Legal
Privacy Notice
This notice describes our current personal-data processing practices under the applicable UK data-protection framework, which includes the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
At a glance
- The data controller is Apefo Ltd. There is no statutory Data Protection Officer to appoint; you can reach us at hello@seoryx.app.
- We use Google Analytics 4 (via Google Site Kit) with Google Consent Mode: analytics storage is denied by default, so ordinary browsing sets no analytics cookies until you accept. We use no advertising, marketing or cross-site tracking. Opening the pilot form may load Cloudflare Turnstile and necessary security storage.
- We process only the data you send us (enquiries and pilot-form details) or the accounts you choose to connect (for example, Search Console, analytics, crawl, rank or content sources).
- We do not make solely automated decisions that produce legal or similarly significant effects. A human operator reviews and approves before any decision becomes a work order, and Seoryx does not change your site itself.
- We rely on a small, named set of subprocessors; the current list is set out below and is also available on request.
Who we are
The controller responsible for the personal data described in this notice is Apefo Ltd, a limited company registered in England and Wales under company number 16610465, with its registered office at Office 1, Izabella House, 24–26 Regent Place, City Centre, Birmingham, United Kingdom, B1 3NJ. Apefo Ltd operates Seoryx, the decision-trace and verification layer for iGaming and affiliate SEO teams.
We have not appointed a Data Protection Officer. Privacy matters are handled by the operator and can be raised at hello@seoryx.app. For any question about this notice or about how we handle your data, contact us at hello@seoryx.app.
Data we collect
We collect only what we need to answer enquiries, run pilots and keep the site secure. In practice this covers:
- Form and pilot data. The details you provide when you submit the pilot form or otherwise get in touch, such as your name, email address, company and the message or context you send us.
- Connected-account data you authorise. Where you choose to connect a source to run a pilot, we process the data made available through that connection. This is limited to what you connect or send us — for example, Search Console, analytics, crawl, rank or content data for the pages in scope.
- Correspondence. The content of emails and other messages exchanged with us, so we can respond and keep a record of what was agreed.
- Technical logs. Standard server and security logs generated when a device interacts with the site, such as IP address, user-agent, timestamps and the URLs requested.
- Turnstile security signals. When you submit the pilot form, our anti-bot challenge (Cloudflare Turnstile) processes signals needed to distinguish humans from automated abuse.
We do not seek or ask you to provide special-category data (such as data about health, race, religion, political opinions, sexual orientation or biometrics), and Seoryx is not designed to handle it. Any data we hold about you from third-party sources is only what you connect or send us — we do not buy, scrape or enrich personal data from data brokers.
Purposes and lawful bases
We process personal data for the following purposes and on the following lawful bases under UK GDPR:
- Respond to enquiries and run pilots
- Legitimate interests (to answer questions and evaluate whether Seoryx is a fit) and, where you are entering into or performing an agreement with us, taking steps at your request prior to a contract or performing that contract.
- Operate and secure the site, including Turnstile
- Legitimate interests (to keep the site available, prevent abuse and fraud, and protect the pilot form from automated attack).
- Deliver transactional email
- Legitimate interests and, where relevant, performance of a contract (to send you the messages you have asked for or that relate to a pilot).
- Meet legal obligations and keep records
- Compliance with a legal obligation, and our legitimate interests in maintaining accurate business records and establishing, exercising or defending legal claims.
- Measure aggregate site usage (analytics)
- Consent. We use Google Analytics 4 (via Google Site Kit) only where you have accepted analytics; you can withdraw consent at any time in our cookie banner or on the cookie settings page. With consent denied, Google Consent Mode uses cookieless, aggregated signals.
Where we rely on legitimate interests, we have considered your rights and interests and do not use these grounds where they are overridden. You can object to processing based on legitimate interests as described under Your rights.
Cookies and Turnstile
We use Google Analytics 4 (via Google Site Kit) only with your consent — Google Consent Mode denies analytics storage by default, so no analytics cookies are set until you accept — and we use no advertising or marketing cookies. As of our most recent consent-implementation test (a logged-out browser audit on 16 July 2026), ordinary browsing set no first-party cookies unless analytics was accepted. Strictly-necessary cookies from WordPress and Contact Form 7 (for session, form integrity and nonces) may be set only when you actively submit the pilot form or, for our staff, sign in to the admin area. The only third party involved in this is Cloudflare Turnstile, which runs the anti-bot challenge on the pilot form and may set a cookie on its own domain to do so. For the full breakdown of storage and technologies, see our Cookies notice.
Recipients and subprocessors
We share personal data only with the service providers we rely on to operate Seoryx. Our current subprocessors are:
| Provider | Role | Location / notes |
|---|---|---|
| Cloudflare, Inc. | Authoritative DNS for seoryx.app and Cloudflare Turnstile anti-bot on the pilot form. | Not used here as a CDN or reverse proxy — the site is served directly by nginx. Turnstile may set a cookie on its own domain. |
| Mailgun (operated by Sinch) | Transactional email delivery. | EU region; sending domain email.seoryx.app. |
| Google (Google Ireland Limited, with Google LLC) | Google Analytics 4 (aggregate site-usage analytics), loaded via Google Site Kit, subject to your consent. | Google Consent Mode default-denied; may involve transfer to the USA under the EU-US Data Privacy Framework (UK extension) and/or Standard Contractual Clauses. |
| YNVAR | Website and server hosting. | YNVAR, our hosting provider, on EU-based infrastructure. |
| WordPress.org | Occasional core front-end static assets (for example, emoji). | Only when such assets are used. |
We keep this list current and will provide it on request. Pilot customers receive a fuller list of subprocessors and can enter into a signed data processing agreement; see our Data Processing Addendum.
International transfers
Some of our providers may process personal data outside the United Kingdom or the EEA. Where they do, we rely on appropriate safeguards, such as UK adequacy regulations, the ICO’s International Data Transfer Agreement (IDTA) or addendum, or the EU Standard Contractual Clauses. Where a provider offers it, we prefer EU-region processing — for example, our transactional email is configured to the EU region. Google Analytics may involve transfer to the United States; Google relies on the EU-US Data Privacy Framework (and its UK extension) and/or Standard Contractual Clauses.
Retention
We keep personal data only for as long as we need it, judged against defensible criteria rather than fixed periods we cannot justify:
- Enquiries. Kept only as long as needed to follow up on your message, then deleted.
- Pilot data. Kept for the duration of the pilot and a short wind-down afterwards, then deleted or anonymised — sooner if you ask us to.
- Records required by law. Kept for the period the relevant law requires, then deleted.
Deletion may lag in routine backups, which age out on a normal cycle rather than being edited individually.
Your rights
Subject to the conditions in data-protection law, you have the right to access your personal data; to have it rectified; to have it erased; to restrict or object to its processing; to data portability; and, where we rely on consent, to withdraw that consent at any time (without affecting processing already carried out). To exercise any of these, contact hello@seoryx.app. We may need to verify your identity before we act on a request, so that we do not disclose data to the wrong person.
Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significant effects, by solely automated means. Seoryx’s configurable multi-AI review, where it runs, informs a human operator, who reviews and approves before any decision becomes a work order. Seoryx does not publish or change any website by itself. Its verification window measures change against a locked baseline; it is not causal proof and not a forecast, and outputs may be wrong and must be reviewed.
Complaints
If you have a concern about how we handle your data, please contact us first at hello@seoryx.app so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk, or to your local supervisory authority if you are elsewhere.
Changes to this notice
We may update this notice from time to time to reflect changes in our processing practices or legal obligations. The current version is always available here, and the date the template records as last updated reflects the latest revision.