Back to AstraSEO

Legal center · Updated 4 August 2026

Privacy Notice

How AstraSEO processes account, workspace, usage, billing, integration and product-improvement data.

Operational legal template. Complete every bracketed company field and obtain qualified German/EU legal review before production launch or material business-model changes.

1. Controller

The controller for AstraSEO is AstraSEO OS — operator details pending, [legal form], [registered street, postal code, city, country], represented by [managing director / authorized representative]. Privacy enquiries can be sent to privacy@astraseo.example.

2. Data we process

  • Account and identity data, including name, email, authentication records, locale and organization membership.
  • Workspace and customer content, including sites, keywords, briefs, drafts, reports, settings and files intentionally submitted to the service.
  • Technical and security data, including IP address, device/browser information, session identifiers, audit events, error logs and abuse-prevention signals.
  • Usage and metering data, including feature use, AI token/credit consumption, job execution, provider costs and operational telemetry.
  • Billing and transaction metadata, such as plan, invoice/customer references, payment status and tax country. Complete card or bank details are handled by the selected hosted payment provider and are not stored by AstraSEO.
  • Integration data received from services a tenant connects, such as Search Console, analytics, advertising, CMS, social or CRM systems.

3. Purposes and legal bases

  • Performing the contract and providing requested features, subscriptions, support, credits and integrations (GDPR Art. 6(1)(b)).
  • Complying with accounting, tax, consumer, sanctions and other legal duties (Art. 6(1)(c)).
  • Protecting the platform, preventing fraud, maintaining auditability, improving reliability and understanding aggregated product use (legitimate interests, Art. 6(1)(f)).
  • Sending optional marketing or using non-essential tracking only where valid consent is required and obtained (Art. 6(1)(a)).
  • Processing special instructions on behalf of business tenants as processor under a data processing agreement where applicable.

4. Payment providers and Merchant of Record

The platform administrator may activate Stripe, Dodo Payments, Lemon Squeezy, Paddle, FastSpring or Polar.sh. The active provider is disclosed before checkout. Depending on the provider and transaction, it may act as payment service provider, independent controller, merchant or Merchant of Record and may process identity, fraud, tax and payment data under its own privacy notice. AstraSEO receives only the transaction and subscription data needed to provision and support the service.

Switching the active provider affects new checkouts only. Historical transaction records and signed lifecycle webhooks may continue to be processed for reconciliation, refunds, chargebacks, tax and legal retention.

5. AI and connected providers

Prompts, selected workspace content and necessary context may be sent to AI or data providers chosen by the tenant or platform administrator. AstraSEO applies tenant scoping, encrypted credentials, access controls and configurable provider routing. Customers must not submit personal data or confidential information that is unnecessary for the requested operation.

AI-generated outputs can be inaccurate and are not legal, tax, medical, financial or guaranteed SEO advice. Human review remains required before publication or consequential decisions.

6. Recipients and subprocessors

Data is shared only with personnel, hosting, database, email, monitoring, support, payment, AI, search-data and integration providers that need it for the stated purposes. The current categories and available provider list are described on the Subprocessors page. Business customers may request the applicable DPA and provider-specific details.

7. International transfers

Where data is transferred outside the EEA, AstraSEO relies on an adequacy decision, approved safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. Provider location and safeguards can vary based on administrator and tenant configuration.

8. Retention

  • Account and workspace data: while the account is active and for a limited recovery period after termination, unless earlier deletion is requested or longer retention is required.
  • Billing, invoice and tax records: for statutory accounting and tax retention periods.
  • Security and audit logs: normally up to 24 months, longer where required to investigate abuse or legal claims.
  • Backups: overwritten on a rolling schedule and isolated from ordinary product access.
  • Anonymized or aggregated statistics may be retained where they no longer identify an individual.

9. Your rights

Subject to legal conditions, individuals may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Consent can be withdrawn for the future. Complaints may be lodged with a competent data protection authority. Contact ${legalConfig.privacyEmail}; identity verification may be required to protect account data.

10. Automated decisions

AstraSEO may automate routing, scoring, recommendations, abuse detection and content operations. It does not intentionally make solely automated decisions that produce legal or similarly significant effects on individuals without a lawful basis and appropriate safeguards.

11. Children

The service is intended for businesses and persons legally capable of entering a contract. It is not directed to children, and accounts for minors may be restricted or removed.

12. Changes

Material changes will be communicated through the service or by email where required. The date above identifies the current version.

Privacy Notice · AstraSEO · AstraSEO