Privacy Policy & GDPR
Compliance commitments, personal data collection and exercising your individual rights.
Compliance Commitment & General Principles
This Privacy Policy informs you about how your personal data is collected, processed and protected by SeoLytix.com (SIRET: 751 650 227 00026), pursuant to EU Regulation 2016/679 (GDPR) and applicable data protection legislation.
We commit to respecting core data protection principles: lawfulness, fairness, transparency, purpose limitation, data minimization and enhanced security.
Personal Data Collected
We only collect data strictly necessary for our services to function properly:
- Identity data: Full name, email address, account ID and password (encrypted).
- Usage and analytics data: Analyzed site URLs, SEO audit history, domain monitoring parameters.
- Billing data: Transaction history, billing address, VAT number (payment details are exclusively processed and encrypted by Stripe certified PCI-DSS Level 1; we store no banking data).
- Technical connection data: IP address, browser type, access logs (for security and abuse prevention).
Purposes and Legal Bases of Processing
Every data processing activity is based on a lawful ground:
| Processing Purpose | Legal Basis (GDPR) |
|---|---|
| Provision of SEO tools, audit generation and account management | Performance of a contract (Art. 6.1.b) |
| Billing, accounting and subscription management | Legal obligation (Art. 6.1.c) |
| Site security, fraud prevention and anti-DDoS | Legitimate interest (Art. 6.1.f) |
| Sending notifications, alerts and customer support | Consent / Contract performance |
Data Retention Period
Your data is retained only for the time necessary to fulfill the purposes for which it was collected:
- Account data: Throughout the active account lifespan, deleted upon request.
- Audit and report history: According to your plan retention limit (or manual user deletion).
- Accounting data and invoices: 10 years pursuant to legal commercial code requirements.
Recipients and Approved Sub-processors
SeoLytix.com does not sell, rent or transfer any personal data for advertising purposes.
Data may be transmitted securely to technical sub-processors exclusively for service delivery: OVH SAS (servers located in France / EU), Stripe Inc. secure payment gateway (PCI-DSS Level 1), and transactional email services.
Your Rights Under the GDPR
In accordance with Articles 15 to 22 of the GDPR, you have the following rights:
Right of Access
Obtain confirmation and a complete copy of held personal data.
Right of Rectification
Modify or correct inaccurate data directly from your account.
Right to Erasure
Request permanent deletion of your account and data ("right to be forgotten").
Right to Data Portability
Export your data and audit reports in a structured, readable format (JSON/CSV/PDF).
Security and Technical Measures
We implement all necessary technical and organizational measures to protect your data:
- 256-bit SSL/TLS encryption applied to all communications.
- Strong password hashing (irreversible cryptographic algorithms Bcrypt/Argon2).
- Anti-CSRF tokens on all forms to prevent fraudulent submissions.
- Protection against brute-force attacks and automatic suspicious activity detection.
Cookies and Trackers
The platform uses essential technical cookies for service operation (session maintenance, language preferences, security tokens). You can adjust your consent preferences at any time.
DPO Contact & Complaints to Supervisory Authority
For questions regarding this policy or to exercise your rights, contact our Data Protection Officer:
If you feel your rights are not respected after contacting us, you have the right to lodge a complaint with the CNIL on www.cnil.fr.