Privacy Policy

We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our services.

TL;DR

Most important points

We know privacy policies can be long and complex. Here's a quick summary of the most important points before you dive into the full details below.

We never sell your data

No sale, no sharing for advertising, no advertising profiles, no retargeting pixels. That is true under the GDPR and under every US state statute that defines those terms.

We do not train AI on your content

We operate no model of our own and we fine-tune nothing. § 10 sets out exactly what is sent to our AI providers, and what we can and cannot promise about what happens there.

Your data stays in the EU

The database, file storage and analytics store are in Ireland and Germany. Where a provider is in the US, we transfer on Standard Contractual Clauses, not on the Data Privacy Framework alone.

Two roles, stated plainly

For your account we are the controller. For your customers' data — visitor analytics, agency clients, captured leads — we are your processor, and the DPA governs.

Deletion, with the exceptions named

Delete your account whenever you like. We keep the email address alone for 30 days to stop abuse, and billing records for 10 years because tax law requires it. Nothing else.

Export, and switch away

Take your data with you in a machine-readable format. Under the EU Data Act you can switch provider on no more than two months' notice, and we help you do it.

Most Searched

Quick answers to the most common privacy questions

Reading progress: 0%

This privacy policy explains how Keupera collects, uses, discloses and retains personal data, and what rights you have in relation to it. It is issued under Articles 13 and 14 of the GDPR.

What it covers: the website at keupera.com, the application at app.keupera.com, the public API at app.keupera.com/api/v1, the MCP server at mcp.keupera.com, the Keupera app for ChatGPT, the WordPress and Framer plugins, the embeddable audit widget, and the analytics and bot-tracking scripts we provide for installation on your own website. We refer to all of these together as the Services.

What it does not cover: the websites we analyse on your instruction, the third-party services you connect to your account, and the products of the sub-processors listed in § 14, each of which is governed by its own privacy policy.

Defined terms. Capitalised terms not defined here have the meaning given to them in our Terms of Service. Where this policy and the Terms of Service conflict on a question of data protection, this policy prevails.

Two roles, two documents. For some processing we are the controller; for other processing we are a data processor acting for you. § 2 and § 3 explain which is which. Where we act as a processor, the governing document is our Data Processing Agreement, not this policy.

The controller within the meaning of Art. 4(7) GDPR for the processing described in this policy is:

Keupera

Proprietor: Ole Nepomuk Mai

Address: Goethestrasse 70, 10625 Berlin, Federal Republic of Germany

Legal form: Sole proprietorship (Einzelunternehmen)

VAT identification number: DE335582063

Email: legal@keupera.com

Telephone: +49 30 3977 0918

Data protection contact. Enquiries and requests to exercise your rights should be sent to legal@keupera.com. Please state which right you are exercising and, where you are not writing from the email address on your account, enough information for us to identify you without collecting more data than necessary.

Data protection officer. We have not appointed a data protection officer. The threshold in § 38(1) sentence 1 of the German Federal Data Protection Act (BDSG) - twenty or more persons constantly engaged in automated processing - is not met. We keep the second limb of § 38(1) BDSG under review as our processing changes, and we will publish the appointment here if one becomes necessary.

Representatives. We are established in the European Union and therefore require no representative under Art. 27 GDPR. Where we are required to designate a representative for the United Kingdom, that designation will be published in this section.

Parts of the Services exist to process personal data that belongs to your business rather than to us. For that processing you are the controller and we are your data processor. We act only on your documented instructions, and our Data Processing Agreement - not this policy - sets the terms.

Processing in which we are your processor:

  • Visitor analytics collected by the tracking script you install on your own website
  • Client records you maintain in Agency mode, including names, email addresses, telephone numbers and commercial notes about your own clients
  • Leads captured through the embeddable audit widget you place on your own website
  • Contact details of third-party website owners gathered for your outreach campaigns
  • Content you create, upload, generate or publish through the Services
  • Search Console data retrieved from a property you connect
  • Credentials for the content management systems and mail servers you connect
  • Outbound email you send through your own mail server using the Services

Your obligations as controller. You must have a lawful basis for this data, provide the privacy information your own data subjects are entitled to, and obtain any consent that applies - in particular consent under Art. 5(3) of the ePrivacy Directive and § 25 TDDDG before deploying our tracking script, which contains no consent mechanism of its own.

Where to find the terms. Our Data Processing Agreement is published at keupera.com/legal/dpa and forms part of your contract with us. It incorporates the standard contractual clauses where they are required.

We collect the following categories of personal data in our capacity as controller.

Account and identity data: your name, email address, password in hashed form, profile picture, and - where you sign in with Google - the identifiers and basic profile information Google returns to us.

Organisation and team data: organisation name, membership, role, the websites each member may access, invitations you send, and the email addresses of the people you invite.

Onboarding data: the website you enter, its sector and target market, and your answers to the optional onboarding survey covering your role, team size, objectives and current tools, together with your marketing preference.

Billing data: your subscription tier and status, add-ons, credit balances, metered usage, renewal and trial dates, and the customer and subscription identifiers held by our merchant of record. We never receive or store your card number - payment credentials are collected and held by Polar Software, Inc.

Usage and telemetry data: the features and pages you use, timestamps, request counts, AI credit and crawl credit consumption, model and token counts per AI request, job and error records, and product-analytics events where you have consented.

Device and connection data: IP address, user-agent string, browser, operating system, device type, referring page, and approximate location derived from the IP address at country and city level.

Communications data: the content of support conversations, in-product chat with our AI assistant, contact-form submissions, partner applications, and any correspondence you send us.

Content data: everything you create, upload or generate in the Services - articles, analyses, comments, team messages, notes, uploaded images, and uploaded server log files.

Credential data: access and refresh tokens for connected Google accounts, credentials for connected content management systems, and the username and password of any mail server you configure. These are stored in encrypted form and are described in § 8.

Special categories. We do not seek personal data falling within Art. 9 GDPR, and the Services are not designed to process it. Do not upload it.

We process personal data only where a legal basis under Art. 6 GDPR applies. The table below states each purpose and its basis.

Where we rely on legitimate interest, we have carried out and documented the balancing test that Art. 6(1)(f) requires, and you may obtain a summary of it by writing to legal@keupera.com. Where we rely on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.

No automated decision-making. We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Art. 22 GDPR. Our AI features generate suggestions and analyses; the decision whether to act on them is always yours.

PurposeLegal BasisDescription
Creating and operating your account and organisationArt. 6(1)(b) GDPR - performance of a contractRegistration, authentication, workspace and team management, and delivery of the features included in your plan.
Billing, invoicing and collectionArt. 6(1)(b) and 6(1)(c) GDPRProcessing subscriptions, add-ons and metered usage through our merchant of record, and retaining the records that tax and commercial law require us to keep.
Service and transactional communicationsArt. 6(1)(b) GDPRAccount confirmations, password resets, invoices, security notices, and messages about changes to the Services or to these terms.
Onboarding and product-education emailsArt. 6(1)(f) GDPR, or Art. 6(1)(a) where you opted inA finite sequence of guidance emails after sign-up. Every message carries a one-click unsubscribe link, and unsubscribing does not affect your use of the Services.
Newsletter and product marketingArt. 6(1)(a) GDPR - consent; § 7(3) UWG for existing customersSent only where you have consented, or where the narrow existing-customer exception applies. Withdrawable at any time with effect for the future.
Product analytics and error reportingArt. 6(1)(a) GDPR - consent, read together with § 25(1) TDDDGUnderstanding which features are used and diagnosing faults. Not activated unless you accept the analytics category in our cookie banner.
Affiliate attributionArt. 6(1)(a) GDPR - consent, read together with § 25(1) TDDDGRecording which partner referred a sign-up so that commission can be paid. Not activated unless you accept the marketing category.
Security, abuse prevention and rate limitingArt. 6(1)(f) GDPR - legitimate interestProtecting the Services and other customers against automated abuse, credential attacks and quota evasion. Our interest is the integrity and availability of the Services.
Operating the free tools without an accountArt. 6(1)(b) and 6(1)(f) GDPRDelivering the requested result, and limiting the rate at which anonymous requests can be made. See § 6.
Crawling and analysing third-party websites at your instructionArt. 6(1)(f) GDPR - legitimate interestRetrieving publicly accessible pages to produce audits, competitor analyses and outreach research. Subject to a documented balancing test and to the safeguards in § 7.
Establishing, exercising or defending legal claimsArt. 6(1)(f) GDPR; Art. 9(2)(f) where applicableRetaining the minimum evidence necessary while a claim is live or a limitation period is running.
Compliance with legal obligationsArt. 6(1)(c) GDPRStatutory retention under § 257 HGB and § 147 AO, responses to lawful requests from public authorities, and obligations under the Digital Services Act.

We offer a set of SEO tools on keupera.com that anyone may use without registering. This section applies to those tools, and to the equivalent tools inside the application when used before sign-in.

What we record: the input you submit and the result returned, your IP address, your user-agent string, and a randomly generated guest identifier stored in your browser. These are written to a usage log.

Why: to return the result you asked for, to enforce the rate limits that keep the tools available to everyone, and to detect and block automated abuse. The legal bases are Art. 6(1)(b) and Art. 6(1)(f) GDPR.

Rate limiting. Requests from unauthenticated users are limited by IP address and by guest identifier. This is the reason the IP address is processed; it is not used to build a profile of you.

Onward transfer. Where the tool requires it, the target address or keyword you enter is transmitted to the relevant sub-processor in § 14 - for example a search-data provider or an AI provider - in order to produce the result. We do not transmit your IP address to those providers for this purpose.

Retention. We are reducing the retention of these records. Our commitment is that the IP address and user-agent associated with an anonymous request are erased within 30 days, after which only aggregate counts remain. Where you were signed in, the record is retained for 12 months.

Your rights. You may object to this processing, and request erasure of the records associated with your guest identifier or IP address, by writing to legal@keupera.com. Because we hold no other identifier for anonymous users, please include the approximate date and the tool used.

Some data reaches us from sources other than the person it concerns. Art. 14 GDPR requires us to be explicit about this, and we are.

Owners and contacts of third-party websites. When a customer runs backlink or outreach research, we retrieve publicly accessible pages and, from them, contact names and email addresses published on those pages. The source is always the public web. The legal basis is Art. 6(1)(f) GDPR; our interest, and that of our customer, is in identifying appropriate professional contacts for a business communication. We do not collect data from private or access-controlled areas, we do not attempt to defeat access controls, and we do not enrich this data from data brokers.

Any email you subsequently receive is sent by our customer, from our customer's own mail server, and our customer is the controller of that communication. If you write to legal@keupera.com we will nevertheless erase your details from our systems and, on request, tell you which customer holds them.

Leads captured by our customers. Where a customer places our audit widget on their website, a visitor who requests a report may provide an email address, which we store together with the IP address, user-agent and referring page. For this data we are a data processor and the customer is the controller. Please direct requests to that customer in the first instance; we will assist them, and we will act ourselves where they do not.

Visitors to our customers' websites. See § 11.

Data in uploaded log files. A customer analysing AI-crawler traffic may upload their own server access logs, which typically contain visitor IP addresses. We process that content solely to produce the requested analysis, as a data processor.

People named in customer content. Articles, notes, comments and team messages may mention identifiable people. We process that content only to provide the Services.

The Services can act on other systems on your behalf. Doing so requires us to hold credentials, and we want to be precise about how they are handled.

What we store:

  • Google Search Console: an OAuth access token and refresh token, the token expiry, and the verified property you selected
  • Content management systems: the site address, username and application password or API token for WordPress, Webflow, Shopify, Framer, Ghost, Contentful or a custom endpoint
  • Your mail server: host, port, username and password, together with the sender name and address you configure

How they are protected. Credentials are encrypted at rest with AES-256-GCM under a key held only in our server environment, and are decrypted only in server-side code at the moment an action you configured is carried out. They are never transmitted to your browser, never returned by our API, and never written to application logs.

What we do with them. Only what you have configured: reading your Search Console statistics, publishing or updating the content you schedule, and sending the messages you compose. We do not browse, alter or delete anything else in the connected account.

Your warranties. By connecting an account you confirm that you are entitled to grant that access and that doing so does not breach your agreement with the provider concerned.

Revocation. You may disconnect an integration at any time in the application, which deletes the stored credential. You may additionally revoke Google access at myaccount.google.com/permissions and revoke a WordPress application password from your own WordPress profile. We recommend doing both when you stop using an integration.

Where you connect Google Search Console, our use of the data obtained is governed by the Google API Services User Data Policy, including its Limited Use requirements. This section is the disclosure that policy requires.

Scope requested: https://www.googleapis.com/auth/webmasters.readonly. This is a read-only scope. We cannot modify or delete anything in your Search Console account.

What we access: search performance data for the property you select - queries, pages, clicks, impressions, click-through rate and average position - together with the property list needed to let you choose.

How we use it: solely to display and analyse your own search performance inside your Keupera account, to power the reports, dashboards and AI analyses you request, and to compare that data with the other metrics in your workspace.

How we store it: the retrieved statistics are stored in your workspace in our database in the European Union. The OAuth tokens are stored encrypted as described in § 8.

How we share it: we do not sell, rent or trade Google user data. We disclose it only to the sub-processors in § 14 that are strictly necessary to operate the features you use, and where required by law. Where you ask an AI feature to analyse your search performance, the relevant extract is transmitted to our AI provider for that purpose.

What we never do: we do not use Google user data to serve advertising, we do not use it to train or improve any artificial-intelligence or machine-learning model, whether ours or a third party's, and we do not allow humans to read it except where you have expressly asked for support, where it is necessary for security purposes, or where the law requires it.

Changes: if we ever intend to use Google user data in a way not described here, we will notify you and obtain your consent before doing so.

Revocation and deletion: disconnect the integration in the application, or revoke access at myaccount.google.com/permissions. On disconnection we delete the stored tokens and, on request, the retrieved statistics.

Several parts of the Services are built on large language models operated by third parties. We consider it important that you know exactly what leaves our systems.

Providers: OpenAI, L.L.C. for all text generation, analysis, classification and chat, and BFL GmbH for image generation. Full details are in § 14.

Notice under Art. 50 of the AI Act. Where you interact with our support assistant, the dashboard assistant, the editor assistant or the workflow assistant, you are interacting with an artificial-intelligence system and not with a human being. We are a deployer and downstream provider of these systems; we are not a provider of a general-purpose AI model.

What is transmitted, by feature:

  • Site and page analysis: the address and the text content of pages we retrieved
  • Keyword and competitor research: keywords, domains, and content retrieved from competitor pages
  • Content generation and the editor: outlines, drafts, tone samples and the text you are editing
  • Outreach drafting: the target page's context and the message you are composing
  • AI visibility: brand and competitor names, the prompts you track, and prior model responses
  • Dashboard assistant: an extract of your own workspace records, capped at approximately 12,000 characters
  • Support assistant: your question, truncated to 400 characters, together with our public documentation
  • User-experience audits: the rendered markup of the page being audited

What we store: the conversation history of AI sessions, support-chat messages, and the full text of model responses in AI-visibility campaigns, so that you can revisit them. We also log the model, token counts and cost of each request for billing and capacity purposes.

Training. We do not train, fine-tune or otherwise develop any model on your content, and we operate no model of our own. What our providers may do with data submitted through their APIs is governed by their own terms, which we have accepted on the standard commercial basis for business API use. We will not state that your content is excluded from provider-side retention or model training unless and until we have secured that contractually, and we will update this section when we do.

Accuracy. Model outputs can be wrong, incomplete or fabricated, including where they appear confident. Review anything you intend to publish. Nothing in the Services is a guarantee of a search ranking, of traffic, or of being cited by any AI assistant.

Keupera includes a first-party analytics product. Where you install our script on your own website, we process data about your visitors as your data processor; you are the controller.

What is collected: a visitor identifier, a session identifier, the address, path and host of the page, the referring page, campaign parameters, browser, operating system, device type, country, city, the event name and any properties you attach, and the timestamp.

How the visitor identifier is formed: by hashing the visitor's IP address, user-agent and your site identifier. The raw IP address is not stored in the analytics database.

This is pseudonymisation, not anonymisation. A hash of an IP address can in principle be reversed by an exhaustive search, so the resulting identifier remains personal data under the GDPR. We say so plainly, because describing it otherwise would misstate your obligations as controller.

Country lookup. Country and city are normally derived on our own servers from a local geolocation database. In a narrow fallback path the IP address is sent to ip-api (Artia International S.R.L., Romania) to resolve the country. We are removing this fallback; while it exists, it is disclosed here.

Where it is stored: on our servers at Hetzner Online GmbH in Germany.

Retention: determined by your subscription tier, with a default of one month, and subject to an absolute ceiling of two years enforced at the database level.

Consent is your responsibility. The script has no consent mechanism of its own. It begins collecting when the page loads. You must obtain consent under § 25 TDDDG and Art. 5(3) of the ePrivacy Directive, or the equivalent rule in your jurisdiction, and load the script only after that consent is given.

Bot traffic. We also record requests from identifiable AI crawlers such as GPTBot, ClaudeBot and PerplexityBot. That data describes automated agents, not people.

Storing information on your device, or reading information already stored there, requires your consent under § 25(1) TDDDG unless it is strictly necessary to provide a service you expressly requested. We ask for that consent through the banner shown on your first visit.

Strictly necessary (no consent required, cannot be switched off): the record of your cookie choices, your authentication session, the anonymous token that enforces rate limits on the free tools, and the small set of interface preferences that remember your last workspace and dismissed prompts.

Analytics (off unless you accept): PostHog, which records feature usage and application errors, and TWIPLA, which records visitor statistics. See § 14.

Marketing (off unless you accept): the Affonso affiliate cookie, which records for thirty days which partner referred you, so that commission can be paid.

Cookie-free statistics. keupera.com additionally uses Simple Analytics, which produces aggregate traffic statistics without setting cookies and without any cross-site identifier.

Your record of consent. When you make a choice we store a consent identifier, the time of your decision, the policy revision in force, and which categories you accepted or rejected. This record exists so that we can demonstrate compliance with Art. 7(1) GDPR; it is held in our product-analytics system.

Revisions. If we change our use of cookies materially we increase the policy revision number, and you will be asked to review your choices again.

Scope. Your choice is stored for the whole of keupera.com, including app.keupera.com, and lasts for one year unless you change it sooner.

Changing your mind. Use the button below, or the "Manage preferences" link in the banner, at any time. You can also delete cookies through your browser settings, though doing so will also clear the record of your preferences.

A complete, itemised register of every cookie and storage item - name, provider, purpose and duration - is published in our Cookie Policy at keupera.com/legal/cookies.

Newsletter and product marketing. We send marketing email only where you have consented, or where § 7(3) of the German Act Against Unfair Competition (UWG) permits us to write to an existing customer about our own similar services. Every message contains a one-click unsubscribe link, and we act on unsubscribes without delay. Withdrawing consent has no effect on your use of the Services.

Double opt-in. Where you subscribe on our website, we send a confirmation email and record your subscription only after you confirm it. We store the confirmation and its timestamp as evidence of consent.

Onboarding sequence. After sign-up we send a short, finite sequence of guidance emails about getting started. These are sent on the basis of Art. 6(1)(f) GDPR, or of your consent where you gave it in the onboarding survey, and each one can be stopped with a single click. Your notification preferences in the application control this independently of the newsletter.

Service messages. Invoices, security notices, changes to these documents and messages about your subscription are part of the contract. They cannot be unsubscribed from while you hold an account.

Affiliate programme. If you arrive through a partner link, and you have accepted the marketing cookie category, we record the referring partner for thirty days so that commission can be attributed. Partners see the fact of a referral and the resulting commission; they do not see your account content. Attribution is operated for us by ZASolution (Affonso), whose details are in § 14.

No advertising profiles. We do not build advertising profiles, we do not operate retargeting pixels for advertising networks, and we do not disclose personal data to advertising networks.

We disclose personal data only to the recipients set out below, and only to the extent necessary for the purpose stated.

Categories of recipient: the service providers listed in the table, which act as processors on our documented instructions under Art. 28 GDPR; professional advisers under a duty of confidence; public authorities where we are legally obliged to disclose; and an acquirer in the event of a merger or transfer of the business, of which you would be informed in advance.

How we select them. Each provider is assessed for the technical and organisational measures it maintains, its location and transfer mechanism, and its own sub-processor chain, and is engaged under a written data processing agreement that imposes materially the same obligations we owe you.

Changes. We publish the current list at keupera.com/legal/subprocessors. Before adding or replacing a sub-processor that processes customer data, we give at least thirty days' notice to account owners, who may object on reasonable data-protection grounds under the Data Processing Agreement.

Not a sub-processor: your own mail server. Outreach and audit-result emails are sent through the mail server you configure, under your own sending identity. That provider is your supplier, not ours, and we have no relationship with it.

Not a sub-processor: AI clients you connect. If you connect the Keupera MCP server or the ChatGPT app to a third-party AI client, your workspace data is transmitted to that client at your instruction and under that client's terms. Note that our authorisation server permits dynamic client registration, so applications other than those we have verified may request access; grant it only to applications you trust, and review connected applications regularly.

ServiceLegal NameAddressPurposeLegal BasisPrivacy Policy
SupabaseSupabase, Inc.970 Toa Payoh North, #07-04, Singapore 318992 - data hosted in AWS eu-west-1 (Ireland)Database, authentication, file storage and serverless functions - the primary system of recordArt. 6(1)(b) - contract performanceView Policy
HetznerHetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyServers running the analytics store, the site crawler and the MCP serverArt. 6(1)(b) - contract performanceView Policy
NetlifyNetlify, Inc.44 Montgomery Street, Suite 300, San Francisco, CA 94104, USAApplication hosting and content deliveryArt. 6(1)(b) - contract performanceView Policy
PolarPolar Software, Inc.3500 South DuPont Highway, Dover, DE 19901, USAMerchant of record: checkout, subscriptions, metered billing, invoicing and taxArt. 6(1)(b) - contract performanceView Policy
OpenAIOpenAI, L.L.C.3180 18th Street, San Francisco, CA 94110, USALarge language models behind every AI feature: content generation, analysis, classification and chatArt. 6(1)(b) - contract performanceView Policy
Black Forest LabsBFL GmbHIngeborg-Krummer-Schroth-Strasse 18, 79106 Freiburg im Breisgau, GermanyImage generation for article artworkArt. 6(1)(b) - contract performanceView Policy
Bright DataBright Data Ltd.Habarzel 40, Tel Aviv 6971054, IsraelSearch-engine result data, keyword data and backlink discoveryArt. 6(1)(f) - legitimate interestView Policy
Browserlessbrowserless.io, Inc.23207 NE 192nd Ct, Battle Ground, WA 98604, USAHeadless-browser screenshots of pages you submit for analysisArt. 6(1)(b) - contract performanceView Policy
ResendPlus Five Five, Inc.2261 Market Street, Suite 5039, San Francisco, CA 94114, USATransactional and lifecycle email sent by KeuperaArt. 6(1)(b) - contract performanceView Policy
MailgunMailgun Technologies, Inc.535 Mission Street, San Francisco, CA 94105, USADelivery of contact-form and partner-application messages from keupera.comArt. 6(1)(f) - legitimate interestView Policy
GoogleGoogle Ireland LimitedGordon House, Barrow Street, Dublin 4, IrelandSign-in with Google, and the Search Console API where you connect a propertyArt. 6(1)(b) - contract performanceView Policy
PostHogPostHog, Inc.2261 Market Street #4008, San Francisco, CA 94114, USA - data hosted in the EU Cloud regionProduct analytics, error reporting and the record of your cookie choicesArt. 6(1)(a) - consentView Policy
TWIPLAVisitor Analytics GmbHSeestrasse 76, 82335 Berg, GermanyWebsite visitor statistics for keupera.com and app.keupera.comArt. 6(1)(a) - consentView Policy
Simple AnalyticsSimple Analytics B.V.Hooftlaan 4, 1401 ED Bussum, The NetherlandsAggregate, cookie-free traffic statistics for keupera.comArt. 6(1)(f) - legitimate interestView Policy
AffonsoZASolutionStuttgarter Str. 106, 70736 Fellbach, GermanyAffiliate referral attribution and partner commission accountingArt. 6(1)(a) - consentView Policy
ip-apiArtia International S.R.L.RomaniaFallback lookup of the country associated with a visitor IP address in the analytics productArt. 6(1)(f) - legitimate interestView Policy
ContentfulContentful GmbHRitterstrasse 12-14, 10969 Berlin, GermanyContent management for the Keupera blog and resource libraryArt. 6(1)(f) - legitimate interestView Policy

Primary processing locations. Our database, file storage and application backend run in the European Union (Ireland). Our analytics store, crawler and MCP server run in Germany. Our product analytics is hosted in the European Union.

Transfers to third countries. Certain sub-processors listed in § 14 are established in, or process in, the United States. For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, supplemented by a documented transfer impact assessment and by the technical measures described in § 16.

On the EU-US Data Privacy Framework. Some of our providers are certified under the Framework, and its adequacy decision remains in force. Because an appeal against the General Court's judgment upholding that decision is pending before the Court of Justice, we do not rely on the Framework as our sole basis for any transfer. The standard contractual clauses stand independently of it.

Israel. Transfers to Bright Data Ltd. are made on the basis of the European Commission's adequacy decision for Israel.

Your copy. You may request a copy of the safeguards we rely on, with commercially confidential terms redacted, by writing to legal@keupera.com.

Public authorities. We have received no order requiring bulk disclosure of customer data to any public authority. Where we receive a lawful, specific request we assess it, and where we are permitted to do so we notify the affected customer before responding.

We maintain technical and organisational measures appropriate to the risk, as Art. 32 GDPR requires. The principal measures are:

Access control: row-level security in the database isolates each organisation's records; application roles restrict members to the websites and features assigned to them; tables holding operational data are unreachable from the browser entirely.

Encryption: TLS/SSL for all data in transit; provider-managed encryption at rest; and AES-256-GCM encryption with a dedicated key for the third-party credentials described in § 8.

Credential handling: API keys are stored only as SHA-256 hashes, with a prefix and last four characters retained so you can recognise them; passwords are stored only as salted hashes by our authentication provider.

Network: the analytics and queue infrastructure is not exposed to the public internet; internal services authenticate to one another with dedicated shared secrets.

Minimisation: IP addresses are hashed before entering the analytics store; secrets are never written to application logs.

Data location: the primary database and the analytics store are located in the European Union.

What we do not claim. We hold no ISO 27001 or SOC 2 certification, and we do not represent that we do. We publish the current state of our measures, including their limits, at keupera.com/legal/security, and we update it as they improve.

Personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR, and we notify affected individuals without undue delay where the risk is high. Where we act as a processor, we notify the affected customer without undue delay and in any event within 48 hours, as our Data Processing Agreement provides.

Reporting a vulnerability. Write to security@keupera.com. We will acknowledge your report, keep you informed, and will not pursue researchers who act in good faith and give us a reasonable opportunity to respond before disclosure.

We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires.

Account data: for the duration of your account, and for 30 days after deletion to allow recovery from error.

Billing and tax records: 10 years, as required by § 257 of the German Commercial Code and § 147 of the German Fiscal Code. This obligation overrides a request for erasure.

Content you create: until you delete it, or until your account is deleted, whichever comes first.

Anonymous free-tool records: 30 days for the IP address and user-agent; see § 6.

Authenticated usage records: 12 months.

AI conversations and support chats: 12 months, or until you delete them.

Audit page copies and screenshots: 90 days, or the life of the audit run if shorter.

Visitor analytics: as set out in § 11.

Consent records: for the duration of the consent and 3 years afterwards, as evidence under Art. 7(1) GDPR.

Record of deleted accounts. When an account is deleted we retain the email address alone, in a separate table, for 30 days, to prevent immediate re-registration for the purpose of abusing free allowances. The legal basis is Art. 6(1)(f) GDPR. We disclose this expressly because it means one item of data survives an erasure request for that period. Nothing else is retained.

Content owned by an organisation. Team messages, editor comments, audit runs and captured leads belong to the organisation rather than to the individual who created them, and they remain when that individual's account is deleted. This is necessary for the remaining members to continue using the Services. Contact us if you need such content removed.

Deletion while a subscription is active. The self-service deletion flow will not proceed while a paid subscription is running, because deletion would terminate a live contract. Cancel the subscription first. This is a sequencing requirement, not a restriction on your right to erasure: if you write to legal@keupera.com we will handle the cancellation and the erasure together.

Backups. Data removed from live systems persists in encrypted backups until those backups age out on their normal rotation, after which it is overwritten. Restored backups are re-processed to remove data that was erased in the interim.

Under the GDPR you have the following rights in relation to personal data we hold about you as controller.

Right of access (Art. 15): to obtain confirmation of whether we process personal data about you, a copy of it, and the information set out in Art. 15(1).

Right to rectification (Art. 16): to have inaccurate data corrected and incomplete data completed.

Right to erasure (Art. 17): to have data erased where one of the grounds in Art. 17(1) applies. This right is subject to the statutory retention obligations in § 17.

Right to restriction (Art. 18): to have processing restricted while a dispute about accuracy or legitimacy is resolved.

Right to data portability (Art. 20): to receive the data you provided to us, and data generated by your use of the Services, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to object (Art. 21): to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f). You may object to direct marketing at any time, without giving reasons, and we will stop.

Right to withdraw consent (Art. 7(3)): at any time, with effect for the future.

Right to lodge a complaint (Art. 77): see § 21.

How to exercise them. The application offers self-service export and deletion under Account. Where you want a complete set of everything we hold - which is broader than the current in-app export - write to legal@keupera.com and we will assemble it manually. We are extending the in-app export to cover the full record.

Our response. We respond within one month of receipt. Where a request is complex, or where you have made several, we may extend that period by two further months and will tell you within the first month, with reasons. Our response is free of charge; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.

Identification. Where we have reasonable doubt about the identity of the person making a request we may ask for further information. We will not use anything you send for that purpose for any other end.

This section applies in addition to § 18 if you are a resident of a US state with a comprehensive consumer privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island.

Notice at collection. The categories of personal information we collect, the purposes, and the categories of recipients are set out in § 4, § 5 and § 14. We collect all of it directly from you, from your use of the Services, or from the public sources described in § 7.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA and in the equivalent statutes of other states. We do not process personal information for targeted advertising, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under sixteen.

Sensitive personal information. We do not collect sensitive personal information for the purpose of inferring characteristics, and we use none of it beyond what is necessary to provide the Services.

Data minimisation. We collect only what is reasonably necessary and proportionate to provide the Services you requested. Where the law of your state - Maryland's, in particular - sets a stricter standard, we apply that standard to your data.

Your rights:

  • To know what personal information we collect, use, disclose and retain
  • To access a copy of it, in a portable form
  • To correct inaccurate personal information
  • To delete personal information, subject to the exceptions the statute allows
  • To opt out of sale, sharing and targeted advertising - none of which we carry out
  • To limit the use of sensitive personal information
  • Not to receive discriminatory treatment for exercising any of these rights
  • To appeal a refusal

How to exercise them. Write to legal@keupera.com, or use the self-service tools under Account. We verify requests against the information already associated with your account. An authorised agent may act for you on production of written authority, and we may still ask you to confirm the authorisation directly.

Timing and appeals. We respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you. If we decline a request you may appeal by replying to our decision with the word "Appeal" in the subject line. We decide appeals within 45 days and, if we again decline, we will tell you how to complain to your state Attorney General.

Global Privacy Control. Because we do not sell or share personal information, an opt-out preference signal has no sale or sharing to switch off. We honour it as a withdrawal of consent to non-essential cookies.

The Services are business tools, offered exclusively to persons acting in the course of a trade, business, craft or profession. They are not directed to children and we do not knowingly collect personal data from them.

Age requirement. You must be at least 18 years old to open an account, as our Terms of Service provide. Where a lower age would otherwise apply under Art. 8 GDPR, our contractual minimum of 18 governs.

If we discover a child's data. We will delete it without undue delay and terminate any account concerned. If you believe a child has provided us with personal data, write to legal@keupera.com and we will act promptly.

Content you upload. You must not upload personal data concerning children through the Services. If you do, you are the controller of it, and you must have a lawful basis and any parental consent that applies.

Changes to this policy. We keep this policy under review and update it when our processing changes. The version in force is always published here with its effective date. Where a change is material - a new purpose, a new category of data, a new category of recipient, or a change to the legal basis - we notify account holders by email at least 30 days before it takes effect. Continued use of the Services after that date constitutes acknowledgement; it does not constitute consent where consent is required, which we will always ask for separately.

Version history. Previous versions are available on request from legal@keupera.com.

Complaints to us. If you are dissatisfied with how we handle your personal data, please tell us first at legal@keupera.com. We take complaints seriously, we will investigate, and we will reply substantively.

Complaints to a supervisory authority. You have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. Approaching us first is not a precondition.

Our competent supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59-61, 10555 Berlin, Germany

https://www.datenschutz-berlin.de

Judicial remedy. Art. 79 GDPR additionally gives you the right to an effective judicial remedy, and Art. 82 a right to compensation for damage suffered as a result of an infringement.

Effective date. This policy takes effect on 5 September 2026 and replaces all previous versions.