Compliance & Trust

Survive the compliance meteor.

Data protection, accessibility, and audit-ready documentation — so your SEO program doesn’t get wiped out by the next procurement review.

GDPR & CCPA ready

Lawful data processing, documented consent flows, and the right to access, export, or delete your data on request. DPAs available for every engagement.

WCAG 2.1 AA

Our client portal and marketing surfaces meet WCAG 2.1 AA — semantic markup, keyboard navigation, sufficient contrast, and screen-reader support. Accessibility is also a ranking signal we audit for clients.

SOC 2 alignment

Controls map to SOC 2 trust criteria — access, monitoring, and change management are documented and auditable on request.

How your data is handled.

Every access to your analytics is scoped, logged, and reversible. Here’s exactly what we touch — and what we don’t.

Read-only analytics access

Google Analytics and Search Console are connected via OAuth-scoped, read-only tokens. We never modify your properties, goals, or settings.

Least-privilege, server-side

Row-level security enforces that each client portal account sees only its own property data. No cross-client visibility, ever — enforced server-side, not just in the UI.

Bounded retention

Cached report data is retained for 24 months so you keep trend history without re-pulling. Full deletion is available on request, no questions asked.

Audit trail

Every read of your analytics is logged — what was pulled, when, and by which system. You can review the trail inside your portal at any time.

No data resale or training

Your data is yours. We never share, sell, or train models on client analytics. Period.

Data residency options

Stored on secured, encrypted infrastructure in the US by default; EU residency available for enterprise engagements.

Sub-processors.

The third parties that touch client data, what they do, and the scope of access.

ProviderPurposeScope
Google Analytics & Search ConsoleRead-only traffic and search performance dataRead-only OAuth
Cloud hosting providerEncrypted application and data storageUS / EU regions
Transactional emailClient onboarding and traffic-drop alertsDelivery only

Questions procurement always asks.

Do you need write access to our Google Analytics?

No. We use a read-only analytics scope. We can’t and don’t modify your GA property, goals, or settings.

Can we use our own service account or SSO?

Yes. Enterprise clients can connect through their own Google Cloud service account, and we support SSO for portal access on enterprise plans.

How long is data retained, and can we delete it?

Cached report data is retained for 24 months for trend history. You can request full deletion at any time and we complete it within 30 days.

Is the portal accessible?

Yes. The client portal targets WCAG 2.1 AA, including keyboard navigation, semantic structure, and contrast. VPAT available on request.

Where can I get a DPA or compliance one-pager?

Request it through the form below and we send the standard data processing agreement plus a compliance summary within 48 hours.

Need a DPA, VPAT, or compliance one-pager?

We’ll send our compliance packet — data processing agreement, accessibility statement, and sub-processor list — within 48 hours.

Request compliance docs
Get my free SEO score
60-second audit · see your extinction risk & fixes
Start audit