Menu

Privacy Policy

Last updated: 7 August 2026

This Privacy Policy explains how we collect, use, and protect information when you use the Observa service ("Service"). Observa is operated by Bruno Macedo, an independent service provider established in Portugal.

1. Roles Under GDPR

Observa is the data controller for personal data used to manage accounts, authentication, communications, security, billing records, and operation of the Service.

Where a website you submit contains personal data, you are generally the controller of that data and, where applicable, Observa processes it on your documented instructions to provide the Service.

2. Data We Process

We process only the minimum technical data required to provide the Service and generate crawl reports.

This data may include:

  • URLs and links discovered during crawls
  • HTTP status codes
  • Response times and basic technical metrics
  • Pattern matches explicitly configured by the user

We do not store:

  • HTML source code
  • Page content or text
  • Images, media, or other content assets

3. Lawful Basis for Processing

Processing of data is based on:

  • Performance of a contract (Article 6(1)(b) GDPR)
  • Legitimate interest in providing technical website diagnostics

4. Personal Data on Crawled Websites

Websites submitted to the Service may incidentally contain personal data, such as names included in URLs.

You are responsible for ensuring that:

  • The crawling activity is lawful
  • Any required legal notices or consents are in place

The Service is not designed to profile individuals or extract personal content.

5. Data Retention

Crawl data is retained only for as long as necessary to provide reporting features or to comply with legal obligations.

You may delete crawl data directly via the Service or by contacting support.

You may permanently delete your account from account settings. Account deletion is immediate and irreversible: we remove your account profile, authentication data, sites, schedules, crawl history, local-agent access, and unused credits. Unused credits are forfeited and account deletion does not create a refund entitlement. If you later register with the same email address, it is a new account with a new account identifier and none of the deleted data or credits is restored.

After deletion, we retain only an anonymized Paddle purchase reference and the minimum accounting fields required for financial record keeping. These records are not linked to your account or email and are deleted after 10 years.

Deleted data can remain in access-controlled operational logs and database backups until those copies expire. We retain those operational copies for no more than 30 days.

6. Data Security

We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, or misuse. However, no system can be guaranteed to be completely secure.

7. Sharing of Data

We do not sell or share data with third parties, except where necessary to operate the Service (e.g. infrastructure providers) or where required by law.

8. Your Rights

Under GDPR, you have the right to:

  • Access your data
  • Request correction or deletion
  • Restrict or object to processing
  • Request data portability

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or website.

10. Contact

For questions regarding this Privacy Policy or data protection matters, contact:

[email protected]