This Privacy Policy explains how Vantage (“Vantage”, “we”, “us”) collects, uses, shares, and protects personal data when you use the Vantage ASEO platform and related services (the “Service”). It should be read together with our Terms of Service. We are based in the United Arab Emirates and serve business customers, primarily in the GCC region.
1. Data We Collect
Depending on how you use the Service, we collect the following categories of data:
- Account information — name, email address, company/agency name, and account settings you provide when you sign up or manage your account.
- Payment information — billing details and subscription records. Payments are processed by Stripe; we do not store your full card number. We receive limited data such as the last four digits, card brand, and payment status.
- Website & crawl data — the URLs you submit and content we fetch from those pages in order to run technical checks and AI analysis (for example, page text, metadata, and structure).
- Link-click data — when someone clicks a Campaign Link, we record event data including approximate geographic location, IP address, device and browser type, referrer, and timestamp, used to produce your click analytics.
- AI prompt & analysis data — the inputs sent to AI models (derived from your submitted content) and the resulting scores, summaries, and recommendations.
- Usage, device & cookie data — log data, IP address, device and browser information, pages viewed, and similar diagnostics collected via cookies and comparable technologies (see Section 8).
2. How We Use Data
- To provide, operate, and maintain the Service and its three products.
- To crawl submitted websites and generate AI-assisted analysis, scores, and recommendations.
- To create and display link-click analytics.
- To process subscriptions, billing, and renewals through Stripe.
- To authenticate users, secure accounts, and prevent fraud and abuse.
- To provide support and respond to your requests.
- To improve and develop the Service, including reliability and performance.
- To send service-related communications and, where permitted, product updates (you can opt out of marketing messages).
- To comply with legal obligations and enforce our Terms.
3. Legal Basis for Processing
Where the EU/UK GDPR or the UAE Personal Data Protection Law (PDPL) applies, we rely on one or more of the following legal bases:
- Performance of a contract — to deliver the Service you signed up for.
- Legitimate interests — to secure, analyze, and improve the Service, where not overridden by your rights.
- Consent — for non-essential cookies and optional marketing, which you may withdraw at any time.
- Legal obligation — to meet accounting, tax, and other legal requirements.
4. Third-Party Processors & Sharing
We do not sell your personal data. We share data with trusted service providers who process it on our behalf, under contract, only to provide the Service:
- Stripe — payment processing and subscription management.
- AI providers — Anthropic, OpenAI, and Google, which process submitted content to generate analysis.
- Hosting & infrastructure providers — cloud hosting, databases, and storage used to run the Service.
We may also disclose data where required by law, to protect our rights and users, or in connection with a merger, acquisition, or sale of assets (with notice where required).
5. Data Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, accounting, and dispute-resolution obligations. Crawl and analysis data and link-click event data are retained to provide historical analytics; we may aggregate or anonymize data for longer-term statistical use. When data is no longer needed, we delete or anonymize it.
6. Security
We use technical and organizational measures designed to protect personal data, including:
- Encryption of data in transit (TLS) and encryption of data at rest and backups.
- Tenant isolation so each customer’s data is logically separated from others.
- Access controls, authentication, and least-privilege access for our systems and staff.
- Monitoring, logging, and regular review of our security practices.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to incidents.
7. Your Rights
Subject to applicable law, you may have rights to access, correct, export (portability), restrict, or object to the processing of your personal data, and to request deletion.
- You can exercise these rights by contacting us at privacy@aseo.knockbook.com. We will respond within the timeframes required by applicable law.
- Self-service data export and deletion tooling is on our roadmap; until it ships, please submit these requests to us by email and we will action them.
- If you act on behalf of clients, you are responsible for forwarding relevant requests from your clients’ data subjects to us where needed.
- You may also have the right to lodge a complaint with a competent data-protection authority.
8. Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. Strictly necessary cookies are required for the Service to function; other cookies are used only where permitted. You can control cookies through your browser settings, though disabling some may affect functionality.
9. International Data Transfers
We and our processors may store and process data in countries other than your own, including where our AI providers, payment processor, and hosting providers operate. Where personal data is transferred across borders, we take steps to ensure an appropriate level of protection consistent with applicable law (for example, standard contractual clauses or equivalent safeguards).
10. Children’s Data
The Service is intended for business users and is not directed to individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
11. GDPR & UAE PDPL
Where the EU/UK General Data Protection Regulation (GDPR) or the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, PDPL) applies to our processing, we handle personal data in accordance with those frameworks, including the rights and legal bases described above. Where we act as a processor for data you submit about third parties (such as your clients), you remain the controller of that data.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Please review this page periodically.
13. Contact
For any privacy question or to exercise your rights, contact us at privacy@aseo.knockbook.com.