EN
Language · same page NLNederlands/privacy/ ENEnglish (UK)/en/privacy/ ESEspañol/es/privacidad/ We do not remember your choice and never redirect you automatically.
DOC.P1 · privacy statement version August 2026

Privacy: what we process, and why

This statement describes what actually happens to your data when you visit this site, use one of our free tools or work with us. No legal wallpaper, and nothing we do not do.

Ask your privacy question See the sub-processors measuring without cookies · no Google Analytics · no advertising pixels
DOC.P1z · Which law

Which law you are reading about

This is not a translation of our Dutch privacy statement, and it should not be. The facts about what we process are identical. The law is not. The United Kingdom left the General Data Protection Regulation behind and runs the UK GDPR alongside the Data Protection Act 2018, with the Information Commissioner's Office as its regulator and PECR rather than a Dutch telecoms act for anything stored on your device. Ireland is in the European Union and stays under the GDPR itself, with the Data Protection Commission. A single English text that pretended those two were one market would be wrong in one of them.

TheSEO is established in the Netherlands, which means our lead supervisory authority is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. That does not take away your own route. If you are in the United Kingdom you may complain to the ICO; if you are in Ireland you may complain to the Data Protection Commission. Both routes are set out at the bottom of this page, and neither replaces the other.

Article numbers in the tables below are given as "Article 6(1)(b)" and so on. The UK GDPR keeps the same numbering as the GDPR, so those references read the same in both. Where the two genuinely differ, we say which one we mean.

# OPEN POINT, STATED RATHER THAN GLOSSED OVER
Article 27 UK GDPR can require an organisation outside the United Kingdom that offers goods or services to people there to appoint a representative in the United Kingdom. Whether that applies to us, and whether an exemption fits, is a decision for the business and a question for a lawyer, and it has not been settled. Until it is, this page does not claim that we comply with the UK GDPR, and no form on this site is aimed specifically at visitors in the United Kingdom. What we can say is what we actually do, and that is the rest of this page. Source: ICO guidance for organisations outside the UK and ICO, who does the UK GDPR apply to.
FIG.P1J · which law and which regulator applies where you aresheet 1/1 · the three jurisdictions this one document covers
jurisdictions.doc one statement · three routes · one lead authority
Netherlands · where we sit
LawThe GDPR itself, as it applies in the European Union.
RegulatorAutoriteit Persoonsgegevens, the Dutch Data Protection Authority. This is our lead supervisory authority, because TheSEO is established in the Netherlands.
ReadingThe whole of this page applies to you as written.
United Kingdom · a separate regime
LawThe UK GDPR alongside the Data Protection Act 2018, with PECR rather than a Dutch telecoms act for anything stored on your device.
RegulatorInformation Commissioner's Office. You may complain to the ICO, and that route does not replace the Dutch one.
ReadingThe facts on this page are the same; the law around them is not. The open point on Article 27 above is stated and not yet settled.
Ireland · inside the Union
LawThe GDPR, because Ireland stayed in the European Union.
RegulatorData Protection Commission. You may complain there, and again alongside rather than instead of the Dutch route.
ReadingRead the article references below as GDPR references; they need no translation.

# Why one page and not three. What we process is identical in all three columns. Only the law and the regulator differ, so splitting the facts across three documents would create three chances to say something different about the same thing.
# Article numbering is shared: the UK GDPR keeps the numbering of the GDPR, so "Article 6(1)(b)" reads the same in every column. Where the two genuinely differ, the text says which one it means.

DOC.P1a · Controller

Who is responsible

TheSEO decides why and how the data on this site is used. In the law that is called the controller. You can come to us with any question about it.

This statement covers the whole organisation and therefore the software we build as well. If you use Jarvis, read where to look in this statement when you use Jarvis alongside it. That page points the way and does not replace the text below.

CompanyMansotti. TheSEO is a trading name of Mansotti
Company registrationDutch Chamber of Commerce (KVK) 77834453. We are not registered with Companies House and we are not registered in Spain, and we will not suggest otherwise
Registered addressAlbert Plesmanring 9, 3712 DA Huis ter Heide, the Netherlands
Emailsales@theseo.nl
VAT numberDutch VAT number NL003245282B11
Telephone+31 6 29 91 97 56

Where something has not been settled yet, this page says so in as many words. We do not fill in a period or a safeguard we cannot deliver, and a point like that stays named as open until it is fixed.

We have no separate data protection officer. Privacy questions come straight to the email address above.

DOC.P1b · Measuring

What we measure, and what does not happen

We measure how this site is used with Microsoft Clarity, deliberately in its cookieless mode. Before the script loads we give Clarity the fixed signal that there is no consent for cookies. Clarity then places nothing on your device and cannot recognise you or follow you from page to page: every page view counts as a separate session.

Microsoft sees which pages are looked at, where people click and scroll, how the mouse moves, and technical data such as browser, device and country. What you type into input fields is masked by Clarity in every mode and is not sent to Microsoft. Beyond that there is no analytics software on this site: no Google Analytics, no advertising pixels from Google, Meta or LinkedIn, and no remarketing.

The site itself sets no cookies. Our hosting provider may set a technical cookie to keep out bot traffic and attacks. That one serves security and is not used to recognise or follow you.

Two things are stored in your browser, both on the MyParcel Dashboard pages and both because you chose something yourself:

  • If you select a parcel on the MyParcel Dashboard start page, your browser remembers that choice in session storage, under the key mp-plan. Close the tab and it is gone.
  • If you change the display in the demo of that dashboard, such as theme, density or which columns you see, your browser remembers that in local storage, under the key myparcel-dashboard-preview-preferences. That stays until you clear your browser storage.

Both stay on your own device. They do not come to us and they do not go to anyone else, and they are not used to recognise or follow you.

Why there is no cookie banner, and why that is not laziness

In the United Kingdom, storing information on your device or reading information already stored there needs your consent under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. The same regulation exempts storage that is strictly necessary to provide a service you have explicitly asked for.

That is exactly the position here. Clarity stores nothing. The two keys above exist only because you asked for a setting to be remembered. A banner asking your permission for something that is not happening would not be extra care, it would be a false statement dressed as caution. So there is none, and the full list of what is stored is on the cookie page.

The fonts come from our own server. They used to be fetched directly from Google; since that clean-up your browser makes no connection to Google for them.

DOC.P1c · Data

Which data we process

What you leave behind yourself

  • If you get in touch or ask for a manual scan, we process your name, email address, telephone number, the address of your website and the content of your message.
  • If you use one of the free tools, we process what you enter in that form: company name, trade and town, and for the review tool also the review text, the name of the reviewer and the number of stars. Your email address is optional there.
  • If you have a website scanned, we process the web address you enter.
  • If you use a tool on this site, we record where that use came from: which page of this site the form was on, which site sent you to us if you clicked a link, the campaign code that was in the web address if you arrived through an advert or campaign link, and the time. This is stated at every tool where it happens. Of the referring site we keep only the domain plus the path; everything that followed in the query string is dropped in your own browser and never reaches our server. This does not follow you across other sites: we see only this one step towards us, and only because your browser sends it.
  • What you enter and what the tool gave back are kept in our own database. That holds for every tool on this site. Along with it goes the type of device you used the tool on, derived from what your browser sends: mobile, tablet or desktop, no more than that. We keep no IP address with that record and we set nothing in your browser for it.
  • From that data we work out which of our services would suit you best, with the reason for each point. That is an aid to a conversation and not a decision about you: nothing is automatically refused, granted or priced, and a person looks at it before anything is done with it. If you want to know what it says about you, or want it deleted, the section on your rights below applies as normal.

What comes along automatically

On every visit our hosting provider sees your IP address, your browser and device, which page you request and at what moment. That is needed to send the page to you and to keep out abuse. That data arises from delivering the page itself; we do not link it to a profile and we do not use it to recognise you.

The watermark in the skill downloads

Every skill you download here has two lines at the top of the SKILL.md file: a visible line saying the skill comes from theseo.nl and is free under the MIT licence, and a comment line with a release id in the form tsk-year-month-day-code. That id belongs to that release of the zip and not to you: everyone who downloads the same version gets the same id.

So nothing about you is recorded on a download, no account is needed, and there is no code in the skill that sends anything back to us. The id is there so that a skill turning up somewhere can be traced to us and to the version that was here. If you want to remove those two lines, you may.

If you download one of our WordPress plugins

On tools and plugins there are eight plugins you can download without an account. We ask for nothing at the download: no name, no email address, no form. What happens is the same as on any other page, namely the line our hosting provider writes in its log because it is sending you a file. There is no counter in the zip file and there is no code in it that sends anything back to us.

After that the software sits on your server and we are no longer a party to it. Six of the eight make no outbound request at all: the heatmap and scrollmap and the Core Web Vitals plugin write only to your own database, the AI crawler log writes only what arrived at your own server, and the llms.txt generator, the local schema and the AI transparency label keep only what you enter yourself. So we cannot see that you have installed one of these plugins, let alone what it records.

Two plugins do talk outwards, and in both cases that is your choice. The accessibility plugin fetches your own page from your own domain in page mode, and nothing else; content mode is the default and does not even do that. The AI snippet previewer sends something to OpenAI only if you put a key in it yourself, and that traffic runs on your account and not through us.

What that means for your own role as a controller is set out in the sub-processor overview. None of the eight sets a cookie or writes anything to the browser storage of your visitors, and none of the eight records their IP address.

What is added when we work together

If we work together, the data the work requires is added: contacts, access to your website or advertising account, and the details needed to invoice you.

DOC.P1d · Purposes

What we use it for, and on what basis

The law asks for a lawful basis per purpose. Below is which one, in ordinary language and with the article next to it for anyone who wants to check. Two choices in this table are a position of ours and not a settled fact, and we would rather write that down than hide it.

The first: whether filling in a free tool with no account and no payment already amounts to a contract within the meaning of Article 6(1)(b). Guidelines 2/2019 of the European Data Protection Board read "necessary for the performance of a contract" strictly. The second: whether sharing data with Microsoft for Clarity can rest on legitimate interests, given that Microsoft is itself a controller there. We are putting both to a lawyer; if either turns out differently, the basis stated here changes and not what we do in practice.

PurposeDataLawful basis
Answering your message or requestName, email, telephone, website, messagePerforming what you asked for yourself, Article 6(1)(b)
Making the free tools work and showing you the resultWhat you enter in the formPerforming what you asked for yourself, Article 6(1)(b)
Scheduling a call you request yourself, and sending you the invitation, the confirmation and the reminderName, email address, company name, the chosen time and what the call is about, plus your website and telephone number if you fill them inPerforming what you asked for yourself, Article 6(1)(b)
Getting in touch about a request you made yourself, if you gave your email addressEmail, telephone, and what you enteredLegitimate interests, Article 6(1)(f). Our interest is following up a question that came from you. You can object at any time and it takes effect immediately
Knowing which page, which referring site and which campaign a request or tool use came in throughThe page on this site where you filled in the form, the domain plus path of the site that referred you, the campaign code from the web address if there was one, and the timeLegitimate interests, Article 6(1)(f). Our interest is knowing which pages and campaigns work, without following you across other sites. You can object at any time
Doing the work for clientsContact, project and access detailsContract, Article 6(1)(b)
Invoices and bookkeepingName, address, amounts, payment statusLegal obligation, Article 6(1)(c). The obligation is Dutch tax law, because we are established in the Netherlands
Keeping the site reachable and secureIP address, browser data, technical logsLegitimate interests, Article 6(1)(f). Our interest is a site that stays up and is not abused
Measuring how the site is used, with Microsoft Clarity in cookieless modePage views, click, scroll and mouse movement, browser, device and countryLegitimate interests, Article 6(1)(f). Our interest is seeing what works and where visitors get stuck, without putting anything on your device. You can object at any time

We take no automated decisions with legal effect for you. The tools on this site give a result and advice. What you do with that is up to you, and no decision about you hangs on it.

Marketing email, and the rule that applies where you are

We do not send unsolicited commercial email. If you are in the United Kingdom, the frame for that is PECR regulation 22: unsolicited marketing email needs consent, and the soft opt-in applies only where the contact details were obtained in the course of a sale or negotiations for one, where it concerns similar products or services, and where you are given a simple way to refuse both at collection and in every message. If you are in Ireland or elsewhere in the European Union, the equivalent national ePrivacy rules apply. We keep to the stricter reading in both cases, which is simply: you asked, or we do not send.

DOC.P1e · Parties

Which parties see something of yours

Below is every party that receives data about you through the use of this site, and exactly what goes there.

PartyWhat forWhat goes thereWhere
CloudflareHosting the site and the tools behind itEvery request your browser makes: IP address, browser, page requested, timeUnited States, worldwide network
Google Places APIThe local visibility checkThe company name and town you enterUnited States
SerpAPIThe part of that same check about the local map blockThe company name and town you enterUnited States
MakeThe generators for ad copy, review replies and the brand checkEverything you enter in that form, plus your email address if you give one, the address of the page you filled it in on, the domain plus path of the site that referred you and the campaign code from the web address if there was oneEuropean Union
SupabaseOur own database, where requests and tool use are keptWhat you entered in a form, what the tool gave back, where your visit came from and the type of device. No IP addressProject region Ireland. Sub-contractors of Supabase may sit outside the European Economic Area
MicrosoftUsage measurement with Clarity, in cookieless modePage views, click, scroll and mouse movement, browser, device and country. Input fields are masked and do not go alongMicrosoft's Azure cloud. For the EU the contracting party is Microsoft Ireland Operations Limited; processing in the United States falls under the standard contractual clauses between the Microsoft companies
Google Calendar and Google MeetScheduling a call you request yourself, and the video connection for itYour name, email address, company name, the chosen time and what the call is about. Google then sends you the calendar invitation with the meeting link itselfIreland and the United States
ResendSending the email when you request a manual scan, and the confirmation and reminder when you book a callFor a scan: your name, email address, telephone number, website, message and the scores of the automatic scan. For a call: your name, email address and the chosen timeUnited States
StripePaying, if you follow a payment link on the siteWhat you enter on Stripe's own payment page. That page belongs to Stripe, not to usUnited States and Ireland

What happens inside Make

The generators do not do the work themselves. They pass your input to Make, where a language model writes the text and your request is recorded in a spreadsheet at Google. If you enter no email address, that record stays limited to what you entered about your business.

That same use currently also lands in our own database. That is deliberately double and temporary: we will not switch the spreadsheet off until it is demonstrable that nothing is missing in our own database. As soon as that is so, the spreadsheet leaves this chain and it will say so here.

Who works on our instructions and who does not

Cloudflare, Make, Supabase and Resend process data on our instructions. They may use it only for the task we give them, and not for their own purposes. We record that with those parties in a data processing agreement.

With SerpAPI no such agreement is in our file yet. So we keep what goes there as small as possible: only the company name and the town you enter in the check yourself, as a search query. Your name, your email address and your IP address do not go there.

We do not pretend that this automatically falls outside data protection law: with a sole trader the company name is often a person's name, and then name plus town is very much personal data. As long as that agreement is not in place, there is no documented transfer safeguard here either, which is why SerpAPI sits in our register as an open point. It says the same on the sub-processor page.

Google, Stripe and Microsoft decide for themselves in part what they do with the data. For that part they are responsible themselves and their own privacy terms apply alongside this statement. Microsoft expressly calls itself a controller for Clarity. That is why Microsoft sits in our register with the other recipients and not with the sub-processors, and why we keep what goes there as small as possible: no cookies and masked input fields.

We do not sell your data and we do not pass it to parties that have their own commercial purposes for it.

The full list, with what goes to each party and where that happens, is in our sub-processor register. If we work for you and process data on your behalf, the arrangements in our data processing agreement apply.

DOC.P1f · Retention

How long we keep it

The table below says it exactly. The scale above it says it at a glance: which period is short, which is long, and where the law holds us.

Figure P.01retention periods, longest per category · logarithmic scale
Recordings at Microsoft Clarity30 days
Technical logs at the hosting provider90 days
Input in a free tool, without an email address3 months
Favourite recordings and the sample at Clarity9 months
Contact details and messages from a request12 months
Input in a free tool, with an email address12 months
Client and project data after the work ends5 years
Invoices and bookkeeping7 years
30 days90 days1 year3 years7 years

# The scale is logarithmic, otherwise seven years would flatten thirty days into a stub. Lengths are comparative, not measurable.

CategoryHow long
Invoices and bookkeepingSeven years, counted from the end of the financial year. That is the statutory retention obligation under Dutch tax law, which is the law we are established under
Contact details and messages from a requestTwelve months, counted from the last substantive contact. If work follows from it, the rule for client and project data applies from that moment
A call you scheduled through the siteTwelve months after the call. If you cancel, the appointment disappears from the calendar immediately. If work follows from it, the rule for client and project data applies from that moment
What you enter in the free tools, with an email addressTwelve months, counted from the moment you used the tool. That is the same period as for a request, because with an email address it is one
What you enter in the free tools, without an email addressThree months. Long enough to judge whether a page or campaign delivers anything, short enough to keep nothing nobody has a reason for. After that we empty the personal fields and only the count remains: which tool, which page, which day. That cleaned-up record contains nothing that points to you and is kept so we can see what works
The origin record itself, so which tool, which page, which referring site, which campaign code and what timeIt sits with the record above and does not disappear in that same clean-up: it holds no data about you. It also ends up in the technical logs of the site at Cloudflare, where the rule for technical logs below applies
Client and project data after a collaboration endsFive years after the end of the collaboration. That period exists so we can show what was agreed, delivered and invoiced
Technical logs at the hosting providerNinety days. For a confirmed security incident we keep the evidence longer, up to five years
The usage measurement at Microsoft ClarityRecordings of page visits 30 days. Recordings marked as favourite and a random sample from them stay up to nine months. Those are the periods Microsoft states itself in the Clarity documentation; we do not set them and we cannot make them shorter
# OPEN POINT
What Cloudflare keeps in its own logs follows from their settings, and we are still completing that record. The ninety days is our own rule for security logs.

Beyond that: we keep nothing longer than we need it for. If you ask us to delete something and no legal obligation stops us, we do.

DOC.P1g · Transfers

Data that leaves Europe

Some of the parties above sit in the United States: Cloudflare, Google, Microsoft, Resend, SerpAPI and Stripe. Make runs on a European server, recognisable by the hook address beginning with hook.eu1.

For transfers to the United States the European Commission's standard contractual clauses apply, or the EU-US Data Privacy Framework where the party in question is certified under it. Both are recognised safeguards under the GDPR.

Which of the two applies per party is set out below. The agreements named are in our own supplier register, with version and date.

PartyTransfer safeguard
CloudflareData processing agreement with the standard contractual clauses in it, the Cloudflare Customer DPA version 6.4
ResendData processing agreement with the standard contractual clauses. Where Resend or one of its suppliers is certified under the Data Privacy Framework, that framework applies alongside
StripeStripe's data processing agreement of 18 November 2025. Per service it applies the standard contractual clauses or the Data Privacy Framework
Google, for the Places API and the spreadsheet behind MakeGoogle's own terms, with the standard contractual clauses or the Data Privacy Framework according to Google itself
Microsoft, for ClarityFor the EU the contracting party is Microsoft Ireland Operations Limited. For processing at Microsoft Corporation in the United States, Microsoft states that the standard contractual clauses between those companies apply
SerpAPINo data processing agreement in our file and therefore no documented transfer safeguard. That is why only the search query you type yourself goes there: the company name and the town from the check. Open point, no recorded safeguard
MakeEuropean server, so for the data held there a transfer does not arise. If a transfer does arise inside Make through one of their own suppliers, the standard contractual clauses from their agreement apply
# OPEN POINT, AND IT IS THE ONE THAT MATTERS MOST FOR A UK READER
The safeguards above are the European ones. A transfer that starts in the United Kingdom runs under the United Kingdom's own transfer regime, which is a separate instrument with its own paperwork. Which instrument fits our chain, and what it means for a route running from the United Kingdom into the European Union, is a question for a lawyer and not one to fill in on instinct. So it is named here as open rather than answered with a European clause wearing a British label. Until it is settled we keep the chain as short as it already is, and we do not claim a safeguard we cannot show you.
# OPEN POINT
For Make we are still completing the inventory of the scenarios and the contract evidence. Until then we keep what goes there through the free tools as small as possible.
DOC.P1h · Rights

What you may ask for

You have the rights below. You exercise them by emailing sales@theseo.nl. We respond within a month, usually much sooner. There is no charge.

  • Access. Ask which data we hold about you and what we do with it.
  • Rectification. Have anything corrected that is wrong or incomplete.
  • Erasure. Have deleted what we no longer need or may not keep.
  • Restriction. Have the use put on hold temporarily, for instance while we work out whether the data or the basis is right. We then keep it but do nothing further with it.
  • Portability. Receive the data you supplied yourself in a common file format, or have it sent straight to another party.
  • Objection. Object to processing based on legitimate interests. Against use for direct marketing you can object at any time, and then it stops without any further weighing.
  • Withdraw consent. If you gave consent for something, you may withdraw it at any moment. What we did before that stays lawful; from that moment it stops.

We may ask for extra details to be sure the request comes from you. We ask for no more than is needed for that.

These rights read the same under the UK GDPR and under the GDPR. Where they differ is who you go to if we get it wrong, and that is the next section.

DOC.P1i · Complaints

Complaining, and reporting a data breach

Complaint

If you are unhappy with how we handle your data, tell us first at sales@theseo.nl. If we cannot resolve it together, you have the right to complain to a supervisory authority. Which one depends on where you are, and this is the part of the page a translation would have got wrong.

Where you areWhich authorityWhere
The Netherlands, or anywhere, because it is our lead authorityAutoriteit Persoonsgegevens, the Dutch Data Protection Authorityautoriteitpersoonsgegevens.nl
United KingdomInformation Commissioner's Office, under the UK GDPR and the Data Protection Act 2018ico.org.uk
IrelandData Protection Commission, under the GDPRdataprotection.ie
Elsewhere in the European UnionThe supervisory authority of the country you live in, alongside the Dutch onenot applicable

Data breach or vulnerability

Do you think data has leaked, or do you see a vulnerability on this site? Email sales@theseo.nl with the words data breach in the subject line. Describe as precisely as you can what you see and when. We pick up a report like that with priority and let you know what we do with it.

If it is a vulnerability and not yet a breach, our responsible disclosure page sets out how to report it, what we ask of you and what you get back from us.

If it turns out to be a personal data breach with a risk to the people involved, we report it to the supervisory authority within 72 hours. If the risk is high, we also inform the people it concerns.

Changes

If what we process or which parties we use changes, we update this page. The version is at the top and the date of the last change is below.

See also our terms and conditions for what we agree per product, the sub-processor register for the full list of parties, the data processing agreement for what applies when we process data on your behalf, and the cookie and tracking statement for exactly what is stored on your device. Which AI we use ourselves and what for is in the AI transparency statement; what we have measured on this site for accessibility is in the accessibility statement.

Last changed on 25 August 2026

Section · Next stepreachable 24/7
Book a call