This Privacy Policy explains how Mesarthim labs GmbH (“we”, “us”, “controller”), Geerenstrasse 9b, CH-8157 Dielsdorf, Switzerland (UID/MWST: CHE-452.370.848 MWST), processes personal data when you use Sitescreens websites, dashboards, APIs, and related services (the “Service”). It should be read together with our Terms of Service.
Processing is governed primarily by the Swiss Federal Act on Data Protection (FADP; German: Datenschutzgesetz, DSG) and its ordinance. Where the EU/EEA General Data Protection Regulation (GDPR) applies to you in addition (for example if you are in the EEA), we also observe those requirements to the extent they are mandatory.
1. Controller
The data controller responsible for processing under the FADP is:
Mesarthim labs GmbH
Geerenstrasse 9b
CH-8157 Dielsdorf
Switzerland
UID/MWST: CHE-452.370.848 MWST
Email: contact@sitescreens.com
We have not appointed a data protection representative abroad unless required for a specific offering. Contact the address above for privacy requests.
2. Personal data we process
Account and contact data
When you register or join a team: name, email address, password hash (we do not store plaintext passwords), organization name, role, and related profile fields. If you sign in with a third-party identity provider (for example GitHub or Google), we receive identifiers and profile details those providers share with us.
Billing data
Paid plans are processed by our payment provider (for example Stripe). We receive subscription status, plan identifiers, invoicing metadata, and limited payment references. Card numbers are handled by the payment provider and are not stored on our servers. Swiss VAT (MWST) details may appear on invoices where applicable.
Usage and job data
To operate the Service we process job inputs and outputs you submit or generate: URLs, capture options, overlays, webhook destinations, credit ledger entries, API key metadata (hashed secrets), job status, error messages, and artifacts such as screenshots, PDFs, markdown, video, and related hashes. Public demo captures may be associated with a shared demo organization rather than your personal account. Job content may include personal data if it appears on pages you ask us to capture; you are responsible for having a lawful basis to submit such requests.
Device and log data
We automatically process technical data such as IP address, user agent, request paths, approximate timestamps, and diagnostic events needed for security, rate limiting, abuse prevention, and reliability.
3. Purposes and justification
Under the FADP we process personal data lawfully and in good faith, for stated purposes, and only to the extent proportionate. We process data for the following purposes:
- Contract performance — provide, operate, authenticate, and support the Service; manage teams and API keys; meter credits and deliver artifacts
- Billing and accounting — process subscriptions, invoices, taxes, and payment status
- Security and abuse prevention — protect accounts, detect misuse, debug incidents, and defend legal claims
- Product communications — send service emails (invitations, security notices, billing receipts); optional marketing only where permitted (consent or soft-opt-in rules under Swiss unfair-competition rules, as applicable)
- Legal obligations — comply with Swiss law, respond to authorities, and keep required business records
- Overriding interests — improve reliability and features in a way that does not outweigh your privacy interests, where we rely on this justification
We do not sell personal data. We do not use Customer Content to train general-purpose public AI models. We do not make decisions that produce legal effects solely by automated means without appropriate human involvement, except as strictly necessary to operate security and fraud controls.
4. Disclosure to third parties
We disclose personal data only as needed, in particular to:
- Processors (Auftragsbearbeiter) that host infrastructure, process payments, send email, store artifacts, or provide authentication — bound by contracts requiring them to process data only on our instructions and to protect it
- Team members in your organization, according to roles you configure
- Recipients you choose when you create share links or send webhooks to destinations you control
- Authorities and courts when required by Swiss or other applicable law, or to protect rights, safety, and security
- Successors in a merger, acquisition, or asset transfer, under appropriate confidentiality
5. Cross-border disclosure
Personal data may be processed in Switzerland and in other countries where we or our processors operate (including the EEA and, depending on the provider, the United States or other regions).
Where we disclose personal data abroad, we do so in line with the FADP: either to a state with an adequate level of protection as recognized under Swiss law, or with appropriate safeguards (for example standard contractual clauses or comparable contractual protections), or another justification permitted by the FADP (such as contract performance with you, your consent, or establishment/exercise/defense of legal claims). You may request information about the safeguards used for a specific transfer via the contact details below.
6. Cookies and similar technologies
We use session cookies or similar technologies that are necessary to keep you signed in and to remember preferences such as theme. These are required for the Service to function. We do not use third-party advertising cookies on the core product surfaces described here. Where non-essential cookies are introduced later, we will provide appropriate information and choices as required by Swiss law.
7. Retention
We retain personal data only as long as needed for the purposes stated above, including:
- Account data — while the account is active, then for a limited period for backup, dispute handling, and statutory retention (for example commercial and tax records)
- Job artifacts and logs — according to product settings, plan features (including immutable forensic artifacts), security needs, and operational backups
- Billing records — for the periods required under Swiss commercial and tax law
You may delete eligible jobs and artifacts from the dashboard where the product allows. After deletion, residual copies may remain in encrypted backups for a limited time until rotated.
8. Security
We apply technical and organizational measures appropriate to the risk, including HTTPS in transit, hashed API keys, access controls, and least-privilege practices. No method of transmission or storage is fully secure. Please protect passwords and keys and limit team access appropriately.
9. Your rights under Swiss law
Subject to the conditions and exceptions in the FADP, you may:
- Request information about whether we process your personal data and receive related details (access right)
- Request correction of inaccurate personal data
- Request deletion or restriction where the FADP provides for it (for example when data is no longer needed or was unlawfully processed)
- Object to processing in specific cases provided by law
- Data portability / delivery of certain data in a common electronic format where the FADP grants that right
- Withdraw consent where processing is based on consent, without affecting prior lawful processing
You can update much of your account information in Settings. For other requests, email contact@sitescreens.com and include enough detail for us to verify your identity and respond. We may refuse or limit requests where the FADP allows (for example trade secrets, rights of others, or disproportionate effort).
You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB): www.edoeb.admin.ch. If the GDPR applies to you, you may additionally contact your local supervisory authority.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will take appropriate steps under Swiss law.
11. Changes
We may update this Privacy Policy from time to time. The effective date above will change when we post revisions. For material changes we will provide additional notice where appropriate. Continued use of the Service after an update means you acknowledge the revised policy.
12. Contact
Mesarthim labs GmbH
Geerenstrasse 9b
CH-8157 Dielsdorf
Switzerland
UID/MWST: CHE-452.370.848 MWST
Privacy questions or data-subject requests: contact@sitescreens.com.