Privacy Policy
Your data security and privacy are our highest priorities. We treat your brand intelligence and personal data with enterprise-grade security and full GDPR compliance.
1. Data Controller
VisiaGEO operates as the Data Controller for account, billing, and diagnostic analytics data. For any inquiries regarding personal data protection, exercising your GDPR rights, or requesting data deletion, you can contact our privacy team directly at contact@visiageo.com.
2. Information Collection
We collect and process the following categories of information:
- Account & Identification Data: Email address, name, organization/agency name, user ID, and credentials managed securely via Keycloak OIDC authentication.
- Audit & Brand Parameters: Target brand names, domain URLs, search queries/prompts, and competitor domains submitted to perform GEO diagnostic audits.
- Billing & Transactional Metadata: Subscription status, purchased credit packs, Stripe customer IDs, and transaction histories (card details are processed directly by Stripe and never stored on our servers).
- Technical Logs: API key usage, timestamps, and diagnostic error logs for system security and operational integrity.
3. Subprocessors & Third-Party Integrations
To generate GEO diagnostics, technical audits, and provide secure billing, VisiaGEO collaborates with vetted industry-standard service providers acting as Data Processors:
- AI Model Providers & Inférence Gateways: OpenAI (ChatGPT), Anthropic (Claude), Google Cloud (Gemini), Perplexity AI, Mistral AI, DeepSeek, and OpenRouter. Prompts and queries are transmitted strictly for diagnostic evaluation. Your data is not used to train public foundational AI models.
- Web Crawling & Technical Analysis: Firecrawl for extracting publicly accessible technical signals (robots.txt, metadata, sitemaps).
- Payment Processing: Stripe Inc. for PCI-DSS compliant payment processing, subscriptions, and invoicing.
- Identity & Authentication: Keycloak for secure single sign-on (SSO) and OAuth2/OIDC token issuance.
- Audience Analytics: Plausible Analytics for privacy-first, cookieless audience metrics.
4. Data Security & Storage
All data in transit is encrypted using modern TLS 1.3 / HTTPS encryption. Audit reports and account information are stored in secure PostgreSQL databases with encrypted at-rest storage and strict role-based access control (RBAC). Report data is private and accessible only to authorized workspace users and administrators.
5. Cookies, Local Storage & Audience Analytics
We prioritize user privacy and minimize local storage footprints:
- Strictly Necessary Cookies: Essential for user authentication (Keycloak session tokens) and security. These cannot be disabled.
- Local Storage Preferences: Used locally in your browser to remember non-sensitive UI settings (theme dark mode, language preference, cookie consent status).
- Audience Analytics (Plausible Analytics): We utilize Plausible, a lightweight, privacy-friendly, cookieless analytics solution. Plausible does not set tracking cookies or create cross-device profiles. Analytics are only executed on public marketing routes with prior explicit user consent.
6. Data Retention Policy
We retain data only as long as necessary for providing the service and meeting legal obligations:
- Account & Subscription Data: Retained for the active duration of your account plus statutory limitation periods.
- Audit Reports & Evolution History: Maintained while your account remains active or until explicitly deleted by you via the dashboard.
- Invoicing & Billing Records: Retained for 10 years in compliance with statutory financial and tax obligations.
- Security & API Access Logs: Retained for up to 12 months for security auditing and threat detection.
7. Your GDPR Rights
Under the European General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure (Right to be Forgotten): Request the permanent deletion of your account, API keys, and audit history.
- Right to Data Portability: Export your reports and structured data in standard formats (PDF, JSON, CSV).
- Right to Restriction & Objection: Object to or restrict specific processing activities.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your national supervisory authority (e.g., CNIL in France) if you consider that our processing breaches data protection regulations.
To exercise any of these rights, simply email us at contact@visiageo.com. We respond to all verified requests within 30 days.