Privacy: what we process, and why
This statement describes what actually happens to your data when you visit this site, use one of our free tools or work with us. No legal wallpaper, and nothing we do not do.
Which law you are reading about
TheSEO is established in the Netherlands, which means our lead supervisory authority is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. That does not take away your own route. If you are in the United Kingdom you may complain to the ICO; if you are in Ireland you may complain to the Data Protection Commission. Both routes are set out at the bottom of this page, and neither replaces the other.
Article numbers in the tables below are given as "Article 6(1)(b)" and so on. The UK GDPR keeps the same numbering as the GDPR, so those references read the same in both. Where the two genuinely differ, we say which one we mean.
Article 27 UK GDPR can require an organisation outside the United Kingdom that offers goods or services to people there to appoint a representative in the United Kingdom. Whether that applies to us, and whether an exemption fits, is a decision for the business and a question for a lawyer, and it has not been settled. Until it is, this page does not claim that we comply with the UK GDPR, and no form on this site is aimed specifically at visitors in the United Kingdom. What we can say is what we actually do, and that is the rest of this page. Source: ICO guidance for organisations outside the UK and ICO, who does the UK GDPR apply to.
# Why one page and not three. What we process is identical in all three columns. Only the law and the regulator differ, so splitting the facts across three documents would create three chances to say something different about the same thing.
# Article numbering is shared: the UK GDPR keeps the numbering of the GDPR, so "Article 6(1)(b)" reads the same in every column. Where the two genuinely differ, the text says which one it means.
Who is responsible
TheSEO decides why and how the data on this site is used. In the law that is called the controller. You can come to us with any question about it.
This statement covers the whole organisation and therefore the software we build as well. If you use Jarvis, read where to look in this statement when you use Jarvis alongside it. That page points the way and does not replace the text below.
| Company | Mansotti. TheSEO is a trading name of Mansotti |
|---|---|
| Company registration | Dutch Chamber of Commerce (KVK) 77834453. We are not registered with Companies House and we are not registered in Spain, and we will not suggest otherwise |
| Registered address | Albert Plesmanring 9, 3712 DA Huis ter Heide, the Netherlands |
| sales@theseo.nl | |
| VAT number | Dutch VAT number NL003245282B11 |
| Telephone | +31 6 29 91 97 56 |
Where something has not been settled yet, this page says so in as many words. We do not fill in a period or a safeguard we cannot deliver, and a point like that stays named as open until it is fixed.
We have no separate data protection officer. Privacy questions come straight to the email address above.
What we measure, and what does not happen
We measure how this site is used with Microsoft Clarity, deliberately in its cookieless mode. Before the script loads we give Clarity the fixed signal that there is no consent for cookies. Clarity then places nothing on your device and cannot recognise you or follow you from page to page: every page view counts as a separate session.
Microsoft sees which pages are looked at, where people click and scroll, how the mouse moves, and technical data such as browser, device and country. What you type into input fields is masked by Clarity in every mode and is not sent to Microsoft. Beyond that there is no analytics software on this site: no Google Analytics, no advertising pixels from Google, Meta or LinkedIn, and no remarketing.
The site itself sets no cookies. Our hosting provider may set a technical cookie to keep out bot traffic and attacks. That one serves security and is not used to recognise or follow you.
Two things are stored in your browser, both on the MyParcel Dashboard pages and both because you chose something yourself:
- If you select a parcel on the MyParcel Dashboard start page, your browser remembers that choice in session storage, under the key mp-plan. Close the tab and it is gone.
- If you change the display in the demo of that dashboard, such as theme, density or which columns you see, your browser remembers that in local storage, under the key myparcel-dashboard-preview-preferences. That stays until you clear your browser storage.
Both stay on your own device. They do not come to us and they do not go to anyone else, and they are not used to recognise or follow you.
Why there is no cookie banner, and why that is not laziness
In the United Kingdom, storing information on your device or reading information already stored there needs your consent under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. The same regulation exempts storage that is strictly necessary to provide a service you have explicitly asked for.
That is exactly the position here. Clarity stores nothing. The two keys above exist only because you asked for a setting to be remembered. A banner asking your permission for something that is not happening would not be extra care, it would be a false statement dressed as caution. So there is none, and the full list of what is stored is on the cookie page.
The fonts come from our own server. They used to be fetched directly from Google; since that clean-up your browser makes no connection to Google for them.
Which data we process
What you leave behind yourself
- If you get in touch or ask for a manual scan, we process your name, email address, telephone number, the address of your website and the content of your message.
- If you use one of the free tools, we process what you enter in that form: company name, trade and town, and for the review tool also the review text, the name of the reviewer and the number of stars. Your email address is optional there.
- If you have a website scanned, we process the web address you enter.
- If you use a tool on this site, we record where that use came from: which page of this site the form was on, which site sent you to us if you clicked a link, the campaign code that was in the web address if you arrived through an advert or campaign link, and the time. This is stated at every tool where it happens. Of the referring site we keep only the domain plus the path; everything that followed in the query string is dropped in your own browser and never reaches our server. This does not follow you across other sites: we see only this one step towards us, and only because your browser sends it.
- What you enter and what the tool gave back are kept in our own database. That holds for every tool on this site. Along with it goes the type of device you used the tool on, derived from what your browser sends: mobile, tablet or desktop, no more than that. We keep no IP address with that record and we set nothing in your browser for it.
- From that data we work out which of our services would suit you best, with the reason for each point. That is an aid to a conversation and not a decision about you: nothing is automatically refused, granted or priced, and a person looks at it before anything is done with it. If you want to know what it says about you, or want it deleted, the section on your rights below applies as normal.
What comes along automatically
On every visit our hosting provider sees your IP address, your browser and device, which page you request and at what moment. That is needed to send the page to you and to keep out abuse. That data arises from delivering the page itself; we do not link it to a profile and we do not use it to recognise you.
The watermark in the skill downloads
Every skill you download here has two lines at the top of the SKILL.md file: a visible line saying the skill comes from theseo.nl and is free under the MIT licence, and a comment line with a release id in the form tsk-year-month-day-code. That id belongs to that release of the zip and not to you: everyone who downloads the same version gets the same id.
So nothing about you is recorded on a download, no account is needed, and there is no code in the skill that sends anything back to us. The id is there so that a skill turning up somewhere can be traced to us and to the version that was here. If you want to remove those two lines, you may.
If you download one of our WordPress plugins
On tools and plugins there are eight plugins you can download without an account. We ask for nothing at the download: no name, no email address, no form. What happens is the same as on any other page, namely the line our hosting provider writes in its log because it is sending you a file. There is no counter in the zip file and there is no code in it that sends anything back to us.
After that the software sits on your server and we are no longer a party to it. Six of the eight make no outbound request at all: the heatmap and scrollmap and the Core Web Vitals plugin write only to your own database, the AI crawler log writes only what arrived at your own server, and the llms.txt generator, the local schema and the AI transparency label keep only what you enter yourself. So we cannot see that you have installed one of these plugins, let alone what it records.
Two plugins do talk outwards, and in both cases that is your choice. The accessibility plugin fetches your own page from your own domain in page mode, and nothing else; content mode is the default and does not even do that. The AI snippet previewer sends something to OpenAI only if you put a key in it yourself, and that traffic runs on your account and not through us.
What that means for your own role as a controller is set out in the sub-processor overview. None of the eight sets a cookie or writes anything to the browser storage of your visitors, and none of the eight records their IP address.
What is added when we work together
If we work together, the data the work requires is added: contacts, access to your website or advertising account, and the details needed to invoice you.
What we use it for, and on what basis
The law asks for a lawful basis per purpose. Below is which one, in ordinary language and with the article next to it for anyone who wants to check. Two choices in this table are a position of ours and not a settled fact, and we would rather write that down than hide it.
The first: whether filling in a free tool with no account and no payment already amounts to a contract within the meaning of Article 6(1)(b). Guidelines 2/2019 of the European Data Protection Board read "necessary for the performance of a contract" strictly. The second: whether sharing data with Microsoft for Clarity can rest on legitimate interests, given that Microsoft is itself a controller there. We are putting both to a lawyer; if either turns out differently, the basis stated here changes and not what we do in practice.
| Purpose | Data | Lawful basis |
|---|---|---|
| Answering your message or request | Name, email, telephone, website, message | Performing what you asked for yourself, Article 6(1)(b) |
| Making the free tools work and showing you the result | What you enter in the form | Performing what you asked for yourself, Article 6(1)(b) |
| Scheduling a call you request yourself, and sending you the invitation, the confirmation and the reminder | Name, email address, company name, the chosen time and what the call is about, plus your website and telephone number if you fill them in | Performing what you asked for yourself, Article 6(1)(b) |
| Getting in touch about a request you made yourself, if you gave your email address | Email, telephone, and what you entered | Legitimate interests, Article 6(1)(f). Our interest is following up a question that came from you. You can object at any time and it takes effect immediately |
| Knowing which page, which referring site and which campaign a request or tool use came in through | The page on this site where you filled in the form, the domain plus path of the site that referred you, the campaign code from the web address if there was one, and the time | Legitimate interests, Article 6(1)(f). Our interest is knowing which pages and campaigns work, without following you across other sites. You can object at any time |
| Doing the work for clients | Contact, project and access details | Contract, Article 6(1)(b) |
| Invoices and bookkeeping | Name, address, amounts, payment status | Legal obligation, Article 6(1)(c). The obligation is Dutch tax law, because we are established in the Netherlands |
| Keeping the site reachable and secure | IP address, browser data, technical logs | Legitimate interests, Article 6(1)(f). Our interest is a site that stays up and is not abused |
| Measuring how the site is used, with Microsoft Clarity in cookieless mode | Page views, click, scroll and mouse movement, browser, device and country | Legitimate interests, Article 6(1)(f). Our interest is seeing what works and where visitors get stuck, without putting anything on your device. You can object at any time |
We take no automated decisions with legal effect for you. The tools on this site give a result and advice. What you do with that is up to you, and no decision about you hangs on it.
Marketing email, and the rule that applies where you are
We do not send unsolicited commercial email. If you are in the United Kingdom, the frame for that is PECR regulation 22: unsolicited marketing email needs consent, and the soft opt-in applies only where the contact details were obtained in the course of a sale or negotiations for one, where it concerns similar products or services, and where you are given a simple way to refuse both at collection and in every message. If you are in Ireland or elsewhere in the European Union, the equivalent national ePrivacy rules apply. We keep to the stricter reading in both cases, which is simply: you asked, or we do not send.
Which parties see something of yours
Below is every party that receives data about you through the use of this site, and exactly what goes there.
| Party | What for | What goes there | Where |
|---|---|---|---|
| Cloudflare | Hosting the site and the tools behind it | Every request your browser makes: IP address, browser, page requested, time | United States, worldwide network |
| Google Places API | The local visibility check | The company name and town you enter | United States |
| SerpAPI | The part of that same check about the local map block | The company name and town you enter | United States |
| Make | The generators for ad copy, review replies and the brand check | Everything you enter in that form, plus your email address if you give one, the address of the page you filled it in on, the domain plus path of the site that referred you and the campaign code from the web address if there was one | European Union |
| Supabase | Our own database, where requests and tool use are kept | What you entered in a form, what the tool gave back, where your visit came from and the type of device. No IP address | Project region Ireland. Sub-contractors of Supabase may sit outside the European Economic Area |
| Microsoft | Usage measurement with Clarity, in cookieless mode | Page views, click, scroll and mouse movement, browser, device and country. Input fields are masked and do not go along | Microsoft's Azure cloud. For the EU the contracting party is Microsoft Ireland Operations Limited; processing in the United States falls under the standard contractual clauses between the Microsoft companies |
| Google Calendar and Google Meet | Scheduling a call you request yourself, and the video connection for it | Your name, email address, company name, the chosen time and what the call is about. Google then sends you the calendar invitation with the meeting link itself | Ireland and the United States |
| Resend | Sending the email when you request a manual scan, and the confirmation and reminder when you book a call | For a scan: your name, email address, telephone number, website, message and the scores of the automatic scan. For a call: your name, email address and the chosen time | United States |
| Stripe | Paying, if you follow a payment link on the site | What you enter on Stripe's own payment page. That page belongs to Stripe, not to us | United States and Ireland |
What happens inside Make
The generators do not do the work themselves. They pass your input to Make, where a language model writes the text and your request is recorded in a spreadsheet at Google. If you enter no email address, that record stays limited to what you entered about your business.
That same use currently also lands in our own database. That is deliberately double and temporary: we will not switch the spreadsheet off until it is demonstrable that nothing is missing in our own database. As soon as that is so, the spreadsheet leaves this chain and it will say so here.
Who works on our instructions and who does not
Cloudflare, Make, Supabase and Resend process data on our instructions. They may use it only for the task we give them, and not for their own purposes. We record that with those parties in a data processing agreement.
With SerpAPI no such agreement is in our file yet. So we keep what goes there as small as possible: only the company name and the town you enter in the check yourself, as a search query. Your name, your email address and your IP address do not go there.
We do not pretend that this automatically falls outside data protection law: with a sole trader the company name is often a person's name, and then name plus town is very much personal data. As long as that agreement is not in place, there is no documented transfer safeguard here either, which is why SerpAPI sits in our register as an open point. It says the same on the sub-processor page.
Google, Stripe and Microsoft decide for themselves in part what they do with the data. For that part they are responsible themselves and their own privacy terms apply alongside this statement. Microsoft expressly calls itself a controller for Clarity. That is why Microsoft sits in our register with the other recipients and not with the sub-processors, and why we keep what goes there as small as possible: no cookies and masked input fields.
We do not sell your data and we do not pass it to parties that have their own commercial purposes for it.
The full list, with what goes to each party and where that happens, is in our sub-processor register. If we work for you and process data on your behalf, the arrangements in our data processing agreement apply.
How long we keep it
The table below says it exactly. The scale above it says it at a glance: which period is short, which is long, and where the law holds us.
# The scale is logarithmic, otherwise seven years would flatten thirty days into a stub. Lengths are comparative, not measurable.
| Category | How long |
|---|---|
| Invoices and bookkeeping | Seven years, counted from the end of the financial year. That is the statutory retention obligation under Dutch tax law, which is the law we are established under |
| Contact details and messages from a request | Twelve months, counted from the last substantive contact. If work follows from it, the rule for client and project data applies from that moment |
| A call you scheduled through the site | Twelve months after the call. If you cancel, the appointment disappears from the calendar immediately. If work follows from it, the rule for client and project data applies from that moment |
| What you enter in the free tools, with an email address | Twelve months, counted from the moment you used the tool. That is the same period as for a request, because with an email address it is one |
| What you enter in the free tools, without an email address | Three months. Long enough to judge whether a page or campaign delivers anything, short enough to keep nothing nobody has a reason for. After that we empty the personal fields and only the count remains: which tool, which page, which day. That cleaned-up record contains nothing that points to you and is kept so we can see what works |
| The origin record itself, so which tool, which page, which referring site, which campaign code and what time | It sits with the record above and does not disappear in that same clean-up: it holds no data about you. It also ends up in the technical logs of the site at Cloudflare, where the rule for technical logs below applies |
| Client and project data after a collaboration ends | Five years after the end of the collaboration. That period exists so we can show what was agreed, delivered and invoiced |
| Technical logs at the hosting provider | Ninety days. For a confirmed security incident we keep the evidence longer, up to five years |
| The usage measurement at Microsoft Clarity | Recordings of page visits 30 days. Recordings marked as favourite and a random sample from them stay up to nine months. Those are the periods Microsoft states itself in the Clarity documentation; we do not set them and we cannot make them shorter |
What Cloudflare keeps in its own logs follows from their settings, and we are still completing that record. The ninety days is our own rule for security logs.
Beyond that: we keep nothing longer than we need it for. If you ask us to delete something and no legal obligation stops us, we do.
Data that leaves Europe
Some of the parties above sit in the United States: Cloudflare, Google, Microsoft, Resend, SerpAPI and Stripe. Make runs on a European server, recognisable by the hook address beginning with hook.eu1.
For transfers to the United States the European Commission's standard contractual clauses apply, or the EU-US Data Privacy Framework where the party in question is certified under it. Both are recognised safeguards under the GDPR.
Which of the two applies per party is set out below. The agreements named are in our own supplier register, with version and date.
| Party | Transfer safeguard |
|---|---|
| Cloudflare | Data processing agreement with the standard contractual clauses in it, the Cloudflare Customer DPA version 6.4 |
| Resend | Data processing agreement with the standard contractual clauses. Where Resend or one of its suppliers is certified under the Data Privacy Framework, that framework applies alongside |
| Stripe | Stripe's data processing agreement of 18 November 2025. Per service it applies the standard contractual clauses or the Data Privacy Framework |
| Google, for the Places API and the spreadsheet behind Make | Google's own terms, with the standard contractual clauses or the Data Privacy Framework according to Google itself |
| Microsoft, for Clarity | For the EU the contracting party is Microsoft Ireland Operations Limited. For processing at Microsoft Corporation in the United States, Microsoft states that the standard contractual clauses between those companies apply |
| SerpAPI | No data processing agreement in our file and therefore no documented transfer safeguard. That is why only the search query you type yourself goes there: the company name and the town from the check. Open point, no recorded safeguard |
| Make | European server, so for the data held there a transfer does not arise. If a transfer does arise inside Make through one of their own suppliers, the standard contractual clauses from their agreement apply |
The safeguards above are the European ones. A transfer that starts in the United Kingdom runs under the United Kingdom's own transfer regime, which is a separate instrument with its own paperwork. Which instrument fits our chain, and what it means for a route running from the United Kingdom into the European Union, is a question for a lawyer and not one to fill in on instinct. So it is named here as open rather than answered with a European clause wearing a British label. Until it is settled we keep the chain as short as it already is, and we do not claim a safeguard we cannot show you.
For Make we are still completing the inventory of the scenarios and the contract evidence. Until then we keep what goes there through the free tools as small as possible.
What you may ask for
You have the rights below. You exercise them by emailing sales@theseo.nl. We respond within a month, usually much sooner. There is no charge.
- Access. Ask which data we hold about you and what we do with it.
- Rectification. Have anything corrected that is wrong or incomplete.
- Erasure. Have deleted what we no longer need or may not keep.
- Restriction. Have the use put on hold temporarily, for instance while we work out whether the data or the basis is right. We then keep it but do nothing further with it.
- Portability. Receive the data you supplied yourself in a common file format, or have it sent straight to another party.
- Objection. Object to processing based on legitimate interests. Against use for direct marketing you can object at any time, and then it stops without any further weighing.
- Withdraw consent. If you gave consent for something, you may withdraw it at any moment. What we did before that stays lawful; from that moment it stops.
We may ask for extra details to be sure the request comes from you. We ask for no more than is needed for that.
These rights read the same under the UK GDPR and under the GDPR. Where they differ is who you go to if we get it wrong, and that is the next section.
Complaining, and reporting a data breach
Complaint
If you are unhappy with how we handle your data, tell us first at sales@theseo.nl. If we cannot resolve it together, you have the right to complain to a supervisory authority. Which one depends on where you are, and this is the part of the page a translation would have got wrong.
| Where you are | Which authority | Where |
|---|---|---|
| The Netherlands, or anywhere, because it is our lead authority | Autoriteit Persoonsgegevens, the Dutch Data Protection Authority | autoriteitpersoonsgegevens.nl |
| United Kingdom | Information Commissioner's Office, under the UK GDPR and the Data Protection Act 2018 | ico.org.uk |
| Ireland | Data Protection Commission, under the GDPR | dataprotection.ie |
| Elsewhere in the European Union | The supervisory authority of the country you live in, alongside the Dutch one | not applicable |
Data breach or vulnerability
Do you think data has leaked, or do you see a vulnerability on this site? Email sales@theseo.nl with the words data breach in the subject line. Describe as precisely as you can what you see and when. We pick up a report like that with priority and let you know what we do with it.
If it is a vulnerability and not yet a breach, our responsible disclosure page sets out how to report it, what we ask of you and what you get back from us.
If it turns out to be a personal data breach with a risk to the people involved, we report it to the supervisory authority within 72 hours. If the risk is high, we also inform the people it concerns.
Changes
If what we process or which parties we use changes, we update this page. The version is at the top and the date of the last change is below.
See also our terms and conditions for what we agree per product, the sub-processor register for the full list of parties, the data processing agreement for what applies when we process data on your behalf, and the cookie and tracking statement for exactly what is stored on your device. Which AI we use ourselves and what for is in the AI transparency statement; what we have measured on this site for accessibility is in the accessibility statement.
Last changed on 25 August 2026