| General Data Protection RegulationEffective Date: April 11, 2026 | Last Updated: April 11, 2026 |
SEO Rank Genius is GDPR-compliant by design. The plugin collects only the minimum data needed to provide the service. It does not collect your visitors’ personal data. It does not share your data for advertising. All Google integrations are opt-in, secured with OAuth 2.0, and can be revoked at any time. You can request access, correction, or deletion of your personal data at any time by emailing support@seorankgenius.com. |
1. What is GDPR?
The General Data Protection Regulation (EU) 2016/679 (“GDPR”) is a regulation passed by the European Parliament and Council of the European Union. It has been enforceable since 25 May 2018 and is the world’s most comprehensive data protection law.
GDPR gives individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland strong rights over their personal data and imposes strict obligations on any organisation — regardless of where in the world it is based — that collects, stores, or processes personal data of EU residents.
Personal data under GDPR means any information that can directly or indirectly identify a living natural person. This includes names, email addresses, IP addresses, location data, online identifiers, and any other information that relates to an identifiable individual.
| Key GDPR Principles• Lawfulness, Fairness, and Transparency — data must be processed on a lawful basis and users must be informed• Purpose Limitation — data may only be used for the specific purpose it was collected for• Data Minimisation — collect only what is necessary, nothing more• Accuracy — keep data accurate and up to date• Storage Limitation — do not keep data longer than necessary• Integrity and Confidentiality — protect data against unauthorised access and breaches• Accountability — be able to demonstrate compliance |
2. Who This Page Is For
This GDPR compliance page is written for:
- WordPress site owners and administrators who use the SEO Rank Genius plugin
- Agencies and freelancers who manage WordPress installations for clients
- Users who have purchased a license and created an account with SEO Rank Genius
- Anyone who wants to understand how their personal data is handled when using our Service
If you are a website visitor on a site that happens to use the SEO Rank Genius plugin, please note that the plugin does not collect, process, or transmit your personal data. Your data is handled by the website owner, not by SEO Rank Genius. The plugin sets no cookies on visitors’ browsers and makes no network requests on their behalf.
3. Our Role Under GDPR
Under GDPR, organisations that handle personal data are classified as either a Data Controller, a Data Processor, or both. Understanding our role is important for knowing your rights.
| Role | Definition | Our Position |
|---|---|---|
| Data Controller | Determines the purposes and means of processing personal data | SEO Rank Genius is the Controller for data you provide directly (account registration, license purchase, support communications) |
| Data Processor | Processes personal data on behalf of a Controller, under their instructions | SEO Rank Genius acts as Processor for Google API data (GSC, GA4) that you authorise us to access on your behalf |
| Your Role | As a WordPress site owner, you are the Controller for your own site visitors’ data | The plugin provides tools to help you manage your site’s SEO. You are responsible for your own GDPR compliance with respect to your visitors |
4. Data We Process and Why
4.1 Account and License Data
When you purchase a license or create an account, we collect:
- Name and email address
- Billing address (for invoice purposes)
- Payment information (processed by Freemius — we never see or store card details)
- WordPress site URL (required for license activation and plugin functionality)
Legal basis: Contract performance (Article 6(1)(b) GDPR) — this data is necessary to provide the Service you have purchased.
4.2 Plugin Usage Data
When the plugin is installed and activated, the following data may be sent to our systems:
- WordPress site URL and admin email address
- Plugin version, WordPress version, PHP version, and active theme
- License status and activation information
- Anonymous feature usage statistics (counts only — no content)
Legal basis: Contract performance (Article 6(1)(b)) for licence management; Legitimate interest (Article 6(1)(f)) for anonymised usage analytics to improve the Service.
4.3 Google Search Console Data
If you choose to connect Google Search Console, we access and temporarily cache:
- Search performance data (clicks, impressions, CTR, average position)
- Query data associated with your website
- URL-level performance metrics
- Sitemap status and URL inspection data
- OAuth 2.0 access and refresh tokens (encrypted at rest)
Legal basis: Consent (Article 6(1)(a) GDPR) — you explicitly authorise this access via Google’s OAuth 2.0 flow. You can withdraw consent at any time.
4.4 Google Analytics 4 Data
If you choose to connect Google Analytics 4, we access and temporarily cache:
- Website traffic metrics (sessions, users, pageviews)
- Engagement data (bounce rate, session duration, pages per session)
- Traffic source data (organic, direct, referral)
- Page-level performance data
- OAuth 2.0 access and refresh tokens (encrypted at rest)
Legal basis: Consent (Article 6(1)(a) GDPR) — you explicitly authorise this access via Google’s OAuth 2.0 flow. You can withdraw consent at any time.
4.5 AI Feature Processing Data
When you use AI-powered features, the following is sent to our cloud (api.seorankgenius.com) for processing:
- Post title, excerpt, and a limited content snippet (typically under 800 characters)
- Focus keywords and content structure metadata
- Site name and language/locale setting
This data is processed in real time and is NOT retained after the response is generated. It is not used for any purpose other than generating the requested AI output.
Legal basis: Contract performance (Article 6(1)(b)) — necessary to provide the AI feature you have activated.
4.6 Support Communications
When you contact us via email or support ticket, we retain the contents of those communications for up to 2 years for quality assurance purposes.
Legal basis: Legitimate interest (Article 6(1)(f)) — to maintain service quality and resolve disputes.
5. Data We Do NOT Collect
| The following is explicitly NOT collected by SEO Rank Genius:✔ The personal data of your website visitors✔ The content of your posts, pages, or custom post types (beyond the small snippets sent for AI features)✔ Credit card details or full payment information✔ Passwords — authentication is handled by WordPress and OAuth providers✔ Precise geolocation data✔ Biometric data or any special category data under Article 9 GDPR✔ Data for advertising, profiling, or marketing to third parties |
6. Data Retention
| Data Type | Retention Period | Notes |
|---|---|---|
| Account and licence data | Active licence period + 90 days after cancellation | Deleted upon written request |
| Google Search Console data | Maximum 6 hours (cached) | Permanently deleted upon disconnection |
| Google Analytics 4 data | Maximum 6 hours (cached) | Permanently deleted upon disconnection |
| OAuth tokens (GSC and GA4) | Until you disconnect the integration | Encrypted at rest, deleted immediately on disconnect |
| AI processing data | Not retained | Processed in real time, discarded after response |
| Support communications | Up to 2 years from last communication | Retained for quality assurance |
| WordPress site data (plugin settings, SEO meta) | On your own server only | Removed when you uninstall the plugin |
| Anonymous usage statistics | Up to 3 years in aggregated form | No personal identifiers retained |
7. Your Rights Under GDPR
If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights under GDPR. We take these rights seriously and will act on your request without undue delay and within 30 days.
| Your Right | What It Means | How to Exercise It |
|---|---|---|
| Right of Access (Art. 15) | Request a copy of all personal data we hold about you, including what it is, why we have it, and how long we will keep it. | Email support@seorankgenius.com with subject: “GDPR Access Request” |
| Right to Rectification (Art. 16) | Request correction of any inaccurate or incomplete personal data. | Email us with the specific corrections needed |
| Right to Erasure (Art. 17) | Request deletion of your personal data (“right to be forgotten”). Applies unless we have a legal obligation to retain it. | Email support@seorankgenius.com with subject: “GDPR Erasure Request” |
| Right to Restrict Processing (Art. 18) | Request that we pause processing your data while a dispute is resolved or erasure is being considered. | Email us explaining the restriction you require |
| Right to Data Portability (Art. 20) | Request your data in a structured, machine-readable format (e.g. JSON or CSV) so you can transfer it to another service. | Email us requesting a data export |
| Right to Object (Art. 21) | Object to processing based on legitimate interest. We will stop unless we have compelling legitimate grounds that override your interests. | Email us explaining your objection |
| Right to Withdraw Consent (Art. 7(3)) | Where processing is based on consent (Google integrations), you can withdraw at any time. Withdrawal does not affect prior lawful processing. | Disconnect the integration inside the plugin settings, or email us |
| Right not to be Subject to Automated Decisions (Art. 22) | We do not make any automated decisions with legal or significant effects based on your personal data. | N/A — we do not engage in this activity |
To exercise any of the above rights, please email support@seorankgenius.com. We will confirm receipt within 5 business days and respond fully within 30 days. If your request is complex, we may extend by up to a further 60 days, but will inform you of this extension.
We will never charge a fee for exercising your rights unless the request is manifestly unfounded or excessive.
8. Google API Services and Limited Use
| Google API Services User Data Policy ComplianceSEO Rank Genius’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Visit: https://developers.google.com/terms/api-services-user-data-policy |
8.1 What Google Limited Use Means
The Google API Limited Use policy restricts how applications may use data obtained through Google APIs. SEO Rank Genius complies fully with all Limited Use requirements:
| Requirement | Status | Detail |
|---|---|---|
| Only use data to provide or improve the user-facing features of the app | ✔ Compliant | Data used only to display your SEO/analytics data inside WordPress |
| Do not transfer data to others unless necessary for the service | ✔ Compliant | Data is never shared with third parties |
| Do not use data for serving advertisements | ✔ Compliant | We have no advertising products whatsoever |
| Do not allow humans to read Google user data without consent | ✔ Compliant | Support staff cannot access your Google data |
| Do not use data to train generalised AI or ML models | ✔ Compliant | Google data is never used for model training |
| Do not sell or transfer data to data brokers or advertisers | ✔ Compliant | We do not sell any user data to any third party |
8.2 Revoking Google Access
You can disconnect Google Search Console and/or Google Analytics 4 from SEO Rank Genius at any time:
- Inside the plugin: Navigate to SEO Rank Genius → Settings → Integrations and click “Disconnect”
- Via Google: Visit https://myaccount.google.com/permissions to view and revoke all app access
When you disconnect, all cached Google data and OAuth tokens are immediately and permanently deleted from our systems.
9. Sub-Processors
SEO Rank Genius uses the following third-party sub-processors that may handle your personal data. All sub-processors are bound by data processing agreements consistent with GDPR requirements.
| Sub-Processor | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Freemius, Inc. | Licence management and payment processing | Name, email, billing address, site URL | freemius.com/privacy |
| Google LLC | OAuth authentication (GSC, GA4) | OAuth tokens only; data accessed via API under your authorisation | policies.google.com/privacy |
| Cloud Infrastructure Provider | Hosting for api.seorankgenius.com | Encrypted OAuth tokens, transient AI processing data | Disclosed upon request |
We will update this list if we add new sub-processors. We will notify you of significant changes through the plugin’s admin interface or via email.
10. Data Transfers Outside the EEA
Some of our sub-processors (including Freemius and Google) are based in or transfer data to the United States and other countries outside the EEA. GDPR requires that such transfers have appropriate safeguards in place.
We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Ensuring sub-processors maintain equivalent data protection standards
- Freemius participates in the EU-US Data Privacy Framework
- Google maintains EU-US Standard Contractual Clauses for API data transfers
You can request information about the specific safeguards in place for international data transfers by emailing support@seorankgenius.com.
11. Do You Need a Data Processing Agreement (DPA)?
| Short answer: No, you do not need a DPA to use SEO Rank Genius.The SEO Rank Genius plugin does not access, process, or store the personal data of your website visitors. It only processes your own account data (as described in Section 4) and the Google API data that you explicitly authorise. Since we are not acting as a data processor on your behalf for your visitors’ data, a formal DPA between you and SEO Rank Genius is not required under GDPR. |
However, if your organisation requires a DPA for compliance documentation purposes (e.g. for enterprise procurement or legal review), we are happy to provide one. Please contact support@seorankgenius.com to request a Data Processing Agreement.
12. Security Measures
We implement technical and organisational security measures to protect your personal data in accordance with Article 32 GDPR:
| Measure | Detail |
|---|---|
| Encryption in transit | All data transmission uses HTTPS/TLS 1.2 or higher. API requests are signed with HMAC-SHA256. |
| Encryption at rest | OAuth tokens stored on our cloud server are encrypted at rest. |
| Access controls | Access to user data on our servers is restricted to essential automated systems only. No manual staff access to your personal data. |
| Minimal data storage | We do not store data beyond what is necessary. AI processing data is discarded immediately after use. |
| Regular updates | Our cloud infrastructure receives regular security patches and updates. |
| WordPress standards | The plugin is built to WordPress coding standards, avoiding common vulnerabilities such as SQL injection and XSS. |
12.1 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware, as required by Article 33 GDPR
- Notify affected users without undue delay where the breach is likely to result in high risk, as required by Article 34 GDPR
- Document all breaches, including those not requiring notification, in our internal breach register
13. GDPR and Your Own WordPress Site
As a WordPress site owner using SEO Rank Genius, you are an independent Data Controller for your own website visitors’ data. This means you are responsible for your own GDPR compliance. SEO Rank Genius helps you in the following ways:
| Area | How SEO Rank Genius Helps |
|---|---|
| No visitor tracking | The plugin adds zero tracking scripts to your website frontend. Your visitors’ personal data is not processed by SEO Rank Genius. |
| No frontend cookies | The plugin sets no cookies on your visitors’ browsers, eliminating a common source of GDPR consent complexity. |
| Optional link click tracking | If you enable this feature, it uses aggregate counts only — no personal data, no cookies, no cross-page tracking. |
| Schema markup | Structured data generated by the plugin does not involve personal data. |
| robots.txt and llms.txt | Tools to control what crawlers (including AI crawlers) can access on your site. |
| Privacy-first architecture | Built with GDPR compliance in mind from the ground up — not added as an afterthought. |
Please note: SEO Rank Genius cannot be held responsible for your overall website’s GDPR compliance. You remain responsible for any other plugins, scripts, or services you use on your WordPress site that may collect visitor data.
14. Supervisory Authorities
You have the right to lodge a complaint with a data protection supervisory authority at any time. We ask that you contact us first so we can attempt to resolve your concern directly, but this does not affect your right to complain to a supervisory authority.
| Authority | Jurisdiction | Contact |
|---|---|---|
| ICO (UK) | United Kingdom | ico.org.uk |
| CNIL (France) | France | cnil.fr |
| BfDI (Germany) | Germany | bfdi.bund.de |
| DPC (Ireland) | Ireland | dataprotection.ie |
| AEPD (Spain) | Spain | aepd.es |
| Garante (Italy) | Italy | garanteprivacy.it |
| Your national authority | Any EEA member state | edpb.europa.eu/about-edpb/board/members |
15. Changes to This GDPR Page
We will update this GDPR compliance page if our data practices change or if new legal requirements apply. For material changes, we will notify you via the plugin’s admin dashboard or by email. The “Last Updated” date at the top of this page reflects the most recent revision.
16. Contact Us
For any GDPR-related enquiry, rights request, or complaint, please contact us:
| SEO Rank Genius — Data Privacy Contact Owner / Data Controller: Muhammad Irfan Email: support@seorankgenius.com Subject line for rights requests: “GDPR Request — [Type]” (e.g. GDPR Request — Access) Website: https://seorankgenius.com Response time: Acknowledgement within 5 business days. Full response within 30 days as required by GDPR Article 12. |
| This GDPR compliance page was last updated on April 11, 2026. Version 1.0. |