The details, in plain language
JBR Invest LLC
Data processing
Information about JBRSignal and its automated website analysis service.
Purpose and status of this explanation
This page, dated 2026-09-05, explains the processing involved in the website-analysis workflow. It is not a signed data-processing agreement, a certification or a substitute for terms your organization is required to put in place. An ordinary purchase does not establish that a separately negotiated processor agreement has been executed. If you require one, discuss its scope with the operator before ordering or submitting material subject to special restrictions. The privacy notice separately explains information used to manage the service and customer relationship.
Different processing responsibilities
A controller determines why and how personal information is processed; a processor handles it on behalf of a controller within an applicable arrangement. Those roles depend on the real activity, not solely on the title of a page or the fact that a customer supplied a URL. The operator uses contact, billing and operational information for its own service purposes. An organization submitting website material should consider its authority and responsibilities for that content. This page does not classify every provider or every activity as processor-only.
Input, processing and outputs
The requested website is fetched within the supported public-resource scope. Retrieved page content and technical findings are stored as evidence, then selected evidence is used to generate paid recommendations. Outputs can include suggested metadata, text, structured-data drafts, priorities and a staged implementation plan. Processing also creates operational status and diagnostic records. This workflow does not require a private customer database, administration login or confidential document upload. Report generation and the associated payment, messaging and support activities should be considered separately when documenting an organizational use case.
Choosing suitable information
Only submit public pages you are entitled to analyze. Check whether those pages contain employee details, personal biographies, testimonials or other information about identifiable individuals, and whether the planned use is appropriate. Do not use the service to submit sensitive records, private administration URLs or material that must remain within a particular restricted environment without first discussing the requirement. Public accessibility is not a general permission to disregard content rights. Contact support if you discover that an unsuitable page or piece of information was included.
Services participating in the workflow
OpenAI receives website evidence needed for paid recommendation generation. Stripe handles payment collection and related verification. Mailgun handles service-email delivery, while hosting and database services operate the application and its records. The information sent depends on the task; the website scanner is not an instruction to send your payment-card details to the AI provider. Provider roles, locations, contractual safeguards and retention terms should be checked for the actual arrangement. Ask the operator for the information required by your organization rather than treating this summary as a completed supplier assessment.
Security and confidential access
The application applies private-link and brand-ownership checks to customer resources, staff authorization to administrative functions and input controls to submitted requests. These measures are relevant safeguards, not a promise that all stored data is encrypted in every infrastructure layer or that a named certification has been obtained. Share report links only with intended recipients and do not include credentials in messages. Organizational requirements for access review, incident cooperation, audit rights or additional safeguards should be addressed explicitly in the arrangement applicable to the processing.
Retention, requests and incident concerns
Evidence, deliverables and supporting records are retained for their relevant delivery, support, security and legal purposes. A verified request can lead to review, removal or restricted retention as appropriate; it does not automatically erase payment history or every copy held by independent providers. If you receive an individual request relating to a submitted website, contact the operator with enough context to locate the information without disclosing unnecessary extra data. Report suspected exposure promptly. Any notification or assistance required by applicable law or an agreed contract remains relevant.
Requirements to settle before ordering
Contact the operator before purchase if your organization needs a specified processing region, approved provider list, transfer documentation, retention schedule, return-and-deletion procedure or contractual processor obligations. These requirements must be evaluated against the actual service and any additional agreement; this page does not claim that signed standard contractual clauses, audit reports or bespoke terms already exist. If the arrangement cannot meet a mandatory requirement, do not submit the restricted information on the assumption that a public marketing statement overrides it.