Clear terms, plain language
Privacy Policy
What we collect, why we need it, how long we keep it, and the choices you control.
Version 0.5 · Last updated 3 August 2026
This is the privacy policy of Aevonix B.V. — KinetixSEO ("KinetixSEO", "we", "us", or "our"), provider of the KinetixSEO SaaS platform: a free and paid SEO audit and AI-citation ("GEO") readiness checker. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national implementing legislation.
1. Controller contact details
| Company | Aevonix B.V. — KinetixSEO |
| Address | Heresstraat 1, 9665 NV Oude Pekela, the Netherlands |
| KVK number | 42123774 (Dutch Chamber of Commerce) |
| VAT number | NL869834216B01 |
| Privacy email | privacy@kinetixseo.com |
| Website | https://kinetixseo.com |
We are not required to appoint a Data Protection Officer (DPO). For privacy questions, contact privacy@kinetixseo.com or use the contact form.
2. What personal data we process
2.1 Account data
- Name and email address
- Hashed password (we never see or store the plaintext password)
- Registration timestamp and IP address
- Plan, credit/wallet balance, and billing history
2.2 Scan and audit data
- URLs and domains you submit for a free or paid SEO/AI-citation check, including the resulting report: SEO health score, AI-citation ("GEO") readiness score, category breakdowns, and AI-generated fix recommendations
- Free checks (
/seo-check) do not require an account or email address. Each result gets a shareable link — treat that link as public, since anyone with it can view the report. You choose how long we keep it: leave the box on the check form ticked and the report is deleted after 90 days, or untick it and we delete it after 36 hours (see §5). Report pages are markednoindex, so search engines are asked not to list them - Tracked sites, tracked keywords, competitor comparisons, and generated landing pages tied to your account
2.3 Billing data
- Company name, billing address, and VAT number, if you supply them for invoicing
- Purchase and invoice history
- Payments are processed by Mollie, Stripe, or Coinbase Commerce — we do not store your card number, bank details, or crypto wallet keys ourselves
2.4 Technical and security data
- IP addresses (login, registration, and free-check submissions — used for rate limiting and abuse prevention)
- Session cookie
- Browser type and operating system (User-Agent header)
- Login/logout timestamps and failed login attempts
- Error messages and request traces, processed by our self-hosted monitoring stack (see §4)
2.5 Email communications
Email addresses are used for transactional messages: password resets, purchase receipts and invoices, and replies to the contact form. We do not send marketing email unless you opt in.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Account creation and management | Performance of contract (art. 6(1)(b)) |
| Running the SEO/AI-citation audit you request | Performance of contract (art. 6(1)(b)) |
| Billing and invoicing | Performance of contract + legal obligation (art. 6(1)(b) and (c)) |
| Statutory invoice retention | Legal obligation (art. 6(1)(c)) |
| Platform security, rate limiting, fraud prevention | Legitimate interests (art. 6(1)(f)) |
| Error tracking and platform stability | Legitimate interests (art. 6(1)(f)) |
| Responding to contact-form messages | Legitimate interests / pre-contractual steps (art. 6(1)(f) and (b)) |
We do not build behavioural profiles of you as a person (GDPR art. 4(11)) — our AI analysis evaluates the URL or page you submit, not your personal traits or preferences. One automated check does act on you directly without a human involved at that moment: after several failed payment attempts for the same email, checkout is automatically paused for a short, fixed period as a fraud safeguard; you can simply try again once it lifts, and no permanent decision is made. Whether this qualifies as automated decision-making under GDPR art. 22 is under legal review; if it does, you have the right to request human review of that pause. Every other decision with a legal or similarly significant effect on you, such as suspending an account, is made by a person.
4. Sub-processors and third parties
Running a scan means sending the URL/domain you provide, and in some cases the page content it links to, to the third parties below. We never sell personal data.
The Role column distinguishes the two legal relationships this table mixes: processor means the recipient acts only on our instructions and under our processor agreement (GDPR art. 28); independent controller means the recipient decides its own purposes for the data it receives — payment providers process your payment for their own regulatory, fraud-prevention, and accounting obligations, not just ours. Their own privacy notices govern that separate processing.
| Recipient | Role | Purpose | Data shared | Transfer outside EEA |
|---|---|---|---|---|
| Contabo GmbH | Processor | Application/database hosting; self-hosted monitoring (Grafana, Loki, Tempo, Prometheus); self-hosted outbound email (DirectAdmin/Exim on the same infrastructure — there is no separate third-party transactional email vendor) | All account and scan data; for email, the recipient address and message content | No — Germany (EU) |
| Plausible (self-hosted instance) | Processor | Aggregate page-view analytics. The in-browser script places no cookie or storage item (verified against the exact pinned build — see the Cookie Policy); a separate server-to-server call records each page view without needing browser consent | The URL you viewed, plus your IP address and user agent for that one request | No — Germany (EU), same host as Contabo above |
| DataForSEO | Processor | Rank tracking (daily keyword position checks) and keyword-opportunity data | Tracked keywords and the domain being ranked — not your account credentials | Outside the EEA — SCCs apply (confirming exact processing location with DataForSEO's DPA before launch) |
| Mollie B.V. | Independent controller | Card, wallet, and EU bank transfer payment processing | Billing details, payment status | No — Netherlands (EU) |
| Stripe | Independent controller | Sofort / Klarna Pay Now payment processing | Billing details, payment status | If US infrastructure: yes — SCCs apply |
| Coinbase Commerce | Independent controller | Cryptocurrency payment processing (BTC/ETH/USDC) | Purchase amount, wallet transaction reference | Yes (US) — SCCs apply |
| OpenAI, Anthropic, Google (Gemini) | Processor | AI-generated audit analysis, fix copy, and AI-citation readiness scoring | Submitted URL and its public on-page content — not your account credentials | Yes (US) — SCCs apply |
| Google PageSpeed Insights | Processor | Page performance and domain-authority data used in your report | Submitted URL/domain only | Yes (US) for some providers — SCCs apply |
Where a processor transfers data outside the EEA, we rely on EU Standard Contractual Clauses (SCCs, decision EU 2021/914). Payment providers' own cross-border transfers are governed by their own privacy notices, since that processing is theirs, not ours to contract around.
The self-hosted error/performance monitoring above (Grafana Faro) only runs in your browser after you accept the cookie banner — see our Cookie Policy for what it stores and how to withdraw consent.
5. Retention periods
| Data type | Retention | Reason |
|---|---|---|
| Account data | Until account deletion | Deleted through our account-erasure process when you delete your account |
| Free-check reports (shareable link) | 90 days, or 36 hours if you untick the box on the check form | Your choice at submission; automatically deleted thereafter, and you can re-run a check at any time |
| Authenticated scan history and generated landing pages | 90 days (Free), 365 days ≈ 1 year (Solo), 730 days ≈ 2 years (Growth), 1095 days ≈ 3 years (Scale), 1460 days ≈ 4 years (Pro) — the window active on your plan when the scan or page was created; upgrading extends existing history to the new plan's window, downgrading never shortens it | Product feature — historical comparison, longer on higher tiers |
| Uploaded server access logs | Deleted within seconds of being analysed | The raw log file is parsed once and then deleted — we never keep it. Only the aggregated report (bot hit counts and the URLs those bots wasted crawl budget on) is stored, and that report contains no IP addresses and no human visitor traffic |
| Server log analysis reports | Same window as your scan history — 90 days (Free) through 1460 days ≈ 4 years (Pro), set by the plan active when the analysis was created | Product feature — comparing crawl waste over time; deletable yourself at any time from the analysis page |
| Invoices and payment data | 7 years | Statutory tax retention |
| IP addresses in security/audit logs (routine events: logins, credit spends) | Up to 2 years | Abuse prevention and account security; auto-pruned thereafter |
| Audit records of purchases, reversals, and terms acceptance | Duration of the account plus applicable limitation periods | Evidence for payment disputes and legal claims (GDPR art. 17(3)(e)) |
| Withdrawal requests (statutory withdrawal function) | Duration of the account plus applicable limitation periods, de-linked on deletion | Evidence for withdrawal/legal claims and defense (GDPR art. 17(3)(e)) |
| Session data | Session lifetime | Technical necessity |
| Monitoring traces and logs | 90 days | Debugging; auto-deleted thereafter |
6. Security
- Encryption in transit: TLS for all connections
- Passwords: hashed with bcrypt — never stored or transmitted in plaintext
- Sessions: HTTP-only, secure cookies
- Rate limiting: applied to login, registration, and free-check submissions
If a personal data breach poses a risk to your rights and freedoms, we report it to the competent supervisory authority within 72 hours of becoming aware of it (GDPR art. 33). If the breach is likely to result in a high risk to you, we additionally notify affected users without undue delay (GDPR art. 34).
7. Your rights
| Right | Description | How to exercise |
|---|---|---|
| Access (art. 15) | Request what data we hold about you | Email privacy@kinetixseo.com |
| Rectification (art. 16) | Have inaccurate data corrected | Account settings or email |
| Erasure (art. 17) | Request deletion of your account and data | Account settings or email |
| Restriction (art. 18) | Have processing temporarily restricted | Email privacy@kinetixseo.com |
| Portability (art. 20) | Receive your data in a machine-readable format | Email privacy@kinetixseo.com |
| Objection (art. 21) | Object to processing based on legitimate interests | Email privacy@kinetixseo.com |
| Withdraw consent (art. 7(3)) | Withdraw consent for anything we process on that basis (currently: error/performance monitoring) at any time, as easily as you gave it | The cookie settings control on our Cookie Policy |
We respond within four weeks.
8. Complaints
If you are dissatisfied with how we handle your data, please contact privacy@kinetixseo.com first. You also have the right to lodge a complaint with your national data protection authority — for the Netherlands, that is the Autoriteit Persoonsgegevens.
9. Changes to this policy
We may update this policy when our services or applicable law require it. For material changes we will notify active account holders by email at least 30 days before the effective date.