Privacy Policy

How GA4audit (Wojciech Bednarski Data Wolves) processes personal data - in line with the GDPR.

Last updated: 1 June 2026

This is the English version of the Privacy Policy. The Controller is established in Poland and the Service is provided under Polish law, including the GDPR. In the event of any discrepancy between the English and Polish versions, the Polish version prevails.

Your privacy matters to us. In this Policy we explain who we are, in which situations, for what purpose, and to what extent we process personal data, to whom we transfer it, and what rights you have. We make every effort to process data lawfully, including in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR).

If you do not agree with this Policy, please do not use our Service. Exercising rights that result in preventing the processing of data to the extent necessary to provide the Service is equivalent to cancelling the Service.

1. Controller and contact

The controller of personal data is Wojciech Bednarski Data Wolves, with its registered office at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Tax ID): 7722307415, REGON: 382702660 (the Controller, we), operating the GA4audit web application available in the ga4audit.io and ga4audyt.pl domains (the Service or Application). Whenever we write "Controller", "we", "us", or "our" in this Policy, we mean the entity indicated above, which is also the Operator within the meaning of the Terms of Service.

You can contact us:

by email: contact@ga4audit.io (including on matters relating to personal data),
by post to the registered office address indicated above.

In your request, please provide: (i) the data the request concerns, (ii) a description of the matter, and (iii) the expected way to resolve it.

2. When we are a controller and when we are a processor

This distinction is important for understanding the role in which we process particular data.

We are the controller of your data if you are:

a person creating or operating an Account in the Service (a User who is a natural person, or a person acting on behalf of a User - e.g. an employee, contractor, or member of a governing body);
a person contacting us (email, form, chat);
a person representing a counterparty or designated as a contact.

In this respect, we ourselves determine the purposes and means of processing - the rules are described in the further part of this Policy.

We are not the controller of personal data that may be present in the User's Google Analytics 4 environment (GA4 Property) or on the scanned Website, and which the User makes available to us in connection with using the Service. The User remains the controller of such data. Such data - if it occurs at all - is entrusted to us for processing under a separate data processing agreement (DPA), the terms of which are available at https://ga4audit.io/dpa. We process it solely to provide the Service, on the documented instruction of the User arising from the Agreement. The feature for detecting potential personal data (PII) in GA4 data is signaling in nature and serves solely to indicate possible irregularities in the User's configuration.

3. Security

We make efforts to protect Users' privacy. We apply appropriate technical and organizational measures to protect data against loss, destruction, disclosure, access by unauthorized persons, and misuse. Persons authorized to process data are obliged to maintain confidentiality. We are not responsible for the privacy practices of websites linked from the Service.

4. What we do

We provide a Service consisting of the automated audit of Google Analytics 4 configuration and of the tagging of the User's Website. Within the Service, we analyze GA4 Property settings, verify tagging, detect configuration issues, and generate Reports with recommendations. The Service is provided in a software-as-a-service (SaaS) model. Our Users are primarily companies, agencies, and specialists. Details of providing the Service are set out in the Terms of Service.

5. For what purpose and on what basis we process data

The purpose and basis on which we process your data depends on how you use the Service.

a. Using the Service without registration. We process data to provide the functionality of the Service (browsing content, contact forms, chat, content adaptation). Data obtained via necessary and functional cookies is processed on the basis of our legitimate interest in ensuring the proper operation and personalization of the Service (Article 6(1)(f) GDPR). Data from analytical and marketing cookies is processed on the basis of your consent (Article 6(1)(a) GDPR). Details in the "Cookies" section.

b. Registration and provision of the Service. Using the Service requires Account registration (independently or using a Google account). We process the data provided at registration and the data necessary to operate the Account. The basis is the necessity to conclude and perform the Agreement (Article 6(1)(b) GDPR) and our legitimate interest in being able to establish, pursue, or defend claims (Article 6(1)(f) GDPR).

c. Connection with Google and access to Google Analytics data. To perform the Audit, you connect your Account with a Google account via the Google OAuth mechanism, granting us read-only access to the settings, reporting data and user-access information (the list of users who have access to the account/property) of your GA4 Property. We read user permissions solely to surface access-governance risks in the Audit (for example an excessive number of administrators); we never create, modify or remove any access, and we never modify the configuration of your GA4 Property. The use of data obtained via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements - we use such data solely to provide and improve the Service for you, we do not use it for advertising or sell it to third parties. You may withdraw this access at any time in the Account settings or in the Google account permissions panel. The Google access token obtained via OAuth is kept in your browser's local storage (localStorage) for the token's lifetime (approximately one hour) so the Audit can run without repeated sign-in. To perform the Audit, the token is sent over an encrypted (HTTPS) connection to our server, where it is used transiently and solely to read your GA4 Property configuration and reporting data through the Google Analytics API; it is not stored in our database or logs and is not otherwise persisted on our servers. It is cleared from your browser when you sign out or withdraw access. The basis for processing is the necessity to perform the Agreement (Article 6(1)(b) GDPR). GA4audit is an independent tool and is not affiliated with or endorsed by Google LLC; Google Analytics, GA4 and Google are trademarks of Google LLC.

d. Website scanning. Within the Audit, we automatically load the indicated Website in a browser running in automated (headless) mode and analyze its publicly available content (including the presence and configuration of tags). To measure Consent Mode, we may simulate interaction with the consent banner. You declare that you are authorized to commission the analysis of the given Website. The basis is the necessity to perform the Agreement (Article 6(1)(b) GDPR) and our legitimate interest in the proper provision of the Service (Article 6(1)(f) GDPR).

e. Payments. To process payments for paid Plans and issue invoices, we process billing data (including business name, address, Tax ID, transaction data). Payments are handled by the Payment Processor (Stripe), which independently processes your payment card data. The basis is the necessity to perform the Agreement (Article 6(1)(b) GDPR) and compliance with legal obligations, including tax and accounting obligations (Article 6(1)(c) GDPR).

f. Contact and support. Data provided in correspondence, forms, or chat is processed to handle the request and communicate with you, on the basis of our legitimate interest (Article 6(1)(f) GDPR).

g. Marketing. To the extent that we conduct marketing of our own services, the basis is our legitimate interest (Article 6(1)(f) GDPR), and in the case of sending commercial information electronically or contacting you by phone - your consent, which you may withdraw at any time.

h. Other purposes. We also process data to: establish, pursue, or defend claims; ensure security, detect and prevent abuse, and verify Accounts; monitor, test, and improve the Service; and comply with legal obligations (Article 6(1)(f) and (c) GDPR).

6. What data we process

Depending on the situation, we may process in particular:

first and last name, profession / job title;
business name, Tax ID, business address;
email address, phone number (if provided);
Account data and information about which features and Plans you use;
data necessary for billing and invoicing (transaction data handled by the Payment Processor);
technical and usage data: IP address, device and browser information, cookie identifiers, server logs, information about use of the Service;
data provided in correspondence and requests;
the content and scope of consents granted.

7. Data collected automatically

When using the Service, some data is collected automatically: usage data (including IP address, browser and system type and version, screen resolution, server log data) and information about how the Service is used, collected via cookies and similar technologies (details in the "Cookies" section). We use it to ensure the operation of the Service, to analyze traffic, and - on the basis of consent - for analytical and marketing purposes.

8. How long we retain data

The retention period depends on the purpose and basis of processing:

data processed on the basis of consent - until it is withdrawn;
data processed to perform the Agreement - for its duration or until the Account is deleted, and thereafter for the limitation period of claims;
data processed to comply with legal obligations (e.g. invoices) - for the period resulting from the regulations;
data processed on the basis of legitimate interest - until that interest ceases or an objection is effectively raised.

After the Service ends, we delete the User's data within 30 days, except for data whose retention is required by law. Before deletion, you may export your data available in the Application. After Account deletion, we retain a minimal technical record (email address, date and manner of deletion) - to prevent the Account from being re-created by delayed billing events and to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR) - for the limitation period of claims.

9. To whom we transfer data (recipients and sub-processors)

We share data with entities whose services we need to provide the Service and run our business, solely to the extent necessary for the given purpose. The main categories of recipients include infrastructure and tool providers, the Payment Processor, and - where necessary - providers of accounting, legal, and advisory services, as well as public authorities authorized under the regulations.

The current list of sub-processors includes in particular:

No.EntityRole / purposeProcessing location
1.Google Cloud / Firebase (Google)Hosting, database, authentication, application infrastructureEU (European region) / possible transfers to Google outside the EEA
2.Google - Google Analytics APIsPerforming the Audit (reading the User's GA4 data)Google, possibly outside the EEA
3.Google Tag Manager (Google)Tag management in the Service (analytics / marketing)Google, possibly outside the EEA
4.Google reCAPTCHA / App Check (Google)Protection against abuse and botsGoogle, possibly outside the EEA
5.Stripe Payments Europe, Ltd.Payment handlingEU (Ireland) / possible transfers outside the EEA
The list is informational and is updated in line with the actual state of implementation.

10. Transfers of data outside the European Economic Area

The Controller's server infrastructure is located in the European Union. However, the use of Google services (including infrastructure, Google Analytics APIs, Google Tag Manager, reCAPTCHA) and of the Payment Processor may involve the transfer of data outside the European Economic Area. In the absence of a European Commission decision confirming an adequate level of protection, transfers take place on the basis of standard contractual clauses (SCC) referred to in Article 46 GDPR, together with additional safeguards. You have the right to obtain a copy of your data transferred to a third country. The location of the Controller's servers in the EU does not guarantee that all data is processed solely within the EU.

11. Your rights

You have the following rights:

access to data and obtaining a copy of it;
rectification of incorrect or incomplete data;
erasure of data ("right to be forgotten") - subject to cases where its retention is necessary (e.g. to pursue claims or comply with legal obligations);
restriction of processing;
portability of data to another controller;
objection to processing based on legitimate interest (including to direct marketing and profiling for that purpose);
withdrawal of consent at any time - without affecting the lawfulness of processing before withdrawal;
complaint to the supervisory authority - the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

You may exercise your rights by sending a message to contact@ga4audit.io. Exercising rights is free of charge; in the case of manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse to act. We may ask you to confirm your identity. We respond to requests within one month (with the possibility of extension by two months in complex cases).

Automated decision-making. We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.

12. Voluntariness of providing data

Providing data is voluntary but in some cases necessary - e.g. to conclude the Agreement and create an Account, as well as to comply with legal obligations (where providing data is a statutory requirement). Failure to provide data necessary to provide the Service will make it impossible to use it.

13. Age

The Service is not intended for persons under 18 years of age, and we do not knowingly collect their data. If we become aware that a User is under 18, we will take steps to delete their data and restrict access to the Service.

14. Cookies

What cookies are. Cookies are small text files stored on your device, used among other things to ensure the operation of the Service, remember settings, and for analysis and personalization.

Types of cookies. In the Service we use:

necessary - required for the operation of the Service (including session and login handling, security); disabling them makes the Service inoperable;
functional - remembering selected settings and personalization;
analytical - used to analyze and produce statistics on use of the Service;
marketing - used to tailor and measure content and ads.

Basis and consent. We use necessary cookies on the basis of legitimate interest (Article 6(1)(f) GDPR). Analytical and marketing cookies - including those launched via Google Tag Manager - we use on the basis of your consent (Article 6(1)(a) GDPR), expressed and managed via the cookie settings panel. You may withdraw your consent at any time.

Providers of cookies and similar technologies:

ProviderType
ga4audit.io (Controller)necessary, functional
Google (Google Tag Manager)necessary / analytical / marketing (depending on configuration and consent)
Google (reCAPTCHA / App Check)necessary (security)
Google (Google Analytics)analytical (with consent)
Stripenecessary (payment handling and security)

Managing cookies. You can manage cookies via the cookie settings panel in the Service and via your browser settings - including blocking or deleting cookies. Restricting cookies may affect the operation of the Service. Instructions are available on browser support pages (Chrome, Firefox, Safari, Microsoft Edge, Opera).

15. Changes to the Privacy Policy

The Policy is reviewed on an ongoing basis and updated where necessary, in particular in the event of changes in regulations, the functionality of the Service, or the tools used. We inform of changes via the Service. This Policy enters into force on 1 June 2026.

This Policy forms an integral part of the Terms of Service.

Other documents

Didn't find an answer?

Write to us - we reply clearly and fast, including implementation questions.

Contact us