Privacy Policy
Last updated: May 28, 2026
This Privacy Policy explains how Holiander, Inc. ("we", "us", or "our") collects, uses, and shares information when you use the SEODex service. By using SEODex you consent to the practices described here.
1. Information we collect
Information you provide
- Account information: name, email address, password (hashed), and any agency name, contact email, or branding fields you supply.
- Prospect data: URLs, business names, locations, keywords, and any notes you enter for sales prospects.
- Communications: support requests and any messages you send us.
- Billing information: handled directly by our payment processor (Stripe). We never see or store your full card number.
Information collected automatically
- Server logs: IP address, browser type, pages visited, timestamps, referrer URLs.
- Cookies & session storage: a session cookie to keep you signed in; a CSRF token for security; we do not use third-party advertising or tracking cookies.
- Usage events: actions you take in the app (dossier created, exported, prospect moved between pipeline stages) so we can support you and improve the product.
2. How we use information
- To deliver and operate the SEODex service;
- To process payments and manage subscriptions;
- To send transactional emails (verification, password resets, billing receipts, service notices);
- To provide customer support;
- To detect, prevent, and address fraud, abuse, and security incidents;
- To comply with legal obligations;
- To improve and develop new features (using aggregated, non-identifying patterns).
We do not sell your personal information. We do not use your prospect data to train AI models for the benefit of other customers.
3. Third-party processors
We use the following service providers to deliver functionality. Each is bound by its own data agreement and we share only what's necessary to perform the service.
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Billing & subscriptions | Email, billing details |
| Mailjet | Transactional email | Email, recipient name, message content |
| DataForSEO | SEO data (rankings, GBP, on-page audit) | Prospect URLs, keywords, locations |
| OpenAI | AI Visibility probes (ChatGPT) | Generated prompts referencing the prospect's category and location |
| Google Gemini | AI Visibility probes | Generated prompts referencing the prospect's category and location |
| Anthropic Claude | Pitch summary generation | Aggregated dossier data for the prospect |
| Browserless (self-hosted) | PDF rendering | Dossier content during export only; not stored externally |
We may share information with these processors in their respective regions (typically the United States and European Union). Each processor has been selected for its security posture and data-handling practices.
4. International transfers
Holiander, Inc. operates SEODex from the United States and our servers are located there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the U.S. We rely on standard contractual clauses or equivalent safeguards where applicable.
5. Data retention
We retain account data for as long as your account is active. Dossier outputs are retained while you are a customer plus 30 days after account closure to allow recovery. Server logs are retained for up to 90 days. You may request earlier deletion of your data at any time (see "Your rights" below).
6. Security
We use industry-standard technical and organizational measures to protect your data: encrypted transport (HTTPS), encrypted credentials at rest, hashed passwords, role-based access controls, and audit logging. No system is perfectly secure; if you suspect your account has been compromised, contact us immediately at support@seodex.com.
7. Your rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: request deletion of your account and associated data.
- Portability: receive your data in a machine-readable format.
- Objection: object to certain processing.
- Withdrawal of consent: where we rely on consent, withdraw it at any time.
To exercise any of these rights, email support@seodex.com from the email address on your account. We will respond within 30 days.
For California residents (CCPA / CPRA)
You have the right to know what personal information we collect, to request deletion, and to opt out of sale or sharing of personal information. We do not sell your personal information. To make a request, email support@seodex.com.
For EU/UK/Swiss residents (GDPR / UK GDPR / Swiss DPA)
The legal bases on which we process your personal data are: (a) performance of a contract with you, (b) compliance with our legal obligations, and (c) our legitimate business interests in operating, improving, and securing the Service. You also have the right to lodge a complaint with your local data-protection authority.
8. Children
SEODex is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. If we make material changes we'll notify you by email or in-product notice at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
10. Contact
Privacy requests, support, and general questions: support@seodex.com