1. Who is responsible
The data controller for personal data processed through the Aseoma website and application (the Service) is Aseoma, (to be published), registration number (to be published) (Aseoma, we).
Privacy requests: [email protected]. We have not appointed a Data Protection Officer because our processing does not require one under Article 37 GDPR; the mailbox above is monitored by the people responsible for data protection.
This policy applies to visitors of our website and to users of the Service. Where you use the Service on behalf of an organisation and enter data about other people (for example when you connect a Google Search Console property), that organisation is the controller of that data and we act as its processor under our Terms and Data Processing Agreement.
2. What data we collect
Account data
Name, email address, password hash, organisation name, role, locale, two-factor authentication secrets and recovery codes (encrypted), invitations you send, and the time of registration and last sign-in.
Billing data
Subscriptions are sold by Paddle as Merchant of Record. Paddle collects your name, billing address, VAT ID, payment method and transaction history under its own privacy policy. We receive only what we need to operate your subscription: customer and subscription identifiers, plan, status, invoice numbers, amounts and the country used for tax. We never receive or store full card numbers.
Usage and technical data
Server logs with IP address, user agent, timestamps, requested URLs and response codes; security events such as failed sign-ins; feature usage and credit ledger entries; and error reports. Logs are used to keep the Service secure and working.
Customer Data you enter
Domains, keywords, URLs, competitors, tags, notes, alert settings, notification channels (for example a Slack webhook or a Telegram chat ID) and the reports generated from them. Most of this is not personal data. If you connect Google Search Console we store an encrypted OAuth refresh token and the query, page, click and impression data Google returns for the properties you selected.
Communications
Emails and support messages you send us, including attachments, and our replies.
3. Why we process it and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service: account, projects, rank checks, reports, alerts | Account data, Customer Data, usage data | Performance of a contract (Art. 6(1)(b)) |
| Billing, invoicing, tax compliance, fraud prevention at checkout | Billing data | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, debugging, backups | Technical data, logs | Legitimate interest (Art. 6(1)(f)) in a secure and reliable service |
| Transactional email: verification, password reset, invoices, alerts you set | Email address, name | Contract (Art. 6(1)(b)) |
| Product news and onboarding tips | Email address | Legitimate interest for existing customers (Art. 6(1)(f)) with an unsubscribe link in every message; consent otherwise (Art. 6(1)(a)) |
| Support and answering your requests | Communications | Contract or legitimate interest |
| Product analytics (aggregated feature usage) | Pseudonymous usage events | Legitimate interest; no advertising profiles are built |
We do not sell personal data and do not use it for automated decision-making with legal or similarly significant effects.
6. International transfers
Our servers are in the European Union. Some providers listed above are established or process data outside the EEA (for example Paddle in the United Kingdom and the United States, DataForSEO in the United States). For those transfers we rely on the European Commission’s adequacy decisions where they exist (United Kingdom; EU-US Data Privacy Framework for certified US companies) and otherwise on the Standard Contractual Clauses with additional safeguards. Copies of the relevant clauses are available on request.
7. How long we keep data
- Account and Customer Data: for the life of the Workspace, then 30 days in read-only mode after cancellation or deletion, then deleted from live systems. Encrypted backups are retained for up to 35 additional days.
- Rank history and Search Console data: for the history period of your plan; older data is aggregated or deleted.
- Billing records: as long as tax and accounting law requires, typically 7 to 10 years, held mainly by Paddle.
- Server and security logs: 90 days, unless needed for an ongoing investigation.
- Support correspondence: 2 years after the last message.
8. Security
Data is encrypted in transit (TLS) and at rest on the storage volumes. Passwords are stored using a modern slow hash; OAuth tokens and notification secrets are encrypted at the application level with keys kept outside the database. Access to production systems is limited to named staff with SSH keys and two-factor authentication and is logged. Each Workspace is isolated at the database level by row-level security. We review dependencies and container images for known vulnerabilities and keep backups in a separate location. No method of transmission or storage is completely secure; if we learn of a breach affecting your data we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased where there is no longer a lawful basis to keep it;
- restrict processing while a dispute about accuracy or lawfulness is resolved;
- receive the data you provided in a machine-readable format (portability);
- object to processing based on legitimate interests, including direct marketing at any time;
- withdraw consent, where processing is based on consent, without affecting prior processing;
- lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or workplace. Our lead authority is (to be published).
To exercise a right, email [email protected] from the address linked to your account, or use the export and delete functions in Settings. We answer within one month and may ask for information to verify your identity. Requests are free unless they are manifestly unfounded or excessive.
10. Google API Services
Aseoma’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Search Console data is used only to show your own performance reports inside the Service and to combine them with your rank-tracking data; it is not used for advertising and is not shared with third parties except the hosting provider that stores it. You can revoke access at any time in the project settings or at myaccount.google.com/permissions.
11. Children
The Service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy when our processing, providers or the law change. The date at the top shows the current version. For material changes we notify registered users by email or in the app before the change takes effect.
13. Contact
Aseoma, (to be published). Privacy requests: [email protected]. General enquiries: [email protected]. See also the contact page.
Questions about this document: [email protected]. See also our Terms, Privacy Policy and Refund Policy.