SEOmise

Legal

Privacy policy

Effective from 6 October 2026

This policy explains what personal data we collect when you visit seomise.com or use SEOmise, why we use it, who we share it with, how long we keep it and the rights you have. It is written to meet the EU General Data Protection Regulation (GDPR) and, where it applies, the UK GDPR.

1. Who we are

SEOmise is operated by SEOmise.

For anything about your personal data, contact us by the contact details shown when you sign in.

2. When we are controller and when we are processor

  • Controller. We decide how and why your account, billing and security data is used, and data about visitors to this website. This policy covers that data.
  • Processor. The websites, Google Business Profiles, reviews, backlink data and other content a customer adds to a workspace belong to that customer. We process it only on the customer's instructions to provide the service. If you are a reviewer or a visitor to one of our customers' sites, the customer is the controller and you should contact them first; we will help them respond.

3. What we collect

  • Account data: your name, e-mail address, workspace name, role, password (stored only as a one-way hash), two-step sign-in settings and recovery codes (also hashed), and the date you last signed in.
  • Billing data: your plan, billing period, subscription status, invoices and the customer reference held by our payment provider. Card details are entered on the payment provider's own pages and never reach our servers.
  • Project data: the websites and competitors you add, scan results, backlink and authority data, and, if you connect them, Google Business Profile and Search Console data such as locations, reviews, posts and performance figures.
  • Activity and security data: an audit log of security-relevant actions (sign-ins, role changes, approvals, settings changes) and an action timeline per project. IP addresses are stored only as a keyed hash, which lets us link events together without keeping the address itself.
  • Messages: e-mails you send us and our replies.

We collect this data from you, from people in your workspace who invite you or change your role, from the services you connect, and from our payment provider. We do not buy personal data and we do not use it for advertising.

4. Why we use it and our legal basis

PurposeLegal basis (GDPR Article 6)
Creating and running your account and workspace, and providing the features you usePerformance of our contract with you
Taking payment, issuing invoices and keeping accounting recordsContract, and our legal obligations under tax and company law
Service e-mails: invitations, password resets, alerts, reports you scheduleContract
Keeping the service secure: two-step sign-in, rate limits, the audit log, investigating misuseOur legitimate interest in protecting the service and our customers
Fixing errors and improving how the service worksOur legitimate interest in a reliable product
Answering your questions and requestsContract, or our legitimate interest in replying
Complying with lawful requests from authoritiesLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights and kept the data to what is needed. You can object at any time (see section 9).

5. Reviews and AI

Google reviews can contain reviewers' names and opinions. We keep only what is needed to show, analyse and reply to them. AI features run only when someone in a workspace asks for them, and the result is always a draft for a person to approve. When they run, only the text needed for the task is sent to the AI provider listed below. Under that provider's commercial terms, data sent through its API is not used to train its models.

6. Who we share it with

We use the following service providers (sub-processors). This list is generated from the services that are switched on in this installation, so it is always current; a provider appears here only while it is configured.

No external service providers are switched on at the moment: everything runs on the servers that host SEOmise.

Each provider acts on our instructions under a data processing agreement. We may also disclose data where the law requires it, to protect our rights, or to a buyer of our business, who would be bound by this policy. We never sell personal data.

7. Transfers outside the EEA and the UK

Some providers above process data outside the European Economic Area or the United Kingdom. When they do, the transfer is protected by an adequacy decision (for example the EU–US Data Privacy Framework for certified US companies) or by the European Commission's Standard Contractual Clauses, with the UK addendum where UK data is involved. You can ask us for a copy of the safeguards using the contact details in section 1.

8. How long we keep it

  • Account and project data: while your workspace exists. When a project is deleted, its scans, issues, backlink data and timeline are deleted with it.
  • Scan history: older scans are deleted automatically every day according to your plan. Workspaces without a plan keep scan history for 10 years. The Day 0 baseline (your first scan) and the most recent scan of every site are always kept while the project exists, so you can see progress from the start.
  • Audit log: kept for the life of the workspace. It is append-only, so entries are never edited, and IP addresses in it are keyed hashes.
  • Billing records: invoices and payment records are kept for as long as tax and company law requires, even after a workspace is closed.
  • Sessions: sign-in sessions end when you sign out or after a period of inactivity.

To close a workspace and have its data deleted, an owner can contact us by the contact details shown when you sign in. We delete it within 30 days, except billing records we must keep.

9. Your rights

You have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to our use of it, and to receive the data you gave us in a portable format. You can update your name, e-mail address, password and two-step sign-in yourself under Account. For anything else, contact us by the contact details shown when you sign in; we answer within one month and may ask you to confirm your identity first.

If you are unhappy with how we handle your data, please tell us so we can put it right. You also have the right to complain to the Data Protection Commission (DPC) (dataprotection.ie), or to the supervisory authority where you live or work.

10. How we protect it

Data is encrypted in transit (HTTPS). Passwords and recovery codes are hashed; API keys and connection tokens are encrypted at rest. Access inside a workspace is limited by role, two-step sign-in is available to every user and required for platform administrators, and support access to a workspace needs a recorded reason. The security page has more detail.

11. Cookies

We use only the cookies needed to keep you signed in and to protect forms: a session cookie and a security (CSRF) cookie. They are strictly necessary, so no consent banner is needed. We do not use advertising, analytics or other third-party tracking cookies.

12. Children

SEOmise is a business service and is not meant for anyone under 16. We do not knowingly collect children's data.

13. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we use your data, we tell workspace owners by e-mail before it applies.