Privacy Policy

Privacy Policy | SEOTOOLY

1. Introduction

SEOTOOLY is a service provided by Nikalab Ltd., the data controller responsible for your personal data. We provide SEO visibility audits, including technical SEO audits, keyword research, Speed & Usability Audit, competitor analysis, and tailored SEO Action Plan in PDF, delivered within 24–48 hours. Our services are offered on a contract-free, pay-per-audit basis. Our website and services are not directed to persons under 18, and we do not knowingly collect their data. We are committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use and protect it, and your rights. We operate globally, serving clients including those in the European Union (EU) and the United Kingdom, and comply with applicable data protection laws, such as the EU General Data Protection Regulation (GDPR) and the UK GDPR. By using our website or services, you agree to the practices described in this Policy.

2. Data We Collect

We collect only the personal data necessary to provide our SEO audit services, adhering to the principle of data minimization. We do not intentionally collect special-category data (e.g., data revealing health, political opinions, or religious beliefs). If you believe we have inadvertently processed such data, please contact us to remove it.

  • Information You Provide: When you request an SEO audit via our website forms, we collect your name, email address, and website URL. This data is used to perform the audit and deliver your tailored SEO Action Plan in PDF within 24–48 hours. We do not collect unnecessary data beyond what is required for the service.
  • Payment and Invoicing Information: For paid services, we collect limited information necessary for processing payments and issuing invoices, such as name, email, billing address, or company details. Sensitive payment data (e.g., credit card numbers or bank account details) is handled by third-party providers or financial institutions and not stored by us (see Payments section below).
  • Server Logs: We collect error and access logs (e.g., IP address, user-agent) for security purposes, stored for up to 30 days and not used for tracking or profiling.

4. Cookies

We use only strictly necessary cookies, such as session cookies, to ensure the functionality and security of our website (e.g., for session management and CSRF protection). No analytics or marketing cookies are used, and no consent is required for these essential cookies per GDPR and UK GDPR guidelines. For more details, see our server log practices under the Data We Collect section.

5. Payments

We process payments for our services through secure methods managed by trusted third-party providers or financial institutions. We may also issue invoices for payment processing. We have signed Data Processing Agreements (DPAs) with all payment providers to ensure GDPR and UK GDPR compliance.

  • Data Handling: We do not store sensitive payment information, such as credit card numbers or bank account details. Payment data is processed directly by the chosen payment provider or financial institution. For invoicing, we may collect limited information, such as name, email, billing address, or company details, as required for transaction confirmation or tax purposes.
  • Compliance: All payment and invoicing methods comply with applicable security standards (e.g., PCI-DSS for payment processors or banking regulations) and legal requirements, ensuring the protection of your data.
  • Updates: If we change our payment or invoicing practices, we will update this Policy to reflect those changes, ensuring minimal data collection and secure processing.

6. Data Retention

We retain personal data only as long as necessary for the purposes outlined, unless required by law.

  • SEO Audit Data: We keep your data to perform the audit and deliver your tailored SEO Action Plan in PDF, typically deleting or anonymizing it within 12 months of service completion to maintain order history or support repeat orders, unless further interaction occurs.
  • Communications: Emails and inquiries are retained as needed for support or client relationships, unless you request deletion (where feasible).
  • Payment and Invoicing Data: Invoice-related data (e.g., name, billing address, company details) is retained for up to 6 years to comply with UK tax obligations, then securely deleted or anonymized when no longer needed.
  • Server Logs: Error and access logs are retained for up to 30 days for security purposes.

7. Your Rights

You have rights regarding your personal data, especially under GDPR and UK GDPR, including:

  • Access: Request a copy of your data and information on its use.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of data when no longer needed or if legally required.
  • Restriction: Limit processing in certain cases (e.g., while verifying data accuracy).
  • Portability: Receive your data in a machine-readable format or request its transfer.
  • Object: Object to processing based on legitimate interests.
  • Complain: Lodge a complaint with a data protection authority (e.g., ICO in the UK). We encourage contacting us first to resolve concerns.

To exercise these rights, contact us below. We respond within one month (per GDPR/UK GDPR), with possible extension by up to two further months for complex requests, verifying identity for security. Some rights may have legal exemptions, which we will explain if applicable.

8. International Data Transfers

Your data may be transferred to countries outside your own (e.g., for payment processing by third-party providers). We share data only with contracted service providers under Data Processing Agreements (DPAs) and ensure adequate protection via:

  • GDPR/UK GDPR Safeguards: Standard Contractual Clauses (SCCs) with providers, supported by Transfer Impact Assessments (TIAs).
  • Adequacy Decisions: Transfers to countries with equivalent GDPR/UK GDPR protections, if applicable.
  • Security Measures: Encryption, access controls, and confidentiality agreements with third parties.

By using our services, you consent to such transfers, with protections in place. We do not sell or rent your data to third parties.

9. Data Security

We use technical and organizational measures to protect your data, including TLS 1.3 encryption for data in transit, encryption at rest, multi-factor authentication (MFA) for staff, least-privilege access controls, HTTPS, firewalls, and regular security assessments. Third-party providers also employ strong security. While we strive for robust protection, no system is completely secure. Contact us immediately if you suspect unauthorized access.

10. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

Nikalab Ltd.
71-75 Shelton Street
London WC2H 9JQ
United Kingdom

E-Mail:

11. Legal Notice

Nikalab Ltd.
71-75 Shelton Street
London WC2H 9JQ
United Kingdom

E-Mail:

Company number: 07095303
Registered in England and Wales

12. Changes to This Policy

We may update this Policy to reflect changes in practices or legal requirements. Significant changes will be notified via our website or email. The "Last Updated" date below indicates the latest revision. Review periodically to stay informed.

Last Updated: June 30, 2025