Legal

Privacy Policy

Last updated: July 21, 2026

1. Data Controller

RecommendHQ, UK (“we”, “our”, “us”) is the trading name under which this Service is operated, and is the data controller for personal data processed through this Service. You can contact the controller about any privacy matter via our contact page or by email at privacy@recommendhq.com. Our primary compute infrastructure is located in the EU (europe-west4); where data is processed outside the UK/EEA we rely on the safeguards described in §7.

2. What We Collect

3. How We Use Your Data

Lawful basis (UK GDPR Art. 6): we rely on your consent for the free scan and the service/launch emails you ask us to send; performance of a contract for account and billing data; and our legitimate interestsin securing the Service, preventing abuse, and making the limited business-to-business introductions described immediately below. If you gave us your address yourself, we will not add you to any marketing list without separate, specific opt-in consent, and you can withdraw that consent — or unsubscribe via the one-click link in any marketing email — at any time.

3a. If We Contacted You First (B2B outreach)

We send a small volume of business-to-business email to named contacts at marketing and SEO agencies, offering a sample AI-visibility audit of one of that agency’s publicly listed clients. If you received one of those messages, this section is your notice under UK GDPR Art. 14, because we obtained your details from a source other than you.

3b. Audits You or Our Customers Run on Third-Party Domains

Our free scan and the Pitch Pack let a user run an AI Recommendation Audit on a domain — for example, an agency auditing a prospect before a pitch. Where that domain identifies an individual (such as a sole trader or personal brand), we process a small amount of business data about them as controller, and this section is your notice under UK GDPR Art. 14. Separately, for the account and usage data of a customer running audits through our platform, we act as processor under a Data Processing Agreement, which we can provide to agencies and teams on request; the controller role described here concerns only the business data of the audited party.

4. No AI Training

We do not use client data (including your domain, prompts, R-Score results, or email) to train foundational AI models, fine-tune language models, or share data with any AI model provider for training purposes.

Data submitted through the scan form is used solely to fulfill your scan request, compute your R-Score, and send you the report.

5. Retention

6. Security Measures

7. Third-Party Processors

International transfers. Some processors, including Stripe, OpenAI and Google (reCAPTCHA Enterprise), process data in the United States. Where personal data is transferred outside the UK/EEA, we rely on UK GDPR Article 46 safeguards: the UK International Data Transfer Addendum / EU Standard Contractual Clauses, and, where applicable, each provider’s EU–US Data Privacy Framework certification.

8. Your Rights (UK GDPR)

You have the right to access, rectify, erase, restrict, or port your personal data. To exercise any right, contact us via our contact page. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

9. Cookies

We use only essential cookies and similar technologies: a session cookie for authentication, and the strictly-necessary security cookies/tokens set by Google reCAPTCHA Enterprise (our bot-protection and anti-abuse service) to protect our forms. reCAPTCHA Enterprise is loaded only when you actively submit a protected form, never on page load, and we rely on our legitimate interest in fraud and abuse prevention (and the strictly-necessary exemption) as the lawful basis. We do not use tracking, advertising or analytics cookies. Because nothing non-essential loads before you interact, no cookie-consent banner is required; reCAPTCHA may set cookies on Google’s domain when invoked, governed by Google’s Privacy Policy.

10. We Never Sell Your Data

We do not sell or share your personal information for money or for cross-context behavioral advertising. To exercise any of your rights, contact us via our contact page.

California residents (CCPA/CPRA). In the past 12 months we have not sold or shared your personal information. You have the right to know, access, delete and correct your personal information, and to be free from discrimination for exercising those rights.

11. Changes

Material changes to this policy will be communicated via email at least 14 days before the effective date.

12. Contact

Data protection inquiries: our contact page or privacy@recommendhq.com

See also: Terms of Service