SEO & Chill is built on a simple promise: your content flows directly between your server and the AI provider you choose. We are never in that path. This page shows exactly what data goes where, who our subprocessors are, and how the platform is secured. Everything an agency, DPO or EU buyer needs, public and linkable.
Only when you run an AI action, directly from your server, under your own API agreement:
SEO & Chill servers are not a proxy. We never receive:
The license API receives exactly four things: license key, activated domain, plugin version, activation status. Details per provider are in each provider’s own policy. You choose who you trust with your content.
API keys are encrypted at rest with AES-256-CBC in your own database. Decryption happens only on your server, only to call your provider.
Every admin action is guarded by WordPress capability checks and nonces; database interactions use prepared statements; file integrity is verified on update.
License checks are signed and cached. If our API is ever unreachable, your plugin keeps working for a 14+ day grace window. Your SEO never depends on our uptime.
Marketing, documentation and the customer portal run as separate installs. The portal. The only system with customer data. Sits behind a WAF with mandatory 2FA for all admin users.
All systems are backed up daily to off-site storage, with tested restores.
Cookieless analytics, no ad trackers, and a license API that receives a domain and a version number. Not your content.
| Subprocessor | Purpose | Location | Data involved |
|---|---|---|---|
| Stripe | Payments, billing, invoicing, tax | USA / EU | Card data never touches our servers |
| Cloudflare | CDN, DNS, WAF and edge caching | Global (EU data residency) | Traffic protection for site and API |
| Postmark | Transactional email (receipts, licenses) | USA | Name and email address only |
| Klaviyo | Newsletter delivery & list management | USA (EU-U.S. DPF certified) | Email address of newsletter subscribers only |
| Help Scout | Customer support conversations | USA | What you share in a ticket |
| Plausible | Website analytics | EU | Cookieless, no personal data |
| Instatus | Public status page | USA | No customer data |
AI providers you connect yourself (OpenAI, Anthropic, Google, and the rest of the ten) are your own processors under your own agreements. Not our subprocessors. We announce subprocessor changes on this page before they take effect.
Our Data Processing Addendum is public and automatically forms part of your agreement the moment you purchase. Electronic acceptance is how Art. 28 GDPR contracts work for SaaS. For audits or client files, the public DPA together with your order confirmation is all the evidence you need.
Your content goes directly from your server to the AI provider you connected, under your own API agreement with that provider. We are never in that data path. Whether a provider trains on API traffic is governed by their terms; most major providers do not train on API data by default, but verify this in your provider’s policy.
No. Keys are stored in your own WordPress database, encrypted with AES-256-CBC, and are only ever sent to the provider they belong to. They are never transmitted to SEO & Chill servers.
The minimum needed to validate a license: your license key, the domain it’s activated on, the plugin version and activation status. No site content, no analytics, no personal data of your visitors.
There is nothing to sign. And nothing missing. The Data Processing Addendum is public and automatically forms part of the Terms for every customer, which satisfies Art. 28 GDPR. If your auditor or client asks, point them to the public DPA plus your order confirmation.
Everything the plugin created. Meta, redirects, schema settings. Lives in your WordPress database and stays there. On our side, license and billing records are retained only as long as legally required, then deleted.
Everything on this page is one link. Send it to your DPO and get back to ranking.
Get started →