Privacy Policy
Last Updated: January 16, 2026
1. Introduction
Welcome to SEO Agent, operated by Dpro GmbH ("we," "us," or "our"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our SEO tracking and AI content platform.
By using SEO Agent, you agree to the collection and use of information in accordance with this policy. This policy complies with the EU General Data Protection Regulation (GDPR) and Austrian data protection laws.
2. Data Controller
Dpro GmbH
Wipplingerstraße 20/18
1010 Wien, Austria
Email: office@seo-agent.net
Phone: +43 676 905 4441
VAT ID: ATU81090445
3. Information We Collect
3.1 Information You Provide
- Account Information: When you register, we collect your email address, name, and optionally your company name.
- Authentication Data: If you register with email/password, we store a securely hashed version of your password. If you sign in with Google, we receive your email, name, and profile picture from Google.
- Domain & SEO Data: Website domains you add, keywords you track, competitor websites, business information, target countries, and language preferences.
- Content Data: Blog posts and articles you create using our AI content generation tools.
- Integration Settings: WordPress, Shopify, Webflow, or Wix connection details (API keys, site URLs) if you choose to connect these platforms.
- AI API Keys: If you provide your own API keys for OpenAI, Claude, Gemini, or other AI services.
3.2 Google Search Console Data
When you connect your Google Search Console account, we request read-only access to:
- • Search performance data (queries, impressions, clicks, CTR, position)
- • Site verification status
- • URL inspection data
Important: We only read this data from Google. We do not store Google Search Console data permanently on our servers. The data is fetched in real-time when you view your analytics dashboard and is used solely for display purposes.
3.3 Automatically Collected Information
- Cookies & Session Data: We use HTTP-only cookies to maintain your login session. These cookies expire after 24 hours.
- Usage Data: Last login timestamp, onboarding progress, and subscription plan status.
4. How We Use Your Data
We use your information for the following purposes:
✓ Service Provision
Track keyword rankings, analyze SEO performance, and generate AI content
✓ Account Management
Create and manage your user account, authenticate logins
✓ Communication
Send service updates, notifications, and respond to support requests
✓ Platform Integration
Connect with Google Search Console, WordPress, and other platforms
✓ Security
Protect against unauthorized access and fraudulent activity
✓ Service Improvement
Analyze usage patterns to improve features and user experience
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your data based on:
- a)Contractual Necessity: Processing is necessary to provide the SEO tracking and content generation services you've subscribed to.
- b)Consent: When you connect Google Search Console or third-party integrations, you explicitly consent to data access.
- c)Legitimate Interest: We have a legitimate interest in improving our service, preventing fraud, and ensuring platform security.
6. Data Sharing & Third Parties
We do not sell your personal data. We may share data with the following third parties:
✓ Google APIs
We use Google OAuth 2.0 for authentication and Google Search Console API for SEO data retrieval. Google's use of your data is governed by Google's Privacy Policy.
✓ AI Service Providers
When you generate content, we send your prompts to AI providers (OpenAI, Anthropic, Google Gemini) based on your selection. These providers process data according to their own privacy policies.
✓ CMS Platforms
If you connect WordPress, Shopify, Webflow, or Wix, we use your provided API credentials to publish content on your behalf.
7. Data Storage & Security
- Data Location: Your data is stored on secure servers located in the European Union (EU).
- Encryption: All data transmission is encrypted using HTTPS/TLS. Passwords are hashed using bcrypt with salt.
- Access Control: Only authorized personnel have access to user data, and access is logged for security auditing.
- Retention: We retain your data as long as your account is active. After account deletion, data is permanently removed within 30 days.
8. Your Rights Under GDPR
You have the following rights:
→ Right to Access
Request a copy of your personal data
→ Right to Rectification
Correct inaccurate or incomplete data
→ Right to Erasure
Request deletion of your data ("right to be forgotten")
→ Right to Data Portability
Receive your data in a machine-readable format
→ Right to Object
Object to processing based on legitimate interests
→ Right to Withdraw Consent
Revoke consent for data processing at any time
To exercise these rights, contact us at office@seo-agent.net
9. Cookies
We use essential cookies only to maintain your login session. These cookies are:
- • HTTP-only: Not accessible via JavaScript (enhanced security)
- • SameSite=Lax: Protection against CSRF attacks
- • 24-hour expiry: Automatic logout after 24 hours of inactivity
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
10. Children's Privacy
SEO Agent is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our platform. Continued use of SEO Agent after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact:
Dpro GmbH - Data Protection Officer
Wipplingerstraße 20/18, 1010 Wien, Austria
Email: office@seo-agent.net
Phone: +43 676 905 4441
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): www.dsb.gv.at
Last Updated: January 16, 2026 | Effective Date: January 16, 2026