Privacy Policy

How we handle your data.

In plain English, without the legal jargon. This page explains what we collect, why we collect it, and what we will never do.

Version 1.0 Effective May 20, 2025 Applies to smartseoaudit.com
The short version

Your data is stored in Switzerland on Swiss-operated servers. We don't sell it, share it for advertising, or send it to third parties unless we have to for the service to work (payments, AI analysis). You can export or delete everything in one click from your dashboard. We comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

1. Who we are

Smart SEO Audit is a Swiss-hosted SEO auditing platform operated from Switzerland. We are the data controller for all personal data processed through our website and application at smartseoaudit.com.

You can reach us at any time at [email protected] for anything related to this policy, your data, or your rights.

2. What we collect

We collect only the data we need to provide the service. Nothing we collect is optional padding to "improve the experience" — if it's listed here, it's because the service genuinely needs it.

Data you give us directly

Type of dataWhen we collect it
Email addressWhen you create an account or subscribe to updates
Name (optional)On your profile, if you choose to provide it
Password (hashed, never stored in plain text)When you create an account
Payment detailsWhen you subscribe to a paid plan (handled by Stripe — we never see your card number)
Billing informationCompany name, address, VAT ID — for invoices
Support conversationsWhen you email us or use the in-app contact form
URLs you auditEvery URL, sitemap or HTML snippet you submit for auditing

Data we collect automatically

Type of dataWhy
IP addressFor security (abuse detection, rate limiting) and approximate country detection for currency/language
Browser & device infoFor compatibility debugging and basic security
Usage logsWhich audits were run, when, and whether they succeeded — to debug issues and measure service health
Access times & pages visitedCaptured anonymously via our privacy-first analytics (see Cookies)

What we do NOT collect

3. Why we collect it

Every piece of data we collect has a specific, listed purpose:

Under GDPR Article 6, we rely on the following legal bases:

5. Where your data is stored

Swiss hosting

All application data — your account, your audits, your audit history, your reports — is stored on servers physically located in Switzerland. The servers are operated by Hostpoint, one of Switzerland's largest and most established hosting providers, with data centres in Rapperswil-Jona (SG) and Zurich. All data remains within Swiss jurisdiction and is not transferred to third countries.

We do not replicate your data to US, EU or any other non-Swiss regions — not for backups, not for performance, not for analytics.

Exceptions: where data leaves Switzerland

There are a small number of specific, necessary cases where certain data is processed outside Switzerland. We list each one explicitly:

Payment processing (Stripe)

When you subscribe to a paid plan, your payment details are processed by Stripe Payments Europe, Ltd. (based in Ireland). We never see or store your full card number — Stripe handles it under its own infrastructure, which is PCI-DSS Level 1 compliant. Stripe's data processing is covered by Standard Contractual Clauses under GDPR. See Stripe's privacy policy.

AI-powered audit insights (OpenAI)

If your plan includes AI-generated audit insights, the audit findings for that specific audit are sent to OpenAI (United States) to generate the plain-language recommendations. Specifically:

Important

If data sovereignty is critical for your use case (e.g. auditing sites containing sensitive information), we recommend disabling AI insights. The full audit functionality remains available without AI — only the plain-language recommendations are skipped.

6. Who we share your data with

We share data only with service providers who process it on our behalf ("data processors"). Each processor is bound by a Data Processing Agreement (DPA) and contractually restricted to using the data only to provide the service we contracted them for.

ProcessorPurposeLocation
HostpointHosting infrastructure, databases, backupsSwitzerland
LogiwolfWebsite analytics (aggregated, anonymous)Switzerland
Stripe Payments EuropePayment processingIreland (EU)
OpenAIAI-generated audit insights (optional, can be disabled)United States

We do not share data with advertisers, data brokers, social media platforms, or any third party for marketing or analytics purposes. We will only share data with law enforcement in response to a valid, legally binding request under Swiss law.

7. How long we keep your data

DataRetention period
Account data (email, profile, settings)Until you delete your account
Audit data & reportsAccording to your plan limits; deleted within 90 days of account deletion
Payment & invoice records10 years (Swiss accounting law requires this)
Support conversations3 years, then anonymised
Server & security logs90 days
Marketing email subscriptionUntil you unsubscribe

When you delete your account, we remove your personal data within 90 days, except data we are legally required to retain (such as invoices, for tax purposes). Retained financial records are anonymised where possible.

8. Your rights

Under GDPR and Swiss FADP, you have the following rights over your personal data:

How to exercise your rights

Most actions — exporting your data, deleting your account, unsubscribing from emails — can be done directly from your account settings in one click. For anything else, email [email protected] and we will respond within 30 days.

Lodging a complaint

If you believe we have mishandled your data, you have the right to file a complaint with a supervisory authority:

We would, of course, rather you contact us first so we can resolve the issue directly.

9. Cookies & tracking

We use the minimum necessary cookies. No third-party advertising cookies, no social media trackers, no cross-site tracking.

Essential cookies

These are required for the service to work. They can't be disabled.

Analytics (optional, privacy-first)

We use Logiwolf, a Swiss-hosted, privacy-first website analytics platform. It:

Analytics data is aggregated and anonymous. We use it to understand which pages are useful and where users get stuck — not to track individuals.

10. Security

We take the security of your data seriously. Measures include:

No system is 100% secure. In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Article 33.

11. Children's data

Smart SEO Audit is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please contact us and we will delete the account and any associated data.

12. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our service, legal requirements, or best practices. When we make a material change, we will:

The version history of this policy is available on request.

13. Contact us

For anything related to this privacy policy or your personal data:

We respond to privacy-related enquiries within 30 days, as required by GDPR. Most are resolved within a few business days.

Privacy by design. Swiss by default.

Run your first audit on a platform that actually cares where your data lives. Free plan forever, no credit card.

Start your free audit