wgrin.org · Privacy
Privacy policy
How wgrin.org and WGRIN Verify process personal data. Effective 3 October 2026.
1. Controller
The controller is Michal Rafaj, IČO 23605839, Kanice 119, 664 01 Kanice, Czech Republic (legal notice). Contact for all privacy matters: [email protected].
2. What we process, why, and for how long
Visiting the websites
When you visit wgrin.org, app.wgrin.org or api.wgrin.org, your IP address, the requested address, the time and your browser's user agent are processed to deliver the pages and protect them against abuse (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Logs of app.wgrin.org and api.wgrin.org are kept for 30 days; our hosting and content-delivery providers (see below) keep their own operational logs under their terms.
Cookies and analytics
Technical cookies keep the site working and secure: wgrin_consent remembers your cookie choice
for 180 days; Cloudflare sets security cookies (for example __cf_bm) and Turnstile verifies that a
form is submitted by a person; app.wgrin.org uses sign-in and form-protection cookies. These are necessary and
need no consent.
Analytics cookies (Google Analytics 4: _ga, _ga_*) and marketing signals are used only
with your consent where the law requires it, including the EU/EEA, the United Kingdom and Switzerland (legal basis:
consent, Art. 6(1)(a) GDPR). Before consent, Google's tag sends only cookieless signals. Elsewhere they are on by
default and can be switched off. You can change or withdraw your choice at any time in
Cookie settings at the bottom of every page.
Google Analytics keeps user-level and event-level data (data linked to analytics cookies or identifiers) for 14 months. Each new visit by the same browser restarts this period, so for returning visitors the data is kept until 14 months after their most recent activity. Aggregated reports that do not identify individual users are not subject to this period. Withdrawing consent in Cookie settings removes the analytics cookies from your browser, so later visits can no longer be linked to earlier ones.
Website checks (wgrin.org/verify)
When you check a domain, we store the domain and the technical results. Public check results are deleted after 30 days; checks of organisation domains after 90 days. Your IP address is never stored; it is turned into a keyed, one-way hash used only to limit how many checks one visitor can run (legitimate interest). Cloudflare Turnstile protects the form against automated abuse.
Accounts (app.wgrin.org)
For an account we process your e-mail address, a password hash, your two-factor authentication settings if you enable them, your memberships of organisations and your account activity (legal basis: performance of the contract, Art. 6(1)(b) GDPR). Account data is kept until you delete your account. We send e-mails needed for the account (confirmation, password reset) through Microsoft 365.
Organisation profiles, claims and domain verification
Organisation profiles describe organisations, not people. When you claim a domain, we record the claim and the verification checks of that domain (kept for 180 days; verification tokens of closed claims are erased after 90 days). Profile content you submit is published as part of the organisation's public profile.
Audit log
Security-relevant actions (for example profile changes, domain claims and verification, membership changes and requested checks) are recorded with the acting account and a hashed IP address to keep the service accountable and secure (legitimate interest). When you delete your account, your entries are anonymised.
Website discovery
When this feature is available, members of an organisation can ask WGRIN to read the organisation's own public website and suggest profile information. WGRIN reads a small number of public pages of that domain; e-mail addresses and phone numbers are removed before anything else happens. Public website content submitted for discovery is processed by Azure OpenAI (Microsoft) within the Azure EU Data Boundary. We store only the page addresses, page titles, short quoted excerpts and the suggestions, for 180 days (unsuccessful runs: 30 days). Nothing is added to a profile unless a member accepts it.
Contacting us
If you write to us, we use your message and address to answer and keep the correspondence as long as needed for that purpose.
3. Recipients and processors
- Cloudflare: content delivery, security and Turnstile for all sites.
- Active24 (Czech Republic): hosting of wgrin.org and its database.
- Microsoft Azure (region Sweden Central): hosting of app.wgrin.org and api.wgrin.org, the database and logs; Azure OpenAI for website discovery (EU Data Boundary).
- Microsoft 365: e-mail.
- Google: Google Analytics, only as described above.
Some of these providers are established outside the EU or may access data from outside the EU; such transfers rely on an adequacy decision (including the EU-U.S. Data Privacy Framework) or on standard contractual clauses. We do not sell personal data.
4. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting earlier processing. Write to [email protected]. You can also lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (uoou.gov.cz).
5. Automated decisions
We make no decisions with legal or similarly significant effects based solely on automated processing. Website checks report technical observations; discovery suggestions are reviewed by people before anything is used.
6. Changes
We update this policy when our processing changes. The effective date above shows the current version.