This IMPOSEO privacy policy applies to website visitors, people who request a free SEO audit or free AI Visibility Audit, and prospective clients. We collect only the personal data we need and never sell it. When we process data on behalf of clients while delivering services, we act as a processor under a separate data processing agreement.
Who we are
This website is operated by IMPOSEO (“IMPOSEO”, “we”, “us”). We are responsible for the personal data described here. Our team works remotely, and the best way to reach us about anything in this policy is by email.
Contact us about privacy at rank@imposeo.com.
Personal data we collect
Information you give us
When you complete our lead form or request an audit, we collect:
- your name and email address
- your phone or WhatsApp number, if you choose to provide one
- your company name, website address and country
- project details and anything else you include in your message
- your budget range
- your timezone, for scheduling calls
We also keep the emails, meeting notes and proposals we exchange with you.
Information collected automatically
-
Attribution data. Session storage in your browser remembers your landing page, referrer and campaign parameters such as UTM tags or a click ID. If you submit the form, these are sent with your enquiry so we know how you found us. They clear when you close the tab.
-
Form progress. If you start our proposal form, your browser’s local storage saves your answers so you can pick up where you left off. This stays on your device and is cleared once you submit. Details you enter in our quick form may also be carried into the full form using session storage.
-
Security and technical data. Our hosting provider, Cloudflare, processes your IP address, browser and device details and request data to deliver pages and protect the site. Cloudflare Turnstile checks form submissions to tell people from bots.
-
Analytics data (only with your consent). If you allow analytics, Google Analytics 4 collects pages viewed, approximate location, device and browser type, how you arrived and which forms you completed. IP addresses are anonymized and advertising features are off.
We do not use advertising cookies. See our cookie policy for the full list of cookies and browser storage the site uses.
Information from other sources
To prepare an audit, we review public information about your website, such as its pages, search visibility and backlinks. Please do not include sensitive personal data in forms or messages.
How we use your data and our lawful bases
Under the GDPR and UK GDPR, each use needs a lawful basis:
- Responding to your enquiry and preparing an audit or proposal, including contacting you by the channels you choose: steps you request before entering a contract, and our legitimate interest in answering business enquiries.
- Protecting our site and forms from spam and abuse: our legitimate interest in keeping the site secure.
- Understanding which channels bring enquiries: our legitimate interest in improving our marketing, based on the attribution data sent with your enquiry.
- Website analytics: your consent, which you can withdraw at any time using “Cookie settings” in the footer.
- Occasional updates: your consent where required, otherwise our legitimate interest in keeping business contacts informed. You can unsubscribe at any time.
- Entering into and performing a services agreement: performance of a contract.
- Meeting legal obligations and defending claims: legal obligation and legitimate interests.
Where we rely on legitimate interests, we have weighed them against your rights. We do not make decisions about you based solely on automated processing.
Who we share data with
We do not sell personal data or share it for cross-context behavioral advertising. We share it only with:
- Cloudflare: hosting, content delivery, security and Turnstile bot protection
- Google (Google Workspace): business email, including the emails that deliver your enquiry to our team, plus calendar and document storage
- Google (Google Analytics 4): website usage statistics, only if you allow analytics
- team members and contractors bound by confidentiality who need the data to respond to you
- professional advisers, authorities where the law requires it, or a successor if our business is reorganized or sold
Our service providers act on our instructions under data processing terms.
International transfers
Our team works remotely and our providers operate globally, so your data may be processed outside your country, including in the United States. For transfers from the EEA, UK or Switzerland to countries without an adequacy decision, we use safeguards such as the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework and its UK and Swiss extensions where the recipient is certified. For transfers from Canada, Australia, the UAE, Saudi Arabia and elsewhere, we use the safeguards local law requires. You can ask us for a copy.
How long we keep data
- Enquiries that do not become clients: 24 months after our last contact, then deleted or anonymized
- Client records: for the agreement’s duration, then for as long as legal, tax and accounting obligations require
- Security logs: for the limited periods set by our providers
- Opt-out records: as long as needed to respect your choice
Security
We use encrypted connections, access controls, multi-factor authentication and least-privilege access. No system is completely secure, so tell us promptly if you think your data has been exposed.
Your privacy rights
Your rights depend on where you live. We honor requests under the laws that apply to you, including those of Qatar, Egypt and other markets we serve.
EU, EEA and UK (GDPR and UK GDPR)
You can ask to access, correct, erase or restrict your data, receive it in a portable format and object to processing based on legitimate interests. You can object to direct marketing at any time and withdraw consent without affecting earlier processing. You can also complain to your local data protection authority or, in the UK, the Information Commissioner’s Office.
California and other US states (CCPA as amended by the CPRA)
Where the CCPA applies to us, California residents can ask to know, access, correct and delete their personal information, without discrimination. We do not sell or share personal information or use sensitive personal information. In the past 12 months we collected identifiers, professional information and limited technical data, as described above, from you and your device. An authorized agent may submit a request for you. Residents of other US states with privacy laws may have similar rights.
Canada (PIPEDA)
You can access and correct your personal information, withdraw consent subject to legal or contractual limits, and complain to the Office of the Privacy Commissioner of Canada. Provincial laws, such as Quebec’s, may add rights.
Australia (Privacy Act 1988)
Where the Australian Privacy Principles apply to us, you can access and correct your personal information and complain to us, then to the Office of the Australian Information Commissioner if our response does not resolve it.
United Arab Emirates (PDPL)
Under Federal Decree-Law No. 45 of 2021, you can request information about our processing, access, correction or erasure of your data, restriction or stopping of processing, and portability. In the DIFC or ADGM, their own data protection laws may apply.
Saudi Arabia (PDPL)
Under the Personal Data Protection Law, you can be informed about processing, access your data and obtain a readable copy, have it corrected, and have it destroyed when no longer needed. You can complain to the Saudi Data and Artificial Intelligence Authority (SDAIA).
How to exercise your rights
Email rank@imposeo.com with the subject line “Privacy request” and tell us which right you want to exercise. We will verify your identity, usually by confirming you control the email address you used. We aim to respond within 30 days, and always within the period the applicable law requires. Requests are free unless clearly unfounded or excessive.
Cookies and browser storage
We use only strictly necessary and functional technologies: Cloudflare security cookies, Turnstile form protection, and a few session and local storage items that make our forms and tools work. We use Google Analytics only if you allow it through our consent banner, and we do not use advertising cookies. See our cookie policy for details.
Children
Our website is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy as our services, providers or legal requirements change. The updated date on this page shows the latest version, and we will email active contacts about significant changes.
Contact us
Email IMPOSEO at rank@imposeo.com.