Hyper Agency AB
Privacy policy
Hyper Agency AB privacy policy
What Is SEO? Why It Matters More Than Ever —
And How you can approach SEO with AI.
Effective Date: 13.08.2025
Last Updated: August 2026
Data Controller: Hyper Agency AB, Org. nr 559520-4537 (“we”, “us”, “our”)
Privacy Contact: info@hyperagency.ai
We are committed to processing data in compliance with the EU General Data Protection Regulation (GDPR) and the Swedish Act with supplementary provisions to the GDPR (SFS 2018:218).
1. Scope of This Policy
This Privacy Policy applies to personal data collected and processed through:
- Websites & Digital Touchpoints: Hyperagency.ai, sub-domains, campaign microsites, and online forms (including LinkedIn Lead Gen Forms).
- Software Tools & Platforms: Our entire product suite, including our LLM AI Audit Tool, Brand Tracker platform, and related software applications (collectively, “our tools and services”).
- Direct Communications: Email communications where you opt into company updates, blog posts, or marketing material, as well as customer support and business development inquiries.
Note: This policy does not cover third-party client datasets processed strictly under a Data Processing Agreement (DPA) where we act as a data processor. In those scenarios, your organization is the data controller and processing is governed by the DPA.
2. Our Legal Roles
- Website, Marketing & Lead Capture: We act as the data controller.
- Tool & Account Data: We act as the data controller for account credentials, billing details, and security logs. We act as a data processor for organizational content uploaded into our tools and services when executing a DPA with business customers.
- We maintain internal record logs and formal processing contracts with all sub-processors (cloud hosting, email infrastructure, analytics, etc.).
3. Categories of Data We Collect
A. Account & Contact Data
- Name, work email address, job role, company name, hashed passwords, marketing preferences, timestamps, and proof of consent or opt-out selections.
- Support tickets, meeting requests, and sales correspondence.
B. Tool Data (AI Audits, Brand Tracking & Analytics)
- User inputs (prompts, uploaded files, configuration settings), generated evaluation outputs, performance metrics, and technical metadata (timestamps, user IDs, request sizes, latency, IP addresses).
- Special Categories: Our tools and services are not intended for processing sensitive personal data (e.g., health data, biometrics, political opinions). Please avoid entering sensitive data unless explicitly permitted by your enterprise contract.
C. Device & Browsing Technical Data
- Server logs (IP address, user-agent, referrer URL, access timestamps, requested pages).
- Cookies, local storage, SDKs, and pixel tracking as detailed in Section 8.
D. B2B Professional Sourcing Data
- Public business contact information (e.g., LinkedIn profiles, corporate directories) collected for direct B2B outreach in accordance with our legitimate business interests and applicable marketing regulations.
4. Processing Purposes & Legal Bases
| Processing Purpose | Data Categories Used | Legal Basis (GDPR) |
| Tool & Platform Operation | Account info, tool data, system logs | Contract (Art. 6(1)(b)) & Legitimate Interests for security/uptime (Art. 6(1)(f)) |
| Security & Abuse Prevention | System logs, IP addresses, usage patterns | Legitimate Interests (Art. 6(1)(f)) |
| Product Analytics & Improvement | Aggregated tool metadata, system diagnostics | Legitimate Interests (Art. 6(1)(f)), or Consent where required by e-privacy rules (Art. 6(1)(a)) |
| Service Communications | Contact details | Contract (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c)) |
| Direct B2B Marketing & Newsletters | Contact details, granular preferences | Consent (Art. 6(1)(a)) via unchecked opt-in boxes, freely given and withdrawable anytime |
| Legal Compliance & Record-Keeping | Necessary contact and transaction records | Legal Obligation (Art. 6(1)(c)) |
Age Limits: Our tools and services are designed for enterprise and B2B professionals and are not directed to children. Where information society services are offered to a child in Sweden, independent consent is valid from age 13 under Swedish law (SFS 2018:218).
5. Responsible Handling of Tool & AI Data
- Default Posture: We process tool inputs and analytical content strictly to run evaluations, perform brand tracking, and deliver results within your tenant account.
- Model Training: We do not use your identifiable tool content or client data to train third-party foundation AI models. Any future model optimization features will remain off by default and require explicit opt-in.
- Data Minimization: We strip or hash direct identifiers wherever technical metrics can be stored in aggregate form.
- Administrative Controls: Workspace administrators can configure data retention windows and export or purge project data at any time.
6. Data Sharing & Third Parties
We only share personal data with trusted third parties under strict written contracts:
- Sub-processors: EU/EEA and compliant international providers for cloud hosting, data security, email distribution, meeting scheduling, ad tracking, and secure AI evaluation infrastructure.
- Internal Team Tenants: Account activity and asset views shared within your organization’s workspace.
- Legal Obligations: Courts, law enforcement, or regulatory bodies when mandated by law.
- Corporate Restructuring: Relevant parties in the event of a merger, acquisition, or asset re-organization, governed by strict confidentiality terms.
7. International Data Transfers
We prioritize hosting and processing data within the EU/EEA. Where data is transferred outside the EEA, we enforce GDPR Chapter V protection mechanisms:
- Standard Contractual Clauses (SCCs): Implementing Commission Implementing Decision (EU) 2021/914 alongside Transfer Impact Assessments (TIAs) and supplementary security measures.
- EU–U.S. Data Privacy Framework (DPF): Relying on the EU adequacy decision (EU 2023/1795) for transfers to certified U.S. entities.
8. Cookies & Local Storage (EU / Swedish Rules)
Under the Swedish Electronic Communications Act (LEK, SFS 2022:482), accessing or storing information on your device requires active, informed consent, except for strictly necessary technical operations.
In compliance with Swedish Post and Telecom Authority (PTS) guidelines:
- Non-essential cookies (analytics and marketing) are blocked by default until you actively opt in.
- Rejection of non-essential tracking is as easy as acceptance on our consent management banner.
- Consent can be adjusted or withdrawn at any time via the “Manage Preferences” link on our site.
9. Retention Periods
Personal data is retained only as long as required to fulfill the operational purposes set forth in Section 4:
- Account Data: Active account lifecycle plus 12 months for auditing and seamless reactivation.
- Tool Content & Metrics: Default 30 to 90 days (configurable for enterprise contracts). Workspace admins may purge content earlier.
- Security Logs: 12 months, unless extended to investigate specific security incidents.
- Marketing Consents: Retained until consent is withdrawn, after which minimal suppression records are stored to ensure your unsubscribe preference is honored.
- Accounting & Statutory Records: Retained in accordance with Swedish statutory tax and bookkeeping requirements.
10. Your Rights Under GDPR
You have the right to request access to, rectification of, restriction of, or erasure of your personal data, as well as data portability and the right to object to processing. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.
- Exercising Your Rights: Email your request to info@hyperagency.ai. We will verify identity and respond within statutory GDPR timeframes.
- Supervisory Authority: Sweden’s Integritetsskyddsmyndigheten (IMY) is our lead data protection authority. You have the right to lodge a complaint directly with IMY at imy.se.
- Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
11. Security Measures
We implement technical and organizational security controls, including transit and rest encryption, strict least-privilege access management, continuous vulnerability scanning, audit logging, employee non-disclosure obligations, and vendor due diligence. In the event of a personal data breach, we follow established incident response protocols to notify affected parties and authorities as required by GDPR Articles 33 and 34.
12. Granular Marketing Opt-Ins
When subscribing via our site or lead forms, you can select specific communication channels via unchecked consent boxes:
- Technical updates and research articles
- Commercial offers and product announcements
Consent details (timestamp, IP address, and selected preferences) are logged to satisfy accountability requirements. You can unsubscribe at any point via the link in any email footer or by contacting info@hyperagency.ai.
13. Enterprise & DPA Terms
For business customers utilizing our tools and services:
- We provide a standard Data Processing Agreement (DPA) governing our role as a processor for uploaded content.
- Workspace administrators retain granular control over data export, retention limits, and user seats.
- We assist enterprise customers with Data Protection Impact Assessments (DPIAs) and data subject request workflows upon request.
14. International Users
We process all personal data in accordance with this policy and applicable EU/EEA legal frameworks regardless of user location, while honoring any stronger mandatory local privacy protections that apply to you.
15. Changes to This Policy
We reserve the right to update this policy to reflect operational, technological, or legal changes. Updates will be posted on this page with a revised effective date. Material changes will be communicated via email or in-app notification.
16. Contact Details
Data Controller:
Hyper Agency AB
Org. nr: 559520-4537
Email: info@hyperagency.ai
Lead Supervisory Authority:
Integritetsskyddsmyndigheten (IMY)
Website: imy.se
Appendix A – Data Map Summary
| Processing Purpose | Data Categories | Recipient Categories | Storage Location | Standard Retention |
| Tool Operations | Hashed credentials, prompts/outputs, platform metrics, performance logs | Cloud hosting, security logging, & AI runtime processors | EU/EEA by default; SCCs/DPF for third countries | Default 30–90 days for content; 12 months for security logs |
| Marketing Outreach | Work email, consent status, preference flags | Dedicated email service provider | EU/EEA or certified DPF vendor | Kept until consent withdrawal; minimal suppression list retained |
| Analytics (Opt-in) | Pseudonymous identifiers, usage events | Privacy-compliant analytics platforms | EU/EEA or certified DPF vendor | As configured in Cookie Management System |
| Security & Auditing | IP addresses, request headers, anomaly indicators | Infrastructure protection tools | EU/EEA or certified DPF vendor | 12 months (extended for active investigations) |
| Support & Sales | Contact info, communication logs | Customer service and scheduling infrastructure | EU/EEA or certified DPF vendor | Ticket lifecycle plus 12 months |
No bots. Contact a real person.
We actually answer our own emails. Book a call, take a meeting, or request more information on how we work, protect your data, and deliver results.