Privacy Policy

SEO Analyzer by B2B Marketing.AI — seo.b2bmarketing.ai
Last updated: 11 September 2026

1. Introduction

B2B MARKETING.AI Spółka z o.o. ("B2B Marketing.AI", "we", "us", or "our") operates SEO Analyzer, a technical SEO analysis service available at seo.b2bmarketing.ai (the "Service"). SEO Analyzer is also the name shown on the Google consent screen when you connect a Google account. This Privacy Policy explains how we collect, use, store and protect your information when you use the Service.

This policy covers SEO Analyzer specifically. Our LinkedIn CRM and marketing automation services are covered by a separate privacy policy. The data controller is the same company for both.

We process personal data in compliance with:

2. Data Controller

The data controller responsible for your personal data is:

B2B MARKETING.AI Spółka z o.o.
Ks. Konstantego Budkiewicza 28A
05-091 Ząbki, Poland

NIP: 1251760683
KRS: 0001078873
REGON: 527352449

Contact: contact@b2bmarketing.ai
Data Protection Officer: dpo@b2bmarketing.ai

3. Personal Data We Collect

3.1 Account data

When you create an account we collect your email address. Authentication uses a one-time magic link sent to that address; we do not store a password for your account.

3.2 Data you submit for analysis

You provide the address of a website or sitemap you want analysed. We then fetch the public pages of that site and store the results of the analysis (page titles, meta descriptions, headings, link structure, structured data, response times and similar technical SEO attributes) together with the generated reports.

You are responsible for having the right to analyse the site you submit. Public web pages may incidentally contain personal data (for example an author name on a blog post); we process it only as part of the technical analysis you requested.

Business context (optional). You can describe the analysed site: site type, business goal, target audience, distribution channels, key ("money") pages, target keywords and keywords to exclude. This context is stored per domain, not per account: any signed-in user who enters the same domain in the Service can see it and change it, and the current version is used in every later analysis of that domain — in the report, in the AI recommendations and in choosing competitor keywords. A copy is kept inside each report it was used for. Do not enter anything you consider confidential.

Email address for report delivery. If you are signed in, we send a summary of the report to the email address of your account (see Resend in section 6). We use that address only for this delivery; it is not added to any mailing list, and it appears in our server logs. Without an account, the email address is part of the contact details described in section 3.3.

3.3 Contact details for the free report without an account

When you request the free report without creating an account, we ask for your name, your email address, and your consent to receive commercial information from B2B Marketing.AI by email. The form states plainly that the free report is offered in return for this consent. The consent is a separate checkbox from the report itself, is never pre-ticked, and can be withdrawn at any time (section 8) — withdrawing it does not take back a report you have already received.

Confirming your address (double opt-in). We email the link to your report to the address you gave. Opening that link opens the report and confirms your address, and only then does your marketing consent take effect. If you never confirm the address, we do not use it for marketing. The report email itself carries an unsubscribe link: it opens a page with a single button, and pressing it withdraws your marketing consent for that address, without signing in.

3.4 Google account data (only if you connect it)

Connecting a Google account is optional. The Service works without it. If you choose to connect, we request read-only access to the following scopes and use them only as described:

Google API scope What we read What we use it for
webmasters.readonly
(Google Search Console)
The list of Search Console properties you have access to, used only to find the one that matches the site you analyse. For that property: search queries, impressions, clicks, click-through rate, average position and the URLs they belong to (last 28 days). For analysed URLs (URL Inspection): indexing and coverage status, robots.txt and page-fetch state, last crawl time, the canonical URL you declared and the one Google selected, the mobile-usability verdict and issues, and the rich-result types and issues Google reports. Showing how the analysed site actually performs in search, detecting keyword cannibalisation (several URLs competing for one query), comparing the canonical URL you declare with the one Google chose, and choosing the keywords for the optional competitor comparison.
analytics.readonly
(Google Analytics 4)
The list of Analytics accounts, properties and web data streams you have access to, used only to find the property whose web stream matches the domain you analyse — you do not have to pick it. If no web stream matches, we fall back to matching the property's name against the domain, which can occasionally pick another of your properties; the ID of the matched property is shown in the form before you start the analysis. We keep the ID of the matched property with the report; the rest of the list is not stored. For that property only: organic-search sessions, users, bounce rate, engagement rate and average session duration per page path (last 28 days). Showing organic traffic per URL in the report, marking sitemap pages that received no organic visits, and relating technical SEO findings to real traffic, so that the pages that matter are fixed first.

Both scopes are read-only. We cannot modify, publish or delete anything in your Search Console or Analytics account.

Where your Google data goes

Search Console and Analytics data is stored in the report generated for you (section 5); a few items also appear in our server logs (section 3.6). It leaves our servers only in the following cases, each tied to a feature you switch on for that analysis:

Limited Use commitment for Google user data

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google Search Console and Google Analytics is:

3.5 Google credentials

When you connect your Google account we store the OAuth access token and refresh token issued to us, so that a repeated analysis does not require you to connect again. We never see or store your Google password. You can revoke our access at any time — see section 8.

3.6 Technical data

Our servers record standard request logs (IP address, timestamp, HTTP method, requested path, user agent, response status, response time and, if you are signed in, your account ID). Application logs record the analysed address together with the account ID, the Search Console and Analytics properties used for an analysis, the keywords sent for the competitor comparison (which may come from your Search Console queries), the total of organic sessions found, and the recipient address of report emails. For accounts, we also keep a list of analysed domains to enforce analysis limits and detect abuse. We use all of this to operate the Service, to enforce rate limits and to detect abuse.

3.7 Cookies and browser storage

We use no analytics or advertising cookies. The Service stores only what it needs to work: while you connect a Google account, a strictly necessary cookie that ties the Google response to your browser (deleted after the connection, at the latest after 10 minutes); in your browser's local storage, your sign-in session, and your theme and language choice; for the current tab only, the analysis form you are filling in; and, when you move from the free report to the full analysis, the site address, your name and email address and the report summary, for at most 60 minutes and removed once used, so that the tab you open from the sign-in email can continue where you left off. The CAPTCHA on the public form is Cloudflare Turnstile: it loads from Cloudflare, and we send your IP address to Cloudflare to verify the result.

4. Purposes and Legal Basis for Processing

Purpose Legal basis (GDPR Art. 6)
Providing the SEO analysis and generating reports Art. 6(1)(b) — performance of a contract
Creating and managing your account, authentication Art. 6(1)(b) — performance of a contract
Reading Google Search Console and Analytics data Art. 6(1)(a) — your consent, given in the Google consent screen and withdrawable at any time
Sending a report by email, when you request it Art. 6(1)(b) — performance of a contract
Delivering the free report to the contact details you gave without an account Art. 6(1)(b) — performance of a contract
Sending commercial information by email Art. 6(1)(a) — your consent, together with the Polish rules on electronic direct marketing; withdrawable at any time
Keeping a record of a marketing consent, including after it is withdrawn Art. 6(1)(f) — legitimate interest in demonstrating that consent was given (GDPR Art. 7(1))
Security, abuse prevention, rate limiting, server logs Art. 6(1)(f) — legitimate interest in protecting the Service
Accounting and tax records, where a paid service is involved Art. 6(1)(c) — legal obligation under Polish law

5. Data Retention

Data category Retention period
Account data (email address) Duration of the account, then deleted on request
Generated SEO reports and their underlying analysis data Kept until you ask us to delete them. Reports are deliberately not auto-expired, because they are revisited to compare a site over time. The Service has no delete button yet: write to our DPO (section 8) and we will delete any report you name.
Google access and refresh tokens Until you disconnect your Google account in the Service, or revoke access in your Google Account settings. Disconnecting deletes them from our database immediately.
Search Console and Analytics data retrieved for a report Stored inside that report, and deleted together with it. A temporary checkpoint used to resume an interrupted analysis may also hold it; checkpoints are deleted automatically about 24 hours after they were last written. The items listed in section 3.6 follow the server log retention below.
Business context for a domain Until it is changed, or deleted at your request. The copy inside a report is deleted with that report.
List of domains analysed by an account Duration of the account; deleted together with it
Contact details given for the free report, and the marketing consent Until you withdraw consent or ask us to delete them. After a withdrawal we keep only the record of the consent and its withdrawal, for as long as claims relating to it may be brought under Polish law.
Server, application and access logs Rotated by size, so older entries are overwritten as new ones arrive; kept no longer than 12 months
Accounting and billing records 5 years, as required by Polish tax law

Deletion is irreversible. Export anything you want to keep before deleting it.

6. Data Sharing and Sub-processors

We do not sell your data. We share it only with the service providers below, and only for the purpose stated next to each:

Sub-processor Purpose Safeguard
OVH SAS (France) Application hosting, report storage, server logs Within the EU
Supabase Database and authentication (accounts, Google tokens, report metadata, contact details and consent records for the free report) Hosted in the EU — eu-west-1, Ireland
Google Ireland / Google LLC Authorising access to your Google account, Search Console API, Analytics Admin and Data APIs, PageSpeed Insights API (the URLs of analysed pages are sent to it) EU SCCs / EU-US Data Privacy Framework
Anthropic PBC (United States) Writing the AI recommendations, only when you enable them. We send the technical findings, the business context for the domain and — if you connected Google — the Search Console and Analytics data for the analysed site, as described in section 3.4. EU SCCs. Under Anthropic's commercial API terms, data sent via the API is not used to train models.
DataForSEO Search visibility data and Google search results used for the competitor comparison, when you enable AI recommendations or competitor analysis. We send the analysed domain and up to 10 keywords, which may come from your Search Console queries (section 3.4) and your target keywords. DataForSEO's data processing agreement (part of its Terms of Service); transfers per section 7
SEOMoz, Inc. — Moz (United States) Backlink and domain authority metrics, when you enable AI recommendations or competitor analysis. Only the analysed domain name is sent. Transfers per section 7
Resend Delivering email: the report summary when you request it, and the free report to the contact details you gave EU SCCs
Cloudflare DNS, bot protection (CAPTCHA) for the public form EU SCCs

We may also disclose data where required by law, court order or a lawful request from a public authority.

7. International Data Transfers

Your data is stored within the European Union: the application server and the generated reports are hosted by OVH in Strasbourg, France, and the database holding accounts, Google tokens and report metadata is hosted by Supabase in Ireland (eu-west-1). Where data is transferred outside the EU/EEA — for example to a US-based sub-processor listed above — we rely on:

You may request a copy of the applicable transfer mechanisms by contacting our DPO.

8. Your Rights, and How to Disconnect Google

Under the GDPR you have the right to:

To exercise any of these, write to dpo@b2bmarketing.ai. We respond within one month. You can withdraw marketing consent the same way, or with the unsubscribe link included in the free report email and in every commercial email we send.

Revoking our access to your Google data

You can cut off our access to Search Console and Analytics in two independent ways:

Revoking access does not delete reports already generated. Ask us if you want those removed too.

9. Data Security

No system is perfectly secure. We cannot guarantee absolute security, but we work to protect your data using measures appropriate to the risk.

10. Data Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Polish supervisory authority within 72 hours of becoming aware of it, and we will inform you without undue delay where the risk to you is high.

11. Complaints and Supervisory Authority

If you believe we process your data unlawfully, you may lodge a complaint with the Polish data protection authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl

You may also bring a claim before the competent court.

12. Children's Privacy

The Service is a professional tool intended for adults. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact our DPO and we will delete it.

13. Third-Party Links

Reports may contain links to the websites you analysed and to third-party documentation. We are not responsible for the privacy practices of those sites.

14. Changes to This Policy

We may update this policy. The date at the top always reflects the current version. Where a change materially affects how we handle your data, we will notify you by email or in the application before it takes effect.

15. Contact Us

For any question about this policy, our data practices, or to exercise your rights:

General inquiries: contact@b2bmarketing.ai
Data Protection Officer: dpo@b2bmarketing.ai
Support: support@b2bmarketing.ai

B2B MARKETING.AI Spółka z o.o.
Ks. Konstantego Budkiewicza 28A
05-091 Ząbki, Poland