Privacy Policy

We are committed to protecting your privacy and personal data.

🔒 Last updated: November 30, 2025

1

Introduction

This Privacy Policy explains how ZII Ltd ("we", "us", or "our") collects, uses, discloses, and safeguards your information when you use our AutoSEO service and website.

Data Controller: ZII Ltd is a company registered in England and Wales (Company Number: [PENDING]). Our registered office is located at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

We are committed to protecting your privacy and complying with applicable data protection laws, including the UK GDPR (General Data Protection Regulation) and the Data Protection Act 2018.

Your Rights Under UK GDPR:

This Policy explains your rights regarding your personal data and how we process it. If you have any questions, please contact our Data Protection Officer at [email protected].

2

Information We Collect

2.1 Personal Information

We collect the following personal information:

  • Email addresses: Used for account creation, communication, and service delivery
  • Business URLs: Website addresses provided for SEO analysis and content generation
  • Account information: Name, registration details, and subscription preferences
  • Payment information: Processed securely through Stripe (we do not store payment card details)

2.2 Usage Data

We automatically collect certain information when you use our Service:

  • IP address and location information
  • Browser type and version
  • Pages visited and time spent on our site
  • Device information and screen resolution
  • Referral sources and click patterns
3

How We Use Your Information

3.1 Purposes and Legal Basis

We process your personal data for the following purposes and on the following legal bases:

📋 To Provide and Maintain Our Service

Legal Basis: Contract Performance (Article 6(1)(b) UK GDPR)

This includes generating AI content, publishing to WordPress, managing your account, and providing customer support.

đŸ’ŗ To Process Payments and Manage Subscriptions

Legal Basis: Contract Performance (Article 6(1)(b) UK GDPR)

We process payment information through Stripe to fulfill our contractual obligations.

📧 To Communicate About Your Account and Services

Legal Basis: Contract Performance (Article 6(1)(b) UK GDPR) and Legitimate Interests (Article 6(1)(f) UK GDPR)

We send service updates, billing notifications, and respond to your inquiries.

📊 To Analyze and Improve Our Service

Legal Basis: Legitimate Interests (Article 6(1)(f) UK GDPR)

We have a legitimate interest in understanding how users interact with our Service to improve functionality and user experience.

đŸŽ¯ Marketing Communications (Optional)

Legal Basis: Consent (Article 6(1)(a) UK GDPR)

We only send marketing emails if you have explicitly opted in. You can withdraw consent anytime by clicking "unsubscribe" in any email.

âš–ī¸ To Comply with Legal Obligations

Legal Basis: Legal Obligation (Article 6(1)(c) UK GDPR)

We process data where required by law, including tax and accounting requirements.

3.2 AI Content Generation

When we generate content for you using AI services, we process your website URL and business information. This processing is necessary to perform our contract with you and is done on the legal basis of contract performance.

Note: AI-generated content is owned by you. We retain copies only for service delivery and improvement purposes as described in our Terms and Conditions.

4

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and analyze usage patterns. Specifically, we use:

📊

Our Tracking Tools

We use three main analytics tools to improve your experience

4.1 Google Analytics

🌐 Global Analytics Platform

We use Google Analytics to understand how visitors interact with our website. This helps us improve our service and user experience.

Google Analytics collects information about:

  • Pages visited
  • Time spent on pages
  • Traffic sources
  • User demographics and interests

4.2 Matomo (formerly Piwik)

🔒 Privacy-First Analytics

We use Matomo for website analytics and user behavior tracking. Unlike Google Analytics, Matomo is hosted on our own servers, giving us greater control over your data.

Matomo helps us understand:

  • User journeys through our website
  • Popular content and features
  • Conversion funnels and user flows

4.3 Mouseflow

👆 User Experience Insights

We use Mouseflow to record and analyze user interactions on our website.

This includes:

  • Mouse movements and clicks
  • Scrolling behavior
  • Heatmaps of user engagement
  • Session recordings (anonymized)
✅

Your Privacy Controls and Cookie Consent

Important: We will ask for your consent before activating non-essential tracking technologies like Mouseflow.

You can:

  • Manage your cookie preferences through our cookie consent banner
  • Adjust your browser settings to block or delete cookies
  • Contact us at [email protected] to opt out of tracking
  • Use browser privacy features or extensions to limit tracking
âš ī¸

Session Recording Notice (Mouseflow)

Mouseflow records user sessions including mouse movements, clicks, scrolling, and pages visited. This data helps us understand how users interact with our website.

What Mouseflow Does NOT Record:

  • Mouseflow is configured to exclude sensitive form fields (passwords, payment details)
  • Personal information entered in protected fields is masked

You can opt out: We will only activate Mouseflow if you consent through our cookie banner, and you can withdraw consent anytime.

4.4 Essential vs Non-Essential Cookies

Essential Cookies (No Consent Required):

  • Authentication cookies to keep you logged in
  • Security cookies to protect against fraud
  • Session cookies for basic website functionality

Non-Essential Cookies (Require Consent):

  • Google Analytics for website performance analysis
  • Matomo for user behavior tracking
  • Mouseflow for session recordings and heatmaps
5

Data Sharing and Third-Party Processors

🔒 We Never Sell Your Data

We do not sell, trade, rent, or otherwise transfer your personal information to third parties for their marketing purposes.

5.1 Third-Party Service Providers (Data Processors)

We share your data with the following trusted third-party service providers who assist us in operating our Service. These providers act as data processors under UK GDPR and are contractually bound to protect your data:

🤖 AI Content Generation

Providers: OpenAI (ChatGPT API) and Anthropic (Claude API)

Data Shared: Website URL, business information, content generation requests

Purpose: Generate SEO-optimized content for your website

Location: USA - Data may be processed outside UK/EEA (see Section 9 on International Transfers)

đŸ’ŗ Payment Processing

Provider: Stripe, Inc.

Data Shared: Email, name, payment card details (directly to Stripe), billing address

Purpose: Process subscription payments and manage billing

Note: We never store your payment card details - they go directly to Stripe's secure servers

Location: USA - Stripe maintains UK GDPR-compliant data processing agreements

📊 Analytics Services

Providers: Google Analytics, Matomo (self-hosted)

Data Shared: IP address (anonymized), pages visited, browser info, device info

Purpose: Understand website usage and improve user experience

Location: Google Analytics (USA), Matomo (UK - self-hosted)

👆 Session Recording

Provider: Mouseflow

Data Shared: Mouse movements, clicks, scrolling behavior, page navigation (sensitive fields masked)

Purpose: Understand user interaction patterns to improve website design

Legal Basis: Consent (only activated if you consent via cookie banner)

Location: Denmark/EU - GDPR compliant

5.2 Legal Requirements

We may disclose your personal information if required to do so by law or in response to:

  • Valid legal requests from law enforcement or regulatory authorities
  • Court orders or legal proceedings
  • Protection of our legal rights, property, or safety
  • Prevention of fraud, security threats, or illegal activity

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the acquiring entity. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS encryption for data transmission
  • Secure data storage with access controls
  • Regular security audits and updates
  • Employee training on data protection
7

Data Retention

We retain your personal information only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are:

👤 Account Information

Retention Period: While your account is active + 30 days after account closure

After 30 days, account data is permanently deleted unless retention is required by law (e.g., tax, accounting, or legal requirements which may extend retention to 7 years)

📝 Generated Content

Retention Period: While your account is active + 90 days after account closure

You own the generated content. After account closure, we retain a copy for 90 days to allow reactivation, then permanently delete unless you request earlier deletion

đŸ’ŗ Payment and Billing Information

Retention Period: Handled by Stripe - we do not store payment card details

Billing Records: 7 years (required by UK tax law)

We retain transaction records, invoices, and billing addresses as required by HMRC regulations

📊 Analytics and Cookie Data

Google Analytics: 26 months (configured setting)

Matomo: 24 months

Mouseflow: 6 months

After these periods, data is automatically deleted or aggregated and anonymized

📧 Communication Records

Retention Period: 3 years from last communication

Includes customer support tickets, emails, and chat logs to maintain service quality and resolve disputes

🔍 Logs and Security Data

Retention Period: 90 days

Server logs, security logs, and access logs retained for security and fraud prevention purposes

âš–ī¸

Legal Hold Exception

If we receive a legal request, are involved in litigation, or have reason to believe data relates to illegal activity, we may retain data beyond normal retention periods as required or permitted by law.

đŸ—‘ī¸

Request Early Deletion

You can request deletion of your data at any time by contacting us at [email protected]. We will comply with your request within 30 days, subject to legal retention requirements.

8. Your Rights

Under applicable data protection laws, you have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal information
  • Restriction: Request limitation of processing in certain circumstances
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing based on legitimate interests
9

International Data Transfers

🌍 Where Your Data Is Stored

As a UK-based company, your data is primarily stored and processed within the United Kingdom. However, some of our service providers operate in other countries, including outside the UK and European Economic Area (EEA).

We ensure appropriate safeguards are in place when data is transferred internationally, as required by UK GDPR.

9.1 Transfers to the United States

Some of our key service providers are located in the United States:

🤖 OpenAI and Anthropic (AI Content Generation)

Safeguards:

  • Standard Contractual Clauses (SCCs) approved by UK authorities
  • Data Processing Agreements (DPAs) in place
  • Both providers maintain compliance programs for international data transfers

đŸ’ŗ Stripe (Payment Processing)

Safeguards:

  • Standard Contractual Clauses (SCCs)
  • Stripe is certified under major privacy frameworks
  • PCI DSS Level 1 certified for payment security

📊 Google Analytics

Safeguards:

  • IP anonymization enabled
  • Google's EU-US data transfer framework compliance
  • Data Processing Amendment to Google Ads terms

9.2 Transfers Within EEA

👆 Mouseflow (Denmark)

Location: Denmark (within EEA)

Safeguards: No additional safeguards required - Denmark is subject to UK GDPR adequacy decision (EEA country)

9.3 Your Rights Regarding International Transfers

You have the right to:

  • Request information about the safeguards we have in place for international transfers
  • Request copies of Standard Contractual Clauses
  • Object to transfers to specific countries if you have concerns

To exercise these rights or for more information, contact our Data Protection Officer at [email protected]

â„šī¸

Important Note on US Data Transfers

Following the Schrems II decision, we rely on Standard Contractual Clauses and additional safeguards for transfers to the United States. We regularly review and update our data transfer mechanisms to ensure compliance with evolving UK and EU data protection requirements.

10. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

13. Complaints

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK data protection regulator. You can contact the ICO at:


📞

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: [email protected]
  • Company Name: ZII Ltd
  • Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
  • Company Number: [PENDING]
  • Data Protection Officer: [email protected]
âš–ī¸

Complaints

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK data protection regulator.

ICO Contact:

Website: ico.org.uk

Phone: 0303 123 1113

Email: [email protected]

🔒 This Privacy Policy was last updated on November 30, 2025.