What we collect on this marketing site
The marketing site at dimensionkit.com is a static website that does not require an account, does not set tracking cookies, and does not use third-party analytics. Standard server logs may record the IP address, user agent, and timestamp of requests for security and abuse-prevention purposes; these are retained for a short period and not used to profile visitors.
What we collect in the hosted app
When you take a scorecard on app.dimensionkit.com or on a site that embeds one of our scorecards, we store the answers you submit, the contact details you provide (such as email address and any custom form fields the scorecard owner configured), the IP address of the submission, and a timestamp. This data is stored in a PostgreSQL database operated by us.
If you create an admin account to build scorecards, we also store your name, email address, and a hashed password.
How we use your data
We use submission data only to run the service: to score answers, to display the result, to deliver the result email, to operate anti-abuse protections such as IP rate limiting, and to make the data available to the scorecard owner. We do not sell your data. We do not share it with third parties except service providers acting on our behalf (see below) or when required by law.
Service providers
We run the service on infrastructure provided by Hetzner Online GmbH in Germany. Outbound email is delivered through an SMTP provider. Cloudflare is used in front of the application for DNS and edge protection. When a scorecard has Cloudflare Turnstile enabled, Turnstile receives request metadata for bot detection. Each of these providers processes only the data needed to perform their function and is bound by their own data processing terms.
Embedded scorecards
When a DimensionKit scorecard is embedded on a third-party website, that site is the data controller for the scorecard owner’s use of the form. We act as the processor running the form on their behalf. The scorecard owner is responsible for their own privacy notice covering how they use the submissions.
Cookies and analytics
The marketing site does not use tracking cookies or third-party analytics. The app stores a small amount of local browser state (such as your selected theme) in localStorage. The admin uses a session cookie so you can stay signed in.
Data retention and deletion
Submission data is retained for as long as the corresponding scorecard remains active or until the scorecard owner deletes it. If you submitted a scorecard and want your data removed, contact the scorecard owner directly, or email us and we will route the request to them. We can also remove submission data from our systems on request.
Security
We use standard security measures including TLS in transit, hashed passwords, isolated containers, restricted server access, and standard operating system hardening. No system is perfectly secure and we cannot guarantee absolute security.
Your rights
If you are in the EU/EEA, the UK, or another jurisdiction with comparable laws, you have rights to access, correct, delete, or restrict the processing of your personal data, and to withdraw consent where processing is based on consent. Email [email protected] to exercise any of these rights.
Contact
For privacy questions or data requests, email [email protected]. DimensionKit is operated by Worbee EOOD in Sofia, Bulgaria.