Legal

Privacy Policy

Last updated: May 28, 2026

This Privacy Policy explains how Holiander, Inc. ("we", "us", or "our") collects, uses, and shares information when you use the SEODex service. By using SEODex you consent to the practices described here.

1. Information we collect

Information you provide

  • Account information: name, email address, password (hashed), and any agency name, contact email, or branding fields you supply.
  • Prospect data: URLs, business names, locations, keywords, and any notes you enter for sales prospects.
  • Communications: support requests and any messages you send us.
  • Billing information: handled directly by our payment processor (Stripe). We never see or store your full card number.

Information collected automatically

  • Server logs: IP address, browser type, pages visited, timestamps, referrer URLs.
  • Cookies & session storage: a session cookie to keep you signed in; a CSRF token for security; we do not use third-party advertising or tracking cookies.
  • Usage events: actions you take in the app (dossier created, exported, prospect moved between pipeline stages) so we can support you and improve the product.

2. How we use information

  • To deliver and operate the SEODex service;
  • To process payments and manage subscriptions;
  • To send transactional emails (verification, password resets, billing receipts, service notices);
  • To provide customer support;
  • To detect, prevent, and address fraud, abuse, and security incidents;
  • To comply with legal obligations;
  • To improve and develop new features (using aggregated, non-identifying patterns).

We do not sell your personal information. We do not use your prospect data to train AI models for the benefit of other customers.

3. Third-party processors

We use the following service providers to deliver functionality. Each is bound by its own data agreement and we share only what's necessary to perform the service.

Service Purpose Data shared
Stripe Billing & subscriptions Email, billing details
Mailjet Transactional email Email, recipient name, message content
DataForSEO SEO data (rankings, GBP, on-page audit) Prospect URLs, keywords, locations
OpenAI AI Visibility probes (ChatGPT) Generated prompts referencing the prospect's category and location
Google Gemini AI Visibility probes Generated prompts referencing the prospect's category and location
Anthropic Claude Pitch summary generation Aggregated dossier data for the prospect
Browserless (self-hosted) PDF rendering Dossier content during export only; not stored externally

We may share information with these processors in their respective regions (typically the United States and European Union). Each processor has been selected for its security posture and data-handling practices.

4. International transfers

Holiander, Inc. operates SEODex from the United States and our servers are located there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the U.S. We rely on standard contractual clauses or equivalent safeguards where applicable.

5. Data retention

We retain account data for as long as your account is active. Dossier outputs are retained while you are a customer plus 30 days after account closure to allow recovery. Server logs are retained for up to 90 days. You may request earlier deletion of your data at any time (see "Your rights" below).

6. Security

We use industry-standard technical and organizational measures to protect your data: encrypted transport (HTTPS), encrypted credentials at rest, hashed passwords, role-based access controls, and audit logging. No system is perfectly secure; if you suspect your account has been compromised, contact us immediately at support@seodex.com.

7. Your rights

Depending on where you live, you may have the following rights regarding your personal information:

  • Access: request a copy of the personal data we hold about you.
  • Correction: ask us to correct inaccurate or incomplete data.
  • Deletion: request deletion of your account and associated data.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to certain processing.
  • Withdrawal of consent: where we rely on consent, withdraw it at any time.

To exercise any of these rights, email support@seodex.com from the email address on your account. We will respond within 30 days.

For California residents (CCPA / CPRA)

You have the right to know what personal information we collect, to request deletion, and to opt out of sale or sharing of personal information. We do not sell your personal information. To make a request, email support@seodex.com.

For EU/UK/Swiss residents (GDPR / UK GDPR / Swiss DPA)

The legal bases on which we process your personal data are: (a) performance of a contract with you, (b) compliance with our legal obligations, and (c) our legitimate business interests in operating, improving, and securing the Service. You also have the right to lodge a complaint with your local data-protection authority.

8. Children

SEODex is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

9. Changes to this policy

We may update this policy from time to time. If we make material changes we'll notify you by email or in-product notice at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

10. Contact

Privacy requests, support, and general questions: support@seodex.com