This Privacy and Cookie Policy explains how personal data is processed and how cookies and similar technologies are used in connection with seoassistant.pro and the SEOAssistant application.
I. Definitions
Controller / Operator means SENDINGO spółka z ograniczoną odpowiedzialnością, National Court Register (KRS) number 0000393749, Tax Identification Number (NIP) 8943031099, National Business Registry Number (REGON) 021677255, with its registered office at ul. Władysława Grabskiego 15/10, 53-535 Wrocław, Poland.
Service means seoassistant.pro, the SEOAssistant application and any related address indicated by the Controller. User means a person or organization using the Service. Account means the authenticated area of the Service.
Services means electronically supplied SEO and content operations, including reports, recommendations, content proposals and data integrations. External Data means data retrieved from connected services on the User’s instructions. User Content means data and materials entered by the User or retrieved at the User’s request.
II. Personal data
1. Data we process
Depending on how the Service is used, we may process:
- Account and contact data, including email address, telephone number and a securely hashed password;
- company billing data, including company name, tax number and address;
- communications submitted through contact and support forms;
- technical data, including IP address, browser or device identifiers and system logs required for security and maintenance;
- analytics and marketing identifiers and events, subject to the User’s consent settings.
The Service may technically connect to e-commerce APIs that expose order data. Standard Service functionality is not designed to process order data; the final scope always depends on the integrations configured by the User.
2. Whether data is required
Providing data is voluntary, but certain information is required to create an Account, provide the Services and issue billing documents. Without it, the Services may not be available.
3. Legal bases under the GDPR
- Article 6(1)(b) GDPR — performance of the Agreement and provision of electronically supplied services;
- Article 6(1)(c) GDPR — compliance with legal obligations, including accounting and tax obligations;
- Article 6(1)(f) GDPR — the Controller’s legitimate interests, including security, fraud prevention, service statistics and the establishment or defense of claims;
- Article 6(1)(a) GDPR — consent, where required for direct marketing or analytics and marketing cookies.
4. Purposes
Data is processed to create and operate Accounts, provide and bill for the Services, respond to enquiries, maintain security, analyze and improve the Service and market the Controller’s own services where legally permitted.
5. Marketing communications
Marketing information may be sent on the basis of consent or where permitted for the Controller’s own services. Consent may be withdrawn at any time without affecting processing carried out before withdrawal.
6. Recipients and processors
Data may be shared with hosting and maintenance providers, analytics and marketing providers within the scope of granted consent, payment providers, IT and security providers and public authorities entitled to receive it by law. Processing may be entrusted under appropriate data processing agreements.
7. Main technical providers
| Provider | Processing location | Purpose |
|---|---|---|
| OVHcloud | Warsaw, Poland | Hosting and Service infrastructure |
| Przelewy24 / PayPro S.A. | European Union, Poland | Online payments |
| Google — GA4, Tag Manager and Google Ads | May involve transfers outside the EEA | Analytics, measurement and advertising; transfer safeguards include SCCs where required |
| Meta — Meta Pixel | May involve transfers outside the EEA | Advertising measurement and remarketing |
| Microsoft Clarity | United States | Behavior analytics, heat maps and session recordings |
| OpenAI API | May involve transfers outside the EEA | AI and language-model functionality; transfers are governed by relevant contractual safeguards |
| Controller-operated SMTP server | Poland / European Union | Transactional and system email |
If a newsletter is launched, the Controller may use MailerLite or a self-hosted Mautic installation and will update this Policy accordingly.
8. AI and language-model processing
The Service uses external APIs for AI functionality. Workflows are designed to avoid sending personal data to a model and to transmit only the information required to prepare the requested materials, such as aggregated SEO reports and product or content data. Users should not include personal data in content sent to AI unless it is necessary and lawful. Relevant international transfers are protected using mechanisms such as standard contractual clauses or an applicable adequacy decision.
9. Retention
- Account and Project data is retained while the Services are provided and normally for up to 30 days after Account deletion for technical and export processes;
- after the Agreement ends, supported data exports may remain available for 30 days;
- accounting and billing data is retained for the period required by law, normally at least five years;
- technical logs are retained only as long as necessary for security and diagnostics.
10. User rights
Subject to applicable conditions, the User has the right to access, rectify and erase data, restrict processing, receive portable data, object to processing based on legitimate interests, withdraw consent and lodge a complaint with the President of the Polish Personal Data Protection Office.
Data requests may be sent to contact@seoassistant.pro.
11. No anonymous Account use
The Services cannot be used anonymously or under a pseudonym because an Account is required.
12. Transfers outside the EEA
Google, Meta, Microsoft and OpenAI services may involve transfers outside the European Economic Area. Transfers are made using GDPR mechanisms such as standard contractual clauses or an applicable adequacy decision.
III. Cookies and similar technologies
1. What cookies are
Cookies are small text files stored on a User’s device. The Service uses cookies and similar identifiers for essential operation, analytics and marketing.
2. Purposes
- Essential: session handling, authentication and security;
- Analytics: Service statistics and improvement, including GA4 and Clarity;
- Marketing: advertising measurement and remarketing, including Google Ads and Meta Pixel;
- Functional: operation of selected Service components.
3. Tools
The Service may use Google Analytics 4, Google Tag Manager, Google Ads, Meta Pixel and Microsoft Clarity. Microsoft Clarity data may be stored in the United States.
4. Consent settings
The Service provides a consent management mechanism. Users may accept or reject optional categories and change their settings later through the available cookie settings control.
5. Browser settings
Cookies may also be managed through browser settings. Blocking essential cookies may prevent authentication, session persistence or other parts of the Service from working correctly.
IV. Security
The Controller applies technical and organizational safeguards appropriate to the risk, including access controls, encrypted transmission, backups and server security measures.
V. Final provisions
- This Policy may be updated where law, regulatory guidance, Service functionality or the providers used by the Service change.
- Changes will be published through the Service and apply from the date stated in the updated version.