Privacy Policy

Last updated August 19, 2026

LazySEM is operated by Got Reach s.r.o., a company registered in the Czech Republic, company registration number (IČO) 23712082, VAT number CZ23712082, registered office Zlochova 2405/8, Modřany, 143 00 Praha, Czech Republic. Got Reach s.r.o. is the data controller for the processing described in this Privacy Policy. For privacy matters, contact info@lazysem.com.

Got Reach s.r.o. is established in the Czech Republic, so its lead supervisory authority is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).

This Privacy Policy explains what personal data we collect, how we use it, how we share it, and what choices and rights users may have.

LazySEM provides SEO workflow tools, including content brief generation, URL monitoring, content analysis, clustering, and related automation features.

1. Data we collect

LazySEM may collect and process the following categories of data.

Account data

When you create or use a LazySEM account, we may collect:

  • email address
  • first and last name
  • password hash
  • optional phone number
  • authentication provider information, such as Google login identifiers
  • organization membership and role information
  • last active organization or workspace

Billing data

If you subscribe to a paid plan, billing and payment processing is handled by Stripe.

LazySEM may receive billing-related metadata, such as:

  • billing customer details
  • subscription status
  • selected plan
  • payment status
  • billing address

LazySEM does not directly store full payment card details.

Product usage data

To provide the service, LazySEM may process data submitted or created through the product, including:

  • keywords
  • brand information
  • target audience descriptions
  • user notes
  • content briefing inputs
  • URL monitoring projects
  • clustering keyword lists
  • word cloud snapshots
  • agent chat sessions
  • generated SEO outputs

Free-text fields may contain personal data if a user chooses to enter it. LazySEM does not intentionally request sensitive personal data in SEO workflow fields.

Technical and security data

LazySEM may collect technical and security-related data, including:

  • IP address
  • user agent
  • session identifiers
  • request identifiers
  • route, method, status code, and response time
  • audit log events
  • security events
  • activity events
  • error diagnostic data

This data is used for security, troubleshooting, service reliability, and abuse prevention.

Connected Google services

If you connect Google services, LazySEM may process data from:

  • Google OAuth
  • Google Analytics 4
  • Google Search Console

LazySEM may store OAuth refresh tokens for connected Google accounts. These tokens are stored encrypted in LazySEM’s database.

2. How we use data

LazySEM uses personal data and customer-provided data to:

  • create and manage user accounts
  • authenticate users
  • provide access to organizations and workspaces
  • enforce roles and permissions
  • process subscriptions and billing
  • provide SEO briefings, monitoring, clustering, and related product features
  • connect to Google Analytics or Google Search Console when enabled by the user
  • maintain audit logs and security records
  • detect abuse, fraud, or unauthorized access
  • troubleshoot errors and improve service reliability
  • communicate with users about the service

Legal basis for processing

Under the EU General Data Protection Regulation, we rely on the following legal bases:

PurposeLegal basis
Creating and managing accounts, authenticating users, providing access to organizations and workspaces, enforcing roles and permissionsPerformance of a contract (Art. 6(1)(b))
Providing SEO briefings, monitoring, clustering, similarity analysis and related product features, including AI-assisted generationPerformance of a contract (Art. 6(1)(b))
Connecting Google Analytics or Google Search Console when you enable the integrationPerformance of a contract (Art. 6(1)(b)) — the integration is initiated by you
Processing subscriptions and paymentsPerformance of a contract (Art. 6(1)(b))
Retaining invoices and accounting recordsCompliance with a legal obligation (Art. 6(1)(c))
Maintaining audit logs and security records, detecting abuse, fraud and unauthorized accessOur legitimate interests in securing the service and protecting our users (Art. 6(1)(f))
Troubleshooting errors and maintaining service reliabilityOur legitimate interests in operating a reliable service (Art. 6(1)(f))
Service and administrative messages about your accountPerformance of a contract (Art. 6(1)(b))
Analytics cookies and similar technologiesYour consent (Art. 6(1)(a)) — you may withdraw it at any time

Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms, and you may object to that processing as described in section 9.

3. AI processing

Some LazySEM features use third-party AI providers to generate SEO briefings and related outputs.

Depending on the feature used, LazySEM may send the following types of data to AI providers:

  • keywords
  • brand characteristics
  • target audience descriptions
  • unique selling points
  • customer pain points
  • user notes
  • SERP-derived entities, URLs, and context

LazySEM does not intentionally send account profile information, billing information, or payment card data to AI providers.

Users should avoid entering sensitive personal data or confidential information into free-text product fields unless it is necessary for their SEO workflow.

4. Cookies and analytics

LazySEM uses essential cookies and similar technologies to operate the service, including:

  • authentication cookies
  • refresh/session cookies
  • CSRF protection cookies

LazySEM may also use analytics tools, such as Google Analytics, where consent is provided.

LazySEM may collect diagnostic and error information in the browser to help detect and resolve application issues. This information may be displayed locally for troubleshooting and, where relevant, is sent to LazySEM’s own backend as part of ordinary application requests. LazySEM does not send this data to any third-party error-tracking service.

5. Third-party providers

LazySEM uses third-party providers to operate the service, including providers for:

  • cloud hosting
  • frontend delivery
  • payments and billing
  • AI processing
  • search and SEO data
  • connected Google integrations
  • transactional email delivery

A current list of third-party providers is available on our Subprocessors page: /subprocessors

6. International processing

LazySEM’s own infrastructure is hosted in the European Union: the application services, PostgreSQL databases and cache run in the EU West region of our hosting provider, Railway.

Some of our subprocessors process data outside the European Economic Area — for example AI, search-data and payment providers based in the United States. Where that happens, we rely on one of the following, as applicable to each recipient:

  • an adequacy decision of the European Commission (this covers, for example, transfers to the United Kingdom and to Israel); or
  • the European Commission’s Standard Contractual Clauses (Decision 2021/914), as incorporated into that provider’s data processing agreement, together with the UK International Data Transfer Addendum where UK data is involved.

The categories of provider and their locations are listed on our Subprocessors page. You can request a copy of the safeguards we rely on for any specific provider by emailing info@lazysem.com.

7. Data retention

LazySEM retains data for as long as necessary to provide the service, operate accounts and subscriptions, comply with legal obligations, resolve disputes, maintain security, and support legitimate business operations.

Current retention practices include:

  • account and organization data is generally retained while the account or organization remains active
  • billing records may be retained as required for accounting, tax, and legal purposes
  • audit, security, and activity logs are generally retained based on organization-level retention settings, with a default retention period of 90 days
  • support, diagnostic, and error data may be retained as needed to troubleshoot issues and maintain service reliability

LazySEM is continuing to formalize its retention and deletion procedures for all data categories.

8. Account deletion and data deletion

Users may request deletion of their account or organization data by contacting LazySEM through the support contact listed on the website.

When an account or organization is deleted or closed, LazySEM will take reasonable steps to delete or disable access to associated data, subject to:

  • legal, tax, or accounting retention requirements
  • security and fraud prevention needs
  • backup and disaster recovery processes

These are the only grounds on which LazySEM may delay or limit erasure: where applicable data protection law entitles you to erasure of your personal data, LazySEM will honor that request.

Some data may remain in backups or logs for a limited period before being deleted or overwritten according to applicable retention processes.

9. User rights

Depending on your location and applicable law, you may have rights to:

  • access your personal data
  • correct inaccurate personal data
  • request deletion of personal data
  • object to or restrict certain processing
  • request portability of certain data
  • withdraw consent where processing is based on consent
  • lodge a complaint with a data protection authority

Some data can be exported directly in the product — for example, organization owners and administrators can export audit log data. The in-product export features do not yet cover every data type. This limits the self-service tooling only, not your rights: to exercise your right of access or data portability over any personal data LazySEM holds about you, contact info@lazysem.com and we will respond within the period described at the end of this section.

To make a privacy or data rights request, email info@lazysem.com. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. If your request is complex or you have made several requests, we may extend that period by up to two further months and will tell you within the first month if we do. We may ask you for information needed to confirm your identity before we act on a request. Exercising these rights is free of charge.

10. Security

LazySEM uses technical and organizational measures designed to protect personal data, including:

  • HTTPS (TLS) for public traffic
  • managed infrastructure with encryption at rest
  • restricted production access
  • role-based administrative controls within the application
  • managed database backups
  • encrypted storage of connected Google OAuth tokens

More information is available on our Security page: /security

11. Changes to this policy

LazySEM may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above.

12. Contact

For privacy questions or data rights requests, please contact LazySEM through the support contact listed on our website.

Or via our email address at info@lazysem.com