Privacy Policy
Version 1.0 · Effective 3 June 2026
This Privacy Policy explains how SeoKestrel (“we”, “us”) processes personal data when you use our SEO analytics platform at seokestrel.com. We are the data controller for your account data and a data processor for the SEO data we handle on behalf of our business customers.
1. Who we are
SeoKestrel is operated as an EU-sovereign service. All production data is stored and processed in the European Union (Hetzner, Finland). Contact: [email protected].
2. What data we collect
- Account data: name, email address, role, and authentication data (password hashes, OAuth identifiers, optional 2FA secrets).
- Usage & security data: audit logs of sensitive actions, including IP address and user agent, retained for security (NIS2).
- SEO data: aggregate metrics about your websites (rankings, traffic, Core Web Vitals) obtained via connected providers. This is non-identifying.
3. Why we process it (lawful basis, GDPR Art. 6)
- Contract (Art. 6(1)(b)): account data necessary to provide the service.
- Legal obligation (Art. 6(1)(c)): audit logs required under NIS2.
- Legitimate interest (Art. 6(1)(f)): essential cookies and platform security.
- Consent (Art. 6(1)(a)): analytics & marketing cookies and marketing emails — opt-in only, withdrawable anytime.
4. How long we keep it
- Active account data: until you delete your account.
- Deleted accounts: 30-day grace period, then permanent erasure.
- Audit logs: 7 years (NIS2), then archived and deleted after 10 years.
- Session records: 90 days after expiry.
5. Who we share it with
We use a short, vetted list of sub-processors, all EU-based except a CDN/WAF (data in transit only) and DevOps tooling that never touches customer data. See our Sub-processors page.
6. Your rights (GDPR Art. 15–22)
- Access & portability: export all your data as JSON/CSV.
- Rectification: edit your profile, or request admin correction.
- Erasure: delete your account with a 30-day grace period.
- Restriction & objection: withdraw consent in Settings → Privacy.
Self-service tools live in Settings → Privacy. You may also lodge a complaint with your national supervisory authority.
7. International transfers
Personal data is processed within the EU/EEA. Where a sub-processor operates outside the EEA (e.g. CDN edge), transfers rely on Standard Contractual Clauses and are limited to data in transit.
8. Changes
When we materially change this policy we bump its version and re-prompt signed-in users to accept the new version.