We do not sell personal data. We share personal data only as needed to run the Service.
Sub-processors / Service Providers
Mistral (EU, ZDR configured)
AI inference for image SEO recommendations. ZDR applies within Mistral's contractual and technical scope.
Netcup (Germany)
Application, ancillary hosting, and our self-hosted Umami service.
OVHcloud Object Storage (EU)
S3-compatible storage for uploaded images and generated outputs.
Bunny.net
Public CDN, edge and font delivery, DDoS protection, and web application firewall services. Its globally distributed edge may process request and security data outside the UK/EEA.
Amazon Web Services SES (eu-west-2)
Transactional email delivery.
Stripe
Payment processing. Stripe handles card data directly; we do not store full card numbers. Stripe may also act as an independent controller for fraud prevention, regulatory compliance, and payment-network operations.
PostHog (EU-hosted, when enabled)
Aggregate product analytics configured to minimise personal data collection.
GlitchTip (self-hosted on Netcup)
Sentry-compatible error tracking and diagnostics.
Coarse Product and Campaign Analytics
We use self-hosted Umami to report aggregate server-side event counts. This helps authorised product operators compare coarse product outcomes and approved campaign entry and checkout stages.
We intentionally supply only the event name, bounded product categories, approved campaign source, campaign medium, campaign name and optional content variant, plus fixed, neutral protocol metadata required to deliver the event. The same fixed aggregate identity is used for every event.
We do not intentionally supply an account identity, email address, browser identity, visitor or inbound IP address or user agent, device identity, request or session identity, HMAC-derived identity, payment or Stripe identity, raw URL, query string, referrer, or arbitrary campaign value. Instead, our server supplies one fixed loopback IP substitute and one fixed synthetic protocol user agent, identical for every event. We do not use analytics cookies, analytics local storage, individual profiles, cross-device identity, session replay, visitor journeys, or detailed attribution for this launch measurement.
These counts are not unique visitors or sessions. They cannot show complete or returning-customer journeys, and an outcome may remain unattributed when the visitor does not continue directly from an approved campaign action.
Sub-processor Changes
Where we process Customer Personal Data on your behalf, our DPA contains the current sub-processor schedule and change-notification terms. Request the DPA at privacy@seoptim.ai.
Legal and Compliance
We may disclose personal data if required by applicable law, regulation, court order, or to protect our rights and users, acting proportionately.