Privacy Policy
Last updated: 27 July 2026
1. Who we are (data controller)
WebsiteOS is operated by WebsiteOS LLC, a company registered in the Sharjah Media City Free Zone, United Arab Emirates ("WebsiteOS", "we", "us"). We are the data controller for the personal data described in this policy. Contact: hello@websiteos.ai. Service: websiteos.ai.
For any data protection matter, including where you are in the EU, contact us at hello@websiteos.ai and we will respond and route your request appropriately.
2. Two roles: when we are controller vs processor
3. What data we collect, why, and our legal basis
Each purpose below states its GDPR Art. 6 legal basis.
- Account and onboarding data (name, email, phone, WhatsApp, business name, industry, location, services). Purpose: to create your account, build and manage your website, and run the AI SEO Engine. Basis: performance of a contract (Art. 6(1)(b)).
- Billing data (name, billing contact, payment records; card details are handled by Stripe, not stored by us). Purpose: to take payment and keep tax and accounting records. Basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Prospect contact data (business name, website, role-based email such as info@ or contact@, public phone, public Google Maps profile details), obtained from publicly available sources. Purpose: B2B outreach to service businesses. Basis: legitimate interests (Art. 6(1)(f)) — our interest in offering relevant services to businesses; you can object at any time via the unsubscribe link in any email or by emailing hello@websiteos.ai.
- Website analytics (page views, scroll depth, clicks, and the Google Analytics client identifier, which is personal data). Purpose: to understand how visitors use our site. Basis: consent (Art. 6(1)(a)) — collected only after you accept analytics cookies.
- Technical and security data (IP address, browser, device, operating system). Purpose: security, fraud prevention, and performance. Basis: legitimate interests (Art. 6(1)(f)) — keeping the service secure and operational.
4. Data we obtain from third parties (Art. 14)
5. Who we share data with
6. International data transfers
We are based in the UAE and some of our providers are in the United States, so personal data is transferred outside the EEA. For each transfer we rely on an appropriate safeguard under GDPR Chapter V:
- Providers certified under the EU-US Data Privacy Framework (an adequacy decision under Art. 45).
- Where a provider is not so certified, Standard Contractual Clauses (Art. 46) together with our own supplementary measures (such as EU-region data storage and encryption). Transfers to our UAE operations rely on Standard Contractual Clauses.
The specific mechanism for each provider is shown on the Sub-processors page. You can request a copy of the relevant safeguards by emailing hello@websiteos.ai.
7. How long we keep data
- Account and business data: for the life of your account, then up to 90 days after closure to allow reactivation and export, after which it is deleted.
- Billing and tax records: kept for the period required by applicable tax and accounting law (typically up to 5 years).
- Prospect data: deleted within 12 months if there is no engagement, and immediately on unsubscribe or opt-out.
- Analytics data: retained for up to 14 months.
- Security logs: retained for up to 12 months.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to processing of your personal data, and the right to data portability. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out. To exercise any right, email hello@websiteos.ai; we respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work. In Denmark this is Datatilsynet (datatilsynet.dk).