Skip to content
Seoptist

Privacy Policy

Last updated: 1 October 2026

This policy explains how Handy & Must Ltd (“we”, “us”), trading as Seoptist, handles personal data when you use seoptist.com, the free AI Visibility Check, and the Seoptist application at app.seoptist.com. We are the data controller for this data. Our registered office is 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. You can contact us at [email protected].

1. What we collect

  • Account data: name, email address, company name, password hash, role and organisation membership.
  • Billing data: plan, invoices and VAT number. Card details are handled by Stripe and never touch our servers.
  • Product data: the domains, prompts, competitors and locations you ask us to track, audit results for your websites, and integration data you authorise (Google Search Console and GA4, read-only).
  • Free check data: domain, sector, town, email address and the IP address used to submit the check (for rate limiting and abuse prevention).
  • Usage data: server logs (IP address, user agent, pages requested) kept for 30 days, and Google Analytics 4 (anonymised IP, no advertising features, processor: Google Ireland Ltd) only if you consent on the cookie banner.
  • Support data: messages you send through the contact form or by email.

2. Why we process it and on what basis

  • Providing the service (contract): running checks and audits, showing results, sending verification and report emails, billing.
  • Security and abuse prevention (legitimate interests): rate limiting, fraud checks, logging.
  • Improving the product (legitimate interests, or consent for analytics): aggregated usage statistics.
  • Marketing (consent): we only send newsletters if you opt in, and every email has an unsubscribe link.
  • Legal obligations: keeping accounting records for the period required by HMRC.

3. AI providers and what they see

To measure AI visibility we send the prompts you track (for example “best accountant in Leeds”) to AI providers through their official APIs. We do not send your customers’ personal data to AI providers. Where a provider offers it, we opt out of our requests being used for model training. We use Anthropic’s Claude API for our own internal processing (suggesting prompts, classifying answers); only publicly available website content and the prompts and answers themselves are included.

4. Processors we use

We share data with the following processors under written data processing agreements:

  • Stripe: Payments and invoicing. Location: EU / US (SCCs, UK IDTA).
  • Postmark: Transactional email. Location: US (UK IDTA).
  • OpenAI: ChatGPT API queries (your prompts, never your customer data). Location: US (UK IDTA).
  • Google: Gemini API, Search Console and GA4 integrations, AI Overviews data. Location: EU / US (UK IDTA).
  • Perplexity: Perplexity Sonar API queries. Location: US (UK IDTA).
  • Anthropic: Claude API for prompt suggestions, analysis and visibility queries. Location: US (UK IDTA).
  • DataForSEO: Keyword, ranking and SERP data. Location: EU.
  • SerpApi: Google AI Overviews and AI Mode results. Location: US (UK IDTA).
  • UK cloud hosting provider: Application hosting, databases and backups. Location: United Kingdom.

Our application and databases are hosted in the United Kingdom. Where a processor is outside the UK we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

5. Retention

  • Account and product data: for the life of your account and 30 days after closure (longer if you ask us to export it).
  • Free check data: 90 days, then deleted or anonymised.
  • Server logs: 30 days.
  • Invoices and accounting records: 6 years after the end of the financial year, as required by UK law.

6. Your rights

Under UK GDPR you can ask us for access to your data, correction, deletion, restriction, portability, and to object to processing based on legitimate interests. You can withdraw consent at any time. Email [email protected] and we will respond within one month. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk, although we would appreciate the chance to resolve any concern first.

7. Security

We use encryption in transit and at rest, least-privilege access, audit logging and regular backups. Google integrations use OAuth with read-only scopes and can be revoked from your Google account at any time.

8. Cookies

See our Cookie Policy. In short: essential storage only, plus cookie-free analytics if you accept.

9. Changes

We will post changes here and, for material changes, email account holders at least 14 days in advance.