Privacy Policy
Last updated August 19, 2026
LazySEM is operated by Got Reach s.r.o., a company registered in the Czech Republic, company registration number (IČO) 23712082, VAT number CZ23712082, registered office Zlochova 2405/8, Modřany, 143 00 Praha, Czech Republic. Got Reach s.r.o. is the data controller for the processing described in this Privacy Policy. For privacy matters, contact info@lazysem.com.
Got Reach s.r.o. is established in the Czech Republic, so its lead supervisory authority is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).
This Privacy Policy explains what personal data we collect, how we use it, how we share it, and what choices and rights users may have.
LazySEM provides SEO workflow tools, including content brief generation, URL monitoring, content analysis, clustering, and related automation features.
1. Data we collect
LazySEM may collect and process the following categories of data.
Account data
When you create or use a LazySEM account, we may collect:
- email address
- first and last name
- password hash
- optional phone number
- authentication provider information, such as Google login identifiers
- organization membership and role information
- last active organization or workspace
Billing data
If you subscribe to a paid plan, billing and payment processing is handled by Stripe.
LazySEM may receive billing-related metadata, such as:
- billing customer details
- subscription status
- selected plan
- payment status
- billing address
LazySEM does not directly store full payment card details.
Product usage data
To provide the service, LazySEM may process data submitted or created through the product, including:
- keywords
- brand information
- target audience descriptions
- user notes
- content briefing inputs
- URL monitoring projects
- clustering keyword lists
- word cloud snapshots
- agent chat sessions
- generated SEO outputs
Free-text fields may contain personal data if a user chooses to enter it. LazySEM does not intentionally request sensitive personal data in SEO workflow fields.
Technical and security data
LazySEM may collect technical and security-related data, including:
- IP address
- user agent
- session identifiers
- request identifiers
- route, method, status code, and response time
- audit log events
- security events
- activity events
- error diagnostic data
This data is used for security, troubleshooting, service reliability, and abuse prevention.
Connected Google services
If you connect Google services, LazySEM may process data from:
- Google OAuth
- Google Analytics 4
- Google Search Console
LazySEM may store OAuth refresh tokens for connected Google accounts. These tokens are stored encrypted in LazySEM’s database.
2. How we use data
LazySEM uses personal data and customer-provided data to:
- create and manage user accounts
- authenticate users
- provide access to organizations and workspaces
- enforce roles and permissions
- process subscriptions and billing
- provide SEO briefings, monitoring, clustering, and related product features
- connect to Google Analytics or Google Search Console when enabled by the user
- maintain audit logs and security records
- detect abuse, fraud, or unauthorized access
- troubleshoot errors and improve service reliability
- communicate with users about the service
Legal basis for processing
Under the EU General Data Protection Regulation, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and managing accounts, authenticating users, providing access to organizations and workspaces, enforcing roles and permissions | Performance of a contract (Art. 6(1)(b)) |
| Providing SEO briefings, monitoring, clustering, similarity analysis and related product features, including AI-assisted generation | Performance of a contract (Art. 6(1)(b)) |
| Connecting Google Analytics or Google Search Console when you enable the integration | Performance of a contract (Art. 6(1)(b)) — the integration is initiated by you |
| Processing subscriptions and payments | Performance of a contract (Art. 6(1)(b)) |
| Retaining invoices and accounting records | Compliance with a legal obligation (Art. 6(1)(c)) |
| Maintaining audit logs and security records, detecting abuse, fraud and unauthorized access | Our legitimate interests in securing the service and protecting our users (Art. 6(1)(f)) |
| Troubleshooting errors and maintaining service reliability | Our legitimate interests in operating a reliable service (Art. 6(1)(f)) |
| Service and administrative messages about your account | Performance of a contract (Art. 6(1)(b)) |
| Analytics cookies and similar technologies | Your consent (Art. 6(1)(a)) — you may withdraw it at any time |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms, and you may object to that processing as described in section 9.
3. AI processing
Some LazySEM features use third-party AI providers to generate SEO briefings and related outputs.
Depending on the feature used, LazySEM may send the following types of data to AI providers:
- keywords
- brand characteristics
- target audience descriptions
- unique selling points
- customer pain points
- user notes
- SERP-derived entities, URLs, and context
LazySEM does not intentionally send account profile information, billing information, or payment card data to AI providers.
Users should avoid entering sensitive personal data or confidential information into free-text product fields unless it is necessary for their SEO workflow.
4. Cookies and analytics
LazySEM uses essential cookies and similar technologies to operate the service, including:
- authentication cookies
- refresh/session cookies
- CSRF protection cookies
LazySEM may also use analytics tools, such as Google Analytics, where consent is provided.
LazySEM may collect diagnostic and error information in the browser to help detect and resolve application issues. This information may be displayed locally for troubleshooting and, where relevant, is sent to LazySEM’s own backend as part of ordinary application requests. LazySEM does not send this data to any third-party error-tracking service.
5. Third-party providers
LazySEM uses third-party providers to operate the service, including providers for:
- cloud hosting
- frontend delivery
- payments and billing
- AI processing
- search and SEO data
- connected Google integrations
- transactional email delivery
A current list of third-party providers is available on our Subprocessors page: /subprocessors
6. International processing
LazySEM’s own infrastructure is hosted in the European Union: the application services, PostgreSQL databases and cache run in the EU West region of our hosting provider, Railway.
Some of our subprocessors process data outside the European Economic Area — for example AI, search-data and payment providers based in the United States. Where that happens, we rely on one of the following, as applicable to each recipient:
- an adequacy decision of the European Commission (this covers, for example, transfers to the United Kingdom and to Israel); or
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), as incorporated into that provider’s data processing agreement, together with the UK International Data Transfer Addendum where UK data is involved.
The categories of provider and their locations are listed on our Subprocessors page. You can request a copy of the safeguards we rely on for any specific provider by emailing info@lazysem.com.
7. Data retention
LazySEM retains data for as long as necessary to provide the service, operate accounts and subscriptions, comply with legal obligations, resolve disputes, maintain security, and support legitimate business operations.
Current retention practices include:
- account and organization data is generally retained while the account or organization remains active
- billing records may be retained as required for accounting, tax, and legal purposes
- audit, security, and activity logs are generally retained based on organization-level retention settings, with a default retention period of 90 days
- support, diagnostic, and error data may be retained as needed to troubleshoot issues and maintain service reliability
LazySEM is continuing to formalize its retention and deletion procedures for all data categories.
8. Account deletion and data deletion
Users may request deletion of their account or organization data by contacting LazySEM through the support contact listed on the website.
When an account or organization is deleted or closed, LazySEM will take reasonable steps to delete or disable access to associated data, subject to:
- legal, tax, or accounting retention requirements
- security and fraud prevention needs
- backup and disaster recovery processes
These are the only grounds on which LazySEM may delay or limit erasure: where applicable data protection law entitles you to erasure of your personal data, LazySEM will honor that request.
Some data may remain in backups or logs for a limited period before being deleted or overwritten according to applicable retention processes.
9. User rights
Depending on your location and applicable law, you may have rights to:
- access your personal data
- correct inaccurate personal data
- request deletion of personal data
- object to or restrict certain processing
- request portability of certain data
- withdraw consent where processing is based on consent
- lodge a complaint with a data protection authority
Some data can be exported directly in the product — for example, organization owners and administrators can export audit log data. The in-product export features do not yet cover every data type. This limits the self-service tooling only, not your rights: to exercise your right of access or data portability over any personal data LazySEM holds about you, contact info@lazysem.com and we will respond within the period described at the end of this section.
To make a privacy or data rights request, email info@lazysem.com. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. If your request is complex or you have made several requests, we may extend that period by up to two further months and will tell you within the first month if we do. We may ask you for information needed to confirm your identity before we act on a request. Exercising these rights is free of charge.
10. Security
LazySEM uses technical and organizational measures designed to protect personal data, including:
- HTTPS (TLS) for public traffic
- managed infrastructure with encryption at rest
- restricted production access
- role-based administrative controls within the application
- managed database backups
- encrypted storage of connected Google OAuth tokens
More information is available on our Security page: /security
11. Changes to this policy
LazySEM may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above.
12. Contact
For privacy questions or data rights requests, please contact LazySEM through the support contact listed on our website.
Or via our email address at info@lazysem.com