile bot defense. Turnstile processes telemetry (browser headers, timestamp, screen dimensions) strictly to distinguish human visitors from malicious automated scripts without harvesting personal data, biometric profiles, or tracking users across external websites.
- Vercel, Inc. (Global / EU Edge Serverless Compute): Provides edge hosting, serverless function orchestration, and CDN asset caching under strict GDPR DPA protocols.
- Paddle.com (Paddle Payments Ltd / UK & EU): Authorized Merchant of Record, payment gateway, PCI-DSS Level 1 payment processing, fraud prevention, and automatic EU VAT collection and remittance.
- MongoDB Atlas / Cloud Infrastructure: Encrypted persistence for user accounts, session state, and diagnostic audit records.
06.Lead Supervisory Authority (ANSPDCP & EU DPAs)
If you believe our processing of your personal data infringes the GDPR, you have the statutory right to lodge a complaint with the lead supervisory authority in Romania:
Email: [email protected] · Web: www.dataprotection.ro