Privacy Policy
We engineer our platform around data minimization, cryptographic isolation, and zero-training AI protocols. Learn exactly how your technical search telemetry is handled.
Executive Privacy Commitments
- ✓Zero Foundation Training: Your prompts, keywords, and draft content are never used to train public LLMs.
- ✓Ephemeral Crawl Cache: On-page technical audits and crawl results are retained only for your direct workspace sessions.
- ✓No Third-Party Brokers: We do not sell, rent, or monetize your search intelligence or telemetry.
- ✓Bank-Grade Transit: All data in transit is encrypted using enforced TLS 1.3 with AES-256 GCM cryptographic ciphers.
1. Data Controller & Scope
This Privacy Policy governs the processing of personal data and technical telemetry by GetSEOO (“GetSEOO,” “Company,” “we,” “us,” or “our”), operating the getseoo.com web application, directory subdomains, APIs, and associated automated search intelligence utilities (collectively, the “Platform” or “Services”).
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK Data Protection Act 2018, and California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), GetSEOO acts as the Data Controller with respect to user account and administrative billing information, and as a Data Processor (or “Service Provider”) with respect to customer-submitted target domain audits, crawl targets, and user-generated programmatic content.
2. Categories of Information We Collect
We collect information across three distinct operational layers:
A. Information You Voluntarily Provide
- Account Identifiers: Name, work email address, hashed authentication credentials, and Google OAuth profile tokens.
- Workspace Submissions: Target website domain names, XML sitemap URLs, focus keywords, competitor links, and custom AI content generation prompts.
- Directory Distribution Data: For users of our AI Directory Submission service: company name, product description, founder contact, logo URL, target categories, and social handles submitted for manual publication.
- Billing & Commercial Records: When purchasing commercial services or directory distribution packages, we collect billing contact details, company information, and transaction reference records. All online transactions are processed through certified PCI-DSS compliant payment gateways; raw payment card numbers are never processed or stored directly on GetSEOO servers.
B. Technical Telemetry & Crawl Data
- Public URL Metadata: When you execute an audit or indexing ping, our crawler retrieves publicly declared HTTP response headers, robots.txt directives, OpenGraph tags, schema JSON-LD graphs, and DOM text structures.
- Log Telemetry: Anonymized IP addresses, browser client fingerprints, operating system type, HTTP referrer headers, request timestamps, and API endpoint latency metrics.
C. Cookies & Local Session Storage
We utilize strictly essential session tokens, encrypted JWT authentication cookies, and transient local storage keys to preserve your active audit state, dark/light theme choice, and rate-limit counters. We do not embed invasive cross-site advertising trackers or third-party data broker beacons.
3. Legal Bases for Processing (GDPR Art. 6)
We process your personal data under the following recognized legal foundations:
- Contractual Performance: Processing necessary to provision your account, run diagnostic audits, generate requested programmatic articles, broadcast IndexNow notifications, and execute directory submissions.
- Legitimate Interests: Monitoring platform performance, preventing distributed denial-of-service (DDoS) attacks, detecting fraudulent billing patterns, and refining technical audit algorithms.
- Compliance with Legal Obligations: Retaining financial transaction records, tax invoices, and responding to lawful requests by competent judicial authorities.
- Consent: Sending opt-in marketing newsletters or strategic SEO playbooks, which may be rescinded at any time via one-click unsubscribe links.
4. Generative AI Architecture & Zero-Training Guarantee
Zero Foundation Model Training Commitment
GetSEOO executes generative workflows through commercial enterprise API agreements. Under these strict enterprise data protection addenda (DPAs), your proprietary keywords, brand briefs, draft articles, and private URLs are never retained, indexed, or used to train, retrain, or improve foundational machine learning models.
Technical extraction, E-E-A-T entity mapping, and automated drafting workflows operate through transient, stateless API calls. Once the model outputs structured recommendations or content markdown, the inference session is terminated and no customer data remains in the inference cluster cache.
5. Third-Party Disclosures & Sub-Processors
GetSEOO strictly restricts data access. We disclose information solely to vetted sub-processors bound by confidentiality and data protection obligations commensurate with this policy:
| Sub-Processor | Purpose | Data Location | Safeguards |
|---|---|---|---|
| PostgreSQL Cloud Cluster | Encrypted Application Database | United States / EU | AES-256 Encryption at Rest |
| Enterprise AI Inference Gateways | Generative Semantic Extraction & Content Drafting | United States | Zero Data Retention (ZDR) DPAs |
| Public SaaS Directories | Customer-Requested Manual Listing Publication | Global Public Web | User-Instructed Publication |
6. Cross-Border Data Transfers
If you access the Services from the European Economic Area (EEA), the United Kingdom, or Switzerland, your information may be transferred to, stored, and processed in cloud data centers located in the United States and globally.
To provide an adequate level of data protection in compliance with Chapter V of the GDPR, we execute standard European Commission-approved Standard Contractual Clauses (SCCs) with all international service providers and verify supplementary technical safeguards including end-to-end data encryption.
7. Retention Schedules & Data Erasure
We retain personal data strictly for as long as necessary to fulfill the operational purposes set forth in this policy, unless a longer retention period is mandated by tax, legal, or regulatory reporting frameworks:
- Account Profile & Billing History: Retained for the duration of your active subscription plus 7 fiscal years to satisfy statutory tax accounting requirements.
- Diagnostic Audit Snapshots: Retained for 90 days to provide historical comparison charts in your dashboard, after which logs are permanently scrubbed.
- Directory Submission Proof Records: Retained for the lifetime of your account to verify live inbound backlink and index status.
8. Your Statutory Rights (GDPR & CCPA/CPRA)
Depending on your geographic residency, you are entitled to exercise fundamental privacy rights without experiencing discriminatory pricing or degradation of service:
Right to Access & Portability
Request a full, machine-readable export (JSON/CSV) of all personal data held about your account.
Right to Erasure (“To Be Forgotten”)
Request permanent deletion of your profile, audit records, and associated generated content.
Right to Rectification
Demand immediate correction of inaccurate or incomplete personal identification data.
Right to Opt-Out of Sale / Sharing
We do not sell personal data under CCPA/CPRA definitions. You can exercise opt-out rights at any time.
To submit a verifiable data subject request, contact our compliance team directly at hey@getseoo.com. We acknowledge all requests within 48 business hours and resolve them within statutory 30-day deadlines.
9. Cryptographic & Infrastructure Security
GetSEOO implements enterprise defense-in-depth security practices designed to safeguard information against unauthorized access, destruction, alteration, or exfiltration:
- Mandatory HSTS and TLS 1.3 cryptographic transport across all public and internal service mesh endpoints.
- AES-256 block-level encryption for all persistent database volumes, automated backups, and snapshot replicas.
- Strict Principle of Least Privilege (PoLP) and role-based access control (RBAC) enforced with mandatory multi-factor authentication (MFA) for administrative staff.
- Continuous vulnerability scanning and automated dependency patching cycles.
10. Children’s Privacy Protection
The Services are strictly designed and intended for commercial business use by adult professionals, founders, and enterprises. We do not knowingly solicit or collect personal information from individuals under the age of 18 (or the age of majority in the user’s jurisdiction). If we discover that an individual under 18 has submitted personal information, we will immediately delete such data from our production clusters.
11. Material Amendments & Notifications
We reserve the right to modify or update this Privacy Policy to reflect evolving technological architectures, statutory mandates, or corporate restructuring. When material amendments are introduced, we will update the “Last Revised” timestamp and deliver prominent notice via your registered account email or through a global modal notification on the Platform dashboard at least 14 days prior to implementation.
12. Data Protection Officer & Contact Inquiries
For questions, formal legal notices, or supervisory authority inquiries regarding our data handling practices, please address correspondence to our designated privacy office:
GetSEOO Legal & Compliance Office
Attn: Data Protection Officer (DPO)
Electronic Mail: hey@getseoo.com
Support Desk: getseoo.com/contact