vena
Home / Privacy statement
Privacy

Privacy statement

Below you can read exactly what I do with your data when you visit vena.digital, run the free website check, or get in touch. Plain words, no small print where it is not needed.

Last updated on 11 september 2026. Version 1.1. This is a translation of the Dutch statement; in case of any difference, the Dutch version applies.

I am Tonco. Through Vena Digital I build websites for people who run a business, and on this site you can have your own website checked for free. For those things I sometimes need data from you. I am careful with it: I collect only what is needed, I never sell anything on, and you can always see or delete whatever I hold about you.

Who I am

Vena Digital is responsible for processing your personal data (the law calls this the “controller”). My details:

  • Name: Vena Digital (sole trader)
  • Address: Havenstraat 21B, 1404 EL Bussum, the Netherlands
  • Dutch Chamber of Commerce number: 76076032
  • VAT ID: NL003037147B59
  • Email: hello@vena.digital
  • Phone: +31 6 10 71 42 05

I do not have a data protection officer (a business this size is not required to have one). You can simply put privacy questions to me at hello@vena.digital.

The short version

The heart of it in a few lines; the rest of the page works it out.

  • If you get in touch, I keep your name, email address and phone number so I can answer you.
  • If you run the free check, the website you enter goes to a handful of external services that measure it. I store your IP address only in encrypted (hashed) form, to prevent abuse.
  • I measure how the site is used with Google Analytics and Microsoft Clarity, but only after you have clicked “accept” in the cookie notice. If you decline, no analytics cookies are placed.
  • I never sell your data and I do not use it for advertising.
  • You can always view, correct or delete whatever I hold about you.

What data I process and why

For each situation I explain what data I process, what for, and on what legal basis (the GDPR requires a valid reason for every processing activity).

1. The contact form

If you fill in the contact form, I process your first name, email address and phone number. I use that only to respond to your enquiry and, if you want, to look at your website together. Legal basis: the steps needed to possibly enter into an agreement, and my legitimate interest in handling an incoming enquiry properly. I do not use this data for newsletters or advertising, unless you separately ask me to.

2. The free website check

For the check you enter a website address (URL). I pass that address on to external services that fetch, measure and analyse the page (see who I share data with). Usually it is your own company’s website, but because the outcome is tied to you as a visitor, I treat it carefully.

To keep the free check from being abused, I count per day how often a scan is run from the same device. For that I read your IP address, but I do not store it as it is: I keep only an encrypted (hashed) version of it, with a secret addition. Your raw IP address is therefore not kept. According to the regulator such a hashed version still counts as personal data (not as anonymous), which is why I mention it here honestly. Legal basis: my legitimate interest in preventing abuse and overloading of the free service.

3. Receiving the report by email

If you want the report in your inbox, you enter your email address, and if you like your first name, so I can address you by name in that email. I use the address to send you the report. Legal basis: performing the service you asked for yourself. I do not add your email address to a mailing list and I send you no advertising.

What you enter I also keep alongside the check you ran, so that in my own overview I can see who used the free check and recognise you if you ask me something later. Legal basis: my legitimate interest in knowing who uses my free service and being able to respond properly. How long I keep it is under retention periods. If you want it gone sooner, email me and it is gone.

4. Visitor statistics and session insight

I would like to know what works on the site and what does not, so I can make it better. For that I use two tools, both loaded through Google Tag Manager:

  • Google Analytics 4: general visitor figures, such as which pages are visited, with what kind of device, and roughly from which region.
  • Microsoft Clarity: insight into how visitors use the site, with heatmaps (where people click and how far they scroll) and recordings of mouse movement and clicks during a visit. Text you type is masked by default.

Legal basis: your consent. Both start only after you click “accept” in the cookie notice; if you decline or make no choice, they do not run. I never use this data for advertising. How Microsoft and Google handle data themselves is in the Microsoft privacy statement and the Google privacy statement. More about the cookies is under cookies and statistics.

Cookies and visitor statistics

A cookie is a small file a website can put on your device. This site uses as few as possible:

  • Analytics cookies (Google Analytics 4 and Microsoft Clarity, through Google Tag Manager): only if you accept in the cookie notice. They help me see how the site is used. If you say no, or make no choice, they are not placed. I do not use the measurements for advertising.
  • Functional storage for your cookie choice: I remember in your own browser whether you accepted or declined, so the notice does not keep coming back. No consent is needed for that, because it is purely functional.

I use no advertising cookies and no trackers that follow you across other sites. You can always change your choice through the “Cookies” link at the bottom of every page.

Who I share data with

I use a number of external services that process data on my behalf (in the law: “processors”). With each of them I have or am putting in place the legally required agreement (a data processing agreement). I never sell your data. These are they:

ServiceWhat forWhere / transfer
CloudflareHosting the site, handling traffic, storing screenshotsUS company, servers in the EU. Data Privacy Framework
UpstashStoring check results, the email and contact details you enter, hashed IPDatabase in the EU (Frankfurt); US company, with a processing agreement
ResendSending the report by emailUS. Data Privacy Framework
Google (Analytics, Tag Manager, Gemini, PageSpeed)Statistics, the AI that writes the report text, speed measurementUS. Data Privacy Framework. Paid Gemini tier, so what you enter does not train their AI
Microsoft (Clarity)Heatmaps and session recordings to improve the siteUS. Data Privacy Framework
PerplexityLooking up competitors of the scanned siteUS. Business API terms, not used for training
FirecrawlFetching the page you entered and taking a screenshot of itUS. Processing agreement
DataForSEOFetching search and visibility dataEU/US. Processing agreement
ntfyA ping to me when a new enquiry comes inEU. Contains no personal data

During the check, a screenshot of the page you entered may occasionally show data that happens to be on that page. I keep that screenshot only as long as the report is useful (see retention periods).

Transfers outside the EU

Some of the services above are American companies, so your data may be processed outside the European Economic Area. That is allowed only with extra safeguards. I rely on the EU-US Data Privacy Framework (a European Commission decision that gives certified American companies an adequate level of protection) and, where that does not apply, on the European Commission’s standard contractual clauses. Where I can, I choose storage inside the EU.

How long I keep data

I keep nothing longer than necessary. Concretely:

  • The abuse counter with your hashed IP address: expires automatically after 2 days.
  • The result of a check (measurements and report): 30 days, then deleted automatically. Data I fetch along the way about a checked site I keep for at most 14 days as a temporary cache.
  • Screenshots of the checked page: 30 days, then deleted automatically.
  • The address I send a report to: at most 7 days, then deleted automatically. That is only the note that arranges the sending.
  • Your first name and email address with a check: up to 24 months, then deleted automatically. The same period as data from the contact form, because it is the same kind of contact.
  • Contact details from the form: up to 24 months after your last contact, then deleted automatically.

Security

I take appropriate measures to protect your data: connections are encrypted (https), access is restricted, and I share data only with the services listed above. Notice something that does not look right? Let me know at hello@vena.digital.

Your rights

Under the GDPR you have a number of rights. You may ask me for:

  • Access: a copy of the data I hold about you.
  • Rectification: correcting something that is wrong.
  • Erasure: having your data deleted.
  • Restriction: temporarily stopping the use of your data.
  • Portability: receiving your data in a common file format.
  • Objection: objecting to processing based on legitimate interest.
  • Withdrawing consent: where I rely on consent (such as the statistics), you may withdraw it at any time, without what happened before becoming unlawful.

Send your request to hello@vena.digital. I respond within a month. It is free, and sometimes I will ask you to confirm who you are, so I do not accidentally hand data to the wrong person.

Filing a complaint

If you disagree with something, tell me first; I would much rather sort it out with you. You also always have the right to file a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. If you live in another EU country, you may also complain to your own national authority. And you can go to court.

No automated decision-making

The check uses AI to write a report about a website. That is a tool, not a decision about you as a person with legal or similar consequences. So I make no automated decisions within the meaning of article 22 of the GDPR.

Changes

If something changes about the site or about how I handle data, I update this statement and put a new date on it. The current version is always here. This version is from 11 september 2026.

See also my terms and conditions.