Skip to content
ScanMySEO
Explore ScanMySEO
  • Search intelligence
  • How it works
  • Pricing
  • Articles
  • Contact
Log in Start free
  1. Home
  2. Privacy Policy

Privacy designed around the service

Privacy Policy

This notice explains how ScanMySEO handles information about website visitors, account users, customers, people appearing on audited public websites and others who interact with us. It also explains your choices, privacy rights and how to raise a complaint.

Effective date
12 July 2026
Last updated
12 July 2026
Version
2.0
Controller identity
SCANMYSEO LTD · 17166063

Our practical commitments

Use what is needed, protect it, and explain it

This notice is not a request for blanket consent and is not a substitute for the Terms of Service. We use the lawful basis that fits each purpose, keep collection proportionate and provide specific controls where consent or another choice is required.

01

Card data stays with Stripe

ScanMySEO stores payment and entitlement records, but does not receive or store your complete card number or security code.

02

No sale or behavioural ads

We do not sell or rent personal data and do not use customer information for cross-site behavioural advertising.

03

No public-model training by default

Customer reports, onboarding context and Cozmo conversations are not used to train general-purpose public AI models without explicit opt-in.

04

Public web data is still personal data

An authorised audit can process names or other information on public pages. We describe that processing instead of pretending public means anonymous.

Related controls and documents

Privacy is supported across the product

Browser controls Cookie Policy Cookies, local storage, analytics, reCAPTCHA, OAuth and Stripe technologies. Service contract Terms of Service Account, audit, report, AI, billing and acceptable-use rules. Business customers Request a DPA Agency and Enterprise customers can request data-processing terms and subprocessor information.
Contents
  1. About this notice
  2. Controller and processor roles
  3. Who this notice covers
  4. Account and authentication data
  5. Onboarding and personalisation
  6. Crawl submissions and website data
  7. People on audited websites
  8. Reports and historical records
  9. AI Enhanced Audit and Report AI
  10. Billing and payment data
  11. Communications and support
  12. Technical, usage and security data
  13. Where information comes from
  14. Purposes and lawful bases
  15. Legitimate interests
  16. Personalisation and automated decisions
  17. Recipients and service providers
  18. International transfers
  19. Retention schedule
  20. Account deletion
  21. Your privacy rights
  22. Right to object
  23. Complaints and the ICO
  24. Agency and public-data requests
  25. Children and sensitive data
  26. Security and incidents
  27. Marketing, analytics and benchmarking
  28. Legal and corporate disclosures
  29. Changes to this policy
  30. Contact and DPA

On this page

  1. About this notice
  2. Our legal roles
  3. People covered
  4. Account and authentication
  5. Onboarding
  6. Crawls and website data
  7. Public website personal data
  8. Reports and history
  9. AI features
  10. Billing
  11. Communications
  12. Technical and security
  13. Sources
  14. Purposes and lawful bases
  15. Legitimate interests
  16. Automation
  17. Recipients
  18. Transfers
  19. Retention
  20. Deletion
  21. Rights
  22. Object
  23. Complaints
  24. Agencies and non-users
  25. Children and sensitive data
  26. Security
  27. Marketing and benchmarking
  28. Disclosures
  29. Changes
  30. Contact and DPA
Back to top

1

About this notice and who we are

ScanMySEO is operated by SCANMYSEO LTD, a company registered in England and Wales under company number 17166063. In this notice, “ScanMySEO”, “we”, “us” and “our” refer to SCANMYSEO LTD.

This notice explains what personal data we process, where it comes from, why we use it, the lawful basis, who receives it, how long it is retained, how international transfers are protected and what rights are available. It applies to scanmyseo.com, the ScanMySEO account and audit service, customer dashboards, reports, AI features, billing, support, sales and related business operations.

A privacy notice explains processing; it is not a contract and does not turn every use of personal data into consent. Where we rely on consent, we ask separately and allow it to be withdrawn. The Terms of Service govern the service contract.

Privacy questions do not require an account

Privacy requests, public-data concerns and complaints can be made through the email and contact routes in section 30, including by people who have never used ScanMySEO.

2

When ScanMySEO is a controller or processor

Privacy roles depend on the particular purpose. A company can be a controller for one activity and a processor for another.

ScanMySEO as controller

We decide the purposes and essential means for:

  • website visitor and account administration;
  • authentication, security, rate limiting and fraud prevention;
  • billing accounts, orders, subscriptions, credits, refunds and disputes;
  • support, privacy requests, complaints and service communications;
  • optional analytics, marketing preferences and product administration;
  • legal claims, compliance and corporate governance; and
  • de-identified service reliability and aggregate product statistics.

ScanMySEO as processor or service provider

For a business customer, we may process customer-controlled personal data on instructions when we:

  • crawl an authorised customer or client website;
  • store and present customer-directed audit reports;
  • run AI analysis over selected customer report context;
  • support an agency’s client audit; or
  • perform processing governed by an Enterprise Data Processing Addendum.

Where ScanMySEO acts as processor, the customer is normally responsible for its own transparency, instructions and lawful basis. We still process limited account, security, billing and platform-administration information as an independent controller. A Data Processing Addendum is available for eligible agency and Enterprise customers.

Stripe, Google, LinkedIn and certain other providers may act as separate or independent controllers for their own fraud, legal, account, authentication or service-improvement purposes. Calling a provider a “processor” in one context does not override that provider’s independent legal duties.

3

People covered by this notice

This notice can apply to:

  • public website visitors and prospective customers;
  • registered, Free, subscription, PAYG and Enterprise users;
  • account owners, billing owners, billing administrators, billing viewers and authorised users;
  • agency users, freelancers, client representatives and people invited to a workspace;
  • people who submit an enterprise quote, procurement enquiry, support request, feedback or privacy complaint;
  • newsletter subscribers and recipients of permitted marketing;
  • people whose names, roles, biographies, contact details, images or other information appear on a publicly accessible website submitted for audit;
  • people mentioned in report examples, customer instructions or Cozmo questions;
  • suppliers, advisers, security researchers and business contacts; and
  • administrators and staff whose authorised actions are recorded in operational logs.

Some people covered by this notice never create a ScanMySEO account. Section 24 explains the most practical route for a person who appears on an audited website or customer report.

4

Account, authentication and access information

Depending on how you create and use an account, we may process:

  • username, display name, email address and normalised email value;
  • company or organisation information and account role;
  • password hash, whether local password login is enabled and credential-version information used to invalidate old reset links;
  • email-confirmation status, confirmation and reset timestamps, token events, delivery, bounce and resend information;
  • account creation date, last login, failed login attempts, lockout state and session records;
  • authentication provider, provider subject identifier and whether a Google or LinkedIn email was verified;
  • safe post-authentication destination and a temporary pending crawl URL;
  • account status, Plan, role and permissions;
  • security notifications, password-change and suspicious-sign-in events; and
  • account-deletion request, signed deletion intent and selected subscription action.

4.1 Passwords

ScanMySEO stores a cryptographic password hash rather than a readable password. OAuth-only accounts are configured without a usable local password unless the user later establishes one through an authorised process. Do not reuse a ScanMySEO password elsewhere.

4.2 Google and LinkedIn sign-in

For Google and LinkedIn OpenID Connect sign-in, ScanMySEO requests basic identity scopes: OpenID identity, profile and email. We typically receive a verified email address, provider user identifier and name or profile fields needed to create or match the account. We do not use those permissions to post to the provider account, read private messages, import contacts or access unrelated social content.

Access tokens are normally used transiently to complete authentication and are not kept as a reusable social-account connection. We retain the provider identity link while needed to support sign-in and account security. The provider independently processes the sign-in under its own privacy notice.

5

Onboarding and personalisation information

Optional or required onboarding can include:

  • role or persona, such as owner, in-house marketer, SEO specialist, developer, agency or explorer;
  • audit goals, such as traffic, leads, technical SEO, speed, migration, client reporting or site health;
  • SEO experience level;
  • website type;
  • industry selected for an audit;
  • optional website or business context;
  • whether onboarding was completed, skipped or postponed; and
  • the date preferences were last updated.

We use this information to change explanation depth, prioritisation, suggested starting points, summaries and AI context. It does not change the underlying customer responsibility to verify a finding, and it is not used to make a decision with legal or similarly significant effects.

Keep optional context appropriate

Do not enter passwords, access tokens, API keys, private customer lists, confidential credentials, health data, criminal-offence data or other highly sensitive information in the website-context field.

6

Crawl submissions and website audit data

When an authorised user starts an audit, we may process:

  • submitted website URL, domain, sitemap URL, selected industry, crawl depth, estimated page count and requested limits;
  • the user, account, Plan, entitlement and exact credit reservation associated with the crawl;
  • crawl status, task and queue identifiers, start and completion times, progress, pages discovered, pages fetched and failure reasons;
  • robots, sitemap, redirect, status-code, certificate, security-header and network response information;
  • public page text, metadata, headings, links, image information, structured data, canonical and hreflang signals, technical markup and page-level measurements;
  • performance, Core Web Vitals, script, CSS, third-party-resource and mobile signals;
  • content hashes, duplicate-content comparisons, readability, indexing, internal-linking and architecture evidence;
  • screenshots, rendered or temporary HTML where a particular check requires them;
  • error, retry, bot-blocking, rate-limit and diagnostic information; and
  • generated issue rows, health scores, summaries and output-file locations.

ScanMySEO is intended for publicly accessible website content. It is not designed to bypass logins, paywalls, CAPTCHAs, private administration areas or other access controls. Customers must have lawful authority to submit the website and must not provide private credentials to the crawler.

A target website, CDN, hosting provider, analytics system or security service may record the ScanMySEO crawler’s requests, user agent, source IP, timing and page access. Those records are controlled by the target-site operator and its providers.

7

Personal data found on public websites

Publicly accessible content can still be personal data. An authorised audit may encounter a person’s name, job title, biography, business contact details, photograph, authorship, social link, testimonial, event information or other information published on the target website.

When we act as processor, the customer decides why the website is audited and is normally responsible for its lawful basis and privacy information. ScanMySEO processes the content to produce the requested technical and AI-assisted report, secure the platform, diagnose faults and comply with law. We do not use crawled names or contact details to market to the people appearing on the target site.

We minimise report evidence where full reproduction is unnecessary. Reports can include a URL, short excerpt, page title, image reference or technical evidence needed to explain a finding. Customers must not use ScanMySEO to build unlawful profiles, harass individuals, harvest sensitive personal data or conduct surveillance.

If you appear on an audited website and want information corrected or removed, the website owner or ScanMySEO customer is usually best placed to correct the source. You may also contact us under section 24 and we will assess our role, preserve account security and assist the relevant customer where appropriate.

8

Reports, exports and historical audit records

Report data can include:

  • dashboard findings, Website Health Score and issue counts;
  • page-level evidence, recommendations, owners, effort and priority;
  • PDF, CSV, spreadsheet, JSON and other downloadable outputs;
  • historical snapshots and comparisons between audits of the same domain;
  • report filenames, paths, object-storage URLs, generation timestamps and file sizes;
  • download, access and report-generation events;
  • AI Enhanced Audit findings and selected Report AI content; and
  • support or quality records where a customer reports a report defect.

Reports are private to the authorised account except where the customer downloads or shares them. Administrators may access a report only where reasonably necessary for support, security, legal compliance, billing investigation, service restoration or authorised quality assurance. Access is restricted by role and should be auditable where the relevant system supports audit logging.

ScanMySEO is not a permanent archival-storage service. Customers should download material they must preserve and must protect exported reports that contain client, website or personal information.

9

AI Enhanced Audit, Cozmo Intelligence and Report AI

9.1 What AI features process

Depending on the feature and Plan, AI processing can include:

  • selected public page text, headings, metadata, structured crawl evidence and deterministic issue findings;
  • onboarding context, website type, industry and audit goals;
  • page-level content, trust, freshness, intent, commercial, user-experience and discoverability signals;
  • the user’s Report AI question, timestamp, crawl/report identifier and relevant report examples;
  • generated response, suggested owner, effort, priority, value or direction of change;
  • model family, prompt version, batch or job identifier, token or character counts, latency, retry, timeout and failure metadata;
  • safety, rate-limit and abuse-prevention information; and
  • voluntary feedback about an answer.

9.2 Report-grounded operation

Report AI is designed to answer from the completed crawl’s report context. The current report-chat interface does not browse the live web, accept user file uploads or execute backend changes to a website. It generates explanatory output; the customer decides whether and how to act on it.

9.3 Active model infrastructure

At the effective date, eligible AI Enhanced Audit and Report AI workloads are routed to ScanMySEO-managed inference services hosted on Google Cloud Run in a European region and use a Gemma-family model. Google Cloud provides the infrastructure. This is not the consumer Gemini chat service, and the model creator’s name does not by itself mean that a separate consumer product receives the prompt.

We send only the report excerpts, user question and operational metadata needed for the feature. Temporary HTML prepared specifically for AI analysis is configured for deletion after the run. Core crawl evidence, generated findings and the report may remain under the report-retention rules.

9.4 Training and service improvement

No general-purpose public-model training without opt-in

ScanMySEO does not use customer reports, onboarding context, crawled page content or Cozmo conversations to train or fine-tune a general-purpose public AI model unless the customer gives a separate, explicit opt-in. We may use aggregated or genuinely de-identified reliability metrics and voluntary feedback to evaluate and improve the service, without attempting to re-identify a customer or website.

9.5 Human access

Authorised ScanMySEO personnel may access a limited prompt, output or report context where necessary to answer a support request, investigate abuse, diagnose a failure, protect security, verify billing delivery or perform targeted quality assurance. Access is restricted to appropriate roles and is not a licence for routine browsing of customer reports. Provider personnel may have tightly controlled infrastructure access under the provider’s security and legal arrangements.

9.6 AI accuracy and high-impact use

AI output can be inaccurate, incomplete or inconsistent. It is not used by ScanMySEO to make a solely automated decision that produces a legal or similarly significant effect on an individual. Customers should review recommendations before making technical, legal, employment, financial, security or other high-impact decisions.

10

Billing, payments, credits and procurement

ScanMySEO may process:

  • billing email, company name, tax status, tax identifier, invoice details and purchase-order reference;
  • billing owner, administrator and viewer membership and invitations;
  • Stripe customer, checkout-session, payment-intent, subscription, price, invoice, portal and event identifiers;
  • product, Plan, billing interval, quantity, currency, subtotal, tax, discount and total;
  • order number, status, fulfilment, cancellation, refund, dispute, chargeback and reconciliation information;
  • subscription status, period dates, renewal, scheduled cancellation and plan-change state;
  • included allowances, PAYG tiers, reservations, consumption, restoration and immutable credit-ledger entries;
  • signed Stripe webhook records, processing attempts and error information;
  • spending limits, PAYG quantity limits and account billing preferences; and
  • Enterprise quote information, including business email, company, estimated pages, audit volume, procurement needs and message.
ScanMySEO does not collect full card details

Stripe hosts card entry, payment authentication and the Customer Portal. ScanMySEO does not receive or store the complete card number or card security code. We receive the payment, status and identifier information needed to fulfil, reconcile and support the order. Stripe independently processes payment and fraud data under its own privacy notice.

Billing administrators can see information appropriate to their role. The customer is responsible for inviting the correct people and removing access when authority ends. ScanMySEO administrators may inspect billing records to fulfil orders, reconcile Stripe, answer support questions, prevent fraud and maintain an auditable ledger.

11

Communications, support, feedback and newsletters

We may process:

  • support, contact, feedback and privacy-request messages and attachments;
  • sender and recipient details, timestamps, subject, delivery, bounce and response information;
  • account confirmation, password reset, security, crawl, report, billing and service-notice emails;
  • newsletter name, email, source, consent or permission record, subscription date and unsubscribe status;
  • customer-satisfaction or report-feedback responses;
  • complaint category, evidence, investigation notes, updates and outcome; and
  • telephone or meeting notes where an Enterprise or support interaction is arranged.

11.1 Service messages

Confirmation, password, security, report, billing, legal and material service messages are operational communications. They are not converted into marketing merely because they are sent by email. Some cannot be disabled while the account or transaction remains active.

11.2 Marketing messages

Promotional newsletters are sent where we have consent or another valid electronic- marketing permission. Each marketing email includes an unsubscribe route. We keep a limited suppression record after opt-out so the address is not accidentally re-added.

12

Technical, usage, device and security information

When you use the site or service, we and our providers may process:

  • IP address, approximate region, request time, URL, referrer, user agent, browser, operating system and device properties;
  • session, cookie, local-storage, CSRF, OAuth state and consent-preference information;
  • page views, feature events and aggregate usage information where optional analytics is permitted;
  • Socket.IO connection, user room, reconnection, progress-poll and delivery information;
  • rate-limit keys, hashed email-rate-limit keys, login attempts and bot-risk information;
  • reCAPTCHA token, action and score or verification outcome;
  • application, database, worker, queue, object-storage and API logs;
  • error type, stack or diagnostic metadata, service latency and retry information;
  • administrative access, configuration, export, deletion, reconciliation and security events;
  • security-email and suspected-account-compromise records; and
  • browser notification permission and interaction information where the browser makes it available.

We use this information to operate the service, secure accounts, isolate customer data, detect abuse, investigate incidents, measure reliability and support users. The Cookie Policy explains browser storage and optional analytics in more detail.

13

Where personal data comes from

We obtain information:

  • from you, when you register, complete onboarding, submit a website, ask Cozmo a question, purchase, contact us or change settings;
  • from your organisation or account owner, when they invite you, assign a billing role, provide client context or administer the workspace;
  • from a target website, sitemap, public page, server response or linked public resource during an authorised audit;
  • from Google or LinkedIn, when you select provider sign-in;
  • from Stripe, when you enter checkout, pay, manage billing, obtain a refund or dispute a charge;
  • from devices and browsers, through security logs, cookies, local storage, requests and optional analytics;
  • from service providers, including hosting, email, storage, model infrastructure and content-delivery providers;
  • from public business sources, where reasonably needed to verify an organisation, domain authority, professional contact or legal claim; and
  • from regulators, courts, law enforcement or advisers, where legally permitted or required.

14

Purposes and lawful bases

The lawful basis depends on the purpose and our role. “Contract” includes steps requested before a contract. “Legitimate interests” applies only after balancing our purpose against the person’s rights. Where we act as processor, the customer determines the lawful basis for its instructed processing.

Purposes and lawful bases for ScanMySEO processing
Purpose Information Primary lawful basis Why it is needed
Create and administer an account Identity, email, credentials, confirmation, role and session data Contract; legitimate interests for business-user administration and security To provide the requested workspace, authenticate users and manage access.
Run authorised crawls and generate reports Submitted URLs, public website content, crawl evidence, findings and files Contract; customer instructions where we act as processor; legitimate interests for platform reliability To deliver the core audit and preserve enough evidence to explain the result.
Provide AI Enhanced Audit and Report AI Selected report context, onboarding context, questions, outputs and model diagnostics Contract; customer instructions where processor; legitimate interests for security and fault diagnosis To provide the requested AI-assisted analysis and keep it reliable and safe.
Personalise explanations and priorities Persona, goals, experience, website type, industry and optional context Contract where required for the selected feature; legitimate interests for useful presentation; consent where optional sensitive context is deliberately requested To make reports understandable and relevant without making legally significant decisions.
Process orders, subscriptions and credits Billing contact, Stripe identifiers, orders, invoices, entitlements, ledger and disputes Contract; legal obligation; legitimate interests in reconciliation, fraud prevention and debt or claim management To take payment, grant the correct service, keep financial records and handle disputes.
Protect accounts, target sites and the platform IP, logs, rate limits, reCAPTCHA, authentication and administrative events Legitimate interests; legal obligation where applicable To prevent abuse, unauthorised access, fraud, overload and security incidents.
Provide support and communicate about the service Contact details, account/report context, messages and delivery information Contract; legitimate interests; legal obligation for certain notices and complaints To answer questions, deliver reports, warn about security and resolve problems.
Handle privacy requests and complaints Identity verification, request, evidence, correspondence and outcome Legal obligation; legitimate interests in establishing and documenting compliance To respect rights, investigate fairly and demonstrate the response.
Use optional Google Analytics Pseudonymous device and usage events Consent To understand aggregate use and improve the site without making analytics a condition of service.
Send promotional newsletters Name, email, permission, source and engagement or suppression state Consent or another lawful electronic-marketing permission; legitimate interests for permitted business-to-business contact To share relevant product or SEO updates while providing an unsubscribe route.
Improve reliability using aggregate or de-identified data Aggregated error rates, feature use, audit categories and performance measures Legitimate interests To improve capacity, quality and product decisions without publishing customer identity or confidential content.
Comply with law and manage claims Relevant account, billing, audit, communication and security records Legal obligation; legitimate interests in legal rights and defence To comply with lawful requests, retain accounting records and establish, exercise or defend claims.

Where special-category or criminal-offence data appears incidentally in submitted context or public website content, we do not intentionally infer or use it for profiling. We limit processing, remove unnecessary copies and rely on the customer’s lawful instructions or an applicable legal condition where such processing cannot be avoided.

15

Our legitimate interests

Our legitimate interests include:

  • operating a secure, reliable and commercially sustainable website-audit service;
  • preventing account abuse, payment fraud, credential attacks and harmful crawling;
  • protecting customers, target sites, infrastructure and our legal rights;
  • supporting users and diagnosing failed or inaccurate reports;
  • maintaining an auditable billing, entitlement and credit history;
  • understanding aggregate product performance without optional cross-site advertising;
  • personalising explanations in a proportionate way; and
  • communicating with relevant business contacts where lawful and expected.

We consider the nature of the data, the relationship, reasonable expectations, impact, safeguards and available choices. Safeguards can include minimisation, role-based access, security controls, short retention, aggregation, de-identification, consent for analytics, opt-out routes and human review. You can object to legitimate-interest processing under section 22.

16

Personalisation, profiling and automated decisions

ScanMySEO uses automated rules and models to:

  • classify crawl issues, severity, owner and suggested effort;
  • calculate a Website Health Score and report priorities;
  • adapt explanations using onboarding choices;
  • estimate site size and determine available Plan or credit paths;
  • apply rate limits, account-security checks and bot-risk controls;
  • reserve, consume or restore a credit according to delivery events; and
  • generate AI-assisted findings and answers.

These processes can affect feature availability, report presentation or whether an action is paused for security, but ScanMySEO does not use them to make a solely automated decision about an individual that has a legal or similarly significant effect. A customer can contact support to challenge an entitlement, fraud, security, credit or report decision and request human review where appropriate.

17

Recipients and service providers

We disclose only the information reasonably needed for the relevant service, legal duty or protected interest. Active recipient categories at the effective date include:

Service providers and recipients used by ScanMySEO
Provider or category Purpose and data Role Typical location / transfer note
Salesforce / Heroku and associated platform services Application hosting, database, worker, queue, logs and deployment infrastructure; account, crawl, report, billing and technical data as required. Processor/service provider for hosting; may have independent security and legal duties. Configured regions and global support can include the UK, EEA and United States. Contractual and transfer safeguards apply where required.
Amazon Web Services, including S3 Object and report-file storage, backup or delivery; report files, JSON and technical metadata. Processor/service provider. Production storage region selected in ScanMySEO configuration; cross-border support can occur. Current regional details are available through the subprocessor schedule.
Google Cloud ScanMySEO-managed AI inference on Cloud Run; selected report context, questions, outputs and operational metadata. Cloud infrastructure processor. AI inference is currently hosted in a European region; limited global support access may be possible under contractual controls.
Google Analytics 4 and Google Tag Manager Optional website and product analytics after consent; pseudonymous usage and device information. Provider relationship depends on the service configuration; Google may act as processor and independent controller for defined purposes. Globally operated, including EEA and United States processing. Optional analytics is blocked before consent.
Google reCAPTCHA and Google sign-in Bot and abuse prevention; optional OpenID Connect authentication; device, interaction and basic identity data. Google has independent controller responsibilities for aspects of its security and account services. Globally operated; transfer safeguards and Google’s provider notices apply.
LinkedIn Optional OpenID Connect sign-in; verified email, provider subject and basic profile identity. Independent controller for the LinkedIn account and authentication environment. Globally operated, including United States processing under LinkedIn’s transfer arrangements.
Stripe Checkout, subscriptions, invoices, tax, portal, payment authentication, refunds, disputes and fraud prevention. Processor for some merchant services and independent controller for payment, fraud and legal obligations. Globally operated. Stripe’s contractual and regulatory transfer arrangements apply.
Email and productivity providers, including Microsoft 365 where configured Account, security, report, billing, support, privacy and marketing email delivery and mailbox administration. Processor/service provider; provider may have independent security duties. Configured UK/EEA or global service regions, with contractual safeguards where required.
Content-delivery and browser-library providers Fonts, icons, JavaScript and styles; IP address, request, user-agent and referrer information. Examples can include Google Fonts, jsDelivr, cdnjs/Cloudflare, BootstrapCDN and DataTables CDN. Independent provider or subprocessor depending on integration. Globally distributed edge networks.
Professional advisers, insurers, auditors and corporate counterparties Information relevant to advice, insurance, audit, investment, restructuring, acquisition or sale, subject to confidentiality and necessity. Independent controllers or processors according to the engagement. Location depends on the adviser or transaction; safeguards apply before restricted transfers.
Regulators, courts, law enforcement and affected parties Information reasonably necessary to comply with law, protect rights, investigate incidents or respond to valid process. Independent recipients. Relevant jurisdiction; requests are assessed for validity and scope.

Providers can change as the service develops. We assess privacy, security, role, subprocessing and transfer arrangements before a material provider receives customer data. We update this policy or the business subprocessor schedule before a materially different purpose begins.

18

International data transfers

ScanMySEO is established in the United Kingdom, but providers and support operations can process information in the United Kingdom, European Economic Area, United States and other countries. A destination may not provide the same legal protections as the UK.

Where UK restricted-transfer rules apply, we use one or more of:

  • UK adequacy regulations for a destination recognised as providing adequate protection;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved EU Standard Contractual Clauses;
  • another valid Article 46 safeguard or legally permitted derogation;
  • a transfer-risk assessment; and
  • supplementary technical, organisational or contractual measures such as encryption, access restriction, minimisation and regional hosting.

You can ask for more information about a relevant transfer mechanism, subject to redaction of confidential and security-sensitive terms. A provider’s global privacy notice does not replace our responsibility to assess the transfer for the particular service.

19

Retention schedule

We keep personal data for the shortest period reasonably needed for the purpose, contract, legal obligation, security need or claim. “Up to” is a maximum operational target, not a promise to keep the record for the whole period. We may retain a specific record longer where law, a dispute, fraud investigation, legal hold or customer instruction requires it.

ScanMySEO personal data retention schedule
Record Normal retention Reason or deletion trigger
Unconfirmed account and unused registration state Normally up to 30 days Allows confirmation or correction while limiting dormant registrations; security evidence can be kept longer where abuse is suspected.
Active account, profile, role and onboarding data While the account is active, then normally removed from live product systems within 30 days of confirmed deletion Needed to provide and personalise the account; limited legal, billing, suppression and security records survive separately.
Ordinary login session Under the current production configuration, up to 12 hours Session security; can end sooner on logout, credential reset or revocation.
“Remember me” token Up to 14 days User-requested persistent sign-in; can be revoked sooner.
Password-reset token 30 minutes Short-lived credential recovery; invalidated by credential changes.
Email-confirmation token 1 hour per token Confirms control of the account email; resend and confirmation events can be retained with the account/security log.
Account-deletion confirmation token 30 minutes Confirms a sensitive irreversible request and any signed billing action.
OAuth access token Normally transient for the sign-in request We retain the provider subject and account link while the connection is needed, but do not ordinarily keep a reusable social-access token.
Failed or partial crawl temporary files Usually removed promptly; no later than 30 days unless needed for support or security Allows fault diagnosis and credit restoration while avoiding indefinite storage of unusable crawl content.
Successful crawl evidence, dashboard report, PDF, CSV, spreadsheet and JSON While the account is active and the report is needed to provide requested history, or until the customer deletes it Supports report access and comparisons. We may remove inactive report archives after at least 24 months without account activity, with notice where practicable. ScanMySEO is not permanent archival storage.
Temporary AI-specific raw HTML Configured for deletion after the AI run; failed-cleanup material should be removed within 7 days Needed only to prepare AI analysis; core report evidence follows the report rule.
AI Enhanced Audit findings saved in a report Same as the report Forms part of the customer deliverable.
Report AI job state and transient conversation context Normally up to 24 hours Supports asynchronous answer delivery, polling and recovery.
Report AI question, response or diagnostic excerpt retained for fault, abuse or support investigation Up to 30 days unless attached to an open support, security or legal case Allows targeted diagnosis without promising permanent chat history.
AI model, prompt, latency, retry and failure metadata without unnecessary content Up to 90 days; aggregate statistics may be retained longer Capacity planning, incident analysis and model reliability.
Support and ordinary feedback records Up to 24 months after closure Follow-up, quality and dispute context; routine records are deleted or de-identified when no longer useful.
Data-protection complaint and material rights-request record Up to 6 years after final outcome Demonstrates the investigation, response and legal position.
Newsletter subscription Until unsubscribe, invalid address or purpose ends Permission record supports delivery; a minimal suppression record remains after opt-out.
Marketing suppression record As long as reasonably needed to honour the opt-out Prevents accidental re-subscription; normally limited to address, date and source.
Enterprise quote without completed sale Up to 24 months after last meaningful contact Allows procurement follow-up and avoids indefinite prospect retention.
Orders, invoices, subscriptions, tax records, payment status, credit ledger, refunds and disputes Normally 6 years from the end of the relevant financial year or transaction relationship Accounting, tax, reconciliation, fraud, contract and legal-claim obligations.
Stripe webhook and billing-reconciliation records Up to 6 years where needed to prove fulfilment or ledger integrity; shorter for low-value raw delivery logs Prevents duplicate fulfilment and preserves an auditable payment history.
Routine security, access and administrative audit logs Up to 12 months Detection, investigation and accountability; an incident-related subset may be held up to 6 years.
GA4 event-level user data Up to 14 months after consented collection Aggregate product and website analysis; reports may be aggregated sooner.
GA4 browser identifiers Up to 2 years unless consent is withdrawn or storage is cleared Browser-level analytics after consent; see the Cookie Policy.
Cookie-consent evidence Up to 6 years Demonstrates the version and choice; the browser preference itself is normally refreshed within 6 months.
Backups Normally overwritten within 90 days Disaster recovery. Deleted data is not restored for ordinary product use and is removed through the backup cycle.
Genuinely anonymised aggregate statistics May be retained indefinitely Information that can no longer identify a person is not personal data; we do not attempt re-identification.

20

Account deletion and what remains

An eligible user can start account deletion through the account controls or contact support. ScanMySEO uses a short-lived confirmation token to reduce accidental or malicious deletion. The flow may ask how an active Stripe subscription should be handled so an invisible recurring charge is not left behind.

After confirmed deletion:

  • access is revoked and live sessions are ended;
  • account profile, onboarding, private reports and associated live product data are normally removed within 30 days;
  • backup copies expire through the normal cycle, usually within 90 days;
  • Stripe separately retains payment information under its legal duties;
  • ScanMySEO retains limited order, invoice, subscription, credit-ledger, refund, dispute, tax and reconciliation records for the periods in section 19;
  • security, complaint, legal-claim and suppression records can remain where necessary;
  • provider-side deletion is subject to the provider’s role and retention duties; and
  • genuinely anonymised aggregate information may remain.

Account deletion is distinct from cancelling a subscription or deleting an individual report. Unused paid PAYG credits and refunds are handled under the Terms, Audit Credit Policy and Refund Policy rather than silently rewritten in the ledger.

Download what you need first

Deletion can permanently remove dashboard history and report files. Export reports you are entitled and authorised to keep before confirming deletion.

21

Your privacy rights

Depending on the information, purpose, lawful basis and applicable law, you may have the right to:

  • access personal data and receive information about its processing;
  • rectify inaccurate personal data and complete incomplete information;
  • erase personal data where there is no overriding reason to retain it;
  • restrict processing in specified circumstances;
  • object to direct marketing and certain legitimate-interest or public-task processing;
  • port information you provided where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time, without affecting earlier lawful processing;
  • challenge automated decision-making and request human intervention where the law applies;
  • complain to ScanMySEO and the Information Commissioner’s Office; and
  • authorise a representative, subject to reasonable evidence of authority.

Rights are not absolute. For example, we may retain transaction records required by law, protect another person’s rights, preserve security evidence or refuse disclosure of another customer’s confidential information. We explain any material refusal or limitation.

21.1 How to make a request

Email cozmo@scanmyseo.com with the subject “Privacy rights request” or use the contact form. Describe the account, email, domain, report or processing concerned and the right you wish to exercise.

21.2 Identity and authority checks

We may request proportionate evidence to confirm identity, account control, domain or client authority. We do not ask for more identification than reasonably needed. A request made from the verified account email or through an authenticated account can reduce the evidence required.

21.3 Timing and fees

We normally respond without undue delay and within one month. A legally permitted extension may apply to complex or numerous requests, and we will explain it. Requests are normally free, although the law may permit a reasonable fee or refusal for a manifestly unfounded or excessive request.

22

Your right to object

Direct marketing: you can object at any time

You have an absolute right to object to processing for direct marketing, including related profiling. Use the unsubscribe link in a marketing email or contact us. We will stop the marketing and keep only the limited suppression information needed to honour the choice.

You can also object where we rely on legitimate interests. Tell us the processing and your reasons. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.

Optional analytics is based on consent rather than legitimate interests. Use Cookie Settings to reject or withdraw analytics permission.

23

Data-protection complaints and the ICO

A data-protection complaint is a concern that ScanMySEO has infringed data-protection law in relation to personal data. Send it to cozmo@scanmyseo.com with the subject “Data protection complaint” or use the contact form.

Our complaint process is to:

  1. record the complaint and preserve relevant evidence;
  2. acknowledge it promptly and, where the statutory complaint duty applies, within 30 days;
  3. investigate without undue delay through someone with appropriate authority;
  4. ask focused questions where information is missing;
  5. keep you informed where the investigation takes time;
  6. communicate the outcome, action taken and available escalation route; and
  7. retain a proportionate complaint and outcome record.

You can complain directly to the Information Commissioner’s Office (ICO), the UK supervisory authority, without contacting ScanMySEO first. We welcome the opportunity to resolve concerns, but it is not a precondition. Visit the ICO complaint service.

24

Agency, client and public-data requests

24.1 Agency or customer-controlled data

Where an agency or business customer controls the audit and report, a person should usually contact that organisation first because it decides the website, purpose and use of the report. ScanMySEO assists the customer with rights requests under the DPA where we act as processor and responds directly for our controller data.

24.2 People appearing on an audited website

If your information appears in crawl evidence, tell us the source URL, information and concern. We may need to notify the customer, restrict a report excerpt, correct our copy, remove an unnecessary cached item or direct the correction to the website operator. We do not normally alter the source website and cannot promise to remove content controlled by a third party.

24.3 Domain and workspace disputes

We may request evidence of domain, client or workspace authority before disclosing, transferring or deleting a report. Owning a domain does not automatically entitle someone to another customer’s confidential account information, and an account record does not override a verified legal right in the underlying personal data.

25

Children, sensitive information and prohibited secrets

25.1 Accounts

ScanMySEO accounts and paid services are intended for adults aged 18 or over. We do not knowingly create accounts for children. A parent or guardian who believes a child created an account should contact us so we can verify and take appropriate action.

25.2 Children appearing on public websites

An authorised crawl can incidentally encounter information about a child on a public page, such as a school, charity, sports or family website. Customers should avoid unnecessary submission of sites containing children’s sensitive information and must have a lawful basis. ScanMySEO limits use to the requested audit and does not intentionally profile the child for advertising.

25.3 Special-category and criminal-offence data

The service is not designed to collect health, genetic, biometric, racial or ethnic, religious, political, trade-union, sex-life, sexual-orientation or criminal-offence data. Do not place such information in onboarding, report chat, support or quote fields unless it is genuinely necessary, lawful and agreed with us in advance for an Enterprise service.

25.4 Passwords and secrets

Never submit passwords, private keys, API credentials, payment-card data, access tokens, authentication cookies or confidential database exports through a crawl field, Cozmo question or ordinary support form. If this happens, notify us promptly so we can reduce exposure and advise on credential rotation.

26

Security, confidentiality and incidents

Security measures are selected according to risk and can include:

  • TLS for data in transit and protected cloud storage or databases;
  • cryptographic password hashing and short-lived signed account tokens;
  • Secure, HttpOnly and SameSite controls for authentication cookies;
  • CSRF protection, safe redirects, OAuth state validation and identity-claim checks;
  • role-based access, account ownership checks and user-specific report or Socket.IO rooms;
  • rate limiting, reCAPTCHA, login-event records and security notifications;
  • signed Stripe webhooks, idempotent fulfilment and immutable credit-ledger entries;
  • restricted administrative functions and audit records;
  • provider due diligence, secrets management, backups and recovery controls; and
  • logging minimisation that avoids intentionally writing passwords or full payment-card data.

No online service can guarantee absolute security. Users must protect credentials, remove former team members, use trusted devices and report suspected compromise. We may revoke sessions, require a reset, pause a crawl or restrict an account to contain a risk.

If a personal-data breach creates a risk that requires notification, we follow applicable assessment, regulator and individual-notification duties. We preserve relevant evidence, contain the incident, investigate causes and take proportionate corrective action.

27

Marketing, analytics, aggregate intelligence and commercial neutrality

27.1 No sale, rent or cross-site behavioural advertising

ScanMySEO does not sell or rent personal data. We do not use customer reports, crawl content or Cozmo questions to build a cross-site behavioural advertising profile. We do not permit advertisers to alter technical findings or AI answers.

27.2 Optional analytics

Google Analytics 4 is optional and consent-based. The Cookie Policy explains the approved measurement configuration, retention and withdrawal control. Rejecting analytics does not affect the ordinary audit service.

27.3 Aggregate and de-identified intelligence

We may create aggregate reliability, error-frequency, feature-use, technology-adoption or industry-level statistics where the result does not identify a person, customer or confidential website. We apply aggregation thresholds or other safeguards appropriate to the data and do not attempt to re-identify anonymised information.

We do not sell a customer’s secrets or private report as competitor intelligence. A plan recommendation may use page count, entitlement and usage information, but technical findings are not manufactured or inflated to force an upgrade. Sponsored or affiliate content, if introduced, will be labelled and kept separate from audit methodology.

28

Legal disclosures, external links and corporate events

28.1 Legal and protective disclosures

We may disclose relevant information where reasonably necessary to:

  • comply with law, court order or valid regulatory or law-enforcement request;
  • investigate fraud, security, abuse, unauthorised crawling or threats to a target site;
  • enforce the Terms, protect users or defend legal claims;
  • notify an affected person or organisation of a security incident;
  • recover debt or resolve a payment dispute; or
  • protect vital interests in an emergency.

We assess the requesting authority, jurisdiction, legal basis, scope and available challenge or notice options. We disclose no more than reasonably necessary.

28.2 Corporate transactions

Personal data may be reviewed or transferred as part of investment due diligence, merger, acquisition, restructuring, insolvency or sale of assets. We use confidentiality, minimisation and access controls and provide notice where required. A successor must use the information consistently with applicable law and the commitments that continue to apply.

28.3 External links

Links to Stripe, Google, LinkedIn, articles or other websites lead to services with their own privacy practices. Following a link can disclose IP address, browser headers, referrer and URL information to the destination. ScanMySEO is not responsible for an external service’s independent processing. We avoid placing secrets or sensitive identifiers in external URLs.

29

Changes to this Privacy Policy

We update this notice when processing, providers, retention, rights, product features or law materially changes. The version and date change only after a genuine review; they are not automatically replaced with the date you happen to visit.

Material changes are communicated through the website, account dashboard, email or another appropriate route. Where practicable, we provide advance notice. A new purpose is explained before processing begins, and we obtain fresh consent where the new activity depends on consent. We do not claim that continued use creates consent to an unrelated new privacy purpose.

Previous versions and a meaningful change summary are retained internally and can be made available where reasonably required to understand which notice applied.

30

Contact, privacy requests and Data Processing Addendum

Contact ScanMySEO about this notice, a privacy right, a public-data concern, a complaint or a Data Processing Addendum at cozmo@scanmyseo.com or through the contact form.

Use a clear subject:

  • “Privacy rights request”;
  • “Data protection complaint”;
  • “Public website data concern”;
  • “Security incident”; or
  • “DPA and subprocessor request”.

Do not email passwords, full card details, private keys or unnecessary identity documents. We will tell you a safer route where evidence is needed.

Need a privacy response from a person, not a generic inbox loop?

Use the contact route and identify the account, domain, report or processing concerned.

Contact ScanMySEO
Back to top Cookie Policy Terms of Service

We use cookies to improve your experience and to help us build a better application. Please select whether you accept or decline the use of non-essential cookies. Learn more






Scan My SEO

Your ultimate tool for comprehensive SEO audits and technical insights.


Empowering Your SEO Journey

ScanMySEO is here to help you identify and fix SEO issues with ease. Enter a domain to get started.

Main Links
  • Feedback
  • Pricing
  • Privacy Policy
  • Cookie Policy
  • Terms of Service
Contact Us
Contact
About
How it Works
Articles

Join Our SEO Community!

Get the inside scoop on all things search.

Cookie Settings

© ScanMySEO | Feedback