Privacy Policy
FAST is a technical website auditing tool. It requires no sign-up, keeps no database and sets no tracking cookies. This policy describes, plainly, the few pieces of data that pass through the service.
1. Who the controller is
OpenFlexi, responsible for running FAST and for the decisions about the processing described here. Contact: business@openflexi.com.
2. What data is processed
| Data | Why | For how long |
|---|---|---|
| The URL you submit | To run the requested audit. If the URL carries parameters with personal data, they travel along — avoid submitting addresses with sensitive information in the query string. | During the run |
| IP address | To apply the rate limit that protects the service from abuse, and to log access for security and troubleshooting. | In server logs, until automatic log rotation |
| Browser data | User agent and language, recorded with the access and used to pick the interface language. | In server logs |
| The generated report | To allow PDF export without sending the content back over the network. | Up to 15 minutes, in memory only |
3. What FAST does not do
- No sign-up, login or user profile.
- No database: no report is ever written to disk.
- No tracking cookies, analytics, advertising pixels or fingerprinting.
- No selling, renting or sharing of data with third parties for commercial purposes.
- No automated decision-making producing legal effects on you.
4. Legal basis
Processing rests on legitimate interest (LGPD art. 7, IX): running the service you asked for and protecting it from abuse. The processing is minimal, predictable and limited to what the purpose requires — the very conditions the law attaches to this legal basis. Access logs also serve compliance with a legal obligation (art. 7, II) under the Brazilian Internet Civil Framework.
5. Who the data is shared with
Only the processors the service needs in order to exist:
- Hosting provider — the server the application runs on.
- Content delivery network (CDN) — delivers the pages and sees the IP address of whoever connects.
- Language model — the report is sent to the model that writes the plain-language analysis. The infrastructure is our own, and the content is neither used for training nor retained after the response.
6. International transfer
The CDN distributes content across servers in several regions, which may mean processing outside Brazil (LGPD art. 33). The transfer is limited to the connection data needed to deliver the page.
7. Data subject rights
LGPD art. 18 grants you: confirmation that processing exists, access to the data, correction, anonymisation or deletion, portability, information about sharing, and withdrawal of consent where consent is the applicable basis.
In practice, since FAST stores no reports and keeps no accounts, the data that may exist about you amounts to access logs. To exercise any right, write to business@openflexi.com — we answer within 15 days.
8. Data protection officer (DPO)
The officer in charge of personal data processing, as required by LGPD art. 41, is appointed by OpenFlexi and can be reached at business@openflexi.com. That is also the channel for communications from the Brazilian data protection authority (ANPD).
9. Security
All traffic uses HTTPS with HSTS. The application sends security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy) and does not disclose software versions. Security flaws can be reported as described in security.txt.
10. Changes
Changes to this policy are published on this same page, with the update date at the top revised accordingly.