PRIVACY POLICY

Effective date: 17 February 2025

Last updated: 28 August 2026

1. Data Controller

The controller of personal data processed under this Privacy Policy is:

Olha Tymoshenko, trading as "Seotegrity"

Business ID No. (IČO): 22579206

Registered address: Cimburkova 916/8, 130 00 Praha 3-Žižkov, Czech Republic

Registered in the Trade Register maintained by the competent trade licensing authority of the Czech Republic.

Contact: info@seotegrity.com

2. Personal Data Processed

Depending on the nature of the Client's request or relationship, the Provider may process:

identification and contact details;

information supplied through enquiry forms;

information contained in documents, briefs or access credentials supplied by the Client (for example, access to a website, analytics or advertising account, provided for the performance of the Services);

contractual, billing and payment information;

technical information necessary for Website security and operation.

The Provider shall process only data reasonably necessary for the relevant purpose.

Such data may be provided directly by the Client (for example, via the Website enquiry form, a lead form on social media, or by email, telephone or messaging apps) or collected automatically when the Client visits the Website (for example, IP address, browser type and cookie identifiers, including analytics and, where consent has been given, advertising cookies). Further detail on cookie categories, purposes and consent is available through the Website's cookie-settings tool.

3. Purposes of Processing

Personal data may be processed for:

(a) responding to enquiries;

(b) providing requested Services;

(c) entering into and performing contracts;

(d) planning, setting up and managing advertising campaigns on the Client's behalf;

(e) communicating with Clients;

(f) accounting and tax compliance;

(g) fraud prevention and information security;

(h) compliance with applicable legal obligations; and

(i) other purposes permitted by applicable law.

4. Legal Bases

Depending on the purpose, processing may be based on:

(a) Article 6(1)(b) GDPR — performance of a contract or steps taken at the Client's request before entering into a contract;

(b) Article 6(1)(c) GDPR — compliance with a legal obligation;

(c) Article 6(1)(f) GDPR — legitimate interests; or

(d) Article 6(1)(a) GDPR — consent.

The applicable legal basis shall be determined according to the actual processing activity.

5. Advertising-Campaign Data Sharing

5.1

Where a Client requests digital-marketing or advertising-campaign management, the Provider may transfer information necessary for the requested Service to the relevant third-party advertising platform (such as Google Ads or Meta Ads).

5.2

The information transferred shall be limited to what is reasonably necessary for the requested Service.

5.3

The relevant advertising platform acts in accordance with its own legal, professional and data-protection obligations.

5.4

Where the processing is necessary to take steps at the Client's request before entering into or performing a contract, Article 6(1)(b) GDPR may apply. Where processing is required by law, Article 6(1)(c) GDPR may apply.

6. Data Recipients

Personal data may be disclosed to:

subcontractors and freelance specialists engaged to help deliver the Services;

IT and hosting providers;

advertising and analytics platforms (such as Meta Platforms Ireland Ltd. or Google Ireland Ltd.), where necessary to manage a Client's campaign or, for Website visitors, where the Client or visitor has given the required consent;

professional advisers;

public authorities where legally required; and

other recipients where disclosure is permitted by law.

Where required by Article 28 GDPR, the Provider has concluded a data processing agreement with each such processor.

7. International Data Transfers

7.1

Where personal data is transferred outside the European Economic Area, the Provider shall use an applicable GDPR transfer mechanism.

7.2

Depending on the circumstances, this may include:

an adequacy decision under Article 45 GDPR;

Standard Contractual Clauses under Article 46 GDPR; or

another lawful transfer mechanism.

7.3

The Provider shall not represent that a particular transfer mechanism is used unless that mechanism actually applies to the relevant transfer.

8. Security

8.1

The Provider implements appropriate technical and organisational measures appropriate to the risks of processing.

8.2

Such measures may include access controls, confidentiality measures, backup procedures, security monitoring and other measures appropriate to the nature of the processing.

8.3

The Provider shall not claim to use a specific security technology or certification unless it has actually implemented it and it remains current.

9. Data Retention

9.1

Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law.

9.2

Accounting and tax records shall be retained for the periods required by applicable law.

9.3

Personal data necessary to establish, exercise or defend legal claims may be retained for the applicable limitation period.

9.4

Where information is processed in connection with a third-party advertising-platform account managed on the Client's behalf, it is retained for as long as necessary for that purpose and, where applicable, in accordance with the platform's own data-retention settings.

9.5

By way of illustration, and without limiting Article 9.1: enquiries that do not lead to a contract are generally retained for 24 months from the date of last contact; client data under a contract is generally retained for the duration of the contract and thereafter for the period required by Czech accounting and tax legislation; data processed on the basis of consent is retained until consent is withdrawn; and cookie-related data is retained in accordance with the periods stated in the Website's cookie settings, and in any event no longer than 24 months.

10. Data Subject Rights

Subject to GDPR and applicable law, data subjects may have the right to:

access personal data and obtain a copy of it (Article 15 GDPR);

request rectification of inaccurate or incomplete data (Article 16 GDPR);

request erasure ("right to be forgotten") (Article 17 GDPR);

request restriction of processing (Article 18 GDPR);

object to processing based on legitimate interests, including direct marketing (Article 21 GDPR);

request data portability in a structured, machine-readable format, where applicable (Article 20 GDPR);

withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR);

not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject (Article 22 GDPR) — the Provider does not make such decisions; and

lodge a complaint with the competent supervisory authority.

Requests to exercise these rights may be sent to info@seotegrity.com. The Provider shall respond within one month of receipt; in certain cases this period may be extended by a further two months, and the Provider shall notify the data subject accordingly.

11. Restrictions

Where processing is required by law, certain rights may be restricted to the extent permitted by GDPR and applicable Czech law.

In particular, statutory retention requirements may prevent immediate erasure of certain records.

12. Supervisory Authority

The competent Czech supervisory authority is:

Office for Personal Data Protection

Pplk. Sochora 27

170 00 Praha 7

Czech Republic

Website: uoou.gov.cz

A data subject may lodge a complaint with the competent supervisory authority.

13. Data Protection Officer

Based on the Provider's current assessment of its processing activities, the Provider does not consider that the conditions requiring mandatory appointment of a Data Protection Officer under Article 37 GDPR are currently met.

The Provider shall reassess this position if the nature or scale of its processing materially changes.

14. Changes

This Privacy Policy may be updated where necessary due to changes in processing activities, applicable law, service providers or technical arrangements.

The current version shall be published on the Website.


© All Rights Reserved