Last updated: 14 August 2026
The controller for data processed through this website and in the course of our services is:
Can HaciogluEmail: contact@vibelessqa.com
We have not appointed a data protection officer, as we are not required to under Art. 37 GDPR and § 38 BDSG.
This site sets no cookies, uses no analytics, and loads no third-party scripts or fonts. Nothing is stored on your device and no profile is built about you.
The form on the homepage does not send anything to us. It opens your own email program with a pre-filled message that you review and send yourself. Until you press send in your own mail client, we receive nothing.
Our hosting provider records standard server log data when a page is requested: IP address, date and time, the file requested, referring URL, and browser and operating system identifiers. This is necessary to deliver the site and to detect abuse, and is processed on the basis of our legitimate interest under Art. 6(1)(f) GDPR. These logs are not merged with other data and are deleted by the provider on a short rolling basis.
When you email us, we process your address and the content of your message in order to reply, under Art. 6(1)(b) GDPR where the exchange concerns a contract, otherwise under Art. 6(1)(f). Enquiries that do not lead to an engagement are deleted after twelve months.
To carry out a QA engagement we process what you send us at intake: the application URL, test account credentials, a description of your critical user flows, sandbox payment keys where relevant, and any supporting context you provide. The legal basis is performance of our contract with you, Art. 6(1)(b) GDPR.
Running the check generates evidence: screenshots, screen recordings, browser console output and network logs from the tested application. Where your test environment contains personal data, that data may appear in this evidence. For this reason we ask that you provide test or seed data rather than production records, and we will say so again at intake.
We use a small number of service providers who process data on our behalf under Art. 28 GDPR data processing agreements: our website host, our email provider, and our invoicing software. Automated testing tools used during the breadth pass process the target application and the evidence generated from it.
Where a provider processes data outside the EU or EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell data, and we do not use your data or your findings to train machine learning models.
Findings from your engagement are confidential. We publish anonymised examples of the kinds of defects we encounter, but only where they cannot reasonably be traced back to a specific customer, and never with your name, URL, or identifying detail unless you have given separate written consent.
Under the GDPR you have the right to request access to your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you may withdraw it at any time with effect for the future.
To exercise any of these, email contact@vibelessqa.com. You also have the right to complain to a supervisory authority. The competent authority for us is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden.
We will update this notice when our processing changes. The date at the top reflects the current version.