GDPR Data Protection Policy
Your rights under EU data protection law, and our GDPR commitments.
EU Data Protection Commitment
JustSEO.ai is fully committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable EU data protection laws.
For EU customers: All your personal data is processed and stored exclusively on servers physically located within the European Union. We do not transfer EU personal data outside the EU/EEA without appropriate safeguards.
1. Data Controller Information
The data controller responsible for your personal data is:
Company: Basecamp Labs, Inc (JustSEO.ai)
Email: privacy@justseo.ai
GDPR Contact: dpo@justseo.ai
2261 Market Street STE 18268, San Francisco, CA 94114, United States
We act as the data controller for personal data collected through our Service. In some cases, we may also act as a data processor on behalf of our customers who use our Service to analyze their websites.
2. Legal Basis for Processing Personal Data
Under GDPR Article 6, we process your personal data based on the following legal grounds:
a) Contractual Necessity (Article 6(1)(b))
Processing is necessary to perform our contract with you, including:
- Creating and managing your account
- Providing SEO analysis, crawling, and reporting services
- Processing payments and managing subscriptions
- Delivering customer support
- Fulfilling our obligations under the Terms of Service
b) Legitimate Interests (Article 6(1)(f))
Processing is necessary for our legitimate business interests, including:
- Improving and optimizing our Service
- Analyzing usage patterns and user behavior
- Preventing fraud, abuse, and security threats
- Marketing our services to existing customers
- Conducting business analytics and research
We have balanced our legitimate interests against your rights and freedoms and determined that processing is necessary and proportionate. You have the right to object to processing based on legitimate interests.
c) Consent (Article 6(1)(a))
For certain processing activities, we obtain your explicit consent:
- Marketing communications to non-customers
- Optional cookies and tracking technologies (beyond strictly necessary)
- Sharing data with third-party integrations you authorize
- Processing special categories of personal data (if applicable)
You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
d) Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with legal obligations, including:
- Tax and accounting requirements
- Financial regulations and payment processing laws
- Response to lawful requests from authorities
- Compliance with court orders or legal processes
3. Personal Data We Collect
a) Account and Identity Data
- Registration Information: Name, email address, password (encrypted), account preferences
- Authentication Data: Login credentials, two-factor authentication tokens, OAuth tokens (if using Google sign-in)
- Profile Information: Display name, avatar image, bio, user preferences
b) Payment and Billing Data
- Payment Information: Processed by our payment provider (Stripe) - we do not store full credit card details
- Billing Details: Billing address, VAT number (if applicable), invoice history, subscription status
- Transaction Records: Payment dates, amounts, payment methods, refund information
c) Usage and Service Data
- Analysis Data: URLs submitted for analysis, website content crawled, SEO reports generated, crawl results
- Project Data: Projects created, tracked URLs, project settings, integration configurations
- Usage Metrics: Features used, frequency of use, subscription plan, account activity logs
d) Technical and Device Data
- Device Information: Browser type and version, operating system, device type
- Connection Data: IP address, ISP, approximate geographic location (country/city level)
- Log Data: Access times, pages viewed, errors encountered, API requests
- Cookies and Tracking: Session cookies, authentication tokens, analytics cookies (with consent)
e) Communications Data
- Support Tickets: Messages, attachments, support interactions, ticket history
- Contact Forms: Name, email, subject, message content from contact forms
- Email Communications: Emails sent and received, notification preferences
f) Third-Party Integration Data
- Google Search Console: OAuth tokens, property data, analytics data (with your authorization)
- Slack: Workspace IDs, channel information, notification preferences (with your authorization)
- Other Integrations: Data from third-party services you explicitly connect
4. How We Use Your Personal Data
We process your personal data for the following purposes:
Service Delivery and Performance
- Creating and managing your user account
- Authenticating your identity and authorizing access
- Performing SEO analysis, website crawling, and generating reports
- Storing and presenting analysis results
- Processing API requests and integrations
- Providing customer support and responding to inquiries
Billing and Payments
- Processing subscription payments and managing billing
- Generating invoices and receipts
- Handling refunds and chargebacks
- Preventing payment fraud
- Complying with tax and financial regulations
Service Improvement
- Analyzing usage patterns to improve features and performance
- Conducting research and development for new features
- Testing and debugging the Service
- Training AI models on aggregated, anonymized data
- Optimizing user experience and interface design
Security and Fraud Prevention
- Detecting and preventing security threats, fraud, and abuse
- Monitoring for unusual or suspicious activity
- Enforcing Terms of Service and acceptable use policies
- Protecting our rights, property, and safety
- Investigating and responding to security incidents
Communications
- Sending transactional emails (account notifications, password resets, subscription updates)
- Providing customer support and responding to inquiries
- Sending service announcements and important updates (required communications)
- Sending marketing communications (with consent, where required)
- Conducting user surveys and feedback requests (optional)
Legal and Compliance
- Complying with legal obligations and regulations
- Responding to lawful requests from authorities
- Establishing, exercising, or defending legal claims
- Enforcing our Terms of Service and policies
- Maintaining records for audit and compliance purposes
5. Data Sharing and Disclosure
We do not sell your personal data to third parties. We only share your personal data in the limited circumstances described below:
a) Service Providers (Data Processors)
We engage trusted third-party subprocessors who process personal data on our behalf under strict data processing agreements (GDPR Article 28). Your primary account, project, and report data is stored in the EU (Supabase, West EU / Ireland); some processing takes place in the US under the EU Standard Contractual Clauses (SCCs). Our current subprocessors are:
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Primary database, authentication, and file storage (account, project, and report data) | European Union (West EU / Ireland) | Stored in the EU |
| Vercel | Application hosting and content delivery for the web app and marketing site | United States | EU Standard Contractual Clauses |
| Railway | Background workers and the AI API service that run analyses | United States | EU Standard Contractual Clauses |
| Stripe | Payment processing and subscription management | United States / global | EU Standard Contractual Clauses |
| PostHog | Product analytics (with consent) | United States | EU Standard Contractual Clauses |
| Sentry | Application error monitoring and logging | United States | EU Standard Contractual Clauses |
| OpenAI | AI analysis and AI share-of-voice tracking | United States | EU Standard Contractual Clauses |
| Gemini AI analysis / share-of-voice and PageSpeed performance data | United States | EU Standard Contractual Clauses | |
| Anthropic | Claude AI analysis and AI share-of-voice tracking | United States | EU Standard Contractual Clauses |
| Perplexity | AI share-of-voice tracking | United States | EU Standard Contractual Clauses |
| DeepSeek | AI report generation | United States | EU Standard Contractual Clauses |
| DataForSEO | Search ranking and keyword data | United States | EU Standard Contractual Clauses |
All service providers are:
- Bound by data processing agreements ensuring GDPR compliance
- Required to implement appropriate security measures
- Prohibited from using your data for their own purposes
- Selected based on their security practices and GDPR compliance
b) Integrations You Authorize
When you explicitly authorize integrations with third-party services:
- Google Search Console: We access GSC data via OAuth with your explicit authorization
- Slack: We send notifications to your Slack workspace when you enable the integration
- Other Integrations: Data sharing occurs only with services you explicitly connect
You control these integrations and can revoke access at any time through your account settings.
c) Legal Requirements and Protection
We may disclose personal data when required or permitted by law:
- To comply with legal obligations, court orders, or legal processes
- To respond to lawful requests from law enforcement or government authorities
- To protect our rights, property, or safety, or that of our users or the public
- To detect, prevent, or address fraud, security, or technical issues
- To enforce our Terms of Service or investigate potential violations
d) Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of the transaction. We will notify you of any such change and provide choices regarding your data where applicable.
e) Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This data is not subject to GDPR restrictions as it is not personal data.
6. International Data Transfers
EU Data Residency
For users located in the European Union: Your personal data is processed and stored exclusively on servers physically located within the European Union. This ensures your data remains under EU data protection laws at all times.
Third-Party Services
Some third-party service providers (such as AI model providers) may process data outside the EU/EEA. When transferring personal data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved model clauses for data transfers (GDPR Article 46(2)(c))
- Adequacy Decisions: Transfers to countries with EU adequacy decisions (GDPR Article 45)
- Binding Corporate Rules: For transfers within multinational organizations with approved BCRs
- Certification Mechanisms: EU-US Data Privacy Framework or similar certifications where applicable
Your Rights Regarding Transfers
You have the right to obtain information about safeguards we have implemented for international data transfers. Contact us at dpo@justseo.ai to request copies of relevant safeguard documents.
7. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes.
Retention Periods by Data Type
| Data Type | Retention Period |
|---|---|
| Account Data (active users) | Duration of account + 30 days after deletion |
| SEO Reports and Analysis | 90 days (unless saved to projects) |
| Saved Projects | Duration of account + 30 days after deletion |
| Payment Records | 7 years (legal requirement for tax/accounting) |
| Support Tickets | 3 years after ticket closure |
| Log Files (IP, access logs) | 90 days (rolling) |
| Marketing Consent | Until consent withdrawn or 2 years of inactivity |
| Legal Claims Data | Duration of claim + applicable statute of limitations |
Account Deletion
When you delete your account:
- Your account is immediately deactivated
- Personal data is anonymized or deleted within 30 days
- Some data may be retained for legal compliance (e.g., payment records)
- Aggregated, anonymized data may be retained indefinitely
- Backups are deleted according to our backup retention schedule (maximum 90 days)
Legal Retention Requirements
In some cases, we must retain data longer than standard periods to comply with legal obligations such as:
- Tax and accounting laws (typically 7 years)
- Anti-money laundering regulations
- Ongoing legal proceedings or investigations
- Regulatory requirements applicable to our business
8. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and access to that data.
How to exercise: Request a data export through your account settings or contact dpo@justseo.ai
Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data.
How to exercise: Update your information directly in account settings or contact support
Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data in certain circumstances.
How to exercise: Use the account deletion feature in settings or contact dpo@justseo.ai
Note: Some data may need to be retained for legal compliance
Right to Restriction of Processing (Article 18)
You have the right to request we limit how we process your data in certain situations.
How to exercise: Contact dpo@justseo.ai with your request and reasoning
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
How to exercise: Request a data export (JSON format) through account settings
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing.
How to exercise: Contact dpo@justseo.ai or opt out of marketing via email unsubscribe links
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Note: We do not currently make automated decisions with legal effects about users
Right to Withdraw Consent (Article 7(3))
Where processing is based on consent, you have the right to withdraw that consent at any time.
How to exercise: Manage consent settings in your account or contact dpo@justseo.ai
How to Exercise Your Rights
To exercise any of these rights:
- Email our Data Protection Officer at: dpo@justseo.ai
- Use the data management features in your account settings
- Submit a written request to our business address
Response Time
We will respond to your request:
- Within one month of receiving your request (GDPR requirement)
- Within three months if the request is complex or we receive multiple requests (we will inform you within one month)
- Free of charge (unless requests are manifestly unfounded, excessive, or repetitive)
Verification
To protect your privacy, we will verify your identity before fulfilling requests. We may ask you to provide:
- Proof of identity (government-issued ID)
- Confirmation of account ownership (access to registered email)
- Additional verification for sensitive requests
Right to Lodge a Complaint
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority (supervisory authority).
EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en
However, we encourage you to contact us first at dpo@justseo.ai so we can attempt to resolve your concern directly.
9. Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction (GDPR Article 32).
Technical Security Measures
- Encryption: All data in transit is encrypted using TLS/SSL protocols (HTTPS)
- Database Encryption: Personal data at rest is encrypted using industry-standard encryption
- Password Security: Passwords are hashed using bcrypt with salting (never stored in plain text)
- Access Controls: Role-based access control (RBAC) and principle of least privilege
- Authentication: Two-factor authentication (2FA) available for enhanced account security
- Firewalls: Network-level firewalls and intrusion detection systems
- Security Monitoring: Continuous monitoring for security threats and anomalies
- Secure APIs: API authentication, rate limiting, and input validation
Organizational Security Measures
- Staff Training: Regular security and privacy training for employees
- Access Restrictions: Limited employee access to personal data on a need-to-know basis
- Confidentiality Agreements: All staff and contractors sign confidentiality agreements
- Data Processing Agreements: All third-party processors are bound by GDPR-compliant agreements
- Incident Response Plan: Documented procedures for handling data breaches
- Regular Audits: Periodic security audits and vulnerability assessments
- Data Minimization: We collect and retain only necessary personal data
Infrastructure Security
- EU-Based Hosting: Primary account, project, and report data is stored in the EU (Supabase, West EU / Ireland)
- Compliance: Our own SOC 2 certification is on our roadmap (we are not yet certified)
- Redundancy: Provider-managed backups and disaster recovery procedures
- Access Control: Row-Level Security and least-privilege access to production data
Data Breach Notification
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms:
- We will notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Article 33)
- We will notify affected individuals without undue delay if the breach poses a high risk (GDPR Article 34)
- We will document the breach, its effects, and remedial actions taken
- We will investigate the cause and implement measures to prevent recurrence
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to provide and improve our Service. This section explains what cookies we use and your choices regarding them.
What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us recognize your browser, remember your preferences, and analyze how you use our Service.
Types of Cookies We Use
Strictly Necessary Cookies (No consent required)
Essential for the Service to function. You cannot opt out of these cookies.
- Authentication and session management
- Security and fraud prevention
- Load balancing and performance
Functional Cookies (Consent-based)
Enhance your experience by remembering preferences.
- Language preferences
- Theme settings (light/dark mode)
- UI customization preferences
Analytics Cookies (Consent-based)
Help us understand how users interact with our Service.
- PostHog (product analytics, loaded only with consent)
- Google Tag Manager (tag management, loaded only with consent)
- Usage statistics and feature adoption
Your Cookie Choices
- Cookie Banner: Manage cookie preferences via our cookie consent banner on first visit
- Account Settings: Update cookie preferences in your account settings at any time
- Browser Settings: Configure your browser to reject cookies (may affect functionality)
- Opt-Out Tools: Use browser extensions or opt-out tools for analytics cookies
Third-Party Cookies
Third-party services may set their own cookies:
- PostHog / Google Tag Manager: For product analytics and tag management (with consent)
- Stripe: For payment processing security
- OAuth Providers: For social login functionality
These third parties have their own privacy policies governing how they use cookies.
11. Children's Privacy
Our Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16.
If you are under 16, you may not use the Service or provide any personal data to us. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately at dpo@justseo.ai so we can delete it.
Under GDPR Article 8, if we learn we have collected personal data from a child under 16 without proper parental consent, we will delete that information as quickly as possible.
12. Changes to This GDPR Policy
We may update this GDPR Data Protection Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes:
- We will update the "Last updated" date at the top of this page
- We will notify you via email if you have an account with us
- We may display a prominent notice on our website
- We will seek new consent if required by law
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy, unless additional consent is required by law.
13. Contact and Data Protection Officer
If you have any questions, concerns, or requests regarding this GDPR Policy or how we handle your personal data, please contact us:
Data Protection Officer (DPO)
Email: dpo@justseo.ai
General Privacy Email: privacy@justseo.ai
Support Email: support@justseo.ai
We aim to respond to all legitimate requests within one month. If your request is particularly complex or you have made multiple requests, we may extend this period by two further months, and we will notify you of this within one month.
Related Policies
- Privacy Policy - General privacy practices and data collection
- Terms of Service - Legal terms governing your use of JustSEO.ai