Privacy

Privacy
Policy

Effective: 6 August 2026

01. Controller Details & Contact

Data Controller

RIGHTTHING STUDIO LTD, trading as Seoptim.ai
Registered Office: 71-75 Shelton Street, Covent Garden,
London, WC2H 9JQ, United Kingdom
Company Number: 17084795

Contact Points

General: contact@seoptim.ai
Privacy / Data Rights: privacy@seoptim.ai
Security Incidents: security@seoptim.ai

02. Data Protection Officer

We have not appointed a Data Protection Officer as our processing activities do not meet the threshold requiring a mandatory DPO under GDPR.

For any privacy questions or data rights requests, please contact privacy@seoptim.ai.

03. Scope & Roles (Controller vs Processor)

We Act as Controller

For account and billing administration data—personal data required to create and manage business accounts (e.g., admin user email, login credentials, invoices).

We Act as Processor

For Customer Content—images, website URLs, and prompts/inputs you upload. You (or your organisation) act as controller for this content.

If you require a Data Processing Addendum (DPA), contact privacy@seoptim.ai.

04. Personal Data We Collect

Data You Provide

  • Identity and contact data: full name, email address
  • Business data: business name(s), business address(es)
  • Service input data: website URLs and related metadata you submit

Data Collected Automatically

  • Technical/log data: IP address, device and browser information, timestamps, authentication/session identifiers, and security/audit logs

Image Metadata (EXIF)

We do not process EXIF metadata. Where present, EXIF is cleared/removed as part of our handling of images.

05. How We Use Your Personal Data

Contract Necessity (Article 6(1)(b))

  • Create and administer accounts; authenticate users; provide access to the Service
  • Provide the core Service functions (processing submitted images and URLs to produce optimisation outputs)
  • Provide support by email and respond to service requests

Legitimate Interests (Article 6(1)(f))

  • Maintain Service security (RBAC, access logging, audit trails), prevent fraud/abuse, and investigate incidents
  • Ensure Service reliability and diagnose errors (error tracking and monitoring)
  • Business operations (internal reporting, improving the Service based on aggregate usage patterns)

Consent (Article 6(1)(a))

Marketing communications (opt-in only). You can withdraw consent at any time via unsubscribe links or by emailing privacy@seoptim.ai.

Legal Obligation (Article 6(1)(c))

Retain invoices and accounting records where required by law (see Section 9).

06. Recipients & Sub-processors

We do not sell personal data. We share personal data only as needed to run the Service.

Sub-processors / Service Providers

Mistral (EU, ZDR configured)
AI inference for image SEO recommendations. ZDR applies within Mistral's contractual and technical scope.
Netcup (Germany)
Application, ancillary hosting, and our self-hosted Umami service.
OVHcloud Object Storage (EU)
S3-compatible storage for uploaded images and generated outputs.
Bunny.net
Public CDN, edge and font delivery, DDoS protection, and web application firewall services. Its globally distributed edge may process request and security data outside the UK/EEA.
Amazon Web Services SES (eu-west-2)
Transactional email delivery.
Stripe
Payment processing. Stripe handles card data directly; we do not store full card numbers. Stripe may also act as an independent controller for fraud prevention, regulatory compliance, and payment-network operations.
PostHog (EU-hosted, when enabled)
Aggregate product analytics configured to minimise personal data collection.
GlitchTip (self-hosted on Netcup)
Sentry-compatible error tracking and diagnostics.

Coarse Product and Campaign Analytics

We use self-hosted Umami to report aggregate server-side event counts. This helps authorised product operators compare coarse product outcomes and approved campaign entry and checkout stages.

We intentionally supply only the event name, bounded product categories, approved campaign source, campaign medium, campaign name and optional content variant, plus fixed, neutral protocol metadata required to deliver the event. The same fixed aggregate identity is used for every event.

We do not intentionally supply an account identity, email address, browser identity, visitor or inbound IP address or user agent, device identity, request or session identity, HMAC-derived identity, payment or Stripe identity, raw URL, query string, referrer, or arbitrary campaign value. Instead, our server supplies one fixed loopback IP substitute and one fixed synthetic protocol user agent, identical for every event. We do not use analytics cookies, analytics local storage, individual profiles, cross-device identity, session replay, visitor journeys, or detailed attribution for this launch measurement.

These counts are not unique visitors or sessions. They cannot show complete or returning-customer journeys, and an outcome may remain unattributed when the visitor does not continue directly from an approved campaign action.

Sub-processor Changes

Where we process Customer Personal Data on your behalf, our DPA contains the current sub-processor schedule and change-notification terms. Request the DPA at privacy@seoptim.ai.

Legal and Compliance

We may disclose personal data if required by applicable law, regulation, court order, or to protect our rights and users, acting proportionately.

07. International Data Transfers

Our primary application hosting and object storage are located in Germany or elsewhere in the EU, and transactional email is configured for AWS region eu-west-2. However, some suppliers, their affiliates, support personnel, payment operations, and CDN or security infrastructure may process or access personal data from other countries.

Where personal data is transferred from the United Kingdom or EEA to a country that is not covered by an applicable adequacy regulation or decision, we use an appropriate safeguard where required, such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or the EU Standard Contractual Clauses. We assess relevant transfer risks and apply supplementary safeguards where appropriate.

Information about applicable safeguards may be requested at privacy@seoptim.ai.

08. Cookies

We use strictly necessary cookies for authentication, security, and maintaining your logged-in session.

Launch analytics is sent by our server. It does not load provider analytics code in your browser and does not create an analytics cookie or analytics local-storage identifier. We do not use advertising cookies.

Any future browser-based or individual analytics would be a separate, reviewed project with appropriate privacy and consent controls; it would not be silently mixed into this aggregate launch dataset.

09. Data Retention

Active Accounts

Retained for a maximum of 2 years (subject to continued account activity and necessity)

After Cancellation

Retained for 12 months to enable reactivation and address support queries; then deleted

Aggregate Analytics

Coarse event counts are retained for no longer than 12 months and are visible only to authorised product operators; they are then deleted or aggregated further.

Invoices / Accounting

Retained for 10 years to meet accounting/legal requirements

Security/Audit Logs

Retained as long as reasonably necessary for security and compliance; then deleted or anonymised

Deletion may be delayed where required to comply with legal obligations or to establish, exercise, or defend legal claims.

10. Security Measures

We implement appropriate technical and organisational measures:

  • TLS encryption in transit
  • Encryption at rest
  • Field-level encryption for PII
  • Role-Based Access Control (RBAC) and least-privilege access
  • Access logging and internal security audits
  • Encrypted backups and recovery procedures

No system is 100% secure, but we use reasonable endeavours to protect personal data.

11. Automated Decision-Making & AI

We use AI (Mistral inference with ZDR enabled) to generate image optimisation recommendations.

  • These outputs are recommendations only and do not produce legal or similarly significant effects about individuals
  • We do not perform solely automated decision-making that has legal or similarly significant effects under Article 22 UK/EU GDPR

12. Your Data Protection Rights

Depending on your location and applicable law (UK GDPR / EU GDPR), you may have the right to:

Access
Your personal data
Rectify
Inaccurate data
Erase
Right to be forgotten
Restrict
Processing
Object
To processing
Portability
Transfer your data

To exercise rights, email privacy@seoptim.ai. We may need to verify your identity and authority (for business accounts).

13. Right to Complain

United Kingdom

You can complain to the Information Commissioner's Office (ICO):
https://ico.org.uk/

EU/EEA

If you are located in the EU/EEA, you may complain to your local supervisory authority.

We would appreciate the opportunity to address concerns first—please contact privacy@seoptim.ai.

14. Breach Notification

If we become aware of a personal data breach, we will assess it and:

  • Notify the relevant supervisory authority within 72 hours where required
  • Notify affected users without undue delay where the breach is likely to result in a high risk to individuals' rights and freedoms

Security incident reports: security@seoptim.ai

15. Changes to This Privacy Policy

We may update this Policy from time to time. We will post the updated version on the Service and, where appropriate, notify account administrators by email. The "Effective date" above will show when changes apply.

Questions about this policy?

Contact us to clarify our privacy practices or exercise your data rights.

Contact Privacy