negenio
Launch app →

Privacy Policy

Last updated: August 6, 2026

This Privacy Policy explains how NEOGENIO S.R.L. ("Neogenio", "we", "us", "our") collects, uses, shares, and protects personal data when you use the Neogenio SEO AI Engine (the "Service"): our AI-powered SEO content platform for agencies and businesses. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Romanian law. It applies to visitors to our website, account holders, members of customer organizations, and direct clients whose accounts we manage on their behalf.

1. Introduction and scope

This policy describes what personal data we process in connection with the Service, why we process it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have. It covers our website, the web application, and the automated content, publishing, and billing workflows that make up the Service. It does not cover third-party websites or services you connect to Neogenio (such as your own WordPress site), which are governed by their own privacy policies. Capitalised terms used here have the meaning given to them in our Terms of Service.

2. Data controller and contact

The data controller responsible for your personal data is NEOGENIO S.R.L., with its registered office at Bd. Basarabia 250, Sector 3, București, Romania, registered under CUI RO52397613. For any privacy matter, or to exercise your rights, contact us at contact@neogenio.com.

NEOGENIO S.R.L. has not appointed a Data Protection Officer, as it is not required to do so given the size and nature of its activities under the GDPR. All privacy enquiries and data-subject requests should be directed to contact@neogenio.com.

3. Categories of personal data we collect

Depending on how you use the Service, we may process the following categories of personal data:

  • Account and identity data: your name, the organization you belong to, your role (for example admin, SEO manager, content writer, or viewer), and account preferences.
  • Contact data: email address and any details you provide when communicating with us or receiving transactional messages.
  • Authentication data: credentials used to sign in and secure your account. Passwords are stored only in hashed form by our authentication provider; we never see them in plain text.
  • Billing and payment data: subscription plan, billing details, and transaction records. Card payments are processed by Stripe; we do not store full card numbers on our systems.
  • Connected-site data: the URLs and access credentials (such as application passwords or API keys) for the WordPress site(s) you connect, so we can publish content on your behalf.
  • Content and project data: the keywords, clusters, projects, briefs, articles, and other materials you create, import (manually, by CSV/Excel, or from WordPress), or store in the Service. This content may contain personal data if you choose to include it.
  • AI generation data: the inputs you provide for AI generation (topics, keywords, briefs, brand settings) and the outputs produced (draft articles, images, meta content, internal-link suggestions).
  • Brand-kit data: logos, colour palettes, and brand settings you upload or configure, used to style generated images and content.
  • Usage and technical data: log data, device and browser information, IP address, and interactions with the Service, used for security, reliability, and troubleshooting.
  • Cookie data: information stored via strictly necessary cookies and similar technologies and, if you accept it, a short-lived analytics identifier (see our Cookie Policy).
  • Support and communications data: the content of messages, requests, and correspondence you send to us.
  • Affiliate and referral data: where you participate in our affiliate/referral programme, the information needed to track referrals and process commission payouts.

4. How we collect personal data

We obtain personal data in the following ways:

  • Directly from you: when you register, configure your workspace, connect a site, create or import content, subscribe, or contact us.
  • Automatically: through log files, cookies, and similar technologies when you use the Service.
  • From connected third-party sites: for example, keywords or posts imported from a WordPress site you connect to Neogenio.
  • From data sources used to deliver features: SERP, ranking, and competitor data used to power keyword research, SERP analysis, competitor analysis, and rankings tracking. This data is generally about websites and search results rather than about you personally.

5. Purposes of processing and legal bases

We process personal data for the purposes below. The table sets out, for each purpose, the main categories of data involved and the legal basis under Article 6 GDPR:

PurposeData categoriesLegal basis
Provide and operate the Service (keyword research, clustering, SERP and competitor analysis, projects)Account, identity, authentication, content, usagePerformance of a contract (Art. 6(1)(b))
Generate and refresh AI content and imagesContent, AI generation, brand-kitPerformance of a contract (Art. 6(1)(b))
Publish content to your connected WordPress site(s)Connected-site, contentPerformance of a contract (Art. 6(1)(b))
Manage subscriptions, invoicing, and paymentsBilling and payment, identityContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Provide customer support and respond to requestsContact, support and communicationsContract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Secure, maintain, monitor, and improve the ServiceUsage and technical, log dataLegitimate interests (Art. 6(1)(f))
Operate the affiliate/referral programme and pay commissionsAffiliate and referral, billingContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Comply with legal, accounting, and tax obligationsBilling and payment, identityLegal obligation (Art. 6(1)(c))

6. Legal bases under Article 6 GDPR

We rely on one or more of the following legal bases, as described above:

  • Performance of a contract (Art. 6(1)(b)): to provide the Service you sign up for and take steps at your request before entering into a contract.
  • Consent (Art. 6(1)(a)): where you have given it, for example for optional communications or for the analytics cookie described in our Cookie Policy, which is set only after you accept it and deleted if you refuse. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legitimate interests (Art. 6(1)(f)): to secure, maintain, improve, and promote the Service, balanced against your rights and freedoms.
  • Legal obligation (Art. 6(1)(c)): where we must process or retain data to comply with the law, for example accounting and tax records.

7. AI processing

A core function of the Service is generating and refreshing content using artificial intelligence. To produce articles, images, meta content, and suggestions, the inputs you provide (such as topics, keywords, briefs, and brand settings) are transmitted to our AI sub-processor, Anthropic (Claude), which returns the generated output. This processing is necessary to deliver the AI features you request.

Customer content and inputs processed to generate articles and images are sent to our AI sub-processor, Anthropic (Claude), solely to produce the output you request, and are not used to train third-party AI models. In the future, we may introduce an optional, per-website feature that tailors generated content to a customer's own brand and writing style using only that customer's own website content. Any such feature would be enabled at the customer's choice (opt-in), applied only to that customer's own account and websites, and would never use one customer's data for the benefit of another customer. If and when we introduce it, we will disclose it and, where required, obtain your consent, and we will update this Privacy Policy accordingly.

Writing Style (optional feature). If you enable Writing Style for a website, we analyze content you choose to provide (pages of your website, article links, or documents you upload) to create a writing-style profile for that website. This profile is stored in your account, is used solely to generate content for your own websites, and is never shared with or used for other customers. You can edit the profile at any time, and you can delete the profile and any uploaded documents, or disable the feature, whenever you wish.

AI output may contain errors, inaccuracies, or omissions. You remain responsible for reviewing and verifying generated content before relying on it or publishing it. See our Terms of Service for details on AI-generated content.

8. Sub-processors

We use carefully selected third-party providers (sub-processors) to operate the Service. They process data on our behalf under written agreements that require appropriate security and confidentiality. Your connected WordPress site is a destination you control, not a Neogenio sub-processor, and is listed for transparency.

ProviderPurposeRegionSafeguard
SupabaseDatabase and application hostingEU (eu-central-1)EU processing
StripePayment processingEU / USStandard Contractual Clauses
ResendTransactional email deliveryUnited StatesStandard Contractual Clauses (SCCs)
n8nAutomation and workflow orchestrationEU (n8n Cloud)Within the EU/EEA
Anthropic (Claude)AI content and image generationUSStandard Contractual Clauses
SentryError and security monitoringEU (Germany)EU processing
Your WordPress site(s)Publishing destination for your contentUser-controlledControlled by you

We use Sentry to be alerted when the Service fails. This is processed on the basis of our legitimate interest in the security, availability and correct operation of the Service (Art. 6(1)(f) GDPR), and reports are sent to Sentry's European (Germany) endpoint. Error monitoring is not used for analytics, profiling or advertising: neither session recording nor performance tracking is enabled. We do not intentionally send personal data: no user identifier and no IP address is attached, web addresses are reduced to the page path before sending so that query parameters and access tokens are removed, and browser console output is excluded. A technical error message may still incidentally contain personal data; where it does, it is kept only for as long as the error report itself.

9. International data transfers

Some sub-processors may process data outside the European Economic Area (EEA), for example in the United States. Where this happens, we rely on appropriate safeguards recognised under the GDPR (primarily the European Commission's Standard Contractual Clauses, and adequacy decisions where available) to ensure your personal data continues to benefit from an essentially equivalent level of protection. You may request further information about these safeguards using the contact details above.

10. Data retention

We keep personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Retention periods vary by category:

  • Account and content data: for the duration of your contract with us. After account cancellation or termination, personal data is deleted or anonymised within 90 days of account closure, except where a longer period is required by law (for example, invoicing and tax records retained for the legally mandated minimum) or where retention is necessary to resolve disputes or enforce our agreements.
  • Projects, keywords, and generated content: retained while your account is active so you can access and reuse them; deleted or anonymised after account closure in line with the period above.
  • Billing, invoicing, and tax records: retained for the period required by Romanian accounting and tax law (generally several years) regardless of account closure.
  • Security and technical logs: retained for a limited period necessary for security, troubleshooting, and abuse prevention.

11. Your rights

Subject to the conditions in the GDPR, you have the right to:

  • Access: obtain confirmation of whether we process your data and a copy of it.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data (the "right to be forgotten") where applicable.
  • Data portability: receive certain data in a structured, commonly used, machine-readable format.
  • Objection: object to processing based on our legitimate interests.
  • Restriction: request that we limit processing in certain circumstances.
  • Withdraw consent: where processing is based on consent, at any time.
  • Not be subject to solely automated decisions that produce legal or similarly significant effects (see the automated decision-making section).

To exercise any right, contact us at contact@neogenio.com. We will respond without undue delay and in any case within one month of receiving your request, unless the request is complex, in which case we may extend the period by up to two further months and will inform you. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

12. Right to lodge a complaint

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), based in București, Romania. You may also complain to the supervisory authority in your country of residence or work. We would, however, appreciate the chance to address your concerns first, so please consider contacting us before doing so.

13. Security measures

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption: data is encrypted in transit (TLS) and at rest by our infrastructure providers.
  • Access controls: role-based access, authenticated sessions, and row-level security to restrict access to data.
  • Backups: regular, managed backups of the database to support recovery.
  • Monitoring and maintenance: logging, monitoring, and timely application of security updates.

14. Children's data

The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will take appropriate steps to delete it.

15. Automated decision-making and profiling

The Service uses automation to generate content, compute SEO scores, cluster keywords, and produce suggestions. These are content-production and analysis tools that assist you; they do not make decisions that produce legal effects concerning you or similarly significantly affect you. Final decisions about what to create, edit, and publish remain with you.

16. Third-party links and services

The Service may contain links to, or integrate with, third-party websites and services (such as your WordPress site, Stripe, or external resources). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing them with personal data.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you. We encourage you to review this policy periodically.

18. Contact

For any question about this Privacy Policy or to exercise your rights, contact NEOGENIO S.R.L. at contact@neogenio.com.

Limitation of Liability & Disclaimer

NEOGENIO S.R.L. provides the service and all information it contains "as is" and "as available". To the maximum extent permitted by applicable law, NEOGENIO S.R.L. assumes no responsibility or liability for any damages, losses, errors, omissions, inaccuracies, or consequences arising from your use of the service or reliance on any information or AI-generated content it produces, and makes no warranty of accuracy, completeness, fitness for a particular purpose, or uninterrupted availability. Nothing in this document excludes or limits liability that cannot be excluded or limited under Romanian or EU law — including liability for gross negligence, wilful misconduct, your statutory rights as a consumer, or our data-protection obligations.

Back to home