Legal
Privacy Policy
- 1. Who we are
- 2. Scope
- 3. Information we collect
- 4. How we use information
- 5. Legal bases (GDPR)
- 6. AI processing
- 7. Sites you analyze
- 8. How we share data
- 9. Sub-processors
- 10. International transfers
- 11. Data retention
- 12. Security
- 13. Your rights
- 14. Cookies
- 15. Children
- 16. Changes
- 17. Contact
1. Who we are
Findium Labs (“Findium”, “we”, “us”, or “our”) provides a website-intelligence platform that evaluates websites for search-engine optimization (SEO) and visibility within AI-powered search and assistant systems, and generates recommendations and fixes (the “Service”).
For the purposes of the EU/UK General Data Protection Regulation (“GDPR”), Findium Labs is the data controller of personal data processed about its account holders and visitors. Where you use the Service to analyze sites and process personal data contained in those sites, you act as the controller and Findium acts as your processor (see Section 7).
Controller: Sanzhar Mashabayev, Timofey Sidelnikov 38. Contact: sanzhar.mashabayev@gmail.com.
2. Scope
This policy explains how we handle personal data when you visit findiumlabs.com, create an account, and use the Service. It does not apply to third-party websites we link to, or to the websites you choose to analyze (which are operated by you or your clients).
3. Information we collect
3.1 Information you provide
- Account & identity: name, email address, password (stored only as a salted hash by our authentication provider), and organization/agency name.
- Billing: subscription plan and transaction history. Card payments are processed by our payment provider (Stripe); we do not store full card numbers on our servers.
- Website data you submit: the URLs you ask us to analyze and the publicly accessible content we retrieve from them — HTML, metadata, structured data, sitemap and robots files, headings, links, on-page text, service pages, reviews, and FAQ sections.
- Support & communications: messages you send us by email or through the Service.
3.2 Information we collect automatically
- Usage data: features used, audits run, reports generated, and interactions with the Service.
- Device & log data: IP address, browser type, device and operating system, timestamps, and referring pages.
- Cookies & similar technologies: see Section 14.
4. How we use information
- To provide, operate, and maintain the Service — crawling submitted sites, scoring them, and generating reports, recommendations, and fixes.
- To create and manage your account and authenticate you.
- To process payments and manage subscriptions.
- To provide customer support and respond to your requests.
- To monitor, secure, debug, and improve the Service, and to develop new features.
- To send service and transactional communications, and — where permitted — product updates you can opt out of.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our terms.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service and managing your account | Performance of a contract |
| Billing and payments | Performance of a contract; legal obligation |
| Security, fraud prevention, product improvement | Legitimate interests |
| Marketing communications and non-essential cookies | Consent |
| Compliance with law | Legal obligation |
You may withdraw consent at any time without affecting prior processing.
6. AI processing
To generate visibility analysis and fixes (for example, structured-data markup, FAQ content, and metadata), we send the relevant submitted website content to third-party AI model providers acting as our sub-processors. We instruct these providers to process the content only to return results to you. We do not authorize the use of your submitted content to train third-party foundation models, and we configure data-retention settings to the minimum the provider allows. Generated outputs are returned to your account and stored as part of your audit history until you delete them.
7. Sites you analyze
You are responsible for ensuring you have the right to submit a website for analysis and that doing so complies with applicable law. Public web pages may incidentally contain personal data (for example, staff names, contact details, or reviews). When we process such data on your behalf, we act as your processor: we process it only to provide the Service, on your documented instructions, and we apply appropriate security measures. If you require a Data Processing Agreement (DPA), contact us.
8. How we share data
We do not sell personal data. We share it only with:
- Service providers (sub-processors) who help us operate the Service, under contract and appropriate safeguards (Section 9).
- Professional advisers (e.g., lawyers, accountants) where necessary.
- Authorities where required by law, legal process, or to protect rights, safety, and security.
- Successors in connection with a merger, acquisition, or asset sale, subject to this policy.
9. Sub-processors
We use trusted third parties to deliver the Service, which may include:
| Provider | Purpose |
|---|---|
| Hosting & deployment (e.g., Vercel) | Serving the website and application |
| Database & storage (e.g., Supabase / AWS) | Storing account data, audits, and reports |
| Authentication (e.g., Clerk / Supabase Auth) | Account sign-in and security |
| Payments (Stripe) | Subscription billing and payment processing |
| AI providers (e.g., OpenAI / Anthropic) | Generating analysis and fixes |
| Analytics & email | Product analytics and transactional email |
A current list of sub-processors is available on request.
10. International transfers
We and our sub-processors may process data in countries other than your own, including the United States. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision.
11. Data retention
We keep personal data only as long as necessary for the purposes described in this policy. In general: account data is retained for the life of your account; audit history and reports are retained until you delete them or close your account; billing records are retained as required by tax and accounting law; and log data is retained for a limited period for security and debugging. After deletion, residual copies may persist in backups for a limited time before being overwritten.
12. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, and least-privilege practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your data and will notify you and regulators of a personal-data breach where legally required.
13. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Delete your data (“right to erasure”).
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority.
California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights.
To exercise any right, email sanzhar.mashabayev@gmail.com. We will respond within the timeframe required by applicable law.
14. Cookies
We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, with your consent where required, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
15. Children
The Service is intended for businesses and professionals and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of the Service after changes take effect constitutes acceptance.
17. Contact us
For any privacy question or request, or to exercise your rights, contact:
Findium Labs — Sanzhar Mashabayev
Timofey Sidelnikov 38
Email: sanzhar.mashabayev@gmail.com