This policy explains what personal data AutomateSEO collects, why, who we share it with, how long we keep it, and the rights you have over it.
Who we are. Darran Goulding, a sole trader established in the United Kingdom, trading as Digital Visibility and as AutomateSEO, of 235 Peniel Green Road, Llansamlet, Swansea, Wales, SA7 9BA. We are the controller of the personal data described in this policy.
Contact for privacy matters: privacy@automateseo.app
We are not required to appoint a Data Protection Officer. Privacy questions are handled by our named privacy contact at the address above.
1. Two different roles
It matters which hat we are wearing:
- We are the controller of data about you as our customer — your account, your billing, your use of the platform. That is what this policy covers.
- We are a processor for personal data you put into the platform — for example names and contact details in your business profile, author biographies, spokesperson likenesses, or personal data contained in content you generate or in pages we crawl from your own site. For that data you are the controller and we act on your instructions under our Data Processing Agreement.
2. Data we collect
2.1 You give us
| Data | Examples |
|---|---|
| Account | Email address, name, password hash (or Google sign-in identifier) |
| Business profile | Business name, website, industry, services, locations, target audience, brand voice, contact details |
| Content inputs | Keywords, topic briefs, RSS feed URLs, prompts, uploaded images, author profiles |
| Likeness and voice | Spokesperson photos and voice samples, where you use avatar or video features |
| Connection credentials | API keys, OAuth tokens and webhook secrets for platforms you connect — always encrypted at rest |
| Billing | Name, email, billing address and country. Card details go directly to Stripe; we hold only the last four digits and a token |
| Support | Anything you tell us in an email or support conversation |
2.2 We generate or collect automatically
| Data | Examples |
|---|---|
| Usage | Features used, articles generated, credit transactions, job status and error logs |
| Generated content | Articles, images, audio, video and social posts produced in your account |
| Technical | IP address, browser and device type, timestamps, request paths — in server and edge logs |
| Authentication | Session cookies, login timestamps, sign-up attempt records used for abuse prevention |
| Affiliate attribution | Referral code and click timestamp, if you arrive through an affiliate link |
2.3 We collect from third parties
- Stripe — payment outcome, subscription status, chargeback and refund events.
- Connected Platforms — page names, account identifiers, profile images and performance metrics from platforms you connect (Google Search Console, Facebook, LinkedIn and others).
- Search and SEO data providers — ranking, backlink and competitor data associated with domains you have asked us to track.
We do not buy personal data from data brokers.
3. Why we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Creating and running your account; generating and publishing content you request | Contract — Article 6(1)(b) |
| Taking payment, managing credits and subscriptions | Contract — Article 6(1)(b) |
| Sending service emails (job completion, failures, billing, security, changes to terms) | Contract — Article 6(1)(b) |
| Providing support | Contract — Article 6(1)(b) |
| Keeping the platform secure; preventing fraud, abuse and credit-limit circumvention | Legitimate interests — Article 6(1)(f): protecting our service and our customers |
| Diagnosing faults and improving reliability and quality using aggregated usage data | Legitimate interests — Article 6(1)(f): running and improving a service you have chosen to use |
| Affiliate attribution and commission payment | Legitimate interests — Article 6(1)(f), and contract with the affiliate |
| Marketing emails to existing customers about similar features | Legitimate interests — Article 6(1)(f), with an opt-out in every message |
| Marketing emails to people who are not customers | Consent — Article 6(1)(a) |
| Meeting accounting, tax and other legal obligations | Legal obligation — Article 6(1)(c) |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights. You can object at any time (see section 9).
Special category data. Voice samples and facial images used for avatar or spokesperson video may constitute biometric data when processed to identify or recreate a specific individual. We process this only on your instruction and only to deliver the feature you requested. If the likeness belongs to a real person, you are responsible for obtaining that person's explicit consent before uploading it.
4. AI processing — what happens to your content
Generating an article, image, or video sends your prompt, business profile context and research material to the AI providers listed on our Subprocessors page.
- Your data is not used to train anyone's models. We use commercial API tiers under which customer inputs and outputs are excluded from model training by default.
- Providers may retain inputs briefly for abuse monitoring — typically up to 30 days — before deletion, under their own published terms.
- We do not use your content to train our own models, and we do not use one customer's content to generate another customer's content.
Automated decision-making. The platform makes automated choices about content — topics, structure, wording, which links to insert, when to publish. These decisions concern content, not people, and produce no legal or similarly significant effect on any individual within the meaning of Article 22. No profiling of individuals for decisions about them is carried out.
5. Who we share it with
- Subprocessors — the providers listed on our Subprocessors page, each under a written data processing agreement.
- Connected Platforms — where you have authorised publishing, we send content and credentials to those platforms at your direction.
- Professional advisers — accountants, auditors and lawyers, bound by confidentiality.
- Authorities — where required by law, court order or a valid regulatory request. We will tell you unless legally prohibited.
- A buyer — if we sell or reorganise the business, under confidentiality obligations. We will notify you before your data becomes subject to a different privacy policy.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
We are UK-based. Some subprocessors are in the United States. Where personal data leaves the UK or EEA we rely on:
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the IDTA, for UK transfers; and
- the EU Standard Contractual Clauses (2021/914) for EEA transfers; and
- the EU–US Data Privacy Framework where the recipient is certified;
together with a transfer risk assessment, and encryption in transit and at rest.
Our EU-hosted subprocessors — n8n GmbH (Germany) and DataForSEO OÜ (Estonia) — involve no international transfer.
You may request a copy of the safeguards we rely on from privacy@automateseo.app.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and business profile | While your account is open, then deleted within 30 days of account deletion |
| Articles, media and generated content | While your account is open, then deleted within 30 days of account deletion |
| Seed articles from RSS feeds | Automatically deleted after 3 days unless you save them |
| Connection credentials and tokens | Deleted immediately when you disconnect the integration or delete your account |
| Credit transactions and invoices | 6 years from the end of the relevant financial year — required by UK tax and company law |
| Security, abuse and sign-up attempt logs | 12 months |
| Server and edge logs | 30 days |
| Support correspondence | 24 months after the ticket closes |
| Encrypted backups | Purged on a rolling 90-day cycle; deleted records disappear from backups within that window |
| Marketing suppression list (so we do not email you again) | Indefinitely — this is the record of your opt-out |
8. Security
We protect your data with encryption in transit (TLS) and at rest, AES-256-GCM encryption of all third-party credentials, row-level security in the database, role-based access controls, least-privilege service credentials, and rate limiting. Our full Security Statement has the detail, including how we handle incidents.
If a breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell you without undue delay where the risk is high.
9. Your rights
Under UK and EU GDPR you have the right to:
- Access — get a copy of your personal data;
- Rectification — have inaccurate data corrected;
- Erasure — have your data deleted (see Data Deletion and Export);
- Restriction — have processing paused while a dispute is resolved;
- Portability — receive data you gave us in a machine-readable format, or have it sent to another provider;
- Object — object to processing based on legitimate interests, and to direct marketing at any time, absolutely;
- Withdraw consent — where we rely on consent, without affecting past processing;
- Not be subject to solely automated decisions with legal or similarly significant effects.
How to exercise them. Use the self-serve export and delete tools in Settings → Data and Privacy, or email privacy@automateseo.app. We respond within one month and will not charge you. We may extend by two further months for complex requests, and will tell you if we do. We may ask you to confirm your identity.
Complaints. If you are unhappy with how we have handled your data, please tell us first. You can also complain to the UK Information Commissioner's Office at ico.org.uk (helpline 0303 123 1113), or to the supervisory authority in your EU country of residence.
10. If you are in California
You have the right to know what personal information we collect, to delete it, to correct it, to opt out of sale or sharing, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. The categories we collect and our retention periods are set out in sections 2 and 7. Exercise your rights at privacy@automateseo.app.
11. Cookies
We use a small number of strictly necessary cookies and browser storage keys, and no advertising or third-party analytics trackers. Everything we set is itemised in our Cookie and Local Storage Policy.
12. Children
The Service is for business use and is not directed at children. You must be 18 or over to hold an account. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, email privacy@automateseo.app and we will delete it.
13. Changes to this policy
We will update this page when our practices change and revise the "last updated" date. For changes that materially affect how we use your data, we will give at least 30 days' notice by email or in-app before they take effect.
14. Contact
Darran Goulding, trading as Digital Visibility and as AutomateSEO 235 Peniel Green Road, Llansamlet, Swansea, Wales, SA7 9BA, United Kingdom Sole trader — no company registration number
Privacy contact: privacy@automateseo.app Security reports: security@automateseo.app