Draft — pending legal review. KinetixSEO's operating entity is still being incorporated. Company name, registration number, and VAT number below are placeholders and will be filled in once registration completes; the substantive policy is ready for counsel review now so it can go live the moment those details exist.
Privacy Policy
Version 0.1 (draft) · Last updated 12 July 2026
This is the privacy policy of [KinetixSEO legal entity name — pending registration] ("KinetixSEO", "we", "us", or "our"), provider of the KinetixSEO SaaS platform: a free and paid SEO audit and AI-citation ("GEO") readiness checker. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national implementing legislation.
1. Controller contact details
| Company | [Legal entity name — pending registration] |
| Address | [Street, postal code, city, country] |
| Registration number | [Number — pending registration] |
| Privacy email | privacy@kinetixseo.com |
| Website | https://kinetixseo.com |
We are not required to appoint a Data Protection Officer (DPO). For privacy questions, contact privacy@kinetixseo.com or use the contact form.
2. What personal data we process
2.1 Account data
- Name and email address
- Hashed password (we never see or store the plaintext password)
- Registration timestamp and IP address
- Plan, credit/wallet balance, and billing history
2.2 Scan and audit data
- URLs and domains you submit for a free or paid SEO/AI-citation check, including the resulting report: SEO health score, AI-citation ("GEO") readiness score, category breakdowns, and AI-generated fix recommendations
- Free checks (
/seo-check) do not require an account or email address. Each result gets a shareable permanent link — treat that link as public, since anyone with it can view the report - Tracked sites, tracked keywords, competitor comparisons, and generated landing pages tied to your account
2.3 Billing data
- Company name, billing address, and VAT number, if you supply them for invoicing
- Purchase and invoice history
- Payments are processed by Mollie, Stripe, or Coinbase Commerce — we do not store your card number, bank details, or crypto wallet keys ourselves
2.4 Technical and security data
- IP addresses (login, registration, and free-check submissions — used for rate limiting and abuse prevention)
- Session cookie
- Browser type and operating system (User-Agent header)
- Login/logout timestamps and failed login attempts
- Error messages and request traces, processed by our self-hosted monitoring stack (see §4)
2.5 Email communications
Email addresses are used for transactional messages: password resets, purchase receipts and invoices, and replies to the contact form. We do not send marketing email unless you opt in.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Account creation and management | Performance of contract (art. 6(1)(b)) |
| Running the SEO/AI-citation audit you request | Performance of contract (art. 6(1)(b)) |
| Billing and invoicing | Performance of contract + legal obligation (art. 6(1)(b)(c)) |
| Statutory invoice retention | Legal obligation (art. 6(1)(c)) |
| Platform security, rate limiting, fraud prevention | Legitimate interests (art. 6(1)(f)) |
| Error tracking and platform stability | Legitimate interests (art. 6(1)(f)) |
| Responding to contact-form messages | Legitimate interests / pre-contractual steps (art. 6(1)(f)(b)) |
We never use your data for automated individual decision-making or profiling (GDPR art. 22) without human review.
4. Sub-processors and third parties
Running a scan means sending the URL/domain you provide, and in some cases the page content it links to, to the third parties below. We never sell personal data.
| Sub-processor | Purpose | Data shared | Transfer outside EEA |
|---|---|---|---|
| Contabo GmbH | Application/database hosting; self-hosted monitoring (Grafana, Loki, Tempo, Prometheus) | All account and scan data | No — Germany (EU) |
| Mollie B.V. | iDEAL / Bancontact / SEPA payment processing | Billing details, payment status | No — Netherlands (EU) |
| Stripe | Card / Sofort payment processing | Billing details, payment status | If US infrastructure: yes — SCCs apply |
| Coinbase Commerce | Cryptocurrency payment processing (BTC/ETH/USDC) | Purchase amount, wallet transaction reference | Yes (US) — SCCs apply |
| OpenAI, Anthropic, Google (Gemini) | AI-generated audit analysis, fix copy, and AI-citation readiness scoring | Submitted URL and its public on-page content — not your account credentials | Yes (US) — SCCs apply |
| Google PageSpeed Insights | Page performance and domain-authority data used in your report | Submitted URL/domain only | Yes (US) for some providers — SCCs apply |
| Transactional email provider (finalized before launch) | Delivering password resets, receipts, and contact-form replies | Name, email address, message content | SCCs apply where applicable |
Where a sub-processor transfers data outside the EEA, we rely on EU Standard Contractual Clauses (SCCs, decision EU 2021/914).
5. Retention periods
| Data type | Retention | Reason |
|---|---|---|
| Account data | Until account deletion + 2 years | Business correspondence; GDPR art. 17(3) |
| Free-check reports (shareable link) | Indefinitely, unless you request deletion | Core product feature — permanent shareable link |
| Authenticated scan/audit history | Until account deletion | Product feature — historical comparison |
| Invoices and payment data | 7 years | Statutory tax retention |
| IP addresses in logs | 30 days | Abuse prevention; auto-deleted thereafter |
| Session data | Session lifetime | Technical necessity |
| Monitoring traces and logs | 90 days | Debugging; auto-deleted thereafter |
6. Security
- Encryption in transit: TLS for all connections
- Passwords: hashed with bcrypt — never stored or transmitted in plaintext
- Sessions: HTTP-only, secure cookies
- Rate limiting: applied to login, registration, and free-check submissions
In the event of a personal data breach likely to result in a high risk to your rights, we will notify affected users promptly and report to the competent supervisory authority within 72 hours (GDPR art. 33–34).
7. Your rights
| Right | Description | How to exercise |
|---|---|---|
| Access (art. 15) | Request what data we hold about you | Email privacy@kinetixseo.com |
| Rectification (art. 16) | Have inaccurate data corrected | Account settings or email |
| Erasure (art. 17) | Request deletion of your account and data | Account settings or email |
| Restriction (art. 18) | Have processing temporarily restricted | Email privacy@kinetixseo.com |
| Portability (art. 20) | Receive your data in a machine-readable format | Email privacy@kinetixseo.com |
| Objection (art. 21) | Object to processing based on legitimate interests | Email privacy@kinetixseo.com |
We respond within four weeks.
8. Complaints
If you are dissatisfied with how we handle your data, please contact privacy@kinetixseo.com first. You also have the right to lodge a complaint with your national data protection authority — for the Netherlands, that is the Autoriteit Persoonsgegevens.
9. Changes to this policy
We may update this policy when our services or applicable law require it. For material changes we will notify active account holders by email at least 30 days before the effective date.