Privacy policy
1. Who is responsible for your data?
sirefs is provided by Uneven Bits ApS, CVR no. DK30487842, Dybbølsgade 39, 2. th., 1721 København V, Denmark ("we", "us").
We have two roles, depending on the data:
- We are the data controller for data about the people who use sirefs (account holders and the members of their workspaces), for the free checker on sirefs.com, and for visits to sirefs.com.
- We are a data processor for any personal data contained in the content our customers put into sirefs or ask it to collect (their project data, described below). Our customer is the controller for that data, and our data processing agreement applies.
All processing follows the EU General Data Protection Regulation (GDPR) and Danish data protection law.
2. What data do we process?
Account data (we are the controller). Your name and email address; your password as a hash, or the identifier of your Google account if you sign in with Google; the workspaces you belong to, with each member's name, email address and role; invitations you send (the invitee's email address); payment and billing details, handled by Stripe (we don't store card data); technical data such as IP address, browser type and the session cookie that keeps you signed in; and usage data such as log files, actions in the dashboard and your messages to support.
The free checker (we are the controller). The domain you enter, the report we produce (the GEO audit of your public pages and the answers AI engines gave to the prompts we asked), and a keyed hash of your IP address, not the address itself, which we use to limit how often one address can run the check. The form is protected by Cloudflare Turnstile, which processes signals from your browser to tell people from bots.
Project data (we are the processor). The brands, competitors, domains, prompts, markets and brand facts a customer enters, and the answers AI engines give to those prompts, with the pages they cite. This data is about brands and companies, and normally contains no personal data. Where it does, for example when a person's name is used as a brand or appears in an engine's answer, we process it only on the customer's behalf.
Visits to sirefs.com (we are the controller). Our web server logs requests (IP address, page, time, browser) to keep the site running and secure. sirefs.com sets no advertising or analytics cookies. When you're signed in to the sirefs dashboard, its session cookie is also sent to sirefs.com because it's set for the whole sirefs.com domain; it's strictly necessary and used only to keep you signed in.
3. Why do we process it?
We process account data to provide and administer sirefs: to create and maintain your account and workspace, process payments and invoices, send service emails (email verification, password resets, weekly digests and alerts you've switched on), provide support, protect the service against abuse, meet legal requirements, and improve the product.
We process free checker data to run the check, show you the report at its link, and keep the free checker from being abused.
We process project data only to provide sirefs to the customer: to collect the engines' answers to their prompts, analyse them, and show and send them the results.
4. On what legal basis?
- Contract (Article 6(1)(b) GDPR): what's needed to provide the service you signed up for.
- Legal obligation (Article 6(1)(c)): what we must keep under bookkeeping and tax law.
- Legitimate interests (Article 6(1)(f)): running, securing and developing the service, including limits on sign-in attempts and on the free checker, and knowing how people find us, as long as your interests don't outweigh ours.
- Project data is processed on the customer's documented instructions under the data processing agreement.
5. How long do we keep it?
- Account data: for as long as you have an account, including on the free plan. When you ask us to delete your account, we delete its data within 30 days, unless the law requires us to keep it (for example, the five-year bookkeeping requirement for invoices).
- Free checker reports and the IP hash: for as long as the report's link is useful, and at most 12 months. - Log files and technical data: up to 12 months. - Project data: until the customer deletes it or closes the account; see the data processing agreement.
- Backups: kept for up to 30 days, so deleted data can remain in backups for up to 30 days before it's overwritten.
6. Who do we share it with?
We use these sub-processors to provide sirefs:
| Sub-processor | Location | What they do |
|---|---|---|
| Contabo, or Hetzner if we move or add servers | EU | Hosting of our servers. Our databases (MongoDB and Redis) run on these servers, operated by us. |
| Cloudflare | EU and USA | DNS, network delivery and security for sirefs.com and its subdomains, Turnstile on the free checker, and storage of raw engine answers and backups (R2). |
| DataForSEO | EU (Estonia) | Collects the answers of ChatGPT, Gemini, Google AI Overviews and AI Mode, and Perplexity's API, for the prompts in a project or a free check. Receives the prompts and the market, not account data. |
| Bright Data | Israel | Collects the answers of the Perplexity and Copilot apps for the prompts in a project. Receives the prompts and the market, not account data. |
| Anthropic | USA (and Ireland) | Claude: answers to the prompts in a project, suggestions of brands, competitors and prompts during onboarding and the free check, and analysis of collected answers. Receives prompts, brand and competitor names, the public pages read during onboarding and the answers, not account data. |
| xAI | USA | Grok: answers to the prompts in a project. Receives the prompts, not account data. |
| Brevo | EU | Sending service emails, digests and alerts. |
| Stripe | EU and USA | Payments and invoices. |
| Sentry | EU | Error monitoring. Error reports can contain extracts of the data being processed when the error happened. |
| EU and USA | Sign-in with Google, when you choose it. |
Transfers to the USA are made under the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise under the European Commission's Standard Contractual Clauses. We never sell personal data.
7. What are your rights?
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Where we are the controller, write to [email protected] to use them. Where the data is a customer's project data, contact that customer; if you're unsure, write to us and we'll pass your request on.
You can also complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk) if you believe we process your data in breach of the GDPR.
8. How do you contact us?
Questions about this policy or your data: [email protected], or by post to Uneven Bits ApS, Dybbølsgade 39, 2. th., 1721 København V, Denmark.