Seopotion logosuSeopotion

Yasal

Privacy Policy

What personal data Seopotion collects, why, on what legal basis, who we share it with, how long we keep it, and the GDPR rights you can exercise.

Yürürlük tarihi
29 Temmuz 2026
Son güncelleme
29 Temmuz 2026

Seopotion'ın yasal belgeleri yalnızca İngilizce yayımlanır. Bizimle yaptığınız sözleşmede geçerli olan sürüm İngilizce sürümdür.

This notice explains what personal data Seopotion collects, why, on what legal basis, who we share it with, and what rights you have. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), which applies to us under Article 3(2) because we offer the Service to people in the European Union, and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), which applies to us as a data controller established in Türkiye.

1. Who is responsible for your data

The controller — the veri sorumlusu under the KVKK — of the personal data described in this notice is:

  • Deniz Yazagan, sole trader, trading as "Seopotion"
  • Address: Bengi Sokak 8/1, Erenköy, Kadıköy, Istanbul, Türkiye
  • Email: support@seopotion.co

Seopotion is operated as a sole proprietorship, so the controller is Deniz Yazagan personally, trading under the name Seopotion.

Data protection officer: none appointed. Seopotion does not carry out the large-scale regular and systematic monitoring, or large-scale processing of special-category data, that would require a data protection officer under Article 37 GDPR. Privacy enquiries go to support@seopotion.co.

2. Controller and processor roles

We handle two different categories of data, and our role differs between them.

We are the controller of data about you as a user and customer: your account and profile data, your subscription and billing records, your support correspondence, and technical logs about how you use the Service.

We are a processor for content and data you connect to a workspace and that we process on your instructions — for example, personal data appearing in your website's pages, in content you ask us to generate or publish, or in your Google Search Console data. There, you are the controller, and our processing is governed by the processor commitments in the Terms of Service, clause 12, which you can also request as a separate signed Data Processing Agreement. This notice describes that processing for transparency, but your own privacy notice governs it toward your users.

3. What data we collect

3.1 Account and identity data

Seopotion accounts are created only through Google Sign-In. When you sign in, Google returns and we store:

  • your Google account identifier (sub),
  • your email address,
  • your name, where Google provides it.

We never receive or store your Google password.

3.2 Workspace and website data

  • the website URL you connect;
  • content retrieved from your website when we scan it, and the business profile derived from it — business name, language, country, description, target audience, competitors, blog and sitemap locations, sample articles;
  • your content preferences: article style, tone, internal linking rules, instructions you write for the AI, image style;
  • onboarding metadata, such as how you heard about us and which publishing platforms you selected.

Scanned website content may itself contain personal data (author names, contact details, team pages). We process it as described in clause 2.

3.3 Integration data and credentials

  • Google Search Console: where you connect it, we store an OAuth refresh token encrypted with AES-256-GCM, the Google account email used, and the property you selected. We use the token to read your search performance data (queries, clicks, impressions, positions, pages) with the read-only webmasters.readonly scope.
  • Publishing integrations (e.g. WordPress): we store the access token or application password needed to publish, together with the connection timestamp.

3.4 Content and usage data

Keywords and content plans, generated articles and their revisions, generated images, video suggestions, publication status, quota consumption, and feature usage.

3.5 Billing data

Purchases are processed by Lemon Squeezy, our merchant of record. Lemon Squeezy collects your payment details directly — we never receive or store your card number. We store only: your subscription identifier and customer identifier at the provider, the plan and tier, subscription status, and the current billing period end date.

3.6 Technical and log data

IP address, browser and device information, request timestamps, endpoints called, error traces and performance metrics, collected by our infrastructure and application logs.

3.7 Support and marketing data

The content of emails and support requests you send us, and — where you have opted in — your subscription to product or marketing emails.

3.8 Cookies and local storage

The Seopotion application stores your session token (a JSON Web Token) and workspace state in your browser's local storage. This is strictly necessary to keep you signed in, and is not used for tracking or advertising.

We use no analytics or advertising cookies, and we embed no third-party tracking or advertising scripts. Because everything we store on your device is strictly necessary to deliver the service you asked for, no consent banner is required. If we ever introduce a non-essential cookie or similar technology, this section will list it with its purpose and duration, and we will ask for your consent before setting it.

What we doData usedLegal basis (Art. 6 GDPR)
Create and authenticate your account3.1Contract — Art. 6(1)(b)
Provide the Service: scan your site, research keywords, generate and publish content3.2, 3.3, 3.4Contract — Art. 6(1)(b)
Read Google Search Console performance data3.3Contract — Art. 6(1)(b), after your explicit OAuth authorisation
Take payment, manage subscriptions, invoicing3.1, 3.5Contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c)
Provide support3.1, 3.7Contract — Art. 6(1)(b)
Keep the Service secure, prevent abuse and fraud, enforce limits3.6Legitimate interests — Art. 6(1)(f): protecting the Service and its users
Debug, monitor and improve reliability3.4, 3.6Legitimate interests — Art. 6(1)(f): a working, reliable product
Aggregate, de-identified product analyticsderived from 3.4, 3.6Legitimate interests — Art. 6(1)(f)
Send service and transactional emails (billing, security, changes to terms)3.1Contract — Art. 6(1)(b)
Send product or marketing emails3.1, 3.7Consent — Art. 6(1)(a), withdrawable at any time; or legitimate interests for existing customers where national law permits
Comply with legal requests, accounting and tax dutiesas requiredLegal obligation — Art. 6(1)(c)
Establish, exercise or defend legal claimsas requiredLegitimate interests — Art. 6(1)(f)

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You can ask for details of that assessment, and you can object — see clause 9.

We do not sell personal data, and we do not use your Customer Content or generated Output to train our own or any third party's AI models.

5. AI processing and automated decision-making

Generating content sends your instructions, business profile and related context to third-party AI providers (clause 6). We instruct providers not to use that data for training where their terms allow, and we select providers whose API terms exclude training on API inputs by default.

We do not carry out automated decision-making producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. Content generation is automated, but it produces suggestions you review and control.

6. Who we share data with

We share data only with the providers below, all of whom are bound by contract to process it only on our instructions and to protect it appropriately.

RecipientPurposeData sharedLocation
Amazon Web ServicesHosting, compute, queues, secretsAll categories, at rest and in transitEU — Frankfurt (eu-central-1)
MongoDB AtlasDatabase hosting3.1–3.5EU — Frankfurt
OpenRouterAccess to LLMs for content generationPrompts, business profile, content contextUS / model provider regions
fal.aiAI image generationImage prompts derived from your contentUS
DataForSEOKeyword, SERP and ranking dataKeywords, domain, country/languageUS
Google (Sign-In, Search Console, YouTube)Authentication, search performance, video suggestions3.1, 3.3, site/property identifiersGlobal
Lemon SqueezyPayments as merchant of record, invoicing, taxEmail, billing details you enter, subscription dataUS / EU
Your connected CMS (e.g. WordPress)Publishing content you approveGenerated content and imagesYour own hosting

We may also disclose data: to professional advisers under duty of confidence; to authorities where legally required, after checking the request is valid and proportionate; and to an acquirer in a merger, acquisition or asset sale, in which case we will notify you before your data becomes subject to a different privacy notice.

7. Google user data — Limited Use

Seopotion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • We request the minimum scopes needed: openid and email for sign-in, and https://www.googleapis.com/auth/webmasters.readonly to read Search Console performance data. The Search Console scope is read-only — we cannot change anything in your Google account.
  • We use Google user data only to provide and improve the user-facing features you asked for.
  • We do not transfer Google user data to third parties except as necessary to provide those features, for security purposes, or to comply with applicable law.
  • We do not use Google user data for advertising, and we do not allow humans to read it, except with your explicit consent for specific messages, for security or abuse investigation, to comply with law, or on aggregated, anonymised data for internal operations.

You can revoke our access at any time by disconnecting the integration in Seopotion settings or at myaccount.google.com/permissions. When you disconnect, we delete the stored refresh token.

8. International transfers

Your data is stored in the European Union — our infrastructure and database both run in Frankfurt. Two kinds of transfer out of the EEA still happen, and we are explicit about both:

  • To us, in Türkiye. We administer the Service from Istanbul, so our own staff access EU-hosted data from a country with no European Commission adequacy decision.
  • To providers in the United States — the AI, SERP-data and payment providers listed in clause 6.

For both, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with supplementary technical measures including encryption in transit and at rest and least-privilege access; and, where the recipient is certified, on the EU-US Data Privacy Framework adequacy decision.

Transfers of personal data out of Türkiye are made on the bases permitted by Article 9 of the KVKK — your explicit consent, or a standard contract or undertaking notified to the Turkish Personal Data Protection Authority, as applicable to the recipient.

You may request a copy of the safeguards in place by emailing support@seopotion.co.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten"), where the conditions apply;
  • restrict processing in certain circumstances;
  • data portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on legitimate interests, including profiling — we will stop unless we can show compelling legitimate grounds; and to object at any time and absolutely to direct marketing;
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects (see clause 5); and
  • lodge a complaint with a supervisory authority. We are established in Türkiye and have no establishment in the European Union, so there is no single lead supervisory authority for us under the GDPR's one-stop-shop mechanism. If you are in the EU or EEA, complain to the supervisory authority of the member state of your habitual residence, your place of work, or where the alleged infringement occurred. If you are in Türkiye, apply to us first under Article 13 of the KVKK, and then to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) at kvkk.gov.tr if you are not satisfied with our response or do not receive one within 30 days.

To exercise any right, email support@seopotion.co. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free; we may charge a reasonable fee or refuse where a request is manifestly unfounded or excessive. We may ask for information to verify your identity.

Some rights can be exercised directly in the application: you can edit your business profile and content settings, disconnect integrations, and request account deletion by contacting support.

10. How long we keep data

DataRetention
Account dataFor the life of the account, then deleted 30 days after closure
Workspace, website profile, content settingsFor the life of the workspace, then as above
Generated content and content plansFor the life of the workspace, then as above
Integration tokens (GSC, CMS)Until you disconnect the integration or close the account, then deleted immediately
Subscription and billing records10 years from the transaction, to meet accounting and tax obligations
Support correspondence24 months from the last message
Application and security logs90 days
BackupsOverwritten on a rolling 35-day cycle

After these periods, data is deleted or irreversibly anonymised. Aggregated, de-identified statistics that cannot be linked to you may be kept indefinitely.

11. Security

We apply technical and organisational measures appropriate to the risk, including:

  • TLS encryption for all data in transit;
  • encryption at rest for stored data, and AES-256-GCM encryption for OAuth refresh tokens specifically;
  • authentication via Google, with short-lived signed session tokens; signing secrets stored in AWS Systems Manager Parameter Store as encrypted SecureString values, never in code;
  • least-privilege access controls, with production data accessible only to personnel who need it;
  • network isolation, dependency and vulnerability monitoring, and audit logging of administrative actions.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.

12. Children

The Service is not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@seopotion.co and we will delete it.

13. Changes to this notice

We may update this notice. Material changes will be announced by email or in-app notice at least 30 days before they take effect, unless a change must take effect sooner for legal reasons. The current version, with its effective date, is always at seopotion.co/privacy.

14. Contact

  • Deniz Yazagan, sole trader, trading as "Seopotion"
  • Address: Bengi Sokak 8/1, Erenköy, Kadıköy, Istanbul, Türkiye
  • Privacy enquiries and rights requests: support@seopotion.co
  • Data protection officer: none appointed — see clause 1