Card data stays with Stripe
ScanMySEO stores payment and entitlement records, but does not receive or store your complete card number or security code.
Privacy designed around the service
This notice explains how ScanMySEO handles information about website visitors, account users, customers, people appearing on audited public websites and others who interact with us. It also explains your choices, privacy rights and how to raise a complaint.
Our practical commitments
This notice is not a request for blanket consent and is not a substitute for the Terms of Service. We use the lawful basis that fits each purpose, keep collection proportionate and provide specific controls where consent or another choice is required.
ScanMySEO stores payment and entitlement records, but does not receive or store your complete card number or security code.
We do not sell or rent personal data and do not use customer information for cross-site behavioural advertising.
Customer reports, onboarding context and Cozmo conversations are not used to train general-purpose public AI models without explicit opt-in.
An authorised audit can process names or other information on public pages. We describe that processing instead of pretending public means anonymous.
1
ScanMySEO is operated by SCANMYSEO LTD, a company registered in England and Wales under company number 17166063. In this notice, “ScanMySEO”, “we”, “us” and “our” refer to SCANMYSEO LTD.
This notice explains what personal data we process, where it comes from, why we use it, the lawful basis, who receives it, how long it is retained, how international transfers are protected and what rights are available. It applies to scanmyseo.com, the ScanMySEO account and audit service, customer dashboards, reports, AI features, billing, support, sales and related business operations.
A privacy notice explains processing; it is not a contract and does not turn every use of personal data into consent. Where we rely on consent, we ask separately and allow it to be withdrawn. The Terms of Service govern the service contract.
Privacy requests, public-data concerns and complaints can be made through the email and contact routes in section 30, including by people who have never used ScanMySEO.
2
Privacy roles depend on the particular purpose. A company can be a controller for one activity and a processor for another.
We decide the purposes and essential means for:
For a business customer, we may process customer-controlled personal data on instructions when we:
Where ScanMySEO acts as processor, the customer is normally responsible for its own transparency, instructions and lawful basis. We still process limited account, security, billing and platform-administration information as an independent controller. A Data Processing Addendum is available for eligible agency and Enterprise customers.
Stripe, Google, LinkedIn and certain other providers may act as separate or independent controllers for their own fraud, legal, account, authentication or service-improvement purposes. Calling a provider a “processor” in one context does not override that provider’s independent legal duties.
3
This notice can apply to:
Some people covered by this notice never create a ScanMySEO account. Section 24 explains the most practical route for a person who appears on an audited website or customer report.
4
Depending on how you create and use an account, we may process:
ScanMySEO stores a cryptographic password hash rather than a readable password. OAuth-only accounts are configured without a usable local password unless the user later establishes one through an authorised process. Do not reuse a ScanMySEO password elsewhere.
For Google and LinkedIn OpenID Connect sign-in, ScanMySEO requests basic identity scopes: OpenID identity, profile and email. We typically receive a verified email address, provider user identifier and name or profile fields needed to create or match the account. We do not use those permissions to post to the provider account, read private messages, import contacts or access unrelated social content.
Access tokens are normally used transiently to complete authentication and are not kept as a reusable social-account connection. We retain the provider identity link while needed to support sign-in and account security. The provider independently processes the sign-in under its own privacy notice.
5
Optional or required onboarding can include:
We use this information to change explanation depth, prioritisation, suggested starting points, summaries and AI context. It does not change the underlying customer responsibility to verify a finding, and it is not used to make a decision with legal or similarly significant effects.
Do not enter passwords, access tokens, API keys, private customer lists, confidential credentials, health data, criminal-offence data or other highly sensitive information in the website-context field.
6
When an authorised user starts an audit, we may process:
ScanMySEO is intended for publicly accessible website content. It is not designed to bypass logins, paywalls, CAPTCHAs, private administration areas or other access controls. Customers must have lawful authority to submit the website and must not provide private credentials to the crawler.
A target website, CDN, hosting provider, analytics system or security service may record the ScanMySEO crawler’s requests, user agent, source IP, timing and page access. Those records are controlled by the target-site operator and its providers.
7
Publicly accessible content can still be personal data. An authorised audit may encounter a person’s name, job title, biography, business contact details, photograph, authorship, social link, testimonial, event information or other information published on the target website.
When we act as processor, the customer decides why the website is audited and is normally responsible for its lawful basis and privacy information. ScanMySEO processes the content to produce the requested technical and AI-assisted report, secure the platform, diagnose faults and comply with law. We do not use crawled names or contact details to market to the people appearing on the target site.
We minimise report evidence where full reproduction is unnecessary. Reports can include a URL, short excerpt, page title, image reference or technical evidence needed to explain a finding. Customers must not use ScanMySEO to build unlawful profiles, harass individuals, harvest sensitive personal data or conduct surveillance.
If you appear on an audited website and want information corrected or removed, the website owner or ScanMySEO customer is usually best placed to correct the source. You may also contact us under section 24 and we will assess our role, preserve account security and assist the relevant customer where appropriate.
8
Report data can include:
Reports are private to the authorised account except where the customer downloads or shares them. Administrators may access a report only where reasonably necessary for support, security, legal compliance, billing investigation, service restoration or authorised quality assurance. Access is restricted by role and should be auditable where the relevant system supports audit logging.
ScanMySEO is not a permanent archival-storage service. Customers should download material they must preserve and must protect exported reports that contain client, website or personal information.
9
Depending on the feature and Plan, AI processing can include:
Report AI is designed to answer from the completed crawl’s report context. The current report-chat interface does not browse the live web, accept user file uploads or execute backend changes to a website. It generates explanatory output; the customer decides whether and how to act on it.
At the effective date, eligible AI Enhanced Audit and Report AI workloads are routed to ScanMySEO-managed inference services hosted on Google Cloud Run in a European region and use a Gemma-family model. Google Cloud provides the infrastructure. This is not the consumer Gemini chat service, and the model creator’s name does not by itself mean that a separate consumer product receives the prompt.
We send only the report excerpts, user question and operational metadata needed for the feature. Temporary HTML prepared specifically for AI analysis is configured for deletion after the run. Core crawl evidence, generated findings and the report may remain under the report-retention rules.
ScanMySEO does not use customer reports, onboarding context, crawled page content or Cozmo conversations to train or fine-tune a general-purpose public AI model unless the customer gives a separate, explicit opt-in. We may use aggregated or genuinely de-identified reliability metrics and voluntary feedback to evaluate and improve the service, without attempting to re-identify a customer or website.
Authorised ScanMySEO personnel may access a limited prompt, output or report context where necessary to answer a support request, investigate abuse, diagnose a failure, protect security, verify billing delivery or perform targeted quality assurance. Access is restricted to appropriate roles and is not a licence for routine browsing of customer reports. Provider personnel may have tightly controlled infrastructure access under the provider’s security and legal arrangements.
AI output can be inaccurate, incomplete or inconsistent. It is not used by ScanMySEO to make a solely automated decision that produces a legal or similarly significant effect on an individual. Customers should review recommendations before making technical, legal, employment, financial, security or other high-impact decisions.
10
ScanMySEO may process:
Stripe hosts card entry, payment authentication and the Customer Portal. ScanMySEO does not receive or store the complete card number or card security code. We receive the payment, status and identifier information needed to fulfil, reconcile and support the order. Stripe independently processes payment and fraud data under its own privacy notice.
Billing administrators can see information appropriate to their role. The customer is responsible for inviting the correct people and removing access when authority ends. ScanMySEO administrators may inspect billing records to fulfil orders, reconcile Stripe, answer support questions, prevent fraud and maintain an auditable ledger.
11
We may process:
Confirmation, password, security, report, billing, legal and material service messages are operational communications. They are not converted into marketing merely because they are sent by email. Some cannot be disabled while the account or transaction remains active.
Promotional newsletters are sent where we have consent or another valid electronic- marketing permission. Each marketing email includes an unsubscribe route. We keep a limited suppression record after opt-out so the address is not accidentally re-added.
12
When you use the site or service, we and our providers may process:
We use this information to operate the service, secure accounts, isolate customer data, detect abuse, investigate incidents, measure reliability and support users. The Cookie Policy explains browser storage and optional analytics in more detail.
13
We obtain information:
14
The lawful basis depends on the purpose and our role. “Contract” includes steps requested before a contract. “Legitimate interests” applies only after balancing our purpose against the person’s rights. Where we act as processor, the customer determines the lawful basis for its instructed processing.
| Purpose | Information | Primary lawful basis | Why it is needed |
|---|---|---|---|
| Create and administer an account | Identity, email, credentials, confirmation, role and session data | Contract; legitimate interests for business-user administration and security | To provide the requested workspace, authenticate users and manage access. |
| Run authorised crawls and generate reports | Submitted URLs, public website content, crawl evidence, findings and files | Contract; customer instructions where we act as processor; legitimate interests for platform reliability | To deliver the core audit and preserve enough evidence to explain the result. |
| Provide AI Enhanced Audit and Report AI | Selected report context, onboarding context, questions, outputs and model diagnostics | Contract; customer instructions where processor; legitimate interests for security and fault diagnosis | To provide the requested AI-assisted analysis and keep it reliable and safe. |
| Personalise explanations and priorities | Persona, goals, experience, website type, industry and optional context | Contract where required for the selected feature; legitimate interests for useful presentation; consent where optional sensitive context is deliberately requested | To make reports understandable and relevant without making legally significant decisions. |
| Process orders, subscriptions and credits | Billing contact, Stripe identifiers, orders, invoices, entitlements, ledger and disputes | Contract; legal obligation; legitimate interests in reconciliation, fraud prevention and debt or claim management | To take payment, grant the correct service, keep financial records and handle disputes. |
| Protect accounts, target sites and the platform | IP, logs, rate limits, reCAPTCHA, authentication and administrative events | Legitimate interests; legal obligation where applicable | To prevent abuse, unauthorised access, fraud, overload and security incidents. |
| Provide support and communicate about the service | Contact details, account/report context, messages and delivery information | Contract; legitimate interests; legal obligation for certain notices and complaints | To answer questions, deliver reports, warn about security and resolve problems. |
| Handle privacy requests and complaints | Identity verification, request, evidence, correspondence and outcome | Legal obligation; legitimate interests in establishing and documenting compliance | To respect rights, investigate fairly and demonstrate the response. |
| Use optional Google Analytics | Pseudonymous device and usage events | Consent | To understand aggregate use and improve the site without making analytics a condition of service. |
| Send promotional newsletters | Name, email, permission, source and engagement or suppression state | Consent or another lawful electronic-marketing permission; legitimate interests for permitted business-to-business contact | To share relevant product or SEO updates while providing an unsubscribe route. |
| Improve reliability using aggregate or de-identified data | Aggregated error rates, feature use, audit categories and performance measures | Legitimate interests | To improve capacity, quality and product decisions without publishing customer identity or confidential content. |
| Comply with law and manage claims | Relevant account, billing, audit, communication and security records | Legal obligation; legitimate interests in legal rights and defence | To comply with lawful requests, retain accounting records and establish, exercise or defend claims. |
Where special-category or criminal-offence data appears incidentally in submitted context or public website content, we do not intentionally infer or use it for profiling. We limit processing, remove unnecessary copies and rely on the customer’s lawful instructions or an applicable legal condition where such processing cannot be avoided.
15
Our legitimate interests include:
We consider the nature of the data, the relationship, reasonable expectations, impact, safeguards and available choices. Safeguards can include minimisation, role-based access, security controls, short retention, aggregation, de-identification, consent for analytics, opt-out routes and human review. You can object to legitimate-interest processing under section 22.
16
ScanMySEO uses automated rules and models to:
These processes can affect feature availability, report presentation or whether an action is paused for security, but ScanMySEO does not use them to make a solely automated decision about an individual that has a legal or similarly significant effect. A customer can contact support to challenge an entitlement, fraud, security, credit or report decision and request human review where appropriate.
17
We disclose only the information reasonably needed for the relevant service, legal duty or protected interest. Active recipient categories at the effective date include:
| Provider or category | Purpose and data | Role | Typical location / transfer note |
|---|---|---|---|
| Salesforce / Heroku and associated platform services | Application hosting, database, worker, queue, logs and deployment infrastructure; account, crawl, report, billing and technical data as required. | Processor/service provider for hosting; may have independent security and legal duties. | Configured regions and global support can include the UK, EEA and United States. Contractual and transfer safeguards apply where required. |
| Amazon Web Services, including S3 | Object and report-file storage, backup or delivery; report files, JSON and technical metadata. | Processor/service provider. | Production storage region selected in ScanMySEO configuration; cross-border support can occur. Current regional details are available through the subprocessor schedule. |
| Google Cloud | ScanMySEO-managed AI inference on Cloud Run; selected report context, questions, outputs and operational metadata. | Cloud infrastructure processor. | AI inference is currently hosted in a European region; limited global support access may be possible under contractual controls. |
| Google Analytics 4 and Google Tag Manager | Optional website and product analytics after consent; pseudonymous usage and device information. | Provider relationship depends on the service configuration; Google may act as processor and independent controller for defined purposes. | Globally operated, including EEA and United States processing. Optional analytics is blocked before consent. |
| Google reCAPTCHA and Google sign-in | Bot and abuse prevention; optional OpenID Connect authentication; device, interaction and basic identity data. | Google has independent controller responsibilities for aspects of its security and account services. | Globally operated; transfer safeguards and Google’s provider notices apply. |
| Optional OpenID Connect sign-in; verified email, provider subject and basic profile identity. | Independent controller for the LinkedIn account and authentication environment. | Globally operated, including United States processing under LinkedIn’s transfer arrangements. | |
| Stripe | Checkout, subscriptions, invoices, tax, portal, payment authentication, refunds, disputes and fraud prevention. | Processor for some merchant services and independent controller for payment, fraud and legal obligations. | Globally operated. Stripe’s contractual and regulatory transfer arrangements apply. |
| Email and productivity providers, including Microsoft 365 where configured | Account, security, report, billing, support, privacy and marketing email delivery and mailbox administration. | Processor/service provider; provider may have independent security duties. | Configured UK/EEA or global service regions, with contractual safeguards where required. |
| Content-delivery and browser-library providers | Fonts, icons, JavaScript and styles; IP address, request, user-agent and referrer information. Examples can include Google Fonts, jsDelivr, cdnjs/Cloudflare, BootstrapCDN and DataTables CDN. | Independent provider or subprocessor depending on integration. | Globally distributed edge networks. |
| Professional advisers, insurers, auditors and corporate counterparties | Information relevant to advice, insurance, audit, investment, restructuring, acquisition or sale, subject to confidentiality and necessity. | Independent controllers or processors according to the engagement. | Location depends on the adviser or transaction; safeguards apply before restricted transfers. |
| Regulators, courts, law enforcement and affected parties | Information reasonably necessary to comply with law, protect rights, investigate incidents or respond to valid process. | Independent recipients. | Relevant jurisdiction; requests are assessed for validity and scope. |
Providers can change as the service develops. We assess privacy, security, role, subprocessing and transfer arrangements before a material provider receives customer data. We update this policy or the business subprocessor schedule before a materially different purpose begins.
18
ScanMySEO is established in the United Kingdom, but providers and support operations can process information in the United Kingdom, European Economic Area, United States and other countries. A destination may not provide the same legal protections as the UK.
Where UK restricted-transfer rules apply, we use one or more of:
You can ask for more information about a relevant transfer mechanism, subject to redaction of confidential and security-sensitive terms. A provider’s global privacy notice does not replace our responsibility to assess the transfer for the particular service.
19
We keep personal data for the shortest period reasonably needed for the purpose, contract, legal obligation, security need or claim. “Up to” is a maximum operational target, not a promise to keep the record for the whole period. We may retain a specific record longer where law, a dispute, fraud investigation, legal hold or customer instruction requires it.
| Record | Normal retention | Reason or deletion trigger |
|---|---|---|
| Unconfirmed account and unused registration state | Normally up to 30 days | Allows confirmation or correction while limiting dormant registrations; security evidence can be kept longer where abuse is suspected. |
| Active account, profile, role and onboarding data | While the account is active, then normally removed from live product systems within 30 days of confirmed deletion | Needed to provide and personalise the account; limited legal, billing, suppression and security records survive separately. |
| Ordinary login session | Under the current production configuration, up to 12 hours | Session security; can end sooner on logout, credential reset or revocation. |
| “Remember me” token | Up to 14 days | User-requested persistent sign-in; can be revoked sooner. |
| Password-reset token | 30 minutes | Short-lived credential recovery; invalidated by credential changes. |
| Email-confirmation token | 1 hour per token | Confirms control of the account email; resend and confirmation events can be retained with the account/security log. |
| Account-deletion confirmation token | 30 minutes | Confirms a sensitive irreversible request and any signed billing action. |
| OAuth access token | Normally transient for the sign-in request | We retain the provider subject and account link while the connection is needed, but do not ordinarily keep a reusable social-access token. |
| Failed or partial crawl temporary files | Usually removed promptly; no later than 30 days unless needed for support or security | Allows fault diagnosis and credit restoration while avoiding indefinite storage of unusable crawl content. |
| Successful crawl evidence, dashboard report, PDF, CSV, spreadsheet and JSON | While the account is active and the report is needed to provide requested history, or until the customer deletes it | Supports report access and comparisons. We may remove inactive report archives after at least 24 months without account activity, with notice where practicable. ScanMySEO is not permanent archival storage. |
| Temporary AI-specific raw HTML | Configured for deletion after the AI run; failed-cleanup material should be removed within 7 days | Needed only to prepare AI analysis; core report evidence follows the report rule. |
| AI Enhanced Audit findings saved in a report | Same as the report | Forms part of the customer deliverable. |
| Report AI job state and transient conversation context | Normally up to 24 hours | Supports asynchronous answer delivery, polling and recovery. |
| Report AI question, response or diagnostic excerpt retained for fault, abuse or support investigation | Up to 30 days unless attached to an open support, security or legal case | Allows targeted diagnosis without promising permanent chat history. |
| AI model, prompt, latency, retry and failure metadata without unnecessary content | Up to 90 days; aggregate statistics may be retained longer | Capacity planning, incident analysis and model reliability. |
| Support and ordinary feedback records | Up to 24 months after closure | Follow-up, quality and dispute context; routine records are deleted or de-identified when no longer useful. |
| Data-protection complaint and material rights-request record | Up to 6 years after final outcome | Demonstrates the investigation, response and legal position. |
| Newsletter subscription | Until unsubscribe, invalid address or purpose ends | Permission record supports delivery; a minimal suppression record remains after opt-out. |
| Marketing suppression record | As long as reasonably needed to honour the opt-out | Prevents accidental re-subscription; normally limited to address, date and source. |
| Enterprise quote without completed sale | Up to 24 months after last meaningful contact | Allows procurement follow-up and avoids indefinite prospect retention. |
| Orders, invoices, subscriptions, tax records, payment status, credit ledger, refunds and disputes | Normally 6 years from the end of the relevant financial year or transaction relationship | Accounting, tax, reconciliation, fraud, contract and legal-claim obligations. |
| Stripe webhook and billing-reconciliation records | Up to 6 years where needed to prove fulfilment or ledger integrity; shorter for low-value raw delivery logs | Prevents duplicate fulfilment and preserves an auditable payment history. |
| Routine security, access and administrative audit logs | Up to 12 months | Detection, investigation and accountability; an incident-related subset may be held up to 6 years. |
| GA4 event-level user data | Up to 14 months after consented collection | Aggregate product and website analysis; reports may be aggregated sooner. |
| GA4 browser identifiers | Up to 2 years unless consent is withdrawn or storage is cleared | Browser-level analytics after consent; see the Cookie Policy. |
| Cookie-consent evidence | Up to 6 years | Demonstrates the version and choice; the browser preference itself is normally refreshed within 6 months. |
| Backups | Normally overwritten within 90 days | Disaster recovery. Deleted data is not restored for ordinary product use and is removed through the backup cycle. |
| Genuinely anonymised aggregate statistics | May be retained indefinitely | Information that can no longer identify a person is not personal data; we do not attempt re-identification. |
20
An eligible user can start account deletion through the account controls or contact support. ScanMySEO uses a short-lived confirmation token to reduce accidental or malicious deletion. The flow may ask how an active Stripe subscription should be handled so an invisible recurring charge is not left behind.
After confirmed deletion:
Account deletion is distinct from cancelling a subscription or deleting an individual report. Unused paid PAYG credits and refunds are handled under the Terms, Audit Credit Policy and Refund Policy rather than silently rewritten in the ledger.
Deletion can permanently remove dashboard history and report files. Export reports you are entitled and authorised to keep before confirming deletion.
21
Depending on the information, purpose, lawful basis and applicable law, you may have the right to:
Rights are not absolute. For example, we may retain transaction records required by law, protect another person’s rights, preserve security evidence or refuse disclosure of another customer’s confidential information. We explain any material refusal or limitation.
Email cozmo@scanmyseo.com with the subject “Privacy rights request” or use the contact form. Describe the account, email, domain, report or processing concerned and the right you wish to exercise.
We may request proportionate evidence to confirm identity, account control, domain or client authority. We do not ask for more identification than reasonably needed. A request made from the verified account email or through an authenticated account can reduce the evidence required.
We normally respond without undue delay and within one month. A legally permitted extension may apply to complex or numerous requests, and we will explain it. Requests are normally free, although the law may permit a reasonable fee or refusal for a manifestly unfounded or excessive request.
22
You have an absolute right to object to processing for direct marketing, including related profiling. Use the unsubscribe link in a marketing email or contact us. We will stop the marketing and keep only the limited suppression information needed to honour the choice.
You can also object where we rely on legitimate interests. Tell us the processing and your reasons. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
Optional analytics is based on consent rather than legitimate interests. Use Cookie Settings to reject or withdraw analytics permission.
23
A data-protection complaint is a concern that ScanMySEO has infringed data-protection law in relation to personal data. Send it to cozmo@scanmyseo.com with the subject “Data protection complaint” or use the contact form.
Our complaint process is to:
You can complain directly to the Information Commissioner’s Office (ICO), the UK supervisory authority, without contacting ScanMySEO first. We welcome the opportunity to resolve concerns, but it is not a precondition. Visit the ICO complaint service.
24
Where an agency or business customer controls the audit and report, a person should usually contact that organisation first because it decides the website, purpose and use of the report. ScanMySEO assists the customer with rights requests under the DPA where we act as processor and responds directly for our controller data.
If your information appears in crawl evidence, tell us the source URL, information and concern. We may need to notify the customer, restrict a report excerpt, correct our copy, remove an unnecessary cached item or direct the correction to the website operator. We do not normally alter the source website and cannot promise to remove content controlled by a third party.
We may request evidence of domain, client or workspace authority before disclosing, transferring or deleting a report. Owning a domain does not automatically entitle someone to another customer’s confidential account information, and an account record does not override a verified legal right in the underlying personal data.
25
ScanMySEO accounts and paid services are intended for adults aged 18 or over. We do not knowingly create accounts for children. A parent or guardian who believes a child created an account should contact us so we can verify and take appropriate action.
An authorised crawl can incidentally encounter information about a child on a public page, such as a school, charity, sports or family website. Customers should avoid unnecessary submission of sites containing children’s sensitive information and must have a lawful basis. ScanMySEO limits use to the requested audit and does not intentionally profile the child for advertising.
The service is not designed to collect health, genetic, biometric, racial or ethnic, religious, political, trade-union, sex-life, sexual-orientation or criminal-offence data. Do not place such information in onboarding, report chat, support or quote fields unless it is genuinely necessary, lawful and agreed with us in advance for an Enterprise service.
Never submit passwords, private keys, API credentials, payment-card data, access tokens, authentication cookies or confidential database exports through a crawl field, Cozmo question or ordinary support form. If this happens, notify us promptly so we can reduce exposure and advise on credential rotation.
26
Security measures are selected according to risk and can include:
No online service can guarantee absolute security. Users must protect credentials, remove former team members, use trusted devices and report suspected compromise. We may revoke sessions, require a reset, pause a crawl or restrict an account to contain a risk.
If a personal-data breach creates a risk that requires notification, we follow applicable assessment, regulator and individual-notification duties. We preserve relevant evidence, contain the incident, investigate causes and take proportionate corrective action.
27
ScanMySEO does not sell or rent personal data. We do not use customer reports, crawl content or Cozmo questions to build a cross-site behavioural advertising profile. We do not permit advertisers to alter technical findings or AI answers.
Google Analytics 4 is optional and consent-based. The Cookie Policy explains the approved measurement configuration, retention and withdrawal control. Rejecting analytics does not affect the ordinary audit service.
We may create aggregate reliability, error-frequency, feature-use, technology-adoption or industry-level statistics where the result does not identify a person, customer or confidential website. We apply aggregation thresholds or other safeguards appropriate to the data and do not attempt to re-identify anonymised information.
We do not sell a customer’s secrets or private report as competitor intelligence. A plan recommendation may use page count, entitlement and usage information, but technical findings are not manufactured or inflated to force an upgrade. Sponsored or affiliate content, if introduced, will be labelled and kept separate from audit methodology.
28
We may disclose relevant information where reasonably necessary to:
We assess the requesting authority, jurisdiction, legal basis, scope and available challenge or notice options. We disclose no more than reasonably necessary.
Personal data may be reviewed or transferred as part of investment due diligence, merger, acquisition, restructuring, insolvency or sale of assets. We use confidentiality, minimisation and access controls and provide notice where required. A successor must use the information consistently with applicable law and the commitments that continue to apply.
Links to Stripe, Google, LinkedIn, articles or other websites lead to services with their own privacy practices. Following a link can disclose IP address, browser headers, referrer and URL information to the destination. ScanMySEO is not responsible for an external service’s independent processing. We avoid placing secrets or sensitive identifiers in external URLs.
29
We update this notice when processing, providers, retention, rights, product features or law materially changes. The version and date change only after a genuine review; they are not automatically replaced with the date you happen to visit.
Material changes are communicated through the website, account dashboard, email or another appropriate route. Where practicable, we provide advance notice. A new purpose is explained before processing begins, and we obtain fresh consent where the new activity depends on consent. We do not claim that continued use creates consent to an unrelated new privacy purpose.
Previous versions and a meaningful change summary are retained internally and can be made available where reasonably required to understand which notice applied.
30
Contact ScanMySEO about this notice, a privacy right, a public-data concern, a complaint or a Data Processing Addendum at cozmo@scanmyseo.com or through the contact form.
Use a clear subject:
Do not email passwords, full card details, private keys or unnecessary identity documents. We will tell you a safer route where evidence is needed.
Use the contact route and identify the account, domain, report or processing concerned.