Last updated: 1 June 2026
This is the English version of the Privacy Policy. The Controller is established in Poland and the Service is provided under Polish law, including the GDPR. In the event of any discrepancy between the English and Polish versions, the Polish version prevails.
Your privacy matters to us. In this Policy we explain who we are, in which situations, for what purpose, and to what extent we process personal data, to whom we transfer it, and what rights you have. We make every effort to process data lawfully, including in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR).
If you do not agree with this Policy, please do not use our Service. Exercising rights that result in preventing the processing of data to the extent necessary to provide the Service is equivalent to cancelling the Service.
1. Controller and contact
The controller of personal data is Wojciech Bednarski Data Wolves, with its registered office at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Tax ID): 7722307415, REGON: 382702660 (the Controller, we), operating the GA4audit web application available in the ga4audit.io and ga4audyt.pl domains (the Service or Application). Whenever we write "Controller", "we", "us", or "our" in this Policy, we mean the entity indicated above, which is also the Operator within the meaning of the Terms of Service.
You can contact us:
In your request, please provide: (i) the data the request concerns, (ii) a description of the matter, and (iii) the expected way to resolve it.
2. When we are a controller and when we are a processor
This distinction is important for understanding the role in which we process particular data.
We are the controller of your data if you are:
In this respect, we ourselves determine the purposes and means of processing - the rules are described in the further part of this Policy.
We are not the controller of personal data that may be present in the User's Google Analytics 4 environment (GA4 Property) or on the scanned Website, and which the User makes available to us in connection with using the Service. The User remains the controller of such data. Such data - if it occurs at all - is entrusted to us for processing under a separate data processing agreement (DPA), the terms of which are available at https://ga4audit.io/dpa. We process it solely to provide the Service, on the documented instruction of the User arising from the Agreement. The feature for detecting potential personal data (PII) in GA4 data is signaling in nature and serves solely to indicate possible irregularities in the User's configuration.
3. Security
We make efforts to protect Users' privacy. We apply appropriate technical and organizational measures to protect data against loss, destruction, disclosure, access by unauthorized persons, and misuse. Persons authorized to process data are obliged to maintain confidentiality. We are not responsible for the privacy practices of websites linked from the Service.
4. What we do
We provide a Service consisting of the automated audit of Google Analytics 4 configuration and of the tagging of the User's Website. Within the Service, we analyze GA4 Property settings, verify tagging, detect configuration issues, and generate Reports with recommendations. The Service is provided in a software-as-a-service (SaaS) model. Our Users are primarily companies, agencies, and specialists. Details of providing the Service are set out in the Terms of Service.
5. For what purpose and on what basis we process data
The purpose and basis on which we process your data depends on how you use the Service.
a. Using the Service without registration. We process data to provide the functionality of the Service (browsing content, contact forms, chat, content adaptation). Data obtained via necessary and functional cookies is processed on the basis of our legitimate interest in ensuring the proper operation and personalization of the Service (Article 6(1)(f) GDPR). Data from analytical and marketing cookies is processed on the basis of your consent (Article 6(1)(a) GDPR). Details in the "Cookies" section.
b. Registration and provision of the Service. Using the Service requires Account registration (independently or using a Google account). We process the data provided at registration and the data necessary to operate the Account. The basis is the necessity to conclude and perform the Agreement (Article 6(1)(b) GDPR) and our legitimate interest in being able to establish, pursue, or defend claims (Article 6(1)(f) GDPR).
c. Connection with Google and access to Google Analytics data. To perform the Audit, you connect your Account with a Google account via the Google OAuth mechanism, granting us read-only access to the settings, reporting data and user-access information (the list of users who have access to the account/property) of your GA4 Property. We read user permissions solely to surface access-governance risks in the Audit (for example an excessive number of administrators); we never create, modify or remove any access, and we never modify the configuration of your GA4 Property. The use of data obtained via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements - we use such data solely to provide and improve the Service for you, we do not use it for advertising or sell it to third parties. You may withdraw this access at any time in the Account settings or in the Google account permissions panel. The Google access token obtained via OAuth is kept in your browser's local storage (localStorage) for the token's lifetime (approximately one hour) so the Audit can run without repeated sign-in. To perform the Audit, the token is sent over an encrypted (HTTPS) connection to our server, where it is used transiently and solely to read your GA4 Property configuration and reporting data through the Google Analytics API; it is not stored in our database or logs and is not otherwise persisted on our servers. It is cleared from your browser when you sign out or withdraw access. The basis for processing is the necessity to perform the Agreement (Article 6(1)(b) GDPR). GA4audit is an independent tool and is not affiliated with or endorsed by Google LLC; Google Analytics, GA4 and Google are trademarks of Google LLC.
d. Website scanning. Within the Audit, we automatically load the indicated Website in a browser running in automated (headless) mode and analyze its publicly available content (including the presence and configuration of tags). To measure Consent Mode, we may simulate interaction with the consent banner. You declare that you are authorized to commission the analysis of the given Website. The basis is the necessity to perform the Agreement (Article 6(1)(b) GDPR) and our legitimate interest in the proper provision of the Service (Article 6(1)(f) GDPR).
e. Payments. To process payments for paid Plans and issue invoices, we process billing data (including business name, address, Tax ID, transaction data). Payments are handled by the Payment Processor (Stripe), which independently processes your payment card data. The basis is the necessity to perform the Agreement (Article 6(1)(b) GDPR) and compliance with legal obligations, including tax and accounting obligations (Article 6(1)(c) GDPR).
f. Contact and support. Data provided in correspondence, forms, or chat is processed to handle the request and communicate with you, on the basis of our legitimate interest (Article 6(1)(f) GDPR).
g. Marketing. To the extent that we conduct marketing of our own services, the basis is our legitimate interest (Article 6(1)(f) GDPR), and in the case of sending commercial information electronically or contacting you by phone - your consent, which you may withdraw at any time.
h. Other purposes. We also process data to: establish, pursue, or defend claims; ensure security, detect and prevent abuse, and verify Accounts; monitor, test, and improve the Service; and comply with legal obligations (Article 6(1)(f) and (c) GDPR).
6. What data we process
Depending on the situation, we may process in particular:
7. Data collected automatically
When using the Service, some data is collected automatically: usage data (including IP address, browser and system type and version, screen resolution, server log data) and information about how the Service is used, collected via cookies and similar technologies (details in the "Cookies" section). We use it to ensure the operation of the Service, to analyze traffic, and - on the basis of consent - for analytical and marketing purposes.
8. How long we retain data
The retention period depends on the purpose and basis of processing:
After the Service ends, we delete the User's data within 30 days, except for data whose retention is required by law. Before deletion, you may export your data available in the Application. After Account deletion, we retain a minimal technical record (email address, date and manner of deletion) - to prevent the Account from being re-created by delayed billing events and to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR) - for the limitation period of claims.
9. To whom we transfer data (recipients and sub-processors)
We share data with entities whose services we need to provide the Service and run our business, solely to the extent necessary for the given purpose. The main categories of recipients include infrastructure and tool providers, the Payment Processor, and - where necessary - providers of accounting, legal, and advisory services, as well as public authorities authorized under the regulations.
The current list of sub-processors includes in particular:
| No. | Entity | Role / purpose | Processing location |
|---|---|---|---|
| 1. | Google Cloud / Firebase (Google) | Hosting, database, authentication, application infrastructure | EU (European region) / possible transfers to Google outside the EEA |
| 2. | Google - Google Analytics APIs | Performing the Audit (reading the User's GA4 data) | Google, possibly outside the EEA |
| 3. | Google Tag Manager (Google) | Tag management in the Service (analytics / marketing) | Google, possibly outside the EEA |
| 4. | Google reCAPTCHA / App Check (Google) | Protection against abuse and bots | Google, possibly outside the EEA |
| 5. | Stripe Payments Europe, Ltd. | Payment handling | EU (Ireland) / possible transfers outside the EEA |
The list is informational and is updated in line with the actual state of implementation.
10. Transfers of data outside the European Economic Area
The Controller's server infrastructure is located in the European Union. However, the use of Google services (including infrastructure, Google Analytics APIs, Google Tag Manager, reCAPTCHA) and of the Payment Processor may involve the transfer of data outside the European Economic Area. In the absence of a European Commission decision confirming an adequate level of protection, transfers take place on the basis of standard contractual clauses (SCC) referred to in Article 46 GDPR, together with additional safeguards. You have the right to obtain a copy of your data transferred to a third country. The location of the Controller's servers in the EU does not guarantee that all data is processed solely within the EU.
11. Your rights
You have the following rights:
You may exercise your rights by sending a message to contact@ga4audit.io. Exercising rights is free of charge; in the case of manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse to act. We may ask you to confirm your identity. We respond to requests within one month (with the possibility of extension by two months in complex cases).
Automated decision-making. We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.
12. Voluntariness of providing data
Providing data is voluntary but in some cases necessary - e.g. to conclude the Agreement and create an Account, as well as to comply with legal obligations (where providing data is a statutory requirement). Failure to provide data necessary to provide the Service will make it impossible to use it.
13. Age
The Service is not intended for persons under 18 years of age, and we do not knowingly collect their data. If we become aware that a User is under 18, we will take steps to delete their data and restrict access to the Service.
14. Cookies
What cookies are. Cookies are small text files stored on your device, used among other things to ensure the operation of the Service, remember settings, and for analysis and personalization.
Types of cookies. In the Service we use:
Basis and consent. We use necessary cookies on the basis of legitimate interest (Article 6(1)(f) GDPR). Analytical and marketing cookies - including those launched via Google Tag Manager - we use on the basis of your consent (Article 6(1)(a) GDPR), expressed and managed via the cookie settings panel. You may withdraw your consent at any time.
Providers of cookies and similar technologies:
| Provider | Type |
|---|---|
| ga4audit.io (Controller) | necessary, functional |
| Google (Google Tag Manager) | necessary / analytical / marketing (depending on configuration and consent) |
| Google (reCAPTCHA / App Check) | necessary (security) |
| Google (Google Analytics) | analytical (with consent) |
| Stripe | necessary (payment handling and security) |
Managing cookies. You can manage cookies via the cookie settings panel in the Service and via your browser settings - including blocking or deleting cookies. Restricting cookies may affect the operation of the Service. Instructions are available on browser support pages (Chrome, Firefox, Safari, Microsoft Edge, Opera).
15. Changes to the Privacy Policy
The Policy is reviewed on an ongoing basis and updated where necessary, in particular in the event of changes in regulations, the functionality of the Service, or the tools used. We inform of changes via the Service. This Policy enters into force on 1 June 2026.
This Policy forms an integral part of the Terms of Service.