1. Controller
The controller responsible for processing personal data in connection with this website and the TrueSift service is:
Ventsislav Kolev – WebDigiTech51067 KölnGermany2. Scope of this Privacy Policy
TrueSift is a WebDigiTech product for the technical protection of websites, forms, sign-in processes and other digital interfaces against automated requests, spam and abuse.
This Privacy Policy describes the processing of personal data on the TrueSift website, when access is requested and when the TrueSift interfaces operated by WebDigiTech are used.
If TrueSift is used on another operator's website, that operator's privacy information also applies.
3. Website access and server logs
When this website is accessed, technically necessary connection data is processed. This may include, in particular, the IP address, date and time of the request, the requested address, the amount of data transferred, HTTP status, previously accessed content and information about the browser and operating system.
The processing is necessary to deliver the website, ensure stable and secure operation, detect technical errors and prevent abusive access.
Log data is stored only for as long as necessary for operation, security, error analysis and the prevention of specific attacks. Longer storage takes place only when a security incident must be investigated or legal obligations apply.
4. Requesting TrueSift access
If you request trial access or TrueSift credentials, we process the information you provide.
- Name and email address
- Address of the website to be protected
- Country or region
- Platform used or technical integration
- Optional information about the intended use
- Time and technical status of the request
The data is used to review the request, verify the technical availability of the specified website, provide credentials, answer follow-up questions, restore access and prevent abusive requests.
Access requests that are not confirmed or not fully completed are deleted after the intended confirmation and review periods have expired, unless security or evidentiary obligations require temporary further storage.
5. Challenge and verification check
During a TrueSift security check, technical data required to distinguish automated or abusive requests from normal usage is processed.
- Site Key and technical integration identifier
- Challenge ID and short-lived challenge tokens
- Requested action and requested path
- Origin or source of the request
- Time and duration of the check
- Technical browser and request information
- Honeypot and integrity signals
- Result of the security check
This information is processed exclusively to provide the security function, detect technical manipulation, prevent abuse and support the stability and error analysis of the service.
Security data is not used for personalized advertising, remarketing, creating advertising profiles or selling personal data.
6. IP addresses and technical identifiers
The IP address is inevitably processed during technical communication between browser and server. It may be used to detect unusual request patterns, enforce technical limits and prevent abuse.
Where required for longer-term technical correlation, a cryptographically derived hash may be used instead of the full IP address. It is used to recognize technical abuse patterns, not to identify a natural person.
7. Cookies and browser-side storage
TrueSift does not use cookies for advertising, marketing or tracking purposes as part of the security check.
Where short-lived information is stored in or read from the browser, this takes place exclusively to perform a requested security check, technically associate the check status, prevent replay attacks or ensure the integrity of the process.
Technically necessary identifiers are not used longer than required for the security purpose after the relevant check has been completed or expired.
8. Server-side processing and credentials
Security-relevant credentials and Secret Keys may only be processed server-side. They are not exposed to the browser or other publicly accessible client applications.
Communication from an integrated website can take place through its own server-side interface or a same-origin proxy. This means internal backend addresses and confidential credentials do not need to be included in publicly delivered source code.
Operators integrating TrueSift are responsible for adequately protecting their Secret Keys and using them only for the intended server-side checks.
9. Automated technical classification
TrueSift can automatically classify requests based on technical signals as allowed, requiring review or to be blocked. Possible technical results are returned, for example, as “allow”, “review” or “block”.
The classification is used for technical access control and abuse prevention. It is not used for credit checks, employment decisions, insurance decisions or comparable decisions with legal or similarly significant effects.
The specific response to a check result is determined by the operator of the integrated website.
10. Legal bases
Depending on the relevant process, personal data is processed on the following legal bases:
- Art. 6(1)(b) GDPR for processing access and contract requests and providing agreed services
- Art. 6(1)(f) GDPR for the secure and stable operation of the service, detecting abuse, preventing automated attacks and technical error analysis
- Art. 6(1)(c) GDPR where processing is necessary to comply with legal obligations
- Section 25(2) no. 2 TDDDG where access to information on the terminal device or storage on the terminal device is strictly necessary for the expressly requested security function
Our legitimate interests include, in particular, protecting our technical infrastructure, our customers' and users' systems, preventing spam and abuse and ensuring reliable service operation.
11. Recipients and processors
Personal data is transferred only to parties required for providing, maintaining, securing or legally compliant operation of the service.
These may include hosting, infrastructure, email and technical support providers. Where these providers process personal data on our behalf, they are engaged on the basis of a data processing agreement.
Personal data is not disclosed for third parties' own advertising purposes and is not sold.
12. Allocation of roles for integrated websites
If another website operator uses TrueSift to protect its own website, that operator determines the purpose, scope and specific configuration of the security check.
The respective website operator is generally responsible for informing its users and for privacy-compliant integration. Depending on the specific contractual and integration setup, WebDigiTech processes the resulting data as a processor or under its own responsibility for the secure operation of the TrueSift service.
13. Storage period
Personal data is stored only for as long as necessary for the respective processing purpose or as required by statutory retention obligations.
- Challenge and verification tokens are short-lived and can no longer be used after their technical validity expires.
- Incomplete access requests are deleted after the confirmation and review period has expired.
- Security and error logs are deleted or anonymized as soon as they are no longer required for operation, abuse prevention and error analysis.
- Contract and billing data is stored in accordance with the applicable statutory retention periods.
Longer storage may take place where there are specific indications of a security incident, an attempted abuse or a need to defend legal claims.
14. Your data protection rights
Where the legal requirements are met, you have, in particular, the following rights:
- Right of access to processed personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure of personal data
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interests
- Right to withdraw consent with effect for the future
To exercise your rights, you can contact us using the contact options below.
15. Right to object
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless there are compelling legitimate grounds for the processing or the processing serves the establishment, exercise or defence of legal claims.
16. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
For WebDigiTech's place of business, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia is the competent authority in particular.
17. Data security
We use technical and organizational measures to protect personal data against loss, manipulation, unauthorized access and unauthorized disclosure.
The measures are reviewed regularly and adjusted where necessary, taking into account processing risks, the state of the art and technical developments.
18. Changes to this Privacy Policy
This Privacy Policy may be updated if technical functions, legal requirements or the nature of data processing change.
The current version is published on this page. The date shown at the top of the page indicates the date of the latest revision.
19. Additional WebDigiTech privacy information
For general information about WebDigiTech and other services, the privacy information on the main WebDigiTech website also applies.