# Privacy Policy URL: https://hacktheseo.com/privacy-policy/ Date: 2023-10-16 Last modified: 2026-09-21 Author: Hacktheeric --- **WHO IS RESPONSIBLE FOR YOUR DATA** The data controller is HACK THE SEO, a simplified joint-stock company (société par actions simplifiée) with share capital of €15,000, registered under SIREN 987505708, whose registered office is at La Halle de l’Innovation, ZAC Cambacérès, 10 place Françoise Héritier, 34000 Montpellier, France. Publication director: Eric Ibanez. You can reach us at [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com). **ARTICLE 1 – PERSONAL INFORMATION COLLECTED** Creating an account and subscribing: When you create an account or take out a subscription, we collect the personal information you provide and which is necessary for the service to work, such as your name, your email address and the billing details needed to issue your invoice. We never receive or store your card number: payment is handled by Stripe, and we only ever see the last digits and the status of the transaction. When you browse our site, we automatically receive your computer’s Internet Protocol address (IP address), which tells us the browser and operating system you are using. Data may also be stored in or retrieved from your browser, usually in the form of cookies. See Article 3. Our free WordPress plugin: The Hack The SEO plugin published on wordpress.org contains an optional form offering a guide. If, and only if, you fill it in and tick the consent box, the plugin sends six fields to hacktheseo.com: your email address, your consent, the version of the wording you agreed to, a fixed word identifying the source, the plugin version, and your WordPress language code. Nothing else is sent: not your site address, not your name, no measurement and no content from your site. As with any request made over the internet, our server also receives the IP address of the sending server and the User-Agent header of the request. We pass your email address to Klaviyo, which sends you a confirmation email. You join the list only after you click the link in that email; an address that is never confirmed receives nothing further and is not added to the list. Every message we send carries an unsubscribe link. The plugin sends nothing at all unless you submit that form, and it never sends anything on its own. Emails: If you have decided to follow Hack The SEO by email — through a form on our site, through the plugin form described above, or by ticking the corresponding box when subscribing — we use your email address to send you news about our products and our work. If you no longer wish to receive these emails, you can unsubscribe at any time using the unsubscribe link at the bottom of every email, or by writing to [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com). Unsubscribing through the link takes effect immediately; a request sent by email is handled as soon as we read it. The emailing tool we use is Klaviyo, Inc., located in the United States. Klaviyo acts as a processor on our behalf and is bound by the requirements of the General Data Protection Regulation (GDPR). Transfers of personal data to the United States rely on Klaviyo’s participation in the EU-U.S. Data Privacy Framework, and on the European Commission’s Standard Contractual Clauses for any transfer falling outside that framework. Klaviyo’s privacy notice: [https://www.klaviyo.com/legal/privacy/privacy-notice](https://www.klaviyo.com/legal/privacy/privacy-notice) Audience measurement: We use audience analysis tools, including Google Analytics through Google Tag Manager, to understand activity on our site and improve it. These tools receive data about your browsing on our site. This data is pseudonymised, not anonymous: it is tied to an identifier that can single out a browser. These cookies are placed only after you have accepted them in our consent banner. Advertising: We use advertising cookies, including the Meta (Facebook) pixel, so that we can show you content related to Hack The SEO when you browse other sites. These cookies are placed only after you have accepted them in our consent banner, and never before. The data they collect can single out a browser, so it is personal data even when it does not carry your name. How long are my personal data kept? The length of time we retain personal data depends on our business needs and legal obligations. For a subscription, we keep your account data for as long as the contract lasts, and for 3 years after it ends. Invoices and their supporting accounting records are kept for ten years from the close of the financial year, as Article L123-22 of the French Commercial Code requires. We keep them even after the rest of your data has been deleted, we use them for nothing else, and access is limited to the people who need them for accounting or tax purposes. If you agree to receive our emails, your data is kept until you unsubscribe or ask for deletion, and in any case no longer than 3 years from your last contact with us (for example, a click in one of our emails). The record of your consent — its date, the wording you accepted, and where it was given — is kept for the whole time the consent is valid and for 5 years afterwards, because we must be able to prove it. If an account is created, the data is kept until you ask for its deletion, and in any case no longer than 3 years from the end of the commercial relationship or from your last contact. When you contact us about our products or apply for a job, the data is kept for 3 years from the date of collection or from your last contact. **ARTICLE 2 – LEGAL BASIS AND CONSENT** On what basis do you process my data? Each processing operation rests on one of the legal bases set out in Article 6 of the GDPR: – Your account and your subscription: performance of the contract between you and us.** – Invoices and accounting records: our legal obligations. – Marketing emails, the plugin guide form, audience measurement cookies and advertising cookies: your consent. – Keeping our site and our service secure: our legitimate interest. How do you obtain my consent? Where we rely on consent, we ask for it by a clear affirmative act: a box you tick yourself, or a button you press in our consent banner. We never assume it, and a box is never pre-ticked. Is providing your data obligatory? It depends. The email address and the billing details we ask for when you subscribe are required to enter into and perform the contract: without them we cannot open your account, take your payment, or give you access to the service. Everything else is optional, and refusing it costs you nothing but the feature concerned — the address you give to receive our guide or our newsletter, and every non-essential cookie. Our free WordPress plugin works in full whether or not you ever fill in the guide form. How can I withdraw my consent? You can withdraw your consent at any time, and withdrawing it is as easy as giving it. For emails, use the unsubscribe link at the bottom of any message. For cookies, reopen our consent banner and change your choice. For anything else, write to us at [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com). Withdrawing your consent does not affect what was lawfully done before you withdrew it. ARTICLE 3 – COOKIES** When you browse our site, data may be stored in or retrieved from your browser, usually in the form of cookies. A cookie is a small text file saved by the browser of your computer, tablet or smartphone. We use first-party cookies, placed by Hack The SEO for the site to work. Most of these cannot be switched off in our systems: they remember what you have entered in a form so you do not have to type it twice, and they manage and secure access to your account. Here is a non-exhaustive list of cookies relating to the operation of our site: wordpress_logged_in_[hash]** wordpress_test_cookie wp-settings-{time}-[UID] WordPress uses the wordpress_[hash] cookie to store authentication details during login. This use of the cookie is limited to the administration console. It is not present on the front end of the website, even when the user is logged in. The wordpress_logged_in_[hash] cookie indicates when you are logged in, and who you are. It is also stored on the website interface when you are logged in. Here [hash] represents a value derived from the username and password by a specific mathematical formula, so that neither is stored in readable form. These cookies still identify your session and must be kept confidential: anyone who obtains one can use your session. The wp-settings-{time}-[UID] cookie personalises the display of your administration interface. The value [UID] is the user’s individual identifier in the user database table. WordPress also sets a cookie named wordpress_test_cookie, to check whether cookies are enabled in the browser. For the comments section: WordPress sets cookies for site commenters, so that the fields are filled in automatically and a commenter does not have to enter their details each time. comment_author_[hash] comment_author_email_[hash] comment_author_url_[hash] The comment_author_[hash] cookie remembers the value entered in the name field of the comment form, comment_author_email_[hash] the value entered in the email field, and comment_author_url_[hash] the value entered in the URL field. We also use third-party cookies placed by our partners. These are managed directly by the companies that issue them, which must also comply with data protection law. – audience measurement cookies: to measure site traffic (number of visits, pages viewed) and improve our performance – advertising cookies: to show you content related to Hack The SEO when you browse other sites Accepting or refusing cookies: Cookies that are not strictly necessary — audience measurement and advertising — are placed only after you have accepted them in the consent banner shown on your first visit. You can reopen that banner at any time to change or withdraw your choice, and refusing is as easy as accepting. Cookies that are strictly necessary for the site to work, and audience measurement limited to producing anonymous statistics, do not require your consent. This exemption depends on what the cookie is used for, never on how long it lasts. You can also manage cookies in your browser: Chrome: [https://support.google.com/chrome/answer/95647?hl=fr](https://support.google.com/chrome/answer/95647?hl=fr) Firefox: [https://support.mozilla.org/fr/kb/protection-renforcee-contre-tracking-firefox-computer](https://support.mozilla.org/fr/kb/protection-renforcee-contre-tracking-firefox-computer) Safari: [https://support.apple.com/fr-fr/guide/safari/sfri11471/mac](https://support.apple.com/fr-fr/guide/safari/sfri11471/mac) Most of these cookies expire when you end your visit. Others last longer, and no more than 13 months, in line with the guidance of the French data protection authority (CNIL). Useful links: – CNIL, cookies and other trackers: [https://www.cnil.fr/fr/cookies-et-autres-traceurs](https://www.cnil.fr/fr/cookies-et-autres-traceurs) – Advertising opt-out platforms: [https://thenai.org/how-to-opt-out/](https://thenai.org/how-to-opt-out/) and [https://www.youronlinechoices.com/](https://www.youronlinechoices.com/) – Google’s privacy policy: [https://policies.google.com/privacy](https://policies.google.com/privacy) ARTICLE 4 – DISCLOSURE** We will disclose your personal information if the law requires us to do so, or to establish, exercise or defend a legal claim. Beyond that, we do not sell your personal data and we do not share it with third parties for their own purposes. Your data is passed only to the processors we need to run the service — our host, our payment provider, our emailing tool and our measurement tools — which act on our instructions and are bound to keep it confidential. They are named in Articles 1, 5 and 6. **ARTICLE 5 – HOSTING AND PAYMENT** Our site is hosted by OVH SAS, 2 rue Kellermann, 59100 Roubaix, France. Your data is stored in OVH’s systems and databases, on servers located in the European Union, protected by a firewall. Payment: Payments are processed by Stripe. Stripe collects and stores your card details directly; we never receive them and never store them. Card data is handled in accordance with the security standard set by the payment card industry (PCI-DSS), managed by the PCI Security Standards Council. We keep the information relating to your subscription and your invoices for as long as accounting and tax law requires. Stripe’s privacy policy: [https://stripe.com/privacy](https://stripe.com/privacy) **ARTICLE 6 – SERVICES PROVIDED BY THIRD PARTIES** The third-party providers we use collect, use and disclose your information only to the extent necessary to carry out the services they provide to us. The main ones are: – OVH SAS (France): hosting.** – Stripe (United States and Ireland): payments. – Klaviyo, Inc. (United States): sending our emails. – Google (United States and Ireland): audience measurement, subject to your consent. – Meta (United States and Ireland): advertising, subject to your consent. Some of these providers are located outside the European Union, or have facilities there. Transfers to the United States rely on the provider’s participation in the EU-U.S. Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses. You can check which organisations take part in the framework here: [https://www.dataprivacyframework.gov/](https://www.dataprivacyframework.gov/) We recommend that you read these providers’ own privacy policies to understand how they treat your personal information. Links to other sites: You may leave our website by clicking certain links. We are not responsible for the privacy practices of those other sites, and we recommend that you read their privacy policies. ARTICLE 7 – SECURITY** To protect your personal data, we take reasonable precautions and follow industry practice so that it is not lost, misused, accessed, disclosed, altered or destroyed inappropriately. Our site is served over HTTPS, and access to our administration interface is restricted and authenticated. No method of transmission over the internet or of electronic storage is completely secure, and we cannot promise absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will inform you, as Article 34 of the GDPR requires. We also recommend that you protect your own account: use a long, unique password, do not reuse it on other sites, and keep it confidential. **ARTICLE 8 – AGE** Our services are intended for professionals and are not aimed at children. In France, a minor may consent to the processing of their personal data from the age of 15; below that age, the consent of the holder of parental responsibility is also required. If you believe that a child has provided us with personal data, write to us at [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com) and we will delete it. **ARTICLE 9 – CHANGES TO THIS PRIVACY POLICY** We may modify this privacy policy. Changes take effect when they are published on this page, and the date of the last update is shown below. Where a change materially affects how we use your data, we will inform you by a more visible means. If our business is acquired by or merged with another company, your data may be transferred to the new owner, who will be bound by this policy until it publishes its own. Last updated: 17 September 2026 **YOUR RIGHTS, QUESTIONS AND CONTACT** Under the General Data Protection Regulation, you have the right to access your data, to have it corrected, to have it erased, to restrict its processing, to object to its processing, to receive it in a portable form, and to withdraw your consent at any time where processing is based on consent. Automated decisions. We take no decision producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, within the meaning of Article 22 of the GDPR. The advertising described in Article 1 does involve profiling; you can refuse it in our consent banner, and object to it at any time by writing to us. Data protection officer. We have not appointed one, as we are not required to do so under Article 37 of the GDPR. Requests concerning your personal data are handled directly by us, at [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com). Directions for after your death. Under Article 85 of the French Data Protection Act (loi n° 78-17 of 6 January 1978), you may give us directions about what should happen to your personal data after your death — whether it is to be kept, erased or passed on — and you may name someone to carry them out. Send them to [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com) and we will record them against your account. To exercise these rights, write to [hacktheseofrance@gmail.com](mailto:hacktheseofrance@gmail.com), or to HACK THE SEO, La Halle de l’Innovation, ZAC Cambacérès, 10 place Françoise Héritier, 34000 Montpellier, France. We reply within one month of receiving your request. If your request is complex, or if you have sent us several, we may extend that period by two further months; we will tell you within the first month if we do, and explain why. If we decline to act, we will tell you why. We will ask you for proof of identity only if we have a reasonable doubt about who you are, and we will explain why. You also have the right to lodge a complaint with a supervisory authority. In France, that authority is the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07: [https://www.cnil.fr/fr/plaintes](https://www.cnil.fr/fr/plaintes) --- Source: https://hacktheseo.com/privacy-policy/ Generated by Hack The SEO