Help / Security & compliance / Security & privacy
Security & privacy
For everyone (and their lawyers) · ~4 min read · Last reviewed 22 July 2026
The short version for your due-diligence checklist. Every claim below links to the document that actually governs it — this page summarises, the documents decide.
Where and how your data is kept
- Your data is stored and processed in Finland (EU).
- Google Search Console tokens are stored encrypted at the database level. The Search Console scope is read-only — SeoKestrel cannot change anything on your site or in your Search Console.
- New passwords are screened against known breach datasets, and repeated failed sign-ins lock the account temporarily.
- Administrative actions are recorded in an audit log (Settings → Audit log, visible to admins).
- Your consent choices (terms, privacy, marketing, cookies) are recorded with their full history and manageable under Settings → Privacy.
- Data-subject rights — export and deletion — are handled via Settings → Privacy / Data requests.
- Third-party processors and their regions are listed publicly on the sub-processors page.
Operational security
- Security incidents are tracked in a dedicated incident register (Settings → Incidents, admin-only) through detection → containment → notification, in line with our NIS2 obligations — significant incidents are reported to the national authority within 24 hours.
- Personal API keys (Settings → API keys) are shown once at creation, stored only as a hash, and revocable at any time. Treat them like passwords; revoke immediately if one leaks.
- Crawl data is supplied by SeoSwift, a separate product, over a server-to-server channel: only crawl-derived results cross that boundary. Your Google credentials are never shared with SeoSwift.
The documents
- Terms of Service — the agreement governing use of the platform.
- Privacy Policy — what personal data is processed, why, and for how long.
- Cookie Policy — what is set in your browser (spoiler: very little).
- Data Processing Agreement — for agencies processing client data under GDPR.
- Sub-processors — who else touches the data, and where they are.
Good to know
If your client’s procurement team sends a security questionnaire, the five links above answer most of it. For anything they cover differently, the linked documents — not this summary — are authoritative.
FAQ
- Is my data used to train AI models?
- See the Privacy Policy for the authoritative answer on data use — the summary here is deliberately not the contract.
- How do I delete my account and data?
- Settings → Privacy → submit a data request. Timelines and scope are defined in the Privacy Policy.
- Who can see the audit log?
- Admins — and future-you during an incident review, gratefully.