Legal
Privacy
What we collect, why we collect it, how long we keep it and what you can ask us to do with it.
Last reviewed 1 August 2026. Where this document changes materially, the revision date changes with it.
01
Who this applies to
This policy covers ixseo.com and the services provided through it. IXSEO is a search intelligence and website improvement service. Genyra is the parent technology brand; Elite Security Europe and Intelis contribute specialist expertise to defined parts of the service and are separate organisations.
Where an engagement is agreed under a separate contract, that contract governs the handling of information supplied during it. This document covers the public website and the free services available through it.
02
What we collect
When you run an analysis or use a tool. The website address you enter, the modules you select, and any competitor addresses you supply. We also derive a salted, truncated hash of the network address the request came from. That hash is used to apply a rate limit and cannot be reversed to identify anyone. The address itself is never stored.
When you submit an enquiry or request a report. Your name, email address and whatever else you choose to provide — company, role, telephone number, website and the content of your message. Only the name, email address and your consent to reply are required.
What the analysis itself gathers. Publicly available information about the website you submitted: page content as served, response headers, public DNS records, and measured performance data. Where the Public Exposure module is selected, this may include organisational email addresses published on the website. These are treated as described in the exposure section below.
Visit counting. The address of each page opened, whether it was the page you arrived on, the external website you followed a link from, any campaign tags in the address, and a device category and country code derived from the connection. Nothing is stored on your device to do this and nothing links one page, visit or person to another. It is described in full in the cookie policy.
Google Analytics. Nothing, unless you consent. If you do, a small set of enumerated events is recorded — that an analysis started, that a tool was used, that a report was viewed. Findings, website content, email addresses and message contents are never sent to analytics under any circumstances.
03
Why we collect it
- To provide what you asked for. An analysis cannot run without a website address, and a reply cannot be sent without an email address.
- To prevent abuse. The hashed source identifier exists so that the analysis endpoints cannot be used as a scanning service. Without it, the free tools would have to be withdrawn.
- To follow up on a genuine enquiry. Where you have asked us to reply, we use your details to do so. We do not add enquirers to a marketing list.
- To understand how the site is used. Visit counts that store nothing and identify nobody, and — only with consent — aggregate Google Analytics event counts.
The lawful basis is performance of a contract or steps taken at your request for enquiries and analyses, and legitimate interests for abuse prevention and for counting visits without identifying anyone. Google Analytics relies on consent, which you can withdraw at any time.
05
How long we keep it
Retention periods are configurable and are stated in full on the data retention page. In summary:
- Raw fetched page content is held only for the duration of the analysis and a short window afterwards, then discarded.
- A public snapshot is retained for a limited period so the result page remains reachable, then removed automatically.
- Rate-limit hashes expire within an hour and are not linked to anything else.
- Enquiry details are retained according to business policy for as long as needed to deal with the enquiry and any relationship arising from it.
We will not state a specific deletion timeframe that the implementation does not actually enforce. The periods described are the ones the system applies.
06
Exposure findings and other people's information
The Public Exposure module may identify organisational email addresses published on a website, and may indicate association with known third-party incidents. This concerns people who did not themselves ask to be part of an assessment, which is why it is handled restrictively.
- Public output shows counts, categories and masked samples only. Complete addresses are never displayed publicly.
- Passwords, credential material, raw breach records and stealer-log content are never displayed, retained or processed.
- Detailed organisational findings require domain verification and appropriate authorised access to any third-party source.
- An association with a third-party incident is never presented as evidence that an organisation has been compromised.
07
Your rights
Where data protection law applies to you, you have the right to ask what we hold about you, to have it corrected, to have it deleted, to restrict or object to its processing, and to receive it in a portable form. You may also complain to your supervisory authority.
To exercise any of these, contact us through the contact page. We will ask enough to be satisfied who you are and no more. Because most analysis data is not linked to an identified person, a request about an analysis is usually best made with the result address you want removed.
Withdrawing analytics consent takes effect immediately and can be done at any time from the controls on the cookie policy page.
08
How information is protected
Traffic to this website is encrypted in transit. API keys are held server-side and are never exposed to the browser. Source network addresses are hashed with a salt and truncated before storage. Logs are written without secrets and without the content of enquiries.
No system is beyond compromise, and we would rather say so than imply otherwise. If you believe you have found a weakness in IXSEO’s own infrastructure, the vulnerability disclosure page sets out how to tell us.
09
Changes to this policy
Where this policy changes materially, the review date at the top of the page changes with it. We will not make a change that retrospectively widens how previously collected information is used.
Related documents
Questions about this document can be raised through the contact page. Nothing here is intended to restrict rights you hold under applicable law.