Data Protection and GDPR
Last updated: 10 October 2026
This page is for customers who need to know how OnlyAI SEO fits the EU GDPR and the UK GDPR. The everyday detail of what we collect is in the Privacy Policy; this page covers the roles, the providers we use and what we offer businesses.
Our roles
- Controller. For your account, sign-in, billing and usage records, OnlyAI Matters decides why and how the data is used. See the Privacy Policy.
- Processor. For the text you send to OnlyAI Cloud in an AI request, we act on your instructions. We use it only to produce the answer, we do not store it, and we do not use it to train models. You remain the controller of that content and decide whether it may contain personal data.
Please do not send special-category data (for example health or political data) or other people’s sensitive personal data in an AI request.
Your rights
You can ask for access, correction, deletion, a portable copy, restriction, or object to processing. Email us from the address on your account and we will act within one month. If you are not satisfied, you may complain to your data protection authority.
Sub-processors
We use these providers to deliver OnlyAI SEO. We choose them for their security and sign or accept data protection terms with each.
- Vercel: website and API hosting, and the AI gateway.
- Neon: database for account, key, usage and billing records.
- OpenAI (through the Vercel AI Gateway): processes the text of AI requests.
- AutoArticle AI: fallback AI engine if the main one is unavailable; processes the text of those requests.
- Resend: sends service emails.
- Dodo Payments: merchant of record for paid plans; an independent controller of payment data.
- Cloudflare: DNS and network protection.
If we add or replace a sub-processor that handles the text of AI requests, we will update this list before it starts and email customers with a data processing agreement.
International transfers
We are based in India, and our providers operate in several countries, including outside the EEA and the UK. Where the law requires it, transfers rely on approved safeguards such as the standard contractual clauses and the providers’ own transfer mechanisms.
Security
Passwords are stored as hashes, API keys are hashed for checking and encrypted where a copy is kept, traffic uses HTTPS, sign-in and key use are rate limited, and database access is restricted. We keep usage records to the minimum needed and do not store the text of AI requests.
Personal data breaches
If a breach affects personal data we hold, we will notify the supervisory authority where the law requires it, normally within 72 hours of becoming aware, and tell affected customers without undue delay with what we know and what to do.
Retention and deletion
We keep account data while the account exists and delete it within 30 days of a deletion request. Billing and payment records are kept for as long as tax and accounting law requires.
Data processing agreement
If you need a signed data processing agreement (DPA), including the standard contractual clauses, email us from your account address. It is available to any paid plan, on request and at no extra cost.
Contact
Questions about this page, or a request about your data: [email protected]. We answer within a few working days.
OnlyAI Matters, Bangalore, India.
Privacy · Terms · Refunds · Data protection · License