Sub-processors
The third parties that receive data from SiteVigilante, what each one receives, and why.
Version 1.0 · in effect from 30 August 2026 · TEAMDIGITAL BV, Zaventem, Belgium
Two lists. The first is everyone we send data to, and what each one gets. The second is where the platform itself runs, which is a different relationship and is easy to leave off a page like this by accident. Nothing goes anywhere else.
This page is generated from the application's own configuration, so it changes when the product does.
Recipients
Stripe
Subscription billing.
- What it receives
- Your agency name, billing email address, payment details you enter on Stripe's own form, and the number of websites you have connected. We never see or store a card number.
- Where it runs
- Ireland and the United States.
Mailgun EU
Sending email: alerts, digests, invites, password resets and verification.
- What it receives
- The recipient address and the contents of the message, which can name your websites and what happened on them.
- Where it runs
- European Union.
Anthropic
Explaining an update that failed or was rolled back, in plain language, and writing the analysis in a Growth Scan you have bought.
- What it receives
- The name and type of the plugin or theme, the version it moved between, what the outcome was, the WordPress and PHP versions, the active theme, how many plugins are installed, the last steps of the run, and an excerpt of the error text from the website. Error text is written by the website and can contain a file path or a person's name. Your website's content, its credentials, its database and anything about its visitors are not sent.
- What causes it to be sent
- Running an update that then fails or is rolled back, which sends this automatically; pressing Explain on an entry in your update history; or buying a Growth Scan and confirming it for a named website. All three are actions you take. Nothing is sent for an update that succeeds, and no scan runs without an explicit purchase and an explicit confirmation.
- While it is not configured
- Nothing is sent unless an Anthropic key is configured on this installation by the operator. Without one the explanation is simply unavailable and no request leaves the platform.
- Where it runs
- United States.
Measuring how fast a page loads and how it behaves on a phone, through PageSpeed Insights.
- What it receives
- The address of the page being measured, and nothing else. Google then loads that page itself, over the public internet, exactly as any visitor would. We send no content from the website, nothing about its visitors, and nothing that identifies you.
- What causes it to be sent
- Two things you do, and nothing else. Pressing Measure on a website, or starting a performance measurement across your estate. And buying or spending a credit on a Growth Scan for a website and confirming it: a scan measures the page on a phone and on a desktop. Nothing is measured on a schedule and no scan runs without that explicit confirmation.
- While it is not configured
- PageSpeed answers without a key, at a lower rate, so this one is reachable on any installation. It is still only reached by one of the two actions above. If it cannot be reached, the scan reports that part as not measured rather than as a score of zero.
- Built, but not yet reachable
- Search Console and analytics are built to be read here and are NOT YET REACHABLE: no website can be connected to a Search Console or analytics property in this product, so no property is named, no figures are requested, and neither API has been contacted. When a connection becomes possible it will be one you make yourself, inside your own Google account, with read-only access you can withdraw there.
- Where it runs
- United States.
RDAP bootstrap (rdap.org), and through it the registry for each domain
Reading the published expiry date of a website's domain name (T-52), so an agency is warned before a domain lapses and takes the website and its email with it.
- What it receives
- The domain name of one of your websites, and nothing else. No address inside it, no account, and nothing saying which agency asked.
- Where it runs
- The registry that operates each top-level domain. Location varies by domain.
WordPress.org
Looking up whether a plugin is still published and what it requires.
- What it receives
- The slug of a plugin installed on one of your websites. No address, no account and nothing identifying which website it came from.
- Where it runs
- United States.
Infrastructure
Hetzner Online GmbH
Hosting the SiteVigilante platform: the application server, its database, its queue and its uploaded files.
- What it holds
- Everything SiteVigilante stores. The server holds the database, so every fact on this page that we keep rather than send is kept here.
- Where it runs
- Germany.
Vulnerability matching is not on either list, and that is deliberate. The public CVE list is copied to our own servers and every comparison happens there, so no website, no component inventory and no request about your estate is sent to that source.
These lists are also Annex B of the Data Processing Agreement. What each recipient means for your own data is described in the Privacy Policy.
Questions, or a request about your data, go to support@sitevigilante.com.