Clear terms, plain language

Privacy Policy

What we collect, why we need it, how long we keep it, and the choices you control.

Version 0.5 · Last updated 3 August 2026

This is the privacy policy of Aevonix B.V. — KinetixSEO ("KinetixSEO", "we", "us", or "our"), provider of the KinetixSEO SaaS platform: a free and paid SEO audit and AI-citation ("GEO") readiness checker. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national implementing legislation.

1. Controller contact details

CompanyAevonix B.V. — KinetixSEO
AddressHeresstraat 1, 9665 NV Oude Pekela, the Netherlands
KVK number42123774 (Dutch Chamber of Commerce)
VAT numberNL869834216B01
Privacy emailprivacy@kinetixseo.com
Websitehttps://kinetixseo.com

We are not required to appoint a Data Protection Officer (DPO). For privacy questions, contact privacy@kinetixseo.com or use the contact form.

2. What personal data we process

2.1 Account data

  • Name and email address
  • Hashed password (we never see or store the plaintext password)
  • Registration timestamp and IP address
  • Plan, credit/wallet balance, and billing history

2.2 Scan and audit data

  • URLs and domains you submit for a free or paid SEO/AI-citation check, including the resulting report: SEO health score, AI-citation ("GEO") readiness score, category breakdowns, and AI-generated fix recommendations
  • Free checks (/seo-check) do not require an account or email address. Each result gets a shareable link — treat that link as public, since anyone with it can view the report. You choose how long we keep it: leave the box on the check form ticked and the report is deleted after 90 days, or untick it and we delete it after 36 hours (see §5). Report pages are marked noindex, so search engines are asked not to list them
  • Tracked sites, tracked keywords, competitor comparisons, and generated landing pages tied to your account

2.3 Billing data

  • Company name, billing address, and VAT number, if you supply them for invoicing
  • Purchase and invoice history
  • Payments are processed by Mollie, Stripe, or Coinbase Commerce — we do not store your card number, bank details, or crypto wallet keys ourselves

2.4 Technical and security data

  • IP addresses (login, registration, and free-check submissions — used for rate limiting and abuse prevention)
  • Session cookie
  • Browser type and operating system (User-Agent header)
  • Login/logout timestamps and failed login attempts
  • Error messages and request traces, processed by our self-hosted monitoring stack (see §4)

2.5 Email communications

Email addresses are used for transactional messages: password resets, purchase receipts and invoices, and replies to the contact form. We do not send marketing email unless you opt in.

3. Purposes and legal bases

PurposeLegal basis (GDPR art. 6)
Account creation and managementPerformance of contract (art. 6(1)(b))
Running the SEO/AI-citation audit you requestPerformance of contract (art. 6(1)(b))
Billing and invoicingPerformance of contract + legal obligation (art. 6(1)(b) and (c))
Statutory invoice retentionLegal obligation (art. 6(1)(c))
Platform security, rate limiting, fraud preventionLegitimate interests (art. 6(1)(f))
Error tracking and platform stabilityLegitimate interests (art. 6(1)(f))
Responding to contact-form messagesLegitimate interests / pre-contractual steps (art. 6(1)(f) and (b))

We do not build behavioural profiles of you as a person (GDPR art. 4(11)) — our AI analysis evaluates the URL or page you submit, not your personal traits or preferences. One automated check does act on you directly without a human involved at that moment: after several failed payment attempts for the same email, checkout is automatically paused for a short, fixed period as a fraud safeguard; you can simply try again once it lifts, and no permanent decision is made. Whether this qualifies as automated decision-making under GDPR art. 22 is under legal review; if it does, you have the right to request human review of that pause. Every other decision with a legal or similarly significant effect on you, such as suspending an account, is made by a person.

4. Sub-processors and third parties

Running a scan means sending the URL/domain you provide, and in some cases the page content it links to, to the third parties below. We never sell personal data.

The Role column distinguishes the two legal relationships this table mixes: processor means the recipient acts only on our instructions and under our processor agreement (GDPR art. 28); independent controller means the recipient decides its own purposes for the data it receives — payment providers process your payment for their own regulatory, fraud-prevention, and accounting obligations, not just ours. Their own privacy notices govern that separate processing.

RecipientRolePurposeData sharedTransfer outside EEA
Contabo GmbHProcessor Application/database hosting; self-hosted monitoring (Grafana, Loki, Tempo, Prometheus); self-hosted outbound email (DirectAdmin/Exim on the same infrastructure — there is no separate third-party transactional email vendor) All account and scan data; for email, the recipient address and message contentNo — Germany (EU)
Plausible (self-hosted instance)Processor Aggregate page-view analytics. The in-browser script places no cookie or storage item (verified against the exact pinned build — see the Cookie Policy); a separate server-to-server call records each page view without needing browser consent The URL you viewed, plus your IP address and user agent for that one requestNo — Germany (EU), same host as Contabo above
DataForSEOProcessorRank tracking (daily keyword position checks) and keyword-opportunity dataTracked keywords and the domain being ranked — not your account credentials Outside the EEA — SCCs apply (confirming exact processing location with DataForSEO's DPA before launch)
Mollie B.V.Independent controllerCard, wallet, and EU bank transfer payment processingBilling details, payment statusNo — Netherlands (EU)
StripeIndependent controllerSofort / Klarna Pay Now payment processingBilling details, payment statusIf US infrastructure: yes — SCCs apply
Coinbase CommerceIndependent controllerCryptocurrency payment processing (BTC/ETH/USDC)Purchase amount, wallet transaction referenceYes (US) — SCCs apply
OpenAI, Anthropic, Google (Gemini)ProcessorAI-generated audit analysis, fix copy, and AI-citation readiness scoringSubmitted URL and its public on-page content — not your account credentialsYes (US) — SCCs apply
Google PageSpeed InsightsProcessorPage performance and domain-authority data used in your reportSubmitted URL/domain onlyYes (US) for some providers — SCCs apply

Where a processor transfers data outside the EEA, we rely on EU Standard Contractual Clauses (SCCs, decision EU 2021/914). Payment providers' own cross-border transfers are governed by their own privacy notices, since that processing is theirs, not ours to contract around.

The self-hosted error/performance monitoring above (Grafana Faro) only runs in your browser after you accept the cookie banner — see our Cookie Policy for what it stores and how to withdraw consent.

5. Retention periods

Data typeRetentionReason
Account dataUntil account deletionDeleted through our account-erasure process when you delete your account
Free-check reports (shareable link)90 days, or 36 hours if you untick the box on the check form Your choice at submission; automatically deleted thereafter, and you can re-run a check at any time
Authenticated scan history and generated landing pages 90 days (Free), 365 days ≈ 1 year (Solo), 730 days ≈ 2 years (Growth), 1095 days ≈ 3 years (Scale), 1460 days ≈ 4 years (Pro) — the window active on your plan when the scan or page was created; upgrading extends existing history to the new plan's window, downgrading never shortens it Product feature — historical comparison, longer on higher tiers
Uploaded server access logsDeleted within seconds of being analysed The raw log file is parsed once and then deleted — we never keep it. Only the aggregated report (bot hit counts and the URLs those bots wasted crawl budget on) is stored, and that report contains no IP addresses and no human visitor traffic
Server log analysis reports Same window as your scan history — 90 days (Free) through 1460 days ≈ 4 years (Pro), set by the plan active when the analysis was created Product feature — comparing crawl waste over time; deletable yourself at any time from the analysis page
Invoices and payment data7 yearsStatutory tax retention
IP addresses in security/audit logs (routine events: logins, credit spends)Up to 2 yearsAbuse prevention and account security; auto-pruned thereafter
Audit records of purchases, reversals, and terms acceptanceDuration of the account plus applicable limitation periodsEvidence for payment disputes and legal claims (GDPR art. 17(3)(e))
Withdrawal requests (statutory withdrawal function)Duration of the account plus applicable limitation periods, de-linked on deletionEvidence for withdrawal/legal claims and defense (GDPR art. 17(3)(e))
Session dataSession lifetimeTechnical necessity
Monitoring traces and logs90 daysDebugging; auto-deleted thereafter

6. Security

  • Encryption in transit: TLS for all connections
  • Passwords: hashed with bcrypt — never stored or transmitted in plaintext
  • Sessions: HTTP-only, secure cookies
  • Rate limiting: applied to login, registration, and free-check submissions

If a personal data breach poses a risk to your rights and freedoms, we report it to the competent supervisory authority within 72 hours of becoming aware of it (GDPR art. 33). If the breach is likely to result in a high risk to you, we additionally notify affected users without undue delay (GDPR art. 34).

7. Your rights

RightDescriptionHow to exercise
Access (art. 15)Request what data we hold about youEmail privacy@kinetixseo.com
Rectification (art. 16)Have inaccurate data correctedAccount settings or email
Erasure (art. 17)Request deletion of your account and dataAccount settings or email
Restriction (art. 18)Have processing temporarily restrictedEmail privacy@kinetixseo.com
Portability (art. 20)Receive your data in a machine-readable formatEmail privacy@kinetixseo.com
Objection (art. 21)Object to processing based on legitimate interestsEmail privacy@kinetixseo.com
Withdraw consent (art. 7(3)) Withdraw consent for anything we process on that basis (currently: error/performance monitoring) at any time, as easily as you gave it The cookie settings control on our Cookie Policy

We respond within four weeks.

8. Complaints

If you are dissatisfied with how we handle your data, please contact privacy@kinetixseo.com first. You also have the right to lodge a complaint with your national data protection authority — for the Netherlands, that is the Autoriteit Persoonsgegevens.

9. Changes to this policy

We may update this policy when our services or applicable law require it. For material changes we will notify active account holders by email at least 30 days before the effective date.