Every embedded third-party service that processes personal data — analytics, advertising, fonts, maps, chat, CDN, hosting — must appear in the privacy policy.
Art. 13 GDPR requires details on purpose, legal basis, recipients, retention period and third-country transfer. An incomplete privacy policy is a separate infringement — regardless of whether the embedding itself is lawful.
The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.
This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.