Privacy Policy
Last updated: 2026-10-06
1. Data Controller
The controller within the meaning of the GDPR is:
Antonio Blago
Email: info@antonioblago.com
Website: www.antonioblago.com
If you have any questions about data protection, you can contact us at any time at the above email address.
2. General Information on Data Processing
2.1 Scope of Processing
We only process personal data of our users to the extent necessary to provide a functional website and our services. Processing is generally only carried out with the user's consent or where processing is permitted by law.
2.2 Legal Basis
The processing of personal data is based on the following legal bases of the GDPR:
- Art. 6(1)(a) GDPR: User consent
- Art. 6(1)(b) GDPR: Contract performance or pre-contractual measures
- Art. 6(1)(c) GDPR: Legal obligations
- Art. 6(1)(f) GDPR: Legitimate interests of the controller
2.3 Data Deletion and Storage Period
Personal data is deleted as soon as the purpose of storage no longer applies. Storage may continue if required by law (e.g., tax retention periods of 6-10 years).
3. Collection and Processing of Personal Data
3.1 Registration and User Account
Data collected:
- Email address (required)
- Password (stored encrypted)
- Registration date
- Login history (timestamp, IP address)
Purpose: Provision of user account, authentication, security
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Storage period: Until account deletion plus 30 days backup period
3.2 Subscriptions and Payment Data
Data collected:
- Payment information (processed via Stripe)
- Billing address (if provided)
- Transaction history
- Subscription status and duration
- Purchased credits and usage
Purpose: Payment processing, invoicing, contract management
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligations)
Storage period: 10 years (tax retention requirement)
3.3 Usage Data and Analytics
Data collected:
- Analyzed websites and domains (entered by you)
- EEAT analyses and projects
- Keyword research
- Backlink analyses
- SEO Copilot conversations (temporary for session management)
- Credit usage and API usage
Purpose: Provision of SEO services, platform optimization
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Storage period: As long as the account is active; 30 days after account deletion
3.4 AI Bot Log Analyzer (upload of your own server logs)
The AI Bot Log Analyzer is a free tool that lets you analyze an access log from your own web server. Because such logs typically contain IP addresses, timestamps, requested URLs, referrers and user agents, separate rules apply here.
Processing of the uploaded file:
- The file is read and parsed in memory only. It is never written to disk and is discarded once the analysis completes.
- No individual IP addresses are taken from the log. IP addresses only enter the result as a count of distinct addresses per bot.
- Raw log lines are neither stored nor passed on to third parties. In particular, no data is sent to any AI provider; the analysis runs entirely in our own code on our own server.
What is stored from the analysis:
- Aggregated metrics (total requests, requests per bot, status codes, time series, AI visibility score)
- The most frequently requested URLs of the analyzed domain
- The analyzed domain, where provided or inferable from the log
- The IP address of the upload (not the IP addresses contained in the log) for rate limiting and abuse detection
- Your email address, if you choose to have the report sent to you
Purpose: Providing the analysis, abuse prevention, providing shareable reports
Legal basis: Art. 6(1)(b) GDPR (performing the service you requested), Art. 6(1)(f) GDPR (legitimate interest in system security and abuse prevention)
Storage period: The uploaded file is not stored. The aggregated analysis result is deleted automatically after 90 days. A share link you create expires after 30 days.
Storage location: Servers of our hosting provider PythonAnywhere within the European Union (see section 5.6)
Shareable reports:
On your explicit action you can create a link that makes the aggregated result accessible without login. Anyone who has the link can view the report. The link expires automatically after 30 days and the page is set to "noindex" for search engines. If you do not create a link, the result is not accessible from outside. On request we delete any report earlier at any time.
4. Cookies and Tracking
4.1 Use of Cookies
Our website uses cookies. Cookies are small text files stored on your device that contain certain information for exchange with our system.
4.2 Types of Cookies
| Cookie Type | Purpose | Storage Period |
|---|---|---|
| Session Cookies | Authentication, login status | Until browser session ends |
| Functional Cookies | Language settings, preferences | Up to 1 year |
| Security Cookies | CSRF protection, abuse detection | Session or 24 hours |
| Consent Cookie (ccm_consent) | Stores your choices from the consent banner (see 4.3) | Up to 1 year |
| Statistics Cookies (_ga, _ga_*) | Google Analytics 4, only after consent (see 4.4) | Up to 2 years |
4.3 Consent Management Tool (CCM19)
To obtain, store and prove your consent to cookies and third-party services, we use the consent management tool CCM19 by Papoo Software & Media GmbH, Auguststraße 4, 53229 Bonn, Germany. CCM19 blocks all scripts that require consent (sections 4.4 and 4.5) until you have agreed in the banner. Without consent, these scripts are not loaded.
Why an external server is required: CCM19 is operated as a cloud service. On every page load the banner script is loaded from cloud.ccm19.de, and your decision (consent, refusal, selection of individual categories) is logged there. This log is required so that we can prove consent in accordance with Art. 7(1) GDPR. CCM19's servers are located in Germany; a data processing agreement under Art. 28 GDPR is in place with the provider.
Data processed: anonymised (truncated) IP address, date and time of consent or withdrawal, scope of consent (selected categories), browser and device information, domain and URL visited, consent ID (in the ccm_consent cookie)
Purpose: Obtaining and proving consent, controlling scripts that require consent
Legal basis: Art. 6(1)(c) GDPR (legal obligation to prove consent under Art. 7(1) GDPR) and Section 25(2) No. 2 TDDDG for the technically necessary consent cookie
Retention: consent cookie up to 1 year; the consent log is kept for the duration of the statutory obligation to provide proof
Withdrawal: Via the "Cookie settings" link in the footer of every page you can change or withdraw your choices at any time.
Further information: CCM19 privacy policy
4.4 Google Analytics 4 (only after consent)
Only if you agree to the "Statistics" category in the consent banner do we load Google Analytics 4 by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Without consent, no Google script is loaded and no data is transmitted to Google.
Data processed: truncated IP address (Google Analytics 4 does not store full IP addresses), pages visited, time on page, referrer, approximate location (city/country), device and browser information, pseudonymous client ID
Purpose: Audience measurement and optimisation of the website
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). Transfer to the USA is based on the EU-US Data Privacy Framework, under which Google LLC is certified.
Retention: user and event data for a maximum of 14 months
Withdrawal: at any time via "Cookie settings" in the footer
Further information: Google privacy policy
4.5 Our Own Usage Statistics (only after consent)
Also only after consent to the "Statistics" category, we collect pseudonymous usage data with our own script (pages visited, button clicks, submitted forms, time on page). The data is processed exclusively on our own servers and is not passed on to third parties. The session ID is kept in your browser's sessionStorage and deleted when the tab is closed.
Purpose: Improving the website and our tools
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
5. Integration of Third-Party Services
5.1 Stripe (Payment Processing)
For payment processing, we use Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA.
Data transferred: Email, payment information, transaction data
Purpose: Secure payment processing, fraud prevention
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Privacy Policy: stripe.com/privacy
5.2 DataForSEO (SEO Data API)
For SEO analyses (keywords, backlinks, traffic), we use the DataForSEO API.
Data transferred: Analyzed domains and websites (entered by you)
Purpose: Provision of SEO analysis data
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Important: No personal data about you is transferred to DataForSEO, only the websites to be analyzed.
5.3 Anthropic Claude (AI Analyses)
For AI-powered EEAT analyses and the SEO Copilot, we use the Claude API from Anthropic.
Data transferred: Website content (for analysis), chat queries
Purpose: AI-based SEO analyses and recommendations
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Privacy Policy: anthropic.com/privacy
- We use the Anthropic API in business mode
- No Training: Your data is NOT used to train AI models
- Retention: Anthropic stores API requests for a maximum of 30 days for abuse detection
- We have concluded a Data Processing Agreement (DPA) with Anthropic (GDPR Art. 28)
5.4 OpenAI (Fallback AI System)
As a fallback system for AI analyses, we use the OpenAI API (GPT-4).
Data transferred: Website content (for analysis), chat queries (only when fallback is activated)
Purpose: AI-based SEO analyses as backup when primary system is unavailable
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Privacy Policy: openai.com/privacy
- API Usage: When using the OpenAI API, your data is NOT used by default to train AI models
- No Training: We have activated the training opt-out - your prompts and outputs are not used for model training
- DPA Concluded: We have concluded a Data Processing Addendum (DPA) with OpenAI pursuant to GDPR Art. 28
- Retention: OpenAI stores API requests for a maximum of 30 days for abuse detection and then automatically deletes them
- EU-US Data Privacy Framework: OpenAI is certified under the EU-US Data Privacy Framework
5.5 Google Search Console & Analytics API (OAuth Integration)
For extended SEO analyses, we offer an optional integration with the Google Search Console API and Google Analytics Data API (GA4). This feature requires your explicit consent via Google OAuth 2.0.
Data collected upon connection:
- Google account email address
- List of verified Search Console properties (websites)
- Search performance data (clicks, impressions, CTR, position)
- Keyword data and search queries
- Indexing status and crawling statistics
- Google Analytics 4 properties (if available)
- Analytics data: Sessions, users, page views, traffic sources
Purpose: Provision of detailed SEO analyses based on your actual Google search data and website statistics
Legal basis: Art. 6(1)(a) GDPR (explicit consent)
Storage period: OAuth tokens are stored encrypted with Fernet (AES-128-CBC) until you disconnect. Retrieved analysis data is cached for a maximum of 30 days.
5.6 Hosting (PythonAnywhere)
Our website is hosted on servers of PythonAnywhere LLP, Kenilworth House, 77-85 Hagley Road, Edgbaston, Birmingham B16 8QG, UK.
Data transferred: All data collected on the website
Purpose: Provision of website infrastructure
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
6. Data Transfer to Third Countries
Some of the services used (Stripe, Anthropic, OpenAI, and Google Analytics, only after consent) are based in the USA or process data in the USA. The USA is not considered a safe third country from the EU's perspective under GDPR.
Data transfer is based on:
- Standard Contractual Clauses (SCC): Stripe, Anthropic, OpenAI
- Adequacy Decision (EU-US Data Privacy Framework): Google LLC (Google Analytics 4) and other providers where certified
- Your Consent: Art. 6(1)(a) GDPR in conjunction with Art. 49(1)(a) GDPR
7. Your Rights as a Data Subject
You have the following rights under GDPR:
- Right of Access (Art. 15 GDPR): You can request information about your data stored with us
- Right to Rectification (Art. 16 GDPR): You can request correction of inaccurate data
- Right to Erasure (Art. 17 GDPR): You can request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18 GDPR): You can request restriction of processing
- Right to Data Portability (Art. 20 GDPR): You can receive your data in a structured format
- Right to Object (Art. 21 GDPR): You can object to processing on grounds relating to your particular situation
- Right to Withdraw Consent (Art. 7(3) GDPR): Consent given can be withdrawn at any time
7.1 Exercising Your Rights
To exercise your rights, please contact:
Email: info@antonioblago.com
We will respond to your request within 30 days.
7.2 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
8. Data Security
8.1 Technical Measures
We implement the following security measures:
- SSL/TLS Encryption: All data transfers are encrypted (HTTPS)
- Password Hashing: Passwords are hashed with bcrypt, not stored in plain text
- Access Control: Strict permission management for database access
- Firewall: Protection against unauthorized access
- Regular Backups: Daily database backups
- Security Updates: Regular updates of all systems
8.2 Encryption of Sensitive Data (Encryption at Rest)
Encrypted data categories:
| Data Category | Encryption Method | Key Derivation |
|---|---|---|
| Google OAuth Tokens | Fernet (AES-128-CBC) | Individual per user |
| Revenue Analysis Data | Fernet (AES-128-CBC) | Individual per user |
| API Credentials | Fernet (AES-128-CBC) | Individual per user |
Detailed Technical Documentation: A comprehensive description of our encryption procedures can be found on our Data Encryption page.
9. AI Transparency and EU AI Act Compliance
9.1 AI Systems Used
We use the following AI models:
- Anthropic Claude (Primary): Claude 3.5 Sonnet / Claude 3 Opus for EEAT analyses and SEO Copilot
- OpenAI GPT-4 (Fallback): As backup system when primary system is unavailable
9.2 Risk Classification
Our AI applications fall under the "limited risk" category pursuant to EU AI Act (Art. 52), as they:
- Do not make automated decisions with legal effect
- Are exclusively for analysis and information purposes
- Provide transparent labeling of AI-generated content
- Ensure human control (human-in-the-loop)
9.3 Transparency Requirements
We fulfill the following transparency requirements:
- Labeling: AI-generated content is labeled as such
- No Training: User data is NOT used to train AI models
- Data Processing: Clear documentation of what data is transmitted to AI systems
- Retention Periods: Defined deletion periods (max. 30 days with third-party providers)
9.4 Data Processing Agreements (DPA)
We have concluded Data Processing Agreements (DPA) pursuant to GDPR Art. 28 with all AI providers:
| Provider | DPA Status | Training Opt-Out | Retention |
|---|---|---|---|
| OpenAI | Concluded | Activated (API) | 30 days |
| Anthropic | Concluded | Activated (Business) | 30 days |
9.5 Human Control (Human-in-the-Loop)
All AI-generated analyses and recommendations are designed as decision support. The final assessment and implementation is always up to the user. The AI:
- Does not make automated decisions
- Does not perform independent actions
- Does not change data without explicit user approval
- Only provides recommendations and analyses
9.6 Your Rights Regarding AI Processing
You have the right to:
- Know when AI is used in processing your requests
- Decline AI use (alternative manual analysis on request)
- Receive information about data transmitted to AI systems
- Request deletion of data stored with AI providers
10. Protection of Minors
Our services are intended exclusively for persons aged 18 and over. We do not knowingly collect data from minors. If we become aware that data from minors has been stored, it will be deleted immediately.
11. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy to reflect changes in the legal situation or changes to our services. The current version can always be found on this page.
Last updated: 2026-10-06
Privacy Contact
Controller:
Antonio Blago
Email: info@antonioblago.com
Website: www.antonioblago.com
If you have any questions about data protection or wish to exercise your rights, you can contact us at any time. We will respond to your inquiry within 30 days.
Last updated: 2026-10-06 | Antonio Blago