SEOwriters

Privacy Policy

Last updated: August 4, 2026 · Version 2.4

This is an English translation of our Dutch privacy policy (Privacyverklaring), provided for your convenience. The Dutch original is the legally binding version. In case of any discrepancy between this translation and the Dutch original, the Dutch version prevails. Read the Dutch version.

1. Who we are

Gung Ho B.V. (hereinafter: "SEOwriters", "we" or "us") is a Dutch company, established at Hannie Dankbaarpassage 14, 1053 RT Amsterdam, the Netherlands, and registered with the Dutch Chamber of Commerce (KvK) under number 85797766. Under the brand name SEOwriters we provide a platform for automated SEO content and reporting for SMBs.

For the processing described in this policy, we are the data controller. Questions about privacy or a request regarding your data? Email contact@seowriters.nl. We do not have a legally required Data Protection Officer (DPO); for all privacy questions you can use the address above.

2. What this policy covers

This policy explains which personal data we process when you visit our website or use the SEOwriters platform (onboarding wizard, dashboards, automated publication and reporting), for what purpose and on what legal basis, how long we retain it, and what rights you have.

We process data in two roles:

  • As data controller for your account and contact details and for visitors to our own website. This policy is about that.
  • As processor for the data we process on your behalf from your connected sources (Google Search Console, Google Analytics, WordPress). For that processing, you yourself are the data controller; the arrangements are set out in our data processing agreement, which forms part of your agreement with us.

3. What data we process, for what purpose, and on what legal basis

3.1 Account data, role: data controller

Data: company name, contact person's name, phone number, billing email address, login credentials (email address and temporary magic-link tokens; we do not use passwords) and your communication with our support. Purpose: account and relationship management, billing and communication about the service. Legal basis: performance of the agreement (Art. 6(1)(b) GDPR); for financial administration, also a legal obligation (sub c).

3.2 Visitors to seowriters.nl, role: data controller

Data: technical data automatically sent by your browser (IP address, browser type, requested pages), recorded in server and security logs. Purpose: keeping the website available, secure and functioning, and preventing misuse. Legal basis: legitimate interest (Art. 6(1)(f) GDPR): a secure, functioning website. We use only functional cookies (see section 4) and do not track you.

Visitor statistics. We track how many people visit our website, which pages they view, through which channel they arrive, and how often the intro-call form is submitted. We do this with Vercel Web Analytics, which uses no cookies and stores nothing in your browser. Visits are counted using an encrypted hash of your request, which expires after 24 hours; your IP address is not stored as part of this. What is recorded: the time, the requested page, the referring website, your country and region, and the type of device and browser. We only see totals: no profile is built of you, you are not tracked across other websites, and you are not identifiable as a person in this statistic. When the intro-call form is submitted, we only count that it happened; your name, email address and website are not included in the statistic. Legal basis: legitimate interest (Art. 6(1)(f) GDPR): insight into our own website's reach, in a way that asks as little of you as possible. Vercel is the same party that hosts our website; the safeguards in section 6 apply to the transfer.

3.3 Google Search Console data, role: processor (on your behalf)

If you connect your Google Search Console account via OAuth, we gain access to:

  • impressions, clicks, rankings and CTR for your website;
  • indexed pages and search terms;
  • sitemap information and crawl statistics.

OAuth scope: https://www.googleapis.com/auth/webmasters.readonly, read-only. Purpose: reporting and analysis of your SEO performance and steering our content engine based on real search behavior.

3.4 Google Analytics 4 data, role: processor (on your behalf)

When Google Analytics 4 is connected:

  • organic traffic, sessions, conversions and bounce rates;
  • demographic aggregates (no identification of individual visitors);
  • goal and conversion events.

OAuth scope: https://www.googleapis.com/auth/analytics.readonly, read-only. Purpose: dashboard reporting and measuring the effect of published content.

3.5 WordPress data, role: processor (on your behalf)

When your WordPress site is connected:

  • the Application Password (stored encrypted, see section 5);
  • the site URL and the username used for publishing;
  • the posts we publish on your behalf;
  • category, tag and media structure, to the extent needed to publish correctly.

Purpose: automated publication of content to your site.

3.6 Brand voice data, role: processor (on your behalf)

When you fill in or have your brand voice analyzed:

  • tone of voice, form of address and target audience;
  • preferred words and words to avoid;
  • example URLs of your own content.

If you choose "AI assist," we read 3 to 5 publicly accessible pages of your website to automatically generate a brand voice suggestion using Google Gemini. We only read publicly accessible pages and respect robots.txt. Purpose: aligning content generation with your brand.

3.7 Security and audit data, role: data controller

Data: IP address and User-Agent at login and when changes are made to connected credentials, recorded in an audit log; anonymized error reports via Sentry. Purpose: security, fraud prevention and the ability to investigate incidents. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

3.8 Contact data of prospects, role: data controller

Data: company name and website of organizations we approach as potential customers, and of the contact person there: name, job title, business email address, business phone number and LinkedIn profile. We also record what was discussed in the contact and what the next step is. Purpose: acquisition, approaching organizations we believe our service could help, and tracking the conversations that follow. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). This concerns exclusively business contact data in a business context. Source: the organization's public website, public sources, and conversations we conduct ourselves. We do not purchase address lists. Retention period: see chapter 7. Conversation notes fall under the same period as the contact data: a note such as "called, will get back to us next quarter" is just as much personal data as the contact details themselves. Upon request, we delete contact data immediately; a message to the address in chapter 14 is sufficient, and we do not need to know the reason.

We also analyze the findability of the website of such an organization based on publicly measurable data (search engine rankings, referring websites). That is data about a website, not personal data.

With a request via the intro-call form, we additionally record which page of our site you arrived on and which website you came from (for example, "google.com"). This tells us which of our own articles lead to a request. Nothing is stored on or read from your device for this: this data travels with the form you submit yourself. We only retain the name of the referring website, not what you did or searched for there.

With a request via the scan page, the same applies, with three additions. There you provide your own name, email address and website URL, and optionally your company name and phone number; we only record that phone number if you fill it in. We first send you an email with a confirmation link, so that nobody else can request a scan in your name. If you click that link, we analyze the findability of the website you provided and send you the result as a PDF by email. Without that click, nothing happens and nothing is scanned.

Bot check on the scan page. The request form on the scan page is protected by Vercel BotID, a check that recognizes automated requests. That check looks at technical characteristics of your request and how your browser behaves; nothing is stored on or read from your device, and no profile is built of you or tracked across other websites. The associated script is served from our own domain. If the check identifies your request as automated, we do not store it and no email is sent; you will then see on screen that we will contact you ourselves. This check only runs on the request form on the scan page, not on the rest of the website. Legal basis: legitimate interest (Art. 6(1)(f) GDPR): preventing our form from being misused to send unsolicited email to strangers or to run scans at our expense. Vercel is the same party that hosts our website; the safeguards in section 6 apply to the transfer.

The analysis itself concerns a website, not a person: we read publicly accessible pages of that site and publicly measurable data about its findability.

Of the confirmation link and your email address, our records keep no readable copy, only an irreversible encrypted hash. We use that to count how many requests come from the same address and to check whether you have unsubscribed. Your email address itself is stored once, with your contact data, and falls under the retention period in chapter 7.

Unsubscribing is possible via the link at the bottom of the follow-up email. After that, we will not send you any further follow-up email. We retain that unsubscribe as an encrypted hash of your email address, with no expiry: were it to expire, you would become contactable again after some time without having asked for that. If you subsequently request a scan yourself again, we simply process that request; the unsubscribe applies to unsolicited follow-up email, not to something you ask for yourself.

4. Cookies

On our website and in the platform we currently use only functional cookies. We place no tracking, advertising or analytical cookies, and we do not share data with advertising networks. It concerns two things:

  • Our own session/login cookie, needed to keep you logged in and make the service work.
  • Three cookies from cal.com, the party that provides the appointment calendar on our homepage. As soon as that calendar comes into view, cal.com sets a bot-check cookie (__cf_bm, valid for about 30 minutes) and two security cookies from the booking app (__Secure-next-auth.csrf-token and __Secure-next-auth.callback-url, valid until you close your browser). These serve the security and functioning of the calendar; nothing is tracked with them and nothing goes to advertising networks.

These cookies are strictly necessary for the functioning and security of the relevant components and do not require consent under the Dutch Telecommunications Act.

Our visitor statistics (section 3.2) and the bot check on the scan page deliberately work without cookies and without browser storage. That means no consent is required for them under the Dutch Telecommunications Act, and you will not see a cookie banner on our site.

If we introduce analytical or other non-functional cookies in the future, we will ask for your prior consent via a cookie banner and update this policy accordingly.

5. How we protect your data

Encryption. We store sensitive data encrypted:

  • OAuth tokens (Search Console, Analytics) and WordPress Application Passwords: encrypted with a key derived per customer (Fernet + HKDF), so that only our platform can decrypt them;
  • connections to the database and to external APIs run encrypted (TLS);
  • the database itself is encrypted at rest (encryption at rest, EU-Frankfurt).

Access. Only employees with an operational need have access to production systems. That access is recorded in an audit log. We never share your data with parties other than the subprocessors in section 8.

Awareness and review. We apply the principle of data minimization: connections to Google use read-only permissions only, and we do not process more data than necessary for the service.

6. Transfer outside the European Economic Area (EEA)

We store your platform, content and reporting data within the EEA by default. However, some of our subprocessors are established in the United States or have a US parent company (see section 8). To the extent personal data is processed outside the EEA as a result, this happens exclusively under appropriate safeguards within the meaning of Chapter V GDPR:

  • the European Commission's Standard Contractual Clauses (SCCs), and/or
  • certification under the EU-US Data Privacy Framework (DPF) of the relevant party.

The DPF is currently a valid adequacy framework, but is under legal review by the Court of Justice of the EU. Should the DPF cease to apply, the Standard Contractual Clauses will continue to apply as an independent basis. We design our processing so that storage of your data takes place within the EEA by default.

7. How long we retain data

You may request an export of your data before the 30-day period expires.

8. Subprocessors

We engage the following subprocessors. Where a party has a US parent company or may process data outside the EEA, this happens under the safeguards described in section 6.

OpenAI and Perplexity are only engaged for a site once you enable GEO monitoring (AI visibility) for that site. If GEO monitoring is off, neither party processes your data.

In the event of changes to our subprocessors, we inform business customers at least 30 days in advance, so you can raise an objection if desired.

9. Your rights

Under the GDPR you have the right to:

  • access the data we process about you;
  • rectification of inaccurate data;
  • erasure of your data (subject to statutory retention obligations);
  • restriction of processing;
  • object to a specific processing activity;
  • data portability: receive your data in a machine-readable format;
  • withdraw consent: you can revoke connected Google access at any time via myaccount.google.com/permissions.

Send your request to contact@seowriters.nl. We respond within 30 days. If you are not satisfied with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (autoriteitpersoonsgegevens.nl).

10. No automated decision-making

We do not make decisions with legal effect or similarly significant effect based solely on automated processing. Our AI generates content drafts; the substantive choice and publication remain under your control.

11. Children

Our service is aimed at businesses and is not intended for children. We do not knowingly collect data from individuals under 16 years of age.

12. Data breaches

If we discover a data breach that is likely to pose a risk to you or other data subjects, we will report it in accordance with the GDPR to the Dutch Data Protection Authority and, where required, to you and/or the data subjects. If we process data as a processor on your behalf, we will inform you without delay, as set out in our data processing agreement.

13. Changes to this policy

We may amend this policy. In the event of material changes, we will inform you by email and on your dashboard. The most current version is always available on our website; the date of the last change is stated at the top of this document.

14. Contact

Gung Ho B.V. (trading as SEOwriters) Hannie Dankbaarpassage 14, 1053 RT Amsterdam, the Netherlands KvK: 85797766 · VAT: NL863745751B01 Email: contact@seowriters.nl

Terms and conditions · Data processing agreement