Last updated: 1 October 2026
This Privacy Policy explains how Site SEO AI Audit (the website siteseoaiaudit.com and the application app.siteseoaiaudit.com, together the “Service”) collects and uses personal data. We collect only what we need to run the Service, we do not sell personal data, and we never use your data to train AI models.
1. Who we are (data controller)
The Service is operated by Internet Solutions, UAB, a company registered in the Republic of Lithuania (European Union):
- Company code: 302617697
- VAT code: LT100006088413
- Registered address: Tvenkinių g. 8A, Šakių k., Kauno r. sav., LT-47415, Lithuania
- Correspondence address: Vilniaus g. 72-310, LT-76298 Šiauliai, Lithuania
- E-mail for privacy requests: [email protected]
Internet Solutions, UAB is the controller of the personal data described in this policy, except where we act on behalf of an agency customer (see the section on agency forms).
The Service is used by people and businesses worldwide. We apply the EU General Data Protection Regulation (GDPR) to everyone, wherever you are. If the law of your country gives you additional rights, those rights apply as well.
2. What data we process
| Category | What it includes |
|---|---|
| Account data | E-mail address, name, password (stored only as a one-way hash), plan and plan validity, the time your account was created and when you last signed in, and your choice about receiving tips and product news. |
| Websites you check | The website address you enter, the date and time of the check, the IP address it was started from, the result (scores, findings and the technical facts they are based on) and the private link to the report. A free check needs no account: if you are not signed in, the report is tied to your browser session so you can find it again, and it is attached to your account if you create one in the same session. |
| Data we read from the website | The publicly available pages of the website (up to the page limit of your plan), robots.txt, llms.txt, the sitemap, HTTP response headers, page titles, headings, descriptions, links (including the status of links to other websites), images and structured data. We do not sign in to websites, do not fill in forms and do not read password-protected areas. For each page we store its address, status, title and word count, not the full text of the page. |
| Monitoring and alerts (paid plans) | Your check schedule, the history of reports for your websites, the alerts created for them and the additional e-mail addresses you add for alert recipients. |
| Agency branding and leads (Agency plan) | The company name, website, e-mail, phone, logo and colour you enter for branded reports and, if you use the embedded audit form, the name, e-mail address, website address, IP address and referring page of each visitor who submits it. |
| Billing data | Orders, plan, amount, VAT, payment method and status, invoice numbers, transaction or subscription identifiers from the payment processor, and the invoice details you enter (company name, address, country, VAT number, billing e-mail). For bank and money-transfer payments we see the payer details on our bank statement. We do not receive or store payment card numbers. |
| Communication | Messages you send us and our replies, and service e-mails we send you (for example welcome and password reset e-mails, plan and billing notices, and monitoring alerts). |
| Technical data | IP address, browser and device information, and request logs created by our servers when you use the website or the application; cookies described in the Cookies section. |
The Service is not designed for special categories of personal data (such as health data). Please do not put such data into your account or into the settings of your websites or feeds.
3. Why we process data and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account; running checks and delivering reports; scheduled monitoring; customer support | Performance of our contract with you (Art. 6(1)(b)), including steps you ask for before an account exists, such as a free check or a free feed |
| Payments, invoices, accounting and tax records | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Security, fraud and abuse prevention, enforcing plan and rate limits, debugging, keeping logs | Our legitimate interest in a safe and reliable service (Art. 6(1)(f)) |
| Service e-mails about your account, plan, billing and monitoring alerts | Contract (Art. 6(1)(b)) |
| Tips and product news by e-mail | Your consent (Art. 6(1)(a)); you can switch it off at any time in Settings |
| Showing the domain and score of recently completed free checks on our website | Our legitimate interest in showing that the Service is in use (Art. 6(1)(f)); you can ask us to remove an entry |
| Passing the details submitted through an agency’s embedded form to that agency | On the instructions of the agency, which is the controller (see the section on agency forms) |
| Handling legal claims and requests from authorities | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
Scores, findings and feeds are produced by our own software from the data collected at the time. They concern websites and content, not you as a person. We do not use your data for automated decisions that have legal or similarly significant effects on you, and we do not use it to train AI models.
4. Reports and public information
Anyone who has the link to a report can open it. The link contains a long random code that is hard to guess, but you are responsible for who you share it with.
To show that the Service is in use, the website lists recently completed free checks: the domain name, the overall score, the number of findings and the time. No other report details are shown there. Write to us if you want a domain removed from the list.
5. Agency forms (Agency plan)
A customer on the Agency plan can embed our audit form on its own website. When a visitor submits the form, the visitor’s name, e-mail address, website address, IP address and referring page are collected, saved in the agency’s account and sent to the agency by e-mail, and the visitor receives an e-mail with the report link. For this data the agency is the controller and we act as its processor.
If you submitted such a form and want to use your rights, contact the agency; you can also write to us and we will pass your request on. Agencies are responsible for informing their visitors, for having a lawful basis for contacting them and for linking to their own privacy notice.
6. Who receives your data
We share personal data only with recipients that help us provide the Service, and only to the extent needed:
- Hosting and infrastructure providers in the European Union — servers, storage, backups and security services.
- Network and security services — content delivery, traffic filtering and protection against attacks. They see the IP addresses of visitors.
- Payment processors — PayPal processes subscription payments as an independent controller under its own privacy policy. If you pay by bank transfer or through a money-transfer service, your bank or that service processes the payment under its own terms.
- E-mail delivery providers — sending service e-mails.
- A third-party performance measurement service — to measure speed we send it the address of the page being checked and receive performance data back. It does not receive your account data.
- A font delivery service — pages of the website and the application load fonts from it, so it receives your IP address and browser details when a page is displayed.
- The websites you ask us to check — our software sends requests to their servers, so the owners of those websites can see our robot name (SEOAuditBot) and our server addresses in their logs.
- Agencies — if you submit an agency’s embedded audit form, your details go to that agency.
- Professional advisers and authorities — accountants, lawyers, auditors, courts and authorities when required by law or to protect our rights.
Our hosting, e-mail and similar service providers act as processors under data processing agreements and may use the data only on our instructions. We do not sell or rent personal data and do not share it for advertising.
7. International transfers
We store the Service’s data on servers located in the European Union. Some service providers (for example payment processors, network services or the performance measurement service) may process data outside the European Economic Area. In that case we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses approved by the European Commission, together with additional safeguards where needed. You can ask us for more information about these safeguards.
8. How long we keep data
- Account data and everything linked to it (checked websites, reports, monitoring history, branding) — while your account is active. After the account is deleted, it is removed from our live systems within 30 days and from backups when they are overwritten in the normal backup cycle.
- Checks made without an account — kept so that the report link keeps working and so that the rule of one free check per website can be applied, until you ask us to delete them.
- Invoices, orders and payment records — for the period required by Lithuanian accounting and tax law (currently up to 10 years), even after account deletion.
- Server and security logs — for a limited period, normally not longer than 12 months, unless needed longer to investigate an incident.
- Support correspondence — for as long as needed to handle your request and for up to 3 years afterwards for follow-up questions and legal claims.
- Your choice about product news — until you change it.
Copies of reports, PDF files or feed content that you or others have downloaded, shared or republished stay with them; we cannot remove them.
9. Your rights
You have the right to:
- access your personal data and receive a copy of it;
- correct inaccurate data;
- ask us to delete your data;
- restrict or object to processing based on our legitimate interests;
- receive the data you gave us in a portable, machine-readable format;
- withdraw your consent at any time (this does not affect processing carried out before the withdrawal);
- lodge a complaint with a data protection authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). You can also contact the authority in the country where you live or work.
To use any of these rights, write to [email protected] from the e-mail address registered in your account. If you have no account, tell us which website address, report or feed it concerns. We reply within one month. We may ask you to confirm your identity.
Account deletion
You can ask us to delete your account at any time by writing to [email protected] from your registered e-mail address. We delete the account and its data as described in the section on how long we keep data; invoices and payment records are kept for the period required by law. You can change your name and password and switch product news on or off yourself in Settings.
10. Cookies and similar technologies
We use only cookies that are necessary for the Service to work or that remember your own choice. We do not use advertising, analytics or third-party tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| Website (siteseoaiaudit.com) | ||
pll_language |
Remembers the language you chose | 12 months |
moove_gdpr_popup |
Remembers your choice in the cookie notice | 12 months |
theme |
Remembers light or dark display mode when you switch it (also stored in your browser’s local storage) | 12 months |
| Application (app.siteseoaiaudit.com) | ||
PHPSESSID |
Keeps your session, protects forms against forgery and, if you are not signed in, lets you find the checks you started in this browser | Until the browser is closed |
REMEMBERME |
Keeps you signed in on your device | 30 days |
theme |
Remembers light or dark display mode when you switch it (also stored in your browser’s local storage) | 12 months |
The website shows a cookie notice. It lists only one category, “Strictly necessary cookies”, which cannot be switched off because the Service does not work without them. There are no optional cookie categories, so there is nothing else to accept or refuse; the notice only records that you have seen it.
Fonts are not cookies, but please note that the website and the application load web fonts from a third-party font delivery service, which receives your IP address and browser details (see the section on who receives your data).
The payment pages of payment processors may set their own cookies under their own policies. You can delete cookies in your browser settings; without the session cookie you cannot sign in.
11. Security
We use encrypted connections (HTTPS), store passwords only as one-way hashes, keep the management keys of feeds secret and limit access to personal data to people who need it for their work. No system is completely secure; if a personal data breach is likely to put your rights at risk, we will inform you and the supervisory authority as required by law.
12. Children
The Service is intended for businesses and adults. It is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
13. Personal data of other people
Public pages of the websites you check may contain personal data of other people, for example names of authors or contact details. We process such data only as part of the technical analysis you requested, do not build profiles from it and do not use it for any other purpose.
14. Changes to this policy
We may update this policy when the Service or the law changes. We will post the new version on this page with a new date and, for important changes, inform registered users by e-mail before the changes take effect.
15. Contact
Internet Solutions, UAB, Vilniaus g. 72-310, LT-76298 Šiauliai, Lithuania — [email protected]
See also our Terms of Service and plans and pricing.