Privacy and personal data
How we process data
Core tools work without an account. We use only the data needed for the requested operation, service security, and features you explicitly choose.
Data controller
The operator of SEOInstrumenti.com is the controller for the processing described in this notice. At the end of the page you can use the contact form or reveal the public contact email.
Tool submissions
Submitted URLs, domains and text are processed to run the selected check. They are not published or attached to an account unless a signed-in user explicitly saves a report.
A short-lived technical cache may prevent repeated external requests. Production cache retention is capped at 45 minutes and physical cleanup runs at least every 15 minutes.
Do not submit personal, confidential or contractually protected data unless it is necessary for the check.
Verified text-match corpus
Text submitted for a match check is processed transiently for the current request. We do not add it to the corpus, use it for training, or write the full text to application logs or the crawl queue. If you save a report to an account, the result and cited sources are retained, not the complete submitted text.
A bounded HTML response is fetched temporarily for public pages included in the corpus and visible text is extracted. The complete third-party HTML and article text are not retained after indexing. We keep the necessary text fingerprints, URL and operational records such as crawl date, scope, permission or licence basis, and the outcome of access-rule checks.
A source is included after verified site control, explicit permission or a documented applicable basis. Crawling is restricted to the declared HTTPS origin, path and sitemap, observes robots.txt and applicable TDM signals, and uses a clearly identified crawler. A site owner can withdraw permission or request removal through the contact form.
The corpus has operational limits for sources, pages, response size and refresh frequency. New, private, excluded, unavailable or unlisted publications may therefore be absent from a result.
Security and abuse prevention
The server processes an IP address, User-Agent, time and minimum request data to deliver the service, limit automated attacks and investigate technical incidents. Rate-limit keys are hashed instead of keeping a readable IP history.
Forms use CSRF tokens, honeypots, signed timestamps, minimum completion time, request limits and adaptive temporary blocking. We do not use Google reCAPTCHA or Cloudflare CAPTCHA.
Accounts, favourites and reports
Registration stores your email, username, display name, a secure password hash, preferred language, verification status and operational dates. We record the date and version of the terms accepted when the account is created. Passwords and tokens are never stored in readable form.
Favourites and recent tools can remain in your browser. When signed in, selected favourites and reports you save are associated with the account. You can view, download and delete your own reports.
Contact and service email
The contact form processes your name, email, subject and message so we can reply and protect the form from abuse. We do not use this information for marketing without separate consent.
We send only service messages needed for account verification, access recovery, security changes or a reply to your request.
External sites, analytics and advertising
When you submit a public URL, the relevant tool may make a bounded request to that website. Its server receives the ordinary technical request data. The text-match check searches the first-party verified corpus automatically and can optionally compare additional URLs you supply. Your complete submitted text is not sent to a search engine; supplementary exact-search links open only after your action.
Google Analytics loads only with a valid configuration and analytics consent. When Google AdSense is enabled, eligible public pages may load its Auto ads tag, which also provides Google Privacy & messaging. That Google-certified platform manages the separate advertising choice; the local analytics choice does not authorise advertising profiling.
Google and its selected advertising providers may process the IP address, browser and device data, requested page and consent signals to select, deliver, measure and protect ads according to the visitor’s choice. Advertising and analytics do not restrict access to the tools.
Legal grounds and retention
Requests, accounts and service messages are processed to provide the requested service. Minimal technical security data is processed under our legitimate interest in protecting the platform. Analytics and advertising storage and personalisation are used only when the applicable consent choice permits them, while data required by law is processed to meet a legal obligation.
Technical records, messages, tokens and saved reports are retained only for their stated or configured periods, then deleted or anonymised. A backup may remain until its scheduled rotation and is not reused for another purpose.
Your rights
You may request information, access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. The analytics choice can be changed in “Cookie settings”; when advertising is active, its separate choice can be changed in “Advertising privacy settings”.
We may request sufficient information to verify identity and scope. You may complain to the Bulgarian Commission for Personal Data Protection or your local EU supervisory authority.
Contact
A separate legal identity for the operator has not been configured for publication. The contact form and protected public email remain available, but they do not replace any disclosures required by applicable law.
For privacy, legal and general enquiries, use the contact form or reveal the public contact email.
Effective date: 16 August 2026