ORYON SYSTEMS (“ORYON SYSTEMS,” “SEOryon,” “we,” “us,” or “our”) operates the SEOryon platform at app.seoryon.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
By using SEOryon, you agree to the terms of this Privacy Policy.
1. Who We Are
ORYON SYSTEMS is the data controller for the personal data described in this Policy.
ORYON SYSTEMS
Société par actions simplifiée à associé unique (SASU)
61 rue de Lyon, 75012 Paris, France
SIREN: 107 207 201, RCS Paris
Intra-community VAT number: FR73 107 207 201
Contact: support@seoryon.com
We have not appointed a Data Protection Officer. Data-protection enquiries should be sent to the contact address above.
Supervisory authority. You may lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France. More on the CNIL website. If you are resident in another EEA country, you may instead complain to your local supervisory authority.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password (if not using OAuth), profile photo (optional)
- Project and brand data: business descriptions, brand voice settings, target audiences, color preferences, content goals
- Article content: drafts, published articles, metadata, scheduling preferences
- Payment information: processed by our payment provider (see Section 5.5); we do not store full credit card numbers
- Support communications: messages you send to support@seoryon.com or via in-app support channels
2.2 Information Collected Automatically
- Usage data: pages visited, features used, time spent, click patterns
- Device and browser information: user agent, IP address, screen resolution, operating system, language preference
- Error logs and diagnostic data: stack traces, request IDs, performance metrics
- Cookies and similar technologies for authentication and session management (see Section 11)
2.3 Information From Third-Party Integrations
When you connect SEOryon to third-party services (Webflow, Google Search Console, WordPress, Shopify, etc.), we receive limited data from those services as authorized by you, including:
- API tokens or OAuth credentials (encrypted at rest using AES-256)
- CMS content: existing blog posts, collection schemas, taxonomy data
- Search analytics: impressions, clicks, click-through rate, indexing status (when Google Search Console is connected)
3. How We Use Your Information
We use your information to:
- Provide and operate the SEOryon Service
- Generate, optimize, and publish content on your behalf using AI models
- Connect to and synchronize with third-party services you authorize
- Process payments and manage subscriptions
- Send service-related communications (account notifications, security alerts, billing)
- Improve the Service through aggregated, de-identified usage analytics
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
We do not sell your personal information. We do not use your data to train artificial intelligence models for any purpose other than serving your immediate request to SEOryon. We do not use your data for third-party advertising or interest-based marketing.
4. Google API User Data: Limited Use Disclosure
When you connect Google services to SEOryon (such as Google Search Console and Google Analytics), SEOryon’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 Google Data We Access
With your explicit OAuth consent, SEOryon accesses the following from your Google account:
- Your email address and basic profile information (used solely to identify your SEOryon account when you sign in with Google)
- Google Search Console data via the
webmasters.readonlyscope, including:- Sitemap submission status
- URL indexing status (whether specific URLs are indexed by Google)
- Search analytics: impressions, clicks, click-through rate, average position for queries and pages
- Site verification status
- Google Analytics 4 (GA4) data via the
analytics.readonlyscope, including sessions, users, engagement metrics, traffic sources and channels, and device/geography dimensions for the Analytics properties you connect.
4.2 How We Use Google Data
- Display indexing status of your published articles in the SEOryon dashboard
- Request URL inspections to surface “indexed” vs “discovered but not indexed” status per article
- Display search analytics in the SEOryon dashboard so you can see which articles drive organic traffic
- Inform our content recommendation engine about queries your site ranks for
- Display your website traffic from Google Analytics (sessions, engagement, and traffic sources, including visits referred by AI assistants) in the SEOryon dashboard, so you can see how your content performs.
4.3 Limited Use Commitments
- We do not sell, rent, share, or transfer Google data to any third party for advertising or other purposes
- We do not use Google data for advertising, including retargeting, personalized advertising, or interest-based advertising
- We do not allow humans to read Google data, except: (a) with your explicit consent for support requests, (b) to comply with applicable law, or (c) to investigate security incidents and abuse
- We do not use Google data to train, fine-tune, or improve any machine learning or artificial intelligence model
- Google data is retained only as long as needed to provide the requested SEOryon features and is deleted within 30 days of account closure or upon your request
4.4 Revoking Access
You can revoke SEOryon’s access to your Google data at any time:
- Within SEOryon: go to Settings, then Integrations, then Google Search Console, and click Disconnect
- Within Google: visit your Google account permissions, find SEOryon, and click “Remove access”
Revoking access stops new data from being accessed but does not automatically delete data already stored in SEOryon. To request deletion of all associated data, see Section 8 (Your Rights).
5. Sub-Processors and Third Parties
We share limited data with the following sub-processors to operate the Service. Each is bound by confidentiality and data protection obligations.
5.1 Infrastructure
- Cloudflare, Inc.: application hosting, database (D1), object storage (R2), CDN. Primary data residency: United States and global edge network.
- Supabase, Inc.: user authentication only: sign-up, sign-in, Google OAuth, and password reset. Supabase holds your email address, your authentication credentials and, where you sign in with Google, your OAuth identity. No application data is stored in Supabase. Your account record, projects, and content are held in Cloudflare D1.
5.2 AI Content Generation
- Anthropic, PBC: article generation, content optimization, fact-checking via the Claude API. Content sent for generation is processed transiently per Anthropic’s API policies and is not retained by Anthropic for model training.
- OpenAI, L.L.C.: hero image generation via the gpt-image-1 and dall-e-2 APIs. Image prompts are processed transiently per OpenAI’s API policies.
- Perplexity AI, Inc.: fact-checking and source citation for article content. Article text is sent for fact verification.
5.3 SEO and Data Services
- DataForSEO: keyword volume, competitor analysis, SERP data. We send keywords and competitor URLs; no user account or content data is transmitted.
- Firecrawl: search engine results page (SERP) scraping for competitor analysis. We send queries and target URLs.
- Pexels: stock photography search. We send keyword queries to find relevant stock images; no user content is transmitted.
5.4 Content Management Integrations (User-Initiated)
When you connect SEOryon to your CMS, we exchange data with the following services as needed to publish or manage your content. These transfers occur only with your explicit authorization via OAuth or API credentials:
- Webflow, Inc.: CMS publishing
- Automattic, Inc. (WordPress.com / WordPress.org): CMS publishing (planned integration)
- Shopify Inc.: content publishing for Shopify stores (planned integration)
- Ghost Foundation: CMS publishing (planned integration)
- Wix.com Ltd.: CMS publishing (planned integration)
- Google LLC: Google Search Console and Google Analytics data, as described in Section 4.
5.5 Payment Processing
Subscription payments are processed by Stripe. We do not store full credit card numbers. The payment provider stores payment information securely under their own policies and PCI DSS compliance.
5.6 Analytics and Error Tracking
- Sentry (Functional Software, Inc.): application error tracking and reliability monitoring. Strictly necessary; pseudonymous, with IP addresses not stored and no session recording. Data stored in the European Union.
- PostHog, Inc.: product analytics, used only with your consent (see Section 11). Pseudonymous, with client IP data discarded; no advertising or cross-site tracking. Data stored in the European Union.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service:
- Account data: retained until account deletion
- Article content and project data: retained until you delete it or close your account
- Third-party integration data (including Google Search Console data): refreshed on demand; cached for up to 30 days for performance; deleted when integration is disconnected
- Payment records: retained for ten (10) years, as required of French companies by Article L123-22 of the Code de commerce
- Logs and diagnostic data: retained for 90 days
- Aggregated, de-identified analytics: may be retained indefinitely
Upon account closure, we delete personal data within 30 days, except where retention is required by law (tax records, fraud investigation, legal holds).
7. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) for all data transfers
- Encryption at rest for sensitive data including OAuth tokens (AES-256)
- Access controls limiting employee access to user data on a need-to-know basis
- Regular security audits and prompt patching of vulnerabilities
- Logging and monitoring of suspicious activity
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect your data using reasonable safeguards consistent with industry best practices.
8. Your Rights
8.1 If You Are in the European Economic Area (EEA), United Kingdom, or Switzerland
Under the General Data Protection Regulation (GDPR) and UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correction of inaccurate or incomplete data
- Erasure of your data (“right to be forgotten”)
- Restriction of certain types of processing
- Objection to processing based on legitimate interests
- Data portability: receive your data in a structured, machine-readable format
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a supervisory authority: our lead authority is the Commission Nationale de l’Informatique et des Libertés (CNIL) in France (see Section 1), or you may complain to the authority in your country of residence
8.2 If You Are in California
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to:
- Know what categories of personal information we collect, the sources, and the purposes
- Access a copy of your personal information
- Delete your personal information (subject to certain exceptions)
- Correct inaccurate personal information
- Limit use of sensitive personal information
- Opt out of any “sale” or “sharing” of personal information (note: we do not sell or share personal information for cross-context behavioral advertising)
- Non-discrimination: we will not deny service, charge different prices, or provide a different quality of service for exercising your rights
8.3 Exercising Your Rights
To exercise any of these rights, contact us at support@seoryon.com. We will respond within 30 days. We may verify your identity before processing your request.
9. Children’s Privacy
SEOryon is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact support@seoryon.com so we can delete it.
10. International Data Transfers
SEOryon is operated from France and uses sub-processors located in the European Union, the United States and globally. Your data may therefore be transferred to, stored, and processed in the United States and other countries where our sub-processors operate.
For transfers of personal data from the EEA, United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner’s Office, or equivalent safeguards required by applicable law.
11. Cookies and Similar Technologies
We use cookies and similar technologies in three categories:
- Strictly necessary (always on): authentication, session management, and security, which are required for the Service to function; and error tracking and reliability monitoring (Sentry) used to detect and fix faults. Our error tracking is pseudonymous, does not store your IP address, does not record your screen or session, and is never used for advertising.
- Functional: remembering your preferences (e.g., selected project, UI settings).
- Analytics (consent-based): product analytics (PostHog) that help us understand how features are used. These are set only after you accept them in our cookie banner. They are pseudonymous, your IP address is discarded, the data is stored in the European Union, and they are never used for advertising or cross-site tracking.
We do not use third-party advertising cookies or cross-site tracking technologies.
You choose whether to allow analytics cookies when you first visit, and you can change your choice at any time through the “Cookie preferences” link in our website footer, or by going to Settings, then Data & Privacy. Rejecting analytics, or withdrawing consent later, stops product analytics immediately; strictly-necessary cookies remain because the Service cannot function without them.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by:
- Email to the address associated with your account
- A prominent notice within the SEOryon application
We will provide at least 14 days’ notice before material changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For questions, concerns, or requests related to this Privacy Policy or our data practices:
Email: support@seoryon.com
Mail:
ORYON SYSTEMS
61 rue de Lyon
75012 Paris
France