StandingCheck watches public professional registers. It is not a clinical system and it never touches claimant information. This page says exactly what we hold, why we are allowed to hold it, who else sees it, and how to make us delete it.
The controller of the personal data described here, within the meaning of Article 4(7) GDPR, is:
Eric de Zwart, sole proprietor (Einzelunternehmen), Austria, European Union.
Contact: [email protected]
StandingCheck is the trading name of that business. There is no separate legal entity behind it. We have not appointed a data protection officer; Article 37 GDPR does not require one at our size and scope of processing, and correspondence to the address above reaches the controller directly.
The form on our home page asks for your name, work email address and firm. Nothing else is captured — no hidden fields, no fingerprinting, no IP-based enrichment.
One thing about that form deserves stating rather than leaving to be discovered: the message is delivered to us as a Telegram message, because a notification that reaches a person within a minute is worth more to you than a record sitting in a database nobody checks. That means Telegram FZ LLC processes it in transit, and it stays in our Telegram history until we clear it. If you would rather that not happen, email [email protected] directly instead — our mail runs on our own servers and does not pass through Telegram.
Legal basis: Article 6(1)(b) GDPR — steps taken at your request before entering a contract. We keep enquiries for up to 12 months, and delete on request at any time.
The name, business email address and firm of the person who subscribes, plus whatever is written in emails between us. Held to provide the service and to answer you. Legal basis: Article 6(1)(b) GDPR — performance of the contract you entered into.
To watch a credential we need to know whose credential it is. That means the examiner's name, professional licence or registration numbers, the issuing state or board, and where relevant an NPI. This is personal data about a third party — the physician — and we treat it as such.
That the data is already public does not by itself settle the balance, and we do not claim that it does. It answers whether the processing is possible at all, not whether it is proportionate here. So, the rest of the reasoning, stated so it can be argued with:
We do not get examiner details from the examiner. They come from the client firm and from public registers. That makes this Article 14 processing, not Article 13, and the duty to inform sits with us. It is not discharged by hoping the right person happens to visit this page.
Writing individually to every examiner on every panel would, in our judgement, be disproportionate under Article 14(5)(b) — we hold no contact details for them, and obtaining some would mean collecting more of their personal data than the service needs in order to tell them we hold less. Article 14(5)(b) requires appropriate measures instead of silence. Ours, concretely:
Subscriptions are sold under Stripe Managed Payments. Link, LLC acts as merchant of record, so it — not us — collects and holds the payment instrument, the billing address and the tax data, and it issues the receipt. We receive from Stripe only what we need to run a subscription: your email address, country, subscription status, and the amount and date of each payment. Full card numbers are never transmitted to us and we could not retrieve them if we wanted to. Legal basis: Article 6(1)(b), and Article 6(1)(c) for the transaction records Austrian tax law requires us to keep.
Our website is served by Cloudflare, and our mail passes through servers we operate in Germany. Both keep short-lived connection logs — IP address, timestamp, requested resource — for security and abuse prevention. Legal basis: Article 6(1)(f), our legitimate interest in a service that stays up and is not abused.
Two things about how the service actually runs, which we would rather state plainly than bury.
No decision that produces a legal or similarly significant effect on anyone is made solely by automated means within the meaning of Article 22. An alert tells a human being to go and look; it decides nothing.
| Processor | What for | Where |
|---|---|---|
| Stripe, Inc. / Link, LLC | Payments, merchant of record, tax | US & IE |
| Cloudflare, Inc. | Website hosting and CDN | US, EU edge |
| Hetzner Online GmbH | Servers and mail relay | Germany |
| Anthropic PBC | Automated handling of correspondence and setup | US |
| Telegram FZ LLC | Delivery of website enquiry notifications | UAE / global |
That is the complete list. We add no one to it without updating this page. Beyond it, we disclose personal data only where a law or a court obliges us to.
Transfers outside the EEA. Stripe, Cloudflare and Anthropic are United States companies. Those transfers rest on the European Commission's Standard Contractual Clauses incorporated into each provider's data processing agreement, and where applicable on the provider's certification under the EU–US Data Privacy Framework.
Under Articles 15 to 22 GDPR you may ask us for a copy of your data, correct it, have it erased, restrict or object to how we use it, and receive it in a portable form. Where we rely on legitimate interest — which includes every examiner record we hold — you have an unconditional right to object under Article 21 and we will stop unless we can show compelling grounds that override your interests.
Write to [email protected]. We answer within 30 days and we do not charge for it. An examiner who is on a client's panel may write to us directly — you do not need to go through the firm, and we will not require you to.
If we handle it badly you may complain to a supervisory authority. Ours is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria — [email protected]. You may also complain to the authority where you live or work.
Data in transit is encrypted (TLS, and authenticated SMTP with DKIM and SPF on our mail). Data at rest sits on encrypted volumes on servers we control. Access is limited to the controller and to the processors listed above. We are a small operation and we do not claim a certification we do not hold: we have no SOC 2 report and we will tell you so rather than imply otherwise.
If we change this policy in a way that affects you, we will email every active subscriber before it takes effect and the version line at the top will change. Previous versions are available on request.