Home › Privacy Policy

Privacy Policy

Plain English, no dark patterns. What we collect, why we collect it, who else sees it, and how to make us delete it.

Last updated: [DATE] · Operated by [LEGAL ENTITY NAME], [COUNTRY OF REGISTRATION]

Who and what

The short version.

We are a search growth agency. We collect very little: what you type into our forms, and standard analytics about how the site is used. Our free audit tool collects nothing about you at all. We have never sold personal data and we never will.

Data controller
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. Company number [NUMBER]. For any privacy matter, contact [PRIVACY EMAIL].
Data protection contact
[NAME OR ROLE, e.g. “Founder”] at [PRIVACY EMAIL]. We are [not required to appoint / have appointed] a Data Protection Officer under Article 37 GDPR. [If you appoint one, name them here.]
EU / UK representative
[If you have no EU establishment and target EU visitors, an Article 27 representative may be required. Name them here, or delete this row after confirming it does not apply.]

What we collect

Three categories, and nothing else.

Information you give us
When you submit the audit request form or the contact form: your name, email address, website, company, and whatever you write in the message. If we work together, we also hold billing details and correspondence.
Information collected automatically
Standard server logs (IP address, browser, pages requested, timestamps) kept for security and troubleshooting, and analytics as described below. Cookie details are on our Cookie Policy.
The free SEO audit tool
Nothing about you. You enter a website address; the analysis runs in your own browser. Our server fetches a small number of public pages from the site being audited and caches them briefly so repeated audits do not re-request them. We do not store your results, your identity, or a record of which sites were checked. There is no account and no email gate.
What we never collect
Special category data (health, biometrics, political or religious views, and similar) and payment card numbers — payments are handled by [PAYMENT PROCESSOR], who never share full card details with us. We do not knowingly collect data from anyone under 16.

Why we are allowed to

Legal bases under GDPR and UK GDPR.

If you are in the EEA or UK, we must have a lawful basis for each use. Here they are, mapped honestly.

To reply to your enquiry
Legitimate interests (Article 6(1)(f)) — you contacted us and expect a reply — or steps prior to entering a contract (Article 6(1)(b)).
To deliver client work
Performance of a contract (Article 6(1)(b)).
Analytics and site improvement
Consent (Article 6(1)(a)) where cookies require it, collected through our cookie banner. Withdraw it any time and nothing else changes.
Security, logs, and fraud prevention
Legitimate interests (Article 6(1)(f)).
Accounting and tax records
Legal obligation (Article 6(1)(c)).
Marketing email, if we ever send it
Consent, or the soft opt-in for existing clients where local law allows. Every message carries a one-click unsubscribe.

Sharing

Who else touches your data.

A short list, and none of them are advertisers. Each acts as a processor under a written agreement, and we only use providers who commit to appropriate safeguards.

Hosting and infrastructure
[HOSTING PROVIDER], [COUNTRY] — stores the website and its database.
Email and CRM
[EMAIL / CRM TOOL] — receives form submissions and holds correspondence.
Analytics
[ANALYTICS TOOL] — aggregate usage statistics. See the Cookie Policy.
Payments
[PAYMENT PROCESSOR] — processes invoices; holds billing data under its own policy.
Professional advisers and authorities
Accountants, lawyers, or regulators, where we are legally required or need advice.
We do not
Sell personal data, share it for cross-context behavioural advertising, or trade it in any form. Under the CCPA/CPRA this means we have not sold or shared personal information in the preceding 12 months.

Transfers and retention

Where it goes, and how long it stays.

International transfers
Our providers may process data outside your country, including in the United States. Where data leaves the EEA or UK we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. Ask us at [PRIVACY EMAIL] and we will tell you exactly which applies to which provider.
Enquiries that do not become work
Deleted after [RETENTION, e.g. 24 months] from last contact.
Client records
Kept for the duration of the engagement, then for [RETENTION, e.g. 7 years] where tax and accounting law in [COUNTRY] requires it.
Server logs
[RETENTION, e.g. 30 days].
Analytics data
[RETENTION, e.g. 14 months] or as configured in [ANALYTICS TOOL].

Your rights

What you can make us do.

These rights apply to everyone who contacts us, regardless of where you live. We do not charge for exercising them and we will not treat you differently for doing so.

Access
Ask what we hold about you and get a copy.
Correction
Have inaccurate information fixed.
Deletion
Have your data erased, unless we must keep it by law.
Restriction and objection
Limit how we use your data, or object to processing based on legitimate interests.
Portability
Receive your data in a machine-readable format.
Withdraw consent
Change your mind about cookies or marketing at any time, without affecting anything before that point.
California residents (CCPA/CPRA)
You additionally have the right to know the categories collected, to delete, to correct, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we collect none), and to be free from retaliation for exercising these rights. You may use an authorised agent.
How to exercise any of them
Email [PRIVACY EMAIL]. We respond within 30 days (45 days in California, extendable once with notice). We may ask you to confirm your identity so we do not hand your data to someone else.
If we get it wrong
You can complain to your data protection authority: the ICO in the UK, your national authority in the EEA, the OAIC in Australia, the OPC in Canada, the ANPD in Brazil, or the Information Regulator in South Africa. We would rather you told us first at [PRIVACY EMAIL].

Security and changes

Housekeeping.

How we protect it
HTTPS across the whole site, access limited to people who need it, two-factor authentication on administrative accounts, and regular updates. No system is perfectly secure; if a breach affects your rights we will notify you and the relevant authority within 72 hours where the law requires.
Automated decision-making
We do not make decisions about you by automated means, and we do not profile you.
Changes to this policy
Material changes are posted here with a new date at the top, and existing clients are told directly. Continued use of the site after a change means you accept the updated policy.

Anything unclear? Ask us — a person reads it, not a ticketing bot.