GDPR Compliance
Last updated: March 10, 2026
1. Our Commitment to GDPR
SEO Layers is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page explains how we process personal data of users in the European Economic Area (EEA) and United Kingdom.
2. Data Controller
SEO Layers acts as the data controller for personal data collected through the Extension and Services. For data processing inquiries, contact our Data Protection contact at: [email protected]
3. Lawful Basis for Processing
We process personal data under the following lawful bases:
| Data Type | Lawful Basis | Purpose |
|---|---|---|
| Account information (name, email) | Contract performance | Provide the service, manage subscriptions |
| Payment information | Contract performance | Process subscription payments |
| Subscription & key data | Contract performance | License management, device tracking |
| SEO audit data | Legitimate interest | Provide SEO analysis (processed locally) |
| Google Search Console data | Explicit consent (OAuth) | Display search analytics within the extension |
| Transaction history | Legal obligation | Tax and financial record keeping |
| Referral data | Legitimate interest | Referral program management |
4. Your GDPR Rights
As a data subject in the EEA/UK, you have the following rights:
4.1 Right of Access (Article 15)
You may request a copy of all personal data we hold about you. We will respond within 30 days.
4.2 Right to Rectification (Article 16)
You may request correction of any inaccurate or incomplete personal data.
4.3 Right to Erasure (Article 17)
You may request deletion of your personal data. This includes your account, subscription records, and all associated data in our systems. Note: we may retain certain data required for legal compliance (e.g., transaction records for tax purposes).
4.4 Right to Restrict Processing (Article 18)
You may request that we restrict the processing of your personal data under certain circumstances, such as when you contest the accuracy of the data.
4.5 Right to Data Portability (Article 20)
You may request your personal data in a structured, commonly used, machine-readable format (JSON). This includes your profile data, subscription history, and audit statistics.
4.6 Right to Object (Article 21)
You may object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
4.7 Right to Withdraw Consent (Article 7)
Where processing is based on consent (e.g., Google Search Console access), you may withdraw consent at any time by revoking the OAuth permission in your Google Account settings.
5. Data Processing & Transfers
5.1 Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Google Firebase | Authentication, Firestore database | USA (with EU data residency options) |
| Razorpay | Payment processing | India |
| Google AI (Gemini) | AI-powered SEO insights (Pro) | USA |
| Vercel | Web application hosting | USA / Global CDN |
5.2 International Transfers
When data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions as approved by the European Commission to ensure appropriate data protection.
6. Data Protection by Design
We implement privacy by design principles:
- Local-first processing: SEO audit data is processed entirely in your browser — not sent to our servers.
- Data minimization: We only collect data necessary for service provision.
- Encryption: All API communications use TLS/HTTPS encryption.
- Token-based auth: Firebase ID tokens with short expiration ensure secure authentication.
- HMAC verification: Subscription integrity is verified with cryptographic signatures.
7. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly per Article 34.
8. Supervisory Authority
If you are in the EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.
9. Contact
For GDPR-related inquiries or to exercise your rights: [email protected]