Policies
GDPR Policy
Effective 22 September 2026 · Superstar SEO LLC · Questions to help@legiit.com
How Superstar SEO LLC meets the General Data Protection Regulation and the UK GDPR when people in the European Economic Area or the United Kingdom use Legiit Keywords. Read it with the Privacy Policy, which lists exactly what we collect.
1. Who we are
Superstar SEO LLC, 2411 N. Oak Street 105E, Myrtle Beach, SC 29577, USA, operates Legiit Keywords and is the data controller for the personal data described in the Privacy Policy. Our contact for anything about personal data, including requests under the GDPR, is help@legiit.com. We have not appointed a statutory Data Protection Officer because our processing does not meet the thresholds that require one; the same address reaches the person responsible.
2. What personal data we process
The Service is built around websites, keywords and search results, not people. The personal data we hold is limited to:
- Your email address, display name and sign-in records.
- The sites, keywords and settings you submit, which may identify you or your business.
- Your Stripe customer reference, plan and the ids of your purchases. Card details never reach us.
- Server logs with IP address, browser and pages requested, kept for security.
- Support correspondence you send us.
Pages we read from public websites and search results can contain names or contact details published there. We process them only to produce your research and do not build profiles of the people they concern.
3. Our lawful bases
- Contract (Article 6(1)(b)): running your account, your research and your purchases.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing abuse of free previews and promotions, answering support, and measuring how the Service is used in aggregate. We have balanced these interests against your rights and believe they do not override them.
- Legal obligation (Article 6(1)(c)): keeping tax and accounting records of payments.
- Consent (Article 6(1)(a)): only where we ask for it, for example if we ever email you about new features. You can withdraw consent at any time.
We do not carry out automated decision-making with legal or similarly significant effects on you. Automated systems judge websites and keywords, not people.
4. Your rights
You may ask us to:
- confirm whether we process your personal data and give you a copy of it (access);
- correct data that is wrong or incomplete (rectification);
- delete your data (erasure), which you can also do yourself from Account settings;
- restrict processing while a dispute is settled;
- receive the data you gave us in a portable format;
- object to processing based on our legitimate interests;
- withdraw consent where consent was the basis.
Email help@legiit.com from the address on your account. We answer within one month, or tell you within that month if a complex request needs up to two more. There is no charge unless a request is clearly unfounded or excessive. You also have the right to complain to your supervisory authority: in the UK the Information Commissioner's Office, in the EU the authority of the country where you live or work.
5. Processors and international transfers
We use service providers to host and run Legiit Keywords. Each acts under a written contract that restricts it to our instructions: Supabase (database and sign-in), Vercel (web hosting), Railway (research workers), Stripe (payments), Resend (email), DataForSEO (search data), Firecrawl (page reading) and Anthropic (automated analysis). Some of these providers process data in the United States. Where personal data leaves the EEA or the UK we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as each provider makes available.
6. Retention
Account data and research results are kept while your account exists and deleted within 30 days of your account being closed, except payment records we must keep for tax purposes (seven years) and cached third-party search data that contains no account details. Server logs are kept for 90 days.
7. Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who run the Service, protected by multi-factor authentication, and every account can only reach its own rows in the database. If a breach is likely to put your rights at risk we will tell the supervisory authority within 72 hours and tell you without undue delay.
8. Children
The Service is for businesses and adults. We do not knowingly process the data of anyone under 18 and delete it if we learn we have.
9. Changes
We review this policy at least once a year and whenever our processing changes. The effective date at the top shows the current version.