Privacy and measurement

We use Analytics and navigation tools to understand what to improve. You can accept or reject: the site works either way.

SEO Automation Hub
Features Workflow Blog
Tools
Google snippet preview Meta tag checker robots.txt generator JSON-LD schema generator GEO audit: can AI cite you? All tools →
Comparisons
SEOZoom Semrush Ahrefs Ubersuggest SEOTester Online Mangools
Security Pricing Guide Contact IT EN Log in Start free

Privacy

Privacy Policy

This policy describes how SEO Automation Hub collects, uses and protects the personal data of the users of the service, in compliance with Regulation (EU) 2016/679 (GDPR).

Last updated: 23 June 2026

Index: Data controller · Data collected · Purposes · Legal bases · Google integrations · Processors and recipients · Transfers outside the EU · Retention · Rights · Complaint · Changes

1. Data controller

The data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (“GDPR”) is Swellweb di Marco Caciotti, owner of the SEO Automation Hub service.

  • VAT number: IT12272201000
  • Tax code: CCTMRC79L10H501R
  • Registered office: 61121 Pesaro (PU)
  • Email: info@seoautohub.com

Processing is carried out in compliance with the GDPR and with Legislative Decree 196/2003 (Italian Personal Data Protection Code), as amended by Legislative Decree 101/2018. No DPO has been appointed, as the conditions set out in Article 37 GDPR are not met.

2. Data we collect

  • Account data: name, email address and credentials created at registration.
  • Usage data: domains analysed, audits, workflow tasks, reports and workspace activity.
  • Payment data: handled by Stripe (see § 6); we do not store full card numbers.
  • Technical data: IP address, browser type and access logs, for security and diagnostics.
  • Google integration data: Search Console metrics and basic profile, only with prior consent (see § 5).
  • Public form data (e.g. free audit): email address and domain provided by the data subject.
  • Connected social accounts (Facebook, Instagram, LinkedIn): only if you choose to connect them to publish content: the identifier and name of the Facebook Page, Instagram account or LinkedIn profile, an access token (stored encrypted) and, for posts published through the platform, their identifier, link and public like and comment counts. We do not read messages, contacts or content of your personal profile. You can disconnect them at any time: how to delete this data.

3. Purposes of the processing

  • provision and management of the service and of the workspace (see legal basis in § 4(a));
  • registration, authentication and trial period (§ 4(a));
  • processing of payments and subscriptions (§ 4(a) and (c));
  • support and service communications (§ 4(a));
  • platform security and prevention of abuse (§ 4(d));
  • compliance with legal, tax and accounting obligations (§ 4(c)).

4. Legal bases

Each purpose in § 3 is based on one of the legal bases under Article 6(1) GDPR:

  • a) performance of the contract — Article 6(1)(b): provision of the service requested by the user;
  • b) consent — Article 6(1)(a): optional integrations (Google, § 5) and measurement tools subject to consent (see Cookie policy);
  • c) legal obligation — Article 6(1)(c): retention of tax and accounting documents;
  • d) legitimate interest — Article 6(1)(f): security, fraud prevention and improvement of the service, subject to a balancing test against the rights of the data subject.

5. Google and Search Console integrations

If the user connects a Google account, we request read-only access via OAuth to Google Search Console data (scope webmasters.readonly) and to the basic profile, solely in order to display and organise SEO metrics in the user's workspace. Consent can be withdrawn at any time from the Google account settings or by contacting us (withdrawal of consent pursuant to Article 7(3) GDPR).

The use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements: Google data is not sold, is not used for advertising and is not transferred to third parties except to provide the features visible to the user.

6. Processors and recipients

Data is processed by suppliers appointed as processors pursuant to Article 28 GDPR:

  • Contabo GmbH (Germany) — infrastructure hosting, data on EU servers;
  • Stripe Payments Europe Ltd (Ireland) — payment processing;
  • Google Ireland Ltd — OAuth, Search Console and PageSpeed Insights services;
  • Groq, Inc. (USA) — AI processing of text content; no data identifying the user is sent to the models (see § 7).

Data is not sold or transferred to third parties for marketing purposes.

7. Transfers outside the EU

Some of the suppliers listed in § 6 may process data outside the European Economic Area. In such cases the transfer takes place on the basis of an adequacy decision pursuant to Article 45 GDPR (including the EU-U.S. Data Privacy Framework, where the supplier adheres to it) or of standard contractual clauses pursuant to Article 46(2)(c) GDPR.

8. Data retention

  • Account and workspace data: for the entire duration of the relationship and up to 12 months after the account is closed;
  • Tax documents: 10 years, pursuant to Article 2220 of the Italian Civil Code;
  • Technical logs: up to 12 months, for security purposes;
  • Google tokens: until consent is withdrawn or the account is disconnected.

Once these periods have elapsed, data is deleted or anonymised (storage limitation principle, Article 5(1)(e) GDPR).

9. Rights of the data subject

The data subject may exercise at any time the rights set out in Articles 15-22 GDPR: access (Article 15), rectification (Article 16), erasure — the “right to be forgotten” (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21) and the right not to be subject to a decision based solely on automated processing (Article 22; the service does not take decisions of this kind).

Requests must be sent to info@seoautohub.com. We reply within one month, pursuant to Article 12(3) GDPR.

10. Complaint to the supervisory authority

If you believe that the processing infringes the GDPR, you have the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian supervisory authority) pursuant to Article 77 GDPR, without prejudice to any other administrative or judicial remedy.

11. Changes to this policy and related documents

We may update this policy; material changes will be communicated to registered users. The date of the last update is shown at the top of the page.

Related documents: Cookie policy · Terms of service.

Transparency first

Your data under control, SEO work with peace of mind.

Start 7 days free Talk to us
SEO Automation Hub Audit, content, competitors, Search Console and backlink audit inside a single workflow.
Product Features SEO workflow Guide Blog Free tools Pricing
Solutions For agencies For e-commerce For consultants For freelancers
Free audit Free audit AI Audit (GEO) Best SEO software
Comparisons SEOZoom alternative Semrush alternative
Company Security Contact Members area
Legal Privacy Terms of service Cookie
© 2026 SEO Automation Hub seoautohub.com