Incorporation in Delaware doesn't exempt you from European data protection law. If EU residents buy from you, or you track their behavior on your site, three things are probably missing: an EU Representative, valid data-transfer safeguards, and a GDPR-compliant privacy notice. Find out exactly what, for free.
Enter your URL — our AI checks it against GDPR and the other laws your visitors bring with them, for free.
How it works
No EU legal team required. Our AI reads the regulation so you don't have to.
amalyon crawls your website: languages, currencies, hreflang tags, phone prefixes, cookie banners, legal notices — to confirm which markets you're actually selling into, EU included.
Claude AI checks your site against GDPR (and any other detected law): score out of 100, per-article findings, maximum fine exposure — 4% of global annual revenue under GDPR, not just EU revenue.
Compliance score, fine exposure, and the top 3 fixes to make first — all in your inbox within the hour.
What's usually missing
These aren't covered by a generic GDPR checklist written for EU companies — they only apply because you're outside the EU.
If you offer goods or services to people in the EU, or monitor their behavior, you likely need a representative established in the EU — a local point of contact for supervisory authorities and data subjects. Few US companies have appointed one.
Moving EU personal data to US servers or a US parent company needs a legal basis: Standard Contractual Clauses (SCCs) with your EU customers or vendors, or self-certification under the Data Privacy Framework.
A US Department of Commerce self-certification program that can replace SCCs for EU-US transfers — enforced by the FTC. Useful, but it doesn't cover the rest of GDPR (representative, notices, rights requests) on its own.
Legal coverage
Most US companies selling to Europe also have customers elsewhere. The same scan checks for that automatically.
SELLING BEYOND THE EU AND US? THE SAME SCAN ALSO CHECKS:
Pricing
One-time payment, report delivered by email within the hour. No subscription.
Local
1 jurisdiction (e.g. GDPR)
Regional
Up to 3 jurisdictions (e.g. GDPR + CCPA)
Global
All detected jurisdictions
Frequently asked questions
<html lang> attribute, hreflang attributes, the Content-Language header, displayed currencies, phone number prefixes, mentions of laws or countries in your legal pages, cookie banners (OneTrust, Cookiebot…), and meta geo.region tags.