Privacy Policy

Last Updated: February 2, 2026 | Effective: February 2, 2026

Your Privacy Matters. This Privacy Policy explains how GenieOptimize collects, uses, shares, and protects your information. We comply with GDPR (EU), CCPA/CPRA (California), and major global privacy laws.

1. Introduction & Controller Information

1.1 Who We Are

Data Controller: GenieOptimize (operated by r6lab Radoslaw Jozefowicz)
Address: ul. Akacjowa 3, 55-003 Krzykow, Poland
EU VAT/NIP: PL9730929262
Email: privacy@genieoptimize.com

1.2 Scope

This Privacy Policy applies to all users of GenieOptimize services including: website visitors, dashboard users, API consumers, SDK integrators, and subscribers.

1.3 EU Representative

EU Representative: [Name]
Address: [EU Address]
Email: privacy@genieoptimize.com (Subject: "EU Representative")

2. Information We Collect

2.1 Information You Provide

CategoryData TypesPurpose
Account InfoName, email, password hashAccount creation, authentication
Billing InfoPayment method (via Stripe), billing addressPayment processing
Profile DataCompany name, website URL, industryService customization
Support DataMessages, attachments, feedbackCustomer support
Website ContentURLs submitted for analysis, page contentAI optimization generation

2.2 Information Collected Automatically

CategoryData TypesCollection Method
Usage DataPages viewed, features used, time spentApplication logs
Technical DataIP address, browser type, device type, OSServer logs, analytics
Performance DataLoad times, API response times, errorsMonitoring tools
SDK DataSDK installation status, optimization injection successSDK beacon, API calls
CookiesSession ID, preferences, analyticsBrowser cookies

2.3 Information from Third Parties

2.4 Information We Do NOT Collect

3. How We Use Your Data

3.1 Primary Purposes

3.2 Secondary Purposes

3.3 AI Processing

Important: Your website content is sent to third-party AI providers (primarily Anthropic Claude and OpenAI GPT-4o) for analysis and Recommendation Intelligence generation. These providers:

  • Process data under their own terms/policies
  • Do NOT use your data for model training (per enterprise agreements)
  • May log requests for abuse prevention and system monitoring
  • Are bound by data processing agreements (DPAs) with Standard Contractual Clauses
  • Used to generate: content analysis, optimization rules, recommendation intelligence (use cases, competitive positioning, feature mappings, customer profiles)

4. Legal Bases for Processing (GDPR)

4.1 EU/EEA Users

Under GDPR Article 6, we process data based on:

PurposeLegal BasisGDPR Article
Account creation, service deliveryContract performanceArt. 6(1)(b)
Payment processingContract performanceArt. 6(1)(b)
Legal obligations (tax, AML)Legal obligationArt. 6(1)(c)
Marketing communicationsConsentArt. 6(1)(a)
Product improvement, analyticsLegitimate interestArt. 6(1)(f)
Fraud prevention, securityLegitimate interestArt. 6(1)(f)

4.2 Legitimate Interest Balancing

Where we rely on legitimate interest, we've balanced our interests against your rights:

You may object to legitimate interest processing (see Section 7).

5. Data Sharing & Third Parties

5.1 Service Providers (Processors)

ProviderPurposeData SharedLocation
AnthropicAI analysis, Recommendation Intelligence (Claude)Website content, URLs, product dataUS
OpenAIAI analysis, Recommendation Intelligence (GPT-4o)Website content, URLs, product dataUS
AWSHosting, database, CDNAll service dataUS (us-east-1)
StripePayment processingBilling info, emailUS (GDPR-compliant)
ClerkAuthenticationEmail, name, OAuth profileUS

All processors bound by Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) for EU data.

5.2 We Do NOT Share Data With

5.3 Legal Disclosures

We may disclose data when required by law:

We will notify you unless legally prohibited.

5.4 Business Transfers

In event of merger, acquisition, or asset sale, your data may transfer. We'll notify you and ensure continued protection under this policy or equivalent.

6. International Data Transfers

6.1 Primary Locations

6.2 EU/EEA to US Transfers

Safeguards under GDPR Chapter V:

6.3 Other Regions

6.4 Transfer Impact Assessment

We've conducted Transfer Impact Assessments (TIAs) per Schrems II requirements, concluding appropriate safeguards exist.

7. Your Privacy Rights

7.1 GDPR Rights (EU/EEA/UK)

Under GDPR, you have the right to:

Right of Access (Art. 15)

Right to Rectification (Art. 16)

Right to Erasure / "Right to Be Forgotten" (Art. 17)

Exceptions: Legal obligations, legal claims, public interest

Right to Restrict Processing (Art. 18)

Right to Data Portability (Art. 20)

Right to Object (Art. 21)

Automated Decision-Making (Art. 22)

Right to Lodge Complaint

7.2 CCPA/CPRA Rights (California)

California residents have the right to:

Right to Know (CCPA § 1798.100)

Right to Delete (CCPA § 1798.105)

Right to Opt-Out of Sale/Sharing (CCPA § 1798.120)

Right to Correct (CPRA § 1798.106)

Right to Limit Use of Sensitive Personal Information (CPRA § 1798.121)

Right to Non-Discrimination (CCPA § 1798.125)

7.3 Exercising Your Rights

To exercise any rights:

  1. Email: privacy@genieoptimize.com (for all privacy, GDPR, CCPA, and EU representative inquiries)
  2. Subject: "Privacy Rights Request - [Right Type]"
  3. Include: Account email, specific request, verification info
  4. Response Time: 30 days (GDPR), 45 days (CCPA) - may extend with notice

Verification Process

To prevent unauthorized disclosure, we verify your identity through:

Authorized Agents (CCPA)

California residents may designate authorized agents. Agent must provide:

8. Data Retention & Security

8.1 Retention Periods

Data TypeRetention PeriodReason
Account dataAccount lifetime + 90 daysService provision, account recovery
Billing records7 yearsTax/accounting requirements
Support tickets3 yearsCustomer service improvement
Usage logs1 yearAnalytics, security
Marketing consentUntil withdrawalLegal compliance
Anonymized analyticsIndefinitelyProduct improvement

8.2 Security Measures

Technical Safeguards:

Organizational Safeguards:

8.3 Breach Notification

In event of data breach affecting personal data:

9. Cookies & Tracking Technologies

9.1 Cookie Types

TypePurposeConsent RequiredExpiry
Strictly NecessaryAuthentication, session managementNo (ePrivacy exception)Session / 30 days
FunctionalPreferences, settingsYes (implied by use)1 year
AnalyticsUsage statistics (aggregated)Yes (explicit consent)1 year
MarketingEmail campaign trackingYes (explicit consent)90 days

9.2 Your Cookie Choices

9.3 Third-Party Cookies

See Cookie Policy for full details.

10. Children's Privacy

10.1 Age Restrictions

10.2 Parental Verification

We do not knowingly collect personal data from children. If we discover we've collected such data:

10.3 Reporting

If you believe a child has provided data, contact: privacy@genieoptimize.com

11. Changes & Contact

11.1 Policy Changes

We may update this Privacy Policy. Material changes notified via:

Continued use after changes = acceptance.

11.2 Previous Versions

Archived versions available upon request: privacy@genieoptimize.com

11.3 Contact Us

Privacy, GDPR, CCPA, EU Representative: privacy@genieoptimize.com

Note: As a small SaaS startup, we do not currently have a designated Data Protection Officer (DPO) as it is not required under GDPR Article 37 for our scale and data processing activities. All privacy and GDPR requests are handled through privacy@genieoptimize.com. If we grow to require a DPO in the future, we will update this policy accordingly.

General Inquiries: hello@genieoptimize.com

Support: support@genieoptimize.com

Security: security@genieoptimize.com

Mailing Address:
r6lab Radoslaw Jozefowicz
ul. Akacjowa 3
55-003 Krzykow
Poland

11.4 Supervisory Authorities

You have the right to lodge complaints with: