Privacy notice

Version: 20 September 2026

1. Controller

The controller for data processing on this website is:
SEOTHON GbR (Philipp Friebel & Maximilian Golda), Baumeister-Uhlig-Straße 17, 09128 Chemnitz, Deutschland
Email: [email protected]
Phone: +49 177 218 5707

This notice explains how we process personal data under the EU General Data Protection Regulation (GDPR) when you visit our website, contact us, book a consultation, request an agency partner check, or become a SEOTHON customer.

2. Data collected when you visit the website

When you access our website, our server automatically records technically necessary data (server log files): the page requested, the date and time of access, the amount of data transferred, the browser and operating system used, and the requesting IP address. This processing is based on our legitimate interest (Article 6(1)(f) GDPR) in operating the website securely and reliably.

3. Hosting

We run the website and the dashboard on our own servers in Germany; no external hosting provider is involved. Cloudflare sits in front of them (see section 9).

4. Cookies and storage on your device

This website sets no cookies, neither technically necessary ones nor analytics or marketing cookies. No third-party content is embedded: no external fonts, no map services, no tracking pixels, no social media scripts. All files are served from our own server. A consent banner is therefore not required, and there is none.

In the customer area (dashboard) we set two technically necessary cookies after you sign in: one for your session, one for the project you last selected. Neither can be read by scripts in the browser (HttpOnly), both are sent only to our own server (SameSite=Lax), and both serve solely to operate the customer area, which does not require consent under section 25(2) no. 2 TDDDG. The session ends automatically after 14 days at the latest. Your display preference (light or dark) is stored locally by your browser and is not transmitted to us.

5. Contact form, consultation and partner enquiries

When you submit one of our forms, we process the details you provide in order to handle and answer your enquiry (Article 6(1)(b) or (f) GDPR). Depending on the form we store: name, email address, company, website, phone number, preferred appointment, and your message. For the trial month enquiry we additionally store details about company size and the desired start date.

In addition, for every submission we store your IP address and your browser identification (user agent). The sole purpose is to prevent abuse (automated bulk enquiries, forged senders); the legal basis is our legitimate interest in a functioning contact channel (Article 6(1)(f) GDPR). We do not evaluate these two items for advertising or analytics purposes.

We also store the language of the form you used and the path of the page it was on, so that we can answer you in the same language and document which version of our legal texts was linked at the time.

Enquiries are stored on our server outside the publicly accessible area and are additionally sent to us by email. We delete them as soon as they are no longer needed to handle your enquiry, and at the latest once statutory retention periods have expired.

6. Booking the SEO system review

To book the SEO system review we collect the details listed in section 5, including your preferred appointment. Where the review is subject to a charge, we send you the payment link by email; you complete the payment with the respective provider (see section 8). From there we only receive the information whether and when payment was made, never full card or bank details.

6a. Agency partner check

For the free agency partner check we process name, business email address, agency name, website, and details about your focus, project volume, delivery bottleneck, preferred cooperation model and optional project notes. This processing serves solely to assess and answer the partner enquiry and to prepare a possible non-binding conversation (Article 6(1)(b) or (f) GDPR).

6b. Contacting businesses without prior contact

We contact businesses we consider a suitable match by email without any prior contact having taken place. If you received such a message from us, this section informs you about the processing behind it in accordance with Article 14 GDPR.

Where we get the data: exclusively from publicly available sources, namely the company's own website (in particular legal notice, contact and team pages), the business directory of the German chambers of skilled crafts, OpenStreetMap, public entries in Google Maps, and publicly available visibility data from search engines.

What data we process: company name, address, industry, website, business email address and phone number and, where published on the website, the names and roles of contact persons. In addition the publicly visible content of the website and the assessment derived from it as to whether our service suits the company, for example whether content is published regularly and how visible the website is in search.

Purpose and legal basis: assessing whether a cooperation makes sense, and the subsequent initial business contact. We base this processing on our legitimate interest in establishing business relationships (Article 6(1)(f) GDPR).

Recipients: the website content is analysed using an AI language model provided by Anthropic (USA); research data comes from DataForSEO and Apify. We use our email delivery service to send the message. There are no other recipients; in particular, we do not sell data on.

Storage period: we store the data for as long as the purpose applies, and at the latest until you object.

Your right to object: you may object to this processing, and in particular to being contacted for advertising purposes, at any time, without giving reasons and without incurring any costs. An informal reply to our email or a message to [email protected] is sufficient. After your objection we will not contact you again; to ensure this we keep your address permanently on a suppression list and delete the other data collected about you. You also have all the rights listed in section 11.

7. Customer account and dashboard

If you take out a subscription, we create a customer account. To perform the contract (Article 6(1)(b) GDPR) we process:

Providing your name, email address and payment details is necessary to conclude and perform the contract; without them no customer account can be created. All other details (such as Search Console access, team access, options) are voluntary, and withholding them only limits the corresponding functionality.

If you delete a project, it is first marked as deleted and then permanently removed after 30 days together with its data and files; this period exists so that an accidental deletion can be undone. We create daily backups of our databases which expire automatically after 30 days; until then, deleted data may still be contained in those backups.

Where we process personal data of your own customers or website visitors on your behalf, we do so exclusively on your instructions. Our data processing agreement under Article 28 GDPR applies to this and becomes part of the contract when you take out the subscription.

7a. SEOTHON plugin (WordPress) and SEOTHON app (Shopify)

Instead of storing credentials with us, you can connect your website through our plugin or app. We only process what is necessary to publish your articles.

What is stored on your website: an access token and a signing key created during pairing, plus your settings (target status, author, category). No SEOTHON credentials are stored on your website.

What we transmit to your website: the finished articles including title, text, images and SEO details.

What your website transmits to us: the connection status, the time of the last contact, and the version numbers of the plugin, the CMS and PHP, the latter so that we can detect compatibility problems. No visitor, customer, order or payment data is transmitted.

The permissions are deliberately narrow: the WordPress plugin provides five interfaces that write articles and media files only; it cannot access users, settings or files of the website. The Shopify app requests only the read_content and write_content scopes, so orders, customer data and payment data remain invisible to us.

Transmission is encrypted (TLS) and additionally signed, so that altered or replayed requests are rejected. You can end the connection at any time, in the dashboard under "Project options, Connection" or directly in the plugin. Access then becomes invalid immediately; uninstalling the plugin does this automatically.

The legal basis is the performance of the contract (Article 6(1)(b) GDPR). Where personal data is processed on your behalf, the data processing agreement described in section 7 applies.

8. Payment processing

We process subscriptions, plan changes and one-off purchases (additional articles) through Stripe (Stripe Payments Europe Ltd., Ireland); you manage payment details and invoices in the customer portal provided by Stripe. You enter payment details directly with Stripe; we neither receive nor store full card or bank details, only the identifier of your payment, the subscription status and the invoice data. For the one-off SEO system review we use, depending on your selection, bank transfer, invoice or a payment provider (for example PayPal or card processing) which processes the data under its own privacy terms.

9. Recipients and service providers

We pass on data only where this is necessary for operations. We have data processing agreements under Article 28 GDPR in place with the following service providers:

Transfer to the USA: when articles are created, content is transmitted to Anthropic in the USA. Personal data is not the subject of that processing, but it may be contained in transmitted website content. The transfer relies on the safeguards offered by Anthropic under Articles 44 et seq. GDPR. There is no separate data processing agreement with Anthropic. We transmit only the content required for the respective article or maintenance task, and no credentials or account data. The level of data protection in the USA is not fully comparable to that in the EU; in particular, broader access rights of state authorities cannot be ruled out.

10. No web analytics, no tracking

We use no analytics or tracking services: no Google Analytics, no Matomo, no advertising or retargeting pixels. We do not evaluate your behaviour on this website and do not combine it into profiles. Beyond the plain server accesses described in section 2, no usage data is created.

11. Your rights

You have the right at any time to access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR) and to object to processing (Article 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 5, 01067 Dresden, Deutschland.

An informal message to [email protected] is enough for all of these matters. We will respond within the statutory period of one month. If you want your customer account deleted entirely, you can request this in your account under "My data" or by writing to us; we will then delete the account, the projects and the associated data following the process described in section 7. You can also download your account data as a file there at any time.

12. Storage periods

We store personal data only for as long as it is needed for the respective purpose or as statutory retention periods require. In detail:

13. Language versions

This privacy notice is available in German and in English. Both versions describe the same processing activities and have the same content; the English version is a translation of the German version dated 20 September 2026. Your rights under the General Data Protection Regulation are not limited by the language version you read. If you notice any discrepancy between the two versions, please write to [email protected] and we will correct it.

← Back to the home page