§Legal

    GDPR Data Protection Policy

    Your rights under EU data protection law, and our GDPR commitments.

    Last updated January 2026

    EU Data Protection Commitment

    JustSEO.ai is fully committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable EU data protection laws.

    For EU customers: All your personal data is processed and stored exclusively on servers physically located within the European Union. We do not transfer EU personal data outside the EU/EEA without appropriate safeguards.

    1. Data Controller Information

    The data controller responsible for your personal data is:

    Company: Basecamp Labs, Inc (JustSEO.ai)

    Email: privacy@justseo.ai

    GDPR Contact: dpo@justseo.ai

    2261 Market Street STE 18268, San Francisco, CA 94114, United States

    We act as the data controller for personal data collected through our Service. In some cases, we may also act as a data processor on behalf of our customers who use our Service to analyze their websites.

    2. Legal Basis for Processing Personal Data

    Under GDPR Article 6, we process your personal data based on the following legal grounds:

    a) Contractual Necessity (Article 6(1)(b))

    Processing is necessary to perform our contract with you, including:

    • Creating and managing your account
    • Providing SEO analysis, crawling, and reporting services
    • Processing payments and managing subscriptions
    • Delivering customer support
    • Fulfilling our obligations under the Terms of Service

    b) Legitimate Interests (Article 6(1)(f))

    Processing is necessary for our legitimate business interests, including:

    • Improving and optimizing our Service
    • Analyzing usage patterns and user behavior
    • Preventing fraud, abuse, and security threats
    • Marketing our services to existing customers
    • Conducting business analytics and research

    We have balanced our legitimate interests against your rights and freedoms and determined that processing is necessary and proportionate. You have the right to object to processing based on legitimate interests.

    c) Consent (Article 6(1)(a))

    For certain processing activities, we obtain your explicit consent:

    • Marketing communications to non-customers
    • Optional cookies and tracking technologies (beyond strictly necessary)
    • Sharing data with third-party integrations you authorize
    • Processing special categories of personal data (if applicable)

    You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

    d) Legal Obligation (Article 6(1)(c))

    Processing is necessary to comply with legal obligations, including:

    • Tax and accounting requirements
    • Financial regulations and payment processing laws
    • Response to lawful requests from authorities
    • Compliance with court orders or legal processes

    3. Personal Data We Collect

    a) Account and Identity Data

    • Registration Information: Name, email address, password (encrypted), account preferences
    • Authentication Data: Login credentials, two-factor authentication tokens, OAuth tokens (if using Google sign-in)
    • Profile Information: Display name, avatar image, bio, user preferences

    b) Payment and Billing Data

    • Payment Information: Processed by our payment provider (Stripe) - we do not store full credit card details
    • Billing Details: Billing address, VAT number (if applicable), invoice history, subscription status
    • Transaction Records: Payment dates, amounts, payment methods, refund information

    c) Usage and Service Data

    • Analysis Data: URLs submitted for analysis, website content crawled, SEO reports generated, crawl results
    • Project Data: Projects created, tracked URLs, project settings, integration configurations
    • Usage Metrics: Features used, frequency of use, subscription plan, account activity logs

    d) Technical and Device Data

    • Device Information: Browser type and version, operating system, device type
    • Connection Data: IP address, ISP, approximate geographic location (country/city level)
    • Log Data: Access times, pages viewed, errors encountered, API requests
    • Cookies and Tracking: Session cookies, authentication tokens, analytics cookies (with consent)

    e) Communications Data

    • Support Tickets: Messages, attachments, support interactions, ticket history
    • Contact Forms: Name, email, subject, message content from contact forms
    • Email Communications: Emails sent and received, notification preferences

    f) Third-Party Integration Data

    • Google Search Console: OAuth tokens, property data, analytics data (with your authorization)
    • Slack: Workspace IDs, channel information, notification preferences (with your authorization)
    • Other Integrations: Data from third-party services you explicitly connect

    4. How We Use Your Personal Data

    We process your personal data for the following purposes:

    Service Delivery and Performance

    • Creating and managing your user account
    • Authenticating your identity and authorizing access
    • Performing SEO analysis, website crawling, and generating reports
    • Storing and presenting analysis results
    • Processing API requests and integrations
    • Providing customer support and responding to inquiries

    Billing and Payments

    • Processing subscription payments and managing billing
    • Generating invoices and receipts
    • Handling refunds and chargebacks
    • Preventing payment fraud
    • Complying with tax and financial regulations

    Service Improvement

    • Analyzing usage patterns to improve features and performance
    • Conducting research and development for new features
    • Testing and debugging the Service
    • Training AI models on aggregated, anonymized data
    • Optimizing user experience and interface design

    Security and Fraud Prevention

    • Detecting and preventing security threats, fraud, and abuse
    • Monitoring for unusual or suspicious activity
    • Enforcing Terms of Service and acceptable use policies
    • Protecting our rights, property, and safety
    • Investigating and responding to security incidents

    Communications

    • Sending transactional emails (account notifications, password resets, subscription updates)
    • Providing customer support and responding to inquiries
    • Sending service announcements and important updates (required communications)
    • Sending marketing communications (with consent, where required)
    • Conducting user surveys and feedback requests (optional)

    Legal and Compliance

    • Complying with legal obligations and regulations
    • Responding to lawful requests from authorities
    • Establishing, exercising, or defending legal claims
    • Enforcing our Terms of Service and policies
    • Maintaining records for audit and compliance purposes

    5. Data Sharing and Disclosure

    We do not sell your personal data to third parties. We only share your personal data in the limited circumstances described below:

    a) Service Providers (Data Processors)

    We engage trusted third-party subprocessors who process personal data on our behalf under strict data processing agreements (GDPR Article 28). Your primary account, project, and report data is stored in the EU (Supabase, West EU / Ireland); some processing takes place in the US under the EU Standard Contractual Clauses (SCCs). Our current subprocessors are:

    SubprocessorPurposeLocationTransfer mechanism
    SupabasePrimary database, authentication, and file storage (account, project, and report data)European Union (West EU / Ireland)Stored in the EU
    VercelApplication hosting and content delivery for the web app and marketing siteUnited StatesEU Standard Contractual Clauses
    RailwayBackground workers and the AI API service that run analysesUnited StatesEU Standard Contractual Clauses
    StripePayment processing and subscription managementUnited States / globalEU Standard Contractual Clauses
    PostHogProduct analytics (with consent)United StatesEU Standard Contractual Clauses
    SentryApplication error monitoring and loggingUnited StatesEU Standard Contractual Clauses
    OpenAIAI analysis and AI share-of-voice trackingUnited StatesEU Standard Contractual Clauses
    GoogleGemini AI analysis / share-of-voice and PageSpeed performance dataUnited StatesEU Standard Contractual Clauses
    AnthropicClaude AI analysis and AI share-of-voice trackingUnited StatesEU Standard Contractual Clauses
    PerplexityAI share-of-voice trackingUnited StatesEU Standard Contractual Clauses
    DeepSeekAI report generationUnited StatesEU Standard Contractual Clauses
    DataForSEOSearch ranking and keyword dataUnited StatesEU Standard Contractual Clauses

    All service providers are:

    • Bound by data processing agreements ensuring GDPR compliance
    • Required to implement appropriate security measures
    • Prohibited from using your data for their own purposes
    • Selected based on their security practices and GDPR compliance

    b) Integrations You Authorize

    When you explicitly authorize integrations with third-party services:

    • Google Search Console: We access GSC data via OAuth with your explicit authorization
    • Slack: We send notifications to your Slack workspace when you enable the integration
    • Other Integrations: Data sharing occurs only with services you explicitly connect

    You control these integrations and can revoke access at any time through your account settings.

    c) Legal Requirements and Protection

    We may disclose personal data when required or permitted by law:

    • To comply with legal obligations, court orders, or legal processes
    • To respond to lawful requests from law enforcement or government authorities
    • To protect our rights, property, or safety, or that of our users or the public
    • To detect, prevent, or address fraud, security, or technical issues
    • To enforce our Terms of Service or investigate potential violations

    d) Business Transfers

    In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of the transaction. We will notify you of any such change and provide choices regarding your data where applicable.

    e) Aggregated and Anonymized Data

    We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This data is not subject to GDPR restrictions as it is not personal data.

    6. International Data Transfers

    EU Data Residency

    For users located in the European Union: Your personal data is processed and stored exclusively on servers physically located within the European Union. This ensures your data remains under EU data protection laws at all times.

    Third-Party Services

    Some third-party service providers (such as AI model providers) may process data outside the EU/EEA. When transferring personal data internationally, we ensure appropriate safeguards are in place:

    • Standard Contractual Clauses (SCCs): EU-approved model clauses for data transfers (GDPR Article 46(2)(c))
    • Adequacy Decisions: Transfers to countries with EU adequacy decisions (GDPR Article 45)
    • Binding Corporate Rules: For transfers within multinational organizations with approved BCRs
    • Certification Mechanisms: EU-US Data Privacy Framework or similar certifications where applicable

    Your Rights Regarding Transfers

    You have the right to obtain information about safeguards we have implemented for international data transfers. Contact us at dpo@justseo.ai to request copies of relevant safeguard documents.

    7. Data Retention Periods

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes.

    Retention Periods by Data Type

    Data TypeRetention Period
    Account Data (active users)Duration of account + 30 days after deletion
    SEO Reports and Analysis90 days (unless saved to projects)
    Saved ProjectsDuration of account + 30 days after deletion
    Payment Records7 years (legal requirement for tax/accounting)
    Support Tickets3 years after ticket closure
    Log Files (IP, access logs)90 days (rolling)
    Marketing ConsentUntil consent withdrawn or 2 years of inactivity
    Legal Claims DataDuration of claim + applicable statute of limitations

    Account Deletion

    When you delete your account:

    • Your account is immediately deactivated
    • Personal data is anonymized or deleted within 30 days
    • Some data may be retained for legal compliance (e.g., payment records)
    • Aggregated, anonymized data may be retained indefinitely
    • Backups are deleted according to our backup retention schedule (maximum 90 days)

    Legal Retention Requirements

    In some cases, we must retain data longer than standard periods to comply with legal obligations such as:

    • Tax and accounting laws (typically 7 years)
    • Anti-money laundering regulations
    • Ongoing legal proceedings or investigations
    • Regulatory requirements applicable to our business

    8. Your Rights Under GDPR

    Under GDPR, you have the following rights regarding your personal data:

    Right of Access (Article 15)

    You have the right to obtain confirmation of whether we process your personal data and access to that data.

    How to exercise: Request a data export through your account settings or contact dpo@justseo.ai

    Right to Rectification (Article 16)

    You have the right to correct inaccurate or incomplete personal data.

    How to exercise: Update your information directly in account settings or contact support

    Right to Erasure / "Right to be Forgotten" (Article 17)

    You have the right to request deletion of your personal data in certain circumstances.

    How to exercise: Use the account deletion feature in settings or contact dpo@justseo.ai

    Note: Some data may need to be retained for legal compliance

    Right to Restriction of Processing (Article 18)

    You have the right to request we limit how we process your data in certain situations.

    How to exercise: Contact dpo@justseo.ai with your request and reasoning

    Right to Data Portability (Article 20)

    You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.

    How to exercise: Request a data export (JSON format) through account settings

    Right to Object (Article 21)

    You have the right to object to processing based on legitimate interests or for direct marketing.

    How to exercise: Contact dpo@justseo.ai or opt out of marketing via email unsubscribe links

    Rights Related to Automated Decision-Making (Article 22)

    You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

    Note: We do not currently make automated decisions with legal effects about users

    Right to Withdraw Consent (Article 7(3))

    Where processing is based on consent, you have the right to withdraw that consent at any time.

    How to exercise: Manage consent settings in your account or contact dpo@justseo.ai

    How to Exercise Your Rights

    To exercise any of these rights:

    • Email our Data Protection Officer at: dpo@justseo.ai
    • Use the data management features in your account settings
    • Submit a written request to our business address

    Response Time

    We will respond to your request:

    • Within one month of receiving your request (GDPR requirement)
    • Within three months if the request is complex or we receive multiple requests (we will inform you within one month)
    • Free of charge (unless requests are manifestly unfounded, excessive, or repetitive)

    Verification

    To protect your privacy, we will verify your identity before fulfilling requests. We may ask you to provide:

    • Proof of identity (government-issued ID)
    • Confirmation of account ownership (access to registered email)
    • Additional verification for sensitive requests

    Right to Lodge a Complaint

    If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority (supervisory authority).

    EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en

    However, we encourage you to contact us first at dpo@justseo.ai so we can attempt to resolve your concern directly.

    9. Data Security Measures

    We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction (GDPR Article 32).

    Technical Security Measures

    • Encryption: All data in transit is encrypted using TLS/SSL protocols (HTTPS)
    • Database Encryption: Personal data at rest is encrypted using industry-standard encryption
    • Password Security: Passwords are hashed using bcrypt with salting (never stored in plain text)
    • Access Controls: Role-based access control (RBAC) and principle of least privilege
    • Authentication: Two-factor authentication (2FA) available for enhanced account security
    • Firewalls: Network-level firewalls and intrusion detection systems
    • Security Monitoring: Continuous monitoring for security threats and anomalies
    • Secure APIs: API authentication, rate limiting, and input validation

    Organizational Security Measures

    • Staff Training: Regular security and privacy training for employees
    • Access Restrictions: Limited employee access to personal data on a need-to-know basis
    • Confidentiality Agreements: All staff and contractors sign confidentiality agreements
    • Data Processing Agreements: All third-party processors are bound by GDPR-compliant agreements
    • Incident Response Plan: Documented procedures for handling data breaches
    • Regular Audits: Periodic security audits and vulnerability assessments
    • Data Minimization: We collect and retain only necessary personal data

    Infrastructure Security

    • EU-Based Hosting: Primary account, project, and report data is stored in the EU (Supabase, West EU / Ireland)
    • Compliance: Our own SOC 2 certification is on our roadmap (we are not yet certified)
    • Redundancy: Provider-managed backups and disaster recovery procedures
    • Access Control: Row-Level Security and least-privilege access to production data

    Data Breach Notification

    In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms:

    • We will notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Article 33)
    • We will notify affected individuals without undue delay if the breach poses a high risk (GDPR Article 34)
    • We will document the breach, its effects, and remedial actions taken
    • We will investigate the cause and implement measures to prevent recurrence

    10. Cookies and Tracking Technologies

    We use cookies and similar tracking technologies to provide and improve our Service. This section explains what cookies we use and your choices regarding them.

    What Are Cookies?

    Cookies are small text files stored on your device when you visit our website. They help us recognize your browser, remember your preferences, and analyze how you use our Service.

    Types of Cookies We Use

    Strictly Necessary Cookies (No consent required)

    Essential for the Service to function. You cannot opt out of these cookies.

    • Authentication and session management
    • Security and fraud prevention
    • Load balancing and performance

    Functional Cookies (Consent-based)

    Enhance your experience by remembering preferences.

    • Language preferences
    • Theme settings (light/dark mode)
    • UI customization preferences

    Analytics Cookies (Consent-based)

    Help us understand how users interact with our Service.

    • PostHog (product analytics, loaded only with consent)
    • Google Tag Manager (tag management, loaded only with consent)
    • Usage statistics and feature adoption

    Your Cookie Choices

    • Cookie Banner: Manage cookie preferences via our cookie consent banner on first visit
    • Account Settings: Update cookie preferences in your account settings at any time
    • Browser Settings: Configure your browser to reject cookies (may affect functionality)
    • Opt-Out Tools: Use browser extensions or opt-out tools for analytics cookies

    Third-Party Cookies

    Third-party services may set their own cookies:

    • PostHog / Google Tag Manager: For product analytics and tag management (with consent)
    • Stripe: For payment processing security
    • OAuth Providers: For social login functionality

    These third parties have their own privacy policies governing how they use cookies.

    11. Children's Privacy

    Our Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16.

    If you are under 16, you may not use the Service or provide any personal data to us. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately at dpo@justseo.ai so we can delete it.

    Under GDPR Article 8, if we learn we have collected personal data from a child under 16 without proper parental consent, we will delete that information as quickly as possible.

    12. Changes to This GDPR Policy

    We may update this GDPR Data Protection Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

    When we make material changes:

    • We will update the "Last updated" date at the top of this page
    • We will notify you via email if you have an account with us
    • We may display a prominent notice on our website
    • We will seek new consent if required by law

    Your continued use of the Service after changes become effective constitutes acceptance of the updated policy, unless additional consent is required by law.

    13. Contact and Data Protection Officer

    If you have any questions, concerns, or requests regarding this GDPR Policy or how we handle your personal data, please contact us:

    Data Protection Officer (DPO)

    Email: dpo@justseo.ai

    General Privacy Email: privacy@justseo.ai

    Support Email: support@justseo.ai

    We aim to respond to all legitimate requests within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by two further months, and we will notify you of this within one month.

    Related Policies

    We use cookies

    We use cookies to improve your experience, analyze site traffic, and personalize content. You can customize your preferences at any time.

    Learn more: Cookie PolicyPrivacy Policy

    Customize