Version v1.0 · Controller: TechBiz Hub L.L.C-FZ
Privacy Policy — AVE Website Auditor
Operator: TechBiz Hub L.L.C-FZ · Jurisdiction: AE-MEYDAN-FZ · Version: v1.0 · Effective from: 12 June 2026
1. Who we are
This policy explains how TechBiz Hub L.L.C-FZ (registration no. 104935796300003, registered seat: Meydan Grandstand, 6th floor SHARED DESK, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates) processes personal data in connection with AVE Website Auditor ("AVE"), the website-auditing service at app.techbiz.ae and ave.techbiz.ae. We act as controller of the personal data described here. Our data-protection contact is reachable at dpo@4pro.io.
2. Where we are established — note for EEA/UK visitors
TechBiz Hub L.L.C-FZ is established in AE-MEYDAN-FZ, outside the EEA. If you are in the EEA or UK and the GDPR applies to our processing of your data (Art. 3(2) GDPR), we apply the safeguards described in this policy, and you keep all of the rights listed in Section 8 — regardless of where we are established. Where we transfer EEA-origin data to recipients outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, as noted per recipient below.
3. Audited websites — our core processing
When a user submits a URL, our platform crawls the website and produces an audit. We act as controller of the audit artifacts we store.
- Data categories — the submitted URL; crawled page content; full-page screenshots; cookie and consent-banner scan results; technical findings and scores. Audited pages may incidentally contain personal data of third parties (e.g. names, email addresses, or photos visible on the site).
- Purpose — producing the audit report for the requesting user. Audit artifacts are used only to deliver the report — never for advertising or for profiling the third parties whose data appears on audited pages.
- Lawful basis — our and the requesting user's legitimate interest (Art. 6(1)(f) GDPR) in assessing the quality, security, and compliance of a website, combined with the requesting user's warranty that they are authorized to request the audit (see our Terms of Service).
- Information of third parties — individually informing every person whose data incidentally appears on a scanned public page would involve disproportionate effort (Art. 14(5)(b) GDPR). This policy serves as the public information about that processing. If your data appears in an audit artifact, you can exercise the rights in Section 8 at any time.
4. What we collect from you, and why
- Website submission — the URL you submit, plus technical request data (IP address, browser/user-agent, timestamps). Basis: legitimate interest in operating and securing the Service.
- Unlock / checkout — your email address, an optional first name, and a consent record (your choices, timestamp, and IP). If you tick the optional marketing opt-in, we send occasional product communications; basis: consent, which you can withdraw at any time via the unsubscribe link in each email or by writing to dpo@4pro.io. Delivery of the report itself: performance of a contract / steps prior to a contract.
- Payments — handled by Stripe via our group Checkout Broker (Section 5); we receive payment confirmation and invoicing data, not card numbers. Basis: contract and legal (tax) obligations.
- B2B sales and contracts — business contact data, sales conversations, contracts and e-signatures, for follow-up and contract management. Basis: legitimate interest (B2B relationship management) and contract.
- Communications — email and, where used, WhatsApp message logs related to your enquiries or projects. Basis: legitimate interest / contract.
- Technical and security logs — server and application logs used to keep the Service secure and reliable. Basis: legitimate interest.
We do not require you to create an account or password, and we collect no special categories of data.
5. Recipients and processors
We share personal data only as needed to run the Service, with the following categories of recipients:
- Hosting provider — our platform and audit artifacts are hosted on servers located in the EU/EEA. Role: processor. EEA-origin data remains in the EEA at this layer.
- Stripe — payments are executed via Stripe, with TechBiz Hub L.L.C-FZ as the merchant of record; the checkout session is initiated through our group's central payment infrastructure on our behalf. Stripe processes card data under its own terms; transfers by Stripe outside the EEA are covered by Stripe's safeguards (Standard Contractual Clauses / adequacy).
- AI providers (e.g. Google Gemini, Anthropic, Groq) — used solely for audit analysis and recommendations; under our agreements and their applicable API terms, they are not permitted to use the submitted data to train their models. Role: processors. Where they process EEA-origin data outside the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
- Meta / WhatsApp — only where we communicate with you over WhatsApp in B2B sales contexts. Transfers outside the EEA are covered by Meta's Standard Contractual Clauses / adequacy mechanisms.
- Transactional email provider — delivers report links, receipts, and service emails. Role: processor; EEA-origin data is protected by Standard Contractual Clauses or adequacy where processed outside the EEA.
We do not sell personal data.
6. Retention
- Leads and contact data — 24 months from the last interaction.
- Audit reports and screenshots — 12 months, then deleted or anonymized.
- Contracts and billing records — for statutory retention periods (up to 10 years where tax law requires).
- Communication logs (email/WhatsApp) — 24 months.
- Security and technical logs — 12 months.
7. Automated analysis (AI) — transparency
Audit scores and recommendations are AI-assisted and advisory. They produce no legal or similarly significant effect on you — they are inputs to your own decisions about your website. You may request human review of any audit result at dpo@4pro.io.
8. Your rights
Wherever you are located, we grant you the following rights over your personal data: access, rectification, erasure, restriction of processing, data portability, objection (including to processing based on legitimate interest), and withdrawal of consent at any time (without affecting prior processing).
To exercise any right, email dpo@4pro.io. We respond within one month; for complex or numerous requests this may be extended by two further months, in which case we will tell you within the first month. If you are unhappy with our response, you may lodge a complaint with the supervisory authority of your country of residence.
9. Security
We apply appropriate technical and organizational measures, including encryption in transit, access controls, and segregated infrastructure, proportionate to the risks of the processing described above.
10. Children
The Service is intended for businesses and professionals and is not directed at children under 16. We do not knowingly collect their data.
11. Changes and contact
We may update this policy; the current version is always available at https://legal.knowbest.ro/en/privacy/ave. See also our Terms of Service and Cookie Policy. Questions: dpo@4pro.io, or by post to TechBiz Hub L.L.C-FZ, Meydan Grandstand, 6th floor SHARED DESK, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.
Version v1.0 · Effective from 12 June 2026