Findium Labs ← Back to site

Legal

Privacy Policy

Last updated: 21 June 2026 · Effective: 21 June 2026

Plain-language summary. Findium Labs is a tool that audits websites for SEO and AI-search visibility. We collect the account and billing details we need to run the service, the website URLs and page data you ask us to analyze, and basic usage information. We don't sell your personal data. You can access, correct, export, or delete your data at any time by emailing sanzhar.mashabayev@gmail.com.

1. Who we are

Findium Labs (“Findium”, “we”, “us”, or “our”) provides a website-intelligence platform that evaluates websites for search-engine optimization (SEO) and visibility within AI-powered search and assistant systems, and generates recommendations and fixes (the “Service”).

For the purposes of the EU/UK General Data Protection Regulation (“GDPR”), Findium Labs is the data controller of personal data processed about its account holders and visitors. Where you use the Service to analyze sites and process personal data contained in those sites, you act as the controller and Findium acts as your processor (see Section 7).

Controller: Sanzhar Mashabayev, Timofey Sidelnikov 38. Contact: sanzhar.mashabayev@gmail.com.

2. Scope

This policy explains how we handle personal data when you visit findiumlabs.com, create an account, and use the Service. It does not apply to third-party websites we link to, or to the websites you choose to analyze (which are operated by you or your clients).

3. Information we collect

3.1 Information you provide

3.2 Information we collect automatically

4. How we use information

5. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing the Service and managing your accountPerformance of a contract
Billing and paymentsPerformance of a contract; legal obligation
Security, fraud prevention, product improvementLegitimate interests
Marketing communications and non-essential cookiesConsent
Compliance with lawLegal obligation

You may withdraw consent at any time without affecting prior processing.

6. AI processing

To generate visibility analysis and fixes (for example, structured-data markup, FAQ content, and metadata), we send the relevant submitted website content to third-party AI model providers acting as our sub-processors. We instruct these providers to process the content only to return results to you. We do not authorize the use of your submitted content to train third-party foundation models, and we configure data-retention settings to the minimum the provider allows. Generated outputs are returned to your account and stored as part of your audit history until you delete them.

7. Sites you analyze

You are responsible for ensuring you have the right to submit a website for analysis and that doing so complies with applicable law. Public web pages may incidentally contain personal data (for example, staff names, contact details, or reviews). When we process such data on your behalf, we act as your processor: we process it only to provide the Service, on your documented instructions, and we apply appropriate security measures. If you require a Data Processing Agreement (DPA), contact us.

8. How we share data

We do not sell personal data. We share it only with:

9. Sub-processors

We use trusted third parties to deliver the Service, which may include:

ProviderPurpose
Hosting & deployment (e.g., Vercel)Serving the website and application
Database & storage (e.g., Supabase / AWS)Storing account data, audits, and reports
Authentication (e.g., Clerk / Supabase Auth)Account sign-in and security
Payments (Stripe)Subscription billing and payment processing
AI providers (e.g., OpenAI / Anthropic)Generating analysis and fixes
Analytics & emailProduct analytics and transactional email

A current list of sub-processors is available on request.

10. International transfers

We and our sub-processors may process data in countries other than your own, including the United States. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision.

11. Data retention

We keep personal data only as long as necessary for the purposes described in this policy. In general: account data is retained for the life of your account; audit history and reports are retained until you delete them or close your account; billing records are retained as required by tax and accounting law; and log data is retained for a limited period for security and debugging. After deletion, residual copies may persist in backups for a limited time before being overwritten.

12. Security

We implement administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, and least-privilege practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your data and will notify you and regulators of a personal-data breach where legally required.

13. Your rights

Depending on where you live, you may have the right to:

California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights.

To exercise any right, email sanzhar.mashabayev@gmail.com. We will respond within the timeframe required by applicable law.

14. Cookies

We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, with your consent where required, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.

15. Children

The Service is intended for businesses and professionals and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of the Service after changes take effect constitutes acceptance.

17. Contact us

For any privacy question or request, or to exercise your rights, contact:

Findium Labs — Sanzhar Mashabayev
Timofey Sidelnikov 38
Email: sanzhar.mashabayev@gmail.com