Survive the compliance meteor.
Data protection, accessibility, and audit-ready documentation — so your SEO program doesn’t get wiped out by the next procurement review.
GDPR & CCPA ready
Lawful data processing, documented consent flows, and the right to access, export, or delete your data on request. DPAs available for every engagement.
WCAG 2.1 AA
Our client portal and marketing surfaces meet WCAG 2.1 AA — semantic markup, keyboard navigation, sufficient contrast, and screen-reader support. Accessibility is also a ranking signal we audit for clients.
SOC 2 alignment
Controls map to SOC 2 trust criteria — access, monitoring, and change management are documented and auditable on request.
How your data is handled.
Every access to your analytics is scoped, logged, and reversible. Here’s exactly what we touch — and what we don’t.
Read-only analytics access
Google Analytics and Search Console are connected via OAuth-scoped, read-only tokens. We never modify your properties, goals, or settings.
Least-privilege, server-side
Row-level security enforces that each client portal account sees only its own property data. No cross-client visibility, ever — enforced server-side, not just in the UI.
Bounded retention
Cached report data is retained for 24 months so you keep trend history without re-pulling. Full deletion is available on request, no questions asked.
Audit trail
Every read of your analytics is logged — what was pulled, when, and by which system. You can review the trail inside your portal at any time.
No data resale or training
Your data is yours. We never share, sell, or train models on client analytics. Period.
Data residency options
Stored on secured, encrypted infrastructure in the US by default; EU residency available for enterprise engagements.
Sub-processors.
The third parties that touch client data, what they do, and the scope of access.
| Provider | Purpose | Scope |
|---|---|---|
| Google Analytics & Search Console | Read-only traffic and search performance data | Read-only OAuth |
| Cloud hosting provider | Encrypted application and data storage | US / EU regions |
| Transactional email | Client onboarding and traffic-drop alerts | Delivery only |
Questions procurement always asks.
Do you need write access to our Google Analytics?
No. We use a read-only analytics scope. We can’t and don’t modify your GA property, goals, or settings.
Can we use our own service account or SSO?
Yes. Enterprise clients can connect through their own Google Cloud service account, and we support SSO for portal access on enterprise plans.
How long is data retained, and can we delete it?
Cached report data is retained for 24 months for trend history. You can request full deletion at any time and we complete it within 30 days.
Is the portal accessible?
Yes. The client portal targets WCAG 2.1 AA, including keyboard navigation, semantic structure, and contrast. VPAT available on request.
Where can I get a DPA or compliance one-pager?
Request it through the form below and we send the standard data processing agreement plus a compliance summary within 48 hours.
Need a DPA, VPAT, or compliance one-pager?
We’ll send our compliance packet — data processing agreement, accessibility statement, and sub-processor list — within 48 hours.
Request compliance docs