SEOnorita

SEOnorita · information

Privacy policy

What SEOnorita processes, why it is needed and how to manage your data.

Version: 2026-09-07

1. Controller

The controller is the SEOnorita service provider registered for NPD in Russia. Full details must appear under Provider in the final published version. Contact for data requests: @ker4ik13 on Telegram.

2. Data and purposes

Account and sign-in data includes email, display name, email verification, a protected password representation, language and time zone. Security records include sessions, IP addresses, browser information, second-factor settings and access events. Passwords are not stored in plaintext.

Workspace data includes roles, invitations, projects, submitted materials and change history. Team visibility follows access permissions. Notes become accessible by public link only after that mode is explicitly enabled.

Billing records include amounts, descriptions, timestamps, payment identifiers and status, plans, balances, usage and refunds. A delivery email and, when needed, a business buyer's name and tax ID are collected for documents. Full card details are handled by the payment provider.

Optional features use Telegram identifiers for linked bot sign-in, browser push subscription details when enabled, and API keys for connections you add.

3. Grounds and recipients

Processing supports the agreement, legal obligations, service protection and, where appropriate, separate consent. Marketing requires a separate voluntary choice and is not required to use the service.

Payment providers receive necessary order and buyer information. The Russian tax authority receives NPD receipt data. SMTP providers process delivery addresses and requested email content. The Telegram bot processes sign-in confirmation when enabled. Selected SEO providers receive the requested operation's phrases, domain and parameters. User data is not sold to advertisers.

4. Hosting and transfers

The current server is in Germany. A commercial launch targeting Russian citizens requires a primary collection and storage arrangement that meets applicable localization rules. This draft does not establish that German hosting alone satisfies those requirements.

Before paid launch, the controller identifies and publishes actual primary database locations, relevant processors and grounds for international transfers, and makes required regulatory notifications. Consent does not replace mandatory localization requirements.

5. Retention and protection

Accounts and project materials are retained while needed to provide the service. Subscription expiry does not automatically delete projects. Technical temporary data has separate limited retention; heavy result retention follows the plan. Financial and legally required records are retained for the required periods.

When processing purposes end, data is deleted or anonymized unless another lawful retention basis exists. The controller reviews correction, export and deletion requests after proportionate account verification. Legally retained records are separated from ordinary service use.

Controls include HTTPS, workspace access boundaries, encryption of stored API keys and billing contact data, significant-action audit records and backups. Do not put secrets in project names, notes or public links.

6. Your choices

You can request processing information, correction, restriction or termination where applicable, an export and withdrawal of consent. Some exports are available directly within projects. Withdrawal does not stop processing required by law or another continuing lawful basis.

Contact support through your account or @ker4ik13. The controller will explain the necessary steps and timing. You may contact the relevant authority or court. Material policy changes are published with a version date.