Privacy Policy
Last updated: July 21, 2026
1. Data Controller
RecommendHQ, UK (“we”, “our”, “us”) is the trading name under which this Service is operated, and is the data controller for personal data processed through this Service. You can contact the controller about any privacy matter via our contact page or by email at privacy@recommendhq.com. Our primary compute infrastructure is located in the EU (europe-west4); where data is processed outside the UK/EEA we rely on the safeguards described in §7.
2. What We Collect
- Scan requests: domain name, prompt text, email address, and hashed IP (raw IP is never stored; see §6).
- Account data: email address, authentication timestamps, subscription tier.
- Usage data: pages visited, scan counts, feature interactions (no cross-site tracking).
- Billing data: Stripe customer ID and subscription status only. Card details are held exclusively by Stripe and never transmitted to our servers.
- Waitlist & contact submissions: the email address you give us when joining the launch waitlist or requesting early access, and, via the contact form, the name, company, topic, and message you choose to include.
- Business contact details, where we contacted you first:if you work at an agency we approached, we hold your name, role and work email address, your employer’s public details, a record of the public source we took them from and the date, and a log of our correspondence. We collect these from public business sources rather than from you, so §3 explains that separately.
3. How We Use Your Data
- To perform the free scan and return your R-Score and citation graph.
- To send the scan report you request at the results screen. Nothing else is sent to free-scan leads without separate opt-in consent.
- To send launch updates you explicitly ask for by joining the waitlist, and to answer contact-form messages.
- To enforce rate limits and abuse controls (hashed IP, disposable-email checks).
- To operate, improve, and secure the Service.
Lawful basis (UK GDPR Art. 6): we rely on your consent for the free scan and the service/launch emails you ask us to send; performance of a contract for account and billing data; and our legitimate interestsin securing the Service, preventing abuse, and making the limited business-to-business introductions described immediately below. If you gave us your address yourself, we will not add you to any marketing list without separate, specific opt-in consent, and you can withdraw that consent — or unsubscribe via the one-click link in any marketing email — at any time.
3a. If We Contacted You First (B2B outreach)
We send a small volume of business-to-business email to named contacts at marketing and SEO agencies, offering a sample AI-visibility audit of one of that agency’s publicly listed clients. If you received one of those messages, this section is your notice under UK GDPR Art. 14, because we obtained your details from a source other than you.
- Source:public business sources only — your employer’s own website, a public agency directory, or your public professional profile. The specific source is named in the email itself, and we will confirm it on request. We do not buy lists, scrape at scale, or use data-enrichment vendors.
- Purpose and lawful basis: one relevant commercial introduction, on the basis of our legitimate interests (Art. 6(1)(f)) in reaching businesses whose work our service is built for. We have carried out and recorded a balancing assessment.
- Categories: your name, role and work email address, plus our record of the source and of any correspondence. We hold no personal contact details and build no profile of you.
- Recipients: nobody. We do not share, sell or transfer prospect data, and the message is sent by us directly rather than through a marketing platform.
- Your right to object (Art. 21):absolute for direct marketing. Reply “no” to any message from us, or email privacy@recommendhq.com, and we will stop immediately and permanently. You do not have to give a reason, and we do not weigh it against anything. You have the same rights of access, rectification and erasure set out in §8.
3b. Audits You or Our Customers Run on Third-Party Domains
Our free scan and the Pitch Pack let a user run an AI Recommendation Audit on a domain — for example, an agency auditing a prospect before a pitch. Where that domain identifies an individual (such as a sole trader or personal brand), we process a small amount of business data about them as controller, and this section is your notice under UK GDPR Art. 14. Separately, for the account and usage data of a customer running audits through our platform, we act as processor under a Data Processing Agreement, which we can provide to agencies and teams on request; the controller role described here concerns only the business data of the audited party.
- Purpose and lawful basis: assessing public AI-recommendation visibility for a domain, on the basis of the legitimate interests (Art. 6(1)(f)) of RecommendHQ and the user running the audit. The user confirms at the point of purchase or redemption that they have a legitimate business reason to audit the domain.
- Categories: the domain, an optional brand name, the resulting R-Score and status, and the audit date. We hold no other contact details for the audited party and build no profile of them.
- Recipients: the report is delivered only to the user who ran the audit. We do not sell or publish third-party audit results.
- Your rights (Art. 15, 16, 17, 21): if you are the subject of an audit, email privacy@recommendhq.comand we will action access, rectification, objection or erasure — including removing the audit record — on the same terms set out in §8.
4. No AI Training
We do not use client data (including your domain, prompts, R-Score results, or email) to train foundational AI models, fine-tune language models, or share data with any AI model provider for training purposes.
Data submitted through the scan form is used solely to fulfill your scan request, compute your R-Score, and send you the report.
5. Retention
- Free scan leads: 90 days from scan date (TTL-pruned automatically).
- Waitlist and contact records: kept until we have sent the launch update or reply you asked for, and no longer than 12 months from submission; deleted earlier on request.
- B2B outreach records (§3a): deleted 12 months after our last contact with you, or immediately on request.
- Suppression records: if you opt out or object, we keep your email address on a suppression list indefinitely. That is the minimum we need to guarantee we never contact you again, and it is used for nothing else.
- Account data: retained for the life of your subscription + 30 days after cancellation.
- Prompt cache: results are cached for a limited, surface-specific period. No personal data in cache keys.
- Billing records: retained for as long as UK tax law requires (up to six years).
6. Security Measures
- IP addresses are SHA-256 hashed before any storage write. Raw IPs are never persisted.
- All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- API keys and secrets are stored in a dedicated secrets-management service, not in environment variables.
- Google reCAPTCHA Enterprise (via Firebase App Check) protects our public forms and endpoints — including the scan, contact, and Pitch Pack checkout and redemption flows — against automated abuse. It is loaded only when you submit a protected form or action, not on page load, and processes your IP address and device/interaction signals to tell humans from bots.
7. Third-Party Processors
- Google Cloud — compute and storage (EU region).
- Google reCAPTCHA Enterprise — bot detection and abuse prevention on our public forms (processes IP and device/interaction signals).
- Stripe — payment processing (PCI DSS Level 1).
- Amazon Web Services (SES) — transactional email delivery (EU region).
- OpenAI / Perplexity / Google — AI query surfaces for scan analysis. Only the submitted domain and the derived category query are sent; we do not include your email or IP address.
- SEO Data — licensed SERP-data provider used to collect Google AI Overviews results. Only the derived category query is sent; never your email or IP address.
International transfers. Some processors, including Stripe, OpenAI and Google (reCAPTCHA Enterprise), process data in the United States. Where personal data is transferred outside the UK/EEA, we rely on UK GDPR Article 46 safeguards: the UK International Data Transfer Addendum / EU Standard Contractual Clauses, and, where applicable, each provider’s EU–US Data Privacy Framework certification.
8. Your Rights (UK GDPR)
You have the right to access, rectify, erase, restrict, or port your personal data. To exercise any right, contact us via our contact page. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.
9. Cookies
We use only essential cookies and similar technologies: a session cookie for authentication, and the strictly-necessary security cookies/tokens set by Google reCAPTCHA Enterprise (our bot-protection and anti-abuse service) to protect our forms. reCAPTCHA Enterprise is loaded only when you actively submit a protected form, never on page load, and we rely on our legitimate interest in fraud and abuse prevention (and the strictly-necessary exemption) as the lawful basis. We do not use tracking, advertising or analytics cookies. Because nothing non-essential loads before you interact, no cookie-consent banner is required; reCAPTCHA may set cookies on Google’s domain when invoked, governed by Google’s Privacy Policy.
10. We Never Sell Your Data
We do not sell or share your personal information for money or for cross-context behavioral advertising. To exercise any of your rights, contact us via our contact page.
California residents (CCPA/CPRA). In the past 12 months we have not sold or shared your personal information. You have the right to know, access, delete and correct your personal information, and to be free from discrimination for exercising those rights.
11. Changes
Material changes to this policy will be communicated via email at least 14 days before the effective date.
12. Contact
Data protection inquiries: our contact page or privacy@recommendhq.com
See also: Terms of Service