Privacy Policy
Last updated: 2026-09-02
1. Introduction
In plain terms: we describe the data used to run your account and our AI agents, the recipients we share it with, and how to request access, export, correction, objection, or deletion. The sections below set out the detail.
Atlio Limited (“Atlio Limited”, “we”, “us”, “our”), a company registered in New Zealand, operates the SearchChamp platform at searchchamp.com. SearchChamp is a product of Atlio Limited. Atlio Limited conducts regional operations in the United Arab Emirates through its branch, Atlio Information Technology LLC (Dubai, United Arab Emirates). This policy addresses the New Zealand Privacy Act 2020, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”) and, where applicable, the EU and UK General Data Protection Regulation (“GDPR”). Our control reviews are ongoing; this policy does not by itself establish legal compliance.
This Privacy Policy explains how we collect, use, share, and safeguard your personal data when you access or use our platform, websites, and services. By creating an account or continuing to use SearchChamp, you acknowledge that you have read and understood this policy.
2. Data we collect
We collect the following categories of personal data:
2.1 Data you provide directly
- Account data: name, email address, company name, and job title when you register.
- Payment data: billing address and payment method details processed by Stripe. We never store raw card numbers on our servers.
- Connected platform credentials: credentials you authorise for the website and commerce platforms you connect, such as WordPress Application Passwords, Shopify OAuth tokens, and equivalent credentials for the other platforms we support. These are stored encrypted, used only to perform the actions you request (for example publishing content or applying fixes), and can be revoked at the connected service or disconnected in the app.
- Connected email account (optional): if you connect a Gmail or Outlook account for link outreach, we store the OAuth tokens you authorise, encrypted, in AWS Secrets Manager. We request send-only permission plus your basic profile (your email address); we do not request permission to read your mailbox.
- Other optional connections: a Slack token and channel selection if you connect Slack for notifications, and a scoped Cloudflare API token if you connect Cloudflare for bot-access verification. Both are stored encrypted and can be disconnected at any time.
- Outreach contacts: names, email addresses, and domains of link-building prospects that you add or that the platform finds from public sources for your campaigns. Outreach messages are drafted for your review, and sending is always initiated by you.
- Support communications: messages, attachments, and metadata when you contact our support team.
- Free-tool submissions: the email address you enter and the inputs you submit (for example the domain, competitor domain, or keyword you want analysed) when you request a report from one of our free tools at searchchamp.com. You do not need an account to use these tools.
2.2 Data collected automatically
- Usage data: pages visited, features used, agent jobs initiated, keyword searches run, and timestamps of those actions.
- Device and browser data: IP address, user-agent string, browser type and version, operating system, referrer URL, and screen resolution. Where you submit a request to one of our free tools, the IP address that submission came from is also stored on the submission record itself; see section 7 for what we keep and for how long.
- Abuse-prevention signals: submissions to our free public tools are screened by Google reCAPTCHA, which processes device and usage signals, including your IP address, to distinguish people from automated abuse.
- Performance data: error traces, API response times, and crash reports collected via server-side logging.
2.3 Data from third-party integrations
- Google Search Console and Google Analytics 4: search query data, click data, and audience metrics you authorise us to read on your behalf.
- Google Ads and Google Tag Manager: campaign and keyword data, and tag and container configuration, that you authorise us to read on your behalf.
- DataForSEO: keyword volume, SERP data, and backlink metrics retrieved using your search inputs.
3. How we use your data
We use your personal data to:
- Provide, operate, and improve the SearchChamp platform and its AI agents (including Keyword Research, Content Writer, Site Auditor, AI Visibility Tracker, GTM Assistant, GA4 Insights, and llms.txt Generator).
- Process payments, issue invoices, and manage subscriptions.
- Send transactional emails (account confirmation, password reset, billing receipts) and service notifications, including scheduled report and digest emails, each with preference controls and an unsubscribe link. Product updates and marketing emails are sent only where you have opted in.
- Run AI agent jobs and chat requests on your behalf using the AI model providers listed in section 5. Data submitted to these models is processed as described there.
- Send link-outreach emails from your connected email account at your direction, and deliver notifications to your connected Slack channel, where you have set these up.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations under New Zealand and UAE law and applicable international regulations.
- Analyse how the platform is used to understand feature adoption and improve our product, using aggregated or pseudonymised data wherever possible.
4. Legal basis for processing
Where the GDPR applies to our processing of your data (for example, where you are based in the European Economic Area or the United Kingdom), we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the services you have signed up for, including account management, AI agent execution, and payment processing.
- Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, product analytics, and customer support. We balance these interests against your rights before relying on this basis.
- Consent (Art. 6(1)(a)): marketing emails, and the optional analytics and advertising cookies used on our public marketing pages. Those cookies are set only after you accept them in our consent banner; the default in every region is denied (see our Cookie Policy). You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): retaining invoices and billing records as required by UAE commercial law.
Under the New Zealand Privacy Act 2020, we collect, use, and disclose personal information in accordance with its information privacy principles. Under the UAE PDPL, we process your data on the bases of contractual necessity, legitimate interest, and your consent where required.
5. Data sharing and sub-processors
We do not sell your personal data. We share data only with the following categories of recipients:
- Infrastructure: Amazon Web Services (AWS) eu-west-1 region hosts our application servers, RDS database, and object storage. AWS processes data under Standard Contractual Clauses (SCCs) where applicable.
- AI model providers: Anthropic (Claude API), OpenAI, and Google (Gemini API) process the content and instructions you submit to AI agent jobs, chat requests, and image generation. Some AI tasks are routed through OpenRouter, a gateway that dispatches requests to a fixed allowlist of model hosts; every such request is sent with training denied (
data_collection: deny), so no model host is permitted to train on your data. Under the commercial API terms of Anthropic, OpenAI, and Google, model inputs are likewise not used to train their models. Additional AI engines used by the AI Visibility feature are listed at /legal/sub-processors. - SEO data: DataForSEO OÜ (Estonia, EU) provides keyword, SERP, and backlink data. Queries include keywords and URLs you submit.
- Payment processing: Stripe processes all payment card transactions. Stripe is PCI-DSS Level 1 certified.
- Google integrations (optional): when you connect Google Search Console, Google Analytics 4, Google Ads, or Google Tag Manager, SearchChamp reads that data on your behalf via OAuth tokens you authorise. We use this access only to read your data, we never change your campaigns, tags, or properties, and we never share your data with Google for advertising. You can revoke access at any time.
- Email sending (optional): when you connect a Gmail or Outlook account for link outreach, the messages you approve are sent through Google or Microsoft from your own account. We request send-only permission plus your basic profile (your email address); we cannot read your mailbox.
- Slack (optional): when you connect Slack, the notifications you configure are delivered to your chosen channel through Slack.
- Cloudflare (optional): when you connect Cloudflare, the scoped API token you provide is used solely to read bot-access information for your own zone.
- Abuse prevention: Google reCAPTCHA protects our free public tools and processes device and usage signals, including IP addresses, under Google’s own terms.
- Authentication: AWS Cognito manages identity and MFA. Tokens are stored client-side in your browser and are never stored on our servers.
A full list of sub-processors, their purposes, and data-transfer mechanisms is maintained at /legal/sub-processors and updated whenever a material change occurs.
6. International transfers
Atlio Limited is based in New Zealand, which holds a European Commission adequacy decision for personal data, and conducts regional operations through its UAE branch. Data is processed primarily in AWS eu-west-1 (Ireland). Some recipients operate in other countries: AI model providers such as Anthropic, OpenAI, and Google process data in the United States, and requests routed through the OpenRouter gateway may be served by model hosts in the United States, China, or Sweden, exactly as listed at /legal/sub-processors. For EEA or UK users, these transfers are safeguarded by the providers’ data processing terms, which incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). We assess the legal landscape of each destination country before transferring data.
If you are based in a jurisdiction with specific transfer-restriction requirements, please contact us at privacy@searchchamp.com to request details of the applicable transfer mechanisms.
7. Data retention
We retain your data for the following periods:
- Account data: retained for the lifetime of your account. When you cancel, your account is auto-closed 90 days after cancellation, and data is then deleted within 30 days of closure, unless we are required by law to retain it longer. If you delete your account yourself, you can restore it by signing back in within 30 days, after which its data is deleted.
- AI agent job outputs (keyword lists, content drafts, audit results, reports): retained for the lifetime of your account so your work remains available, and deleted with your account data on closure. You may export your data at any time, including after cancellation, using the in-app export or by contacting support@searchchamp.com, in accordance with your data portability rights.
- Agent job working data (task inputs, model prompts, and intermediate messages): retained for up to 30 days for operational and debugging purposes (currently deleted automatically 7 days after the job is created), then deleted.
- Outreach campaign data (prospect contacts, pitches, and replies to your own pitches): retained with your account and deleted with it. Campaign CSV export files are automatically deleted from storage within 48 hours of generation.
- Billing records: retained for 7 years, in line with New Zealand tax record-keeping requirements and exceeding the five-year minimum under UAE Federal Decree-Law No. 32 of 2021 (Commercial Companies Law).
- Support tickets: retained for 3 years from resolution.
- Operational and audit logs: retention varies by category. Production CloudWatch log groups use a 90-day minimum-retention control, while audit records may be retained longer. Contact privacy@searchchamp.com for the category applicable to a request.
- Free-tool submissions (email address, submitted inputs, and IP address): when you request a report from one of our free tools at searchchamp.com (for example the competitor comparison, rank checker, SERP checker, or mini site audit), we store the email address you enter, the inputs you submitted, and the IP address the request came from. The IP address is stored in raw, unhashed form and is used to detect and prevent abuse of these free tools; the email address is used to send you the report you requested and, where you consented, occasional SearchChamp emails. The IP address is retained for up to 6 months from your submission and then automatically deleted; the email address and submitted inputs are retained until you ask us to delete them. Email privacy@searchchamp.com at any time to request earlier deletion. Unsubscribing from our emails stops further email but does not by itself delete the stored submission record. This is a separate data flow from the verified-bot crawler records described below, where raw IP addresses are never stored.
- Verified-bot crawler visit records (hashed IP + verification verdict): retained on a rolling 90-day window, then purged. Raw crawler IPs are never persisted (see our Security page).
8. Your rights
Under the UAE PDPL and, where applicable, the GDPR, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data (“right to be forgotten”), subject to legal retention requirements.
- Portability: receive your data in a structured, machine-readable format (JSON or CSV).
- Restriction: request that we restrict processing of your data in certain circumstances.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: withdraw any consent you have given at any time, without affecting the lawfulness of prior processing.
You can exercise the most common rights yourself, without contacting us: export your account data as a JSON file from your account page (the download link is valid for 24 hours), and delete your account from the same page.
To exercise any of these rights, email privacy@searchchamp.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data-protection authority.
9. Children
The SearchChamp platform is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data about a child, please contact privacy@searchchamp.com and we will delete it promptly.
11. Security
We maintain technical and organisational measures including AWS-managed encryption at rest for reviewed storage services, HTTPS on public endpoints, application access controls, and category-specific logging. Our Security page describes the current evidence boundaries and readiness work.
Despite these measures, no internet transmission is 100% secure. If you discover a potential security vulnerability, please disclose it responsibly to security@searchchamp.com.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the “Effective” date at the top of this page. Continued use of the platform after the effective date constitutes acceptance of the revised policy.
13. Contact
For privacy-related enquiries or to exercise your data-subject rights:
Atlio Limited (New Zealand)UAE branch: Atlio Information Technology LLC, Dubai, United Arab Emirates
Email: privacy@searchchamp.com
Privacy policy — common questions
In plain terms: we describe the data used to run your account and our AI agents, the recipients we share it with, and the channels for access, export, correction, objection, or deletion requests. Atlio Limited, a company registered in New Zealand with a UAE branch (Atlio Information Technology LLC), operates SearchChamp. Our New Zealand Privacy Act, UAE PDPL, and GDPR control reviews are ongoing.
No. We do not sell your personal data. We share data only with specific categories of recipients: infrastructure, AI model providers, SEO data providers, payment processing, abuse prevention, authentication, and the optional services you choose to connect, each listed in section 5 of this policy.
This policy addresses the New Zealand Privacy Act 2020, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where applicable, the EU and UK GDPR. Our control reviews are ongoing, and this policy is not a legal determination of compliance.
Email privacy@searchchamp.com to request access, rectification, erasure, portability, restriction, or objection, or to withdraw consent. We respond within 30 days. You can also export your account data as a JSON file and delete your account yourself from your account page. You also have the right to lodge a complaint with your local data-protection authority.
Four categories: data you provide directly (account details, payment data via Stripe, credentials for platforms and services you connect, outreach contacts, support communications), data collected automatically (usage data, device and browser data, performance data), data from integrations you authorise (Google Search Console, Google Analytics 4, Google Ads, Google Tag Manager, and SEO data providers), and free-tool submissions. If you use one of our free tools without an account, we store the email address and inputs you submit and the IP address the submission came from (see section 7).
No. AI agent jobs run on your behalf using models from Anthropic, OpenAI, and Google, whose commercial API terms exclude training on model inputs. Requests routed through the OpenRouter gateway are sent with a setting that forbids every model host from training on your data.
It depends on the data type: account data and AI agent outputs follow the account lifecycle; agent job working data is scheduled for up to 30 days; operational and audit-log retention varies by category; support tickets are scheduled for 3 years; and billing records for 7 years. Free-tool submission IP addresses use a 6-month deletion control, while the submitted email address and inputs remain until deletion is requested. The full schedule and its current limitations are in section 7.
We process data primarily in AWS eu-west-1 (Ireland). For EEA or UK users, transfers to AI providers in the United States are safeguarded by those providers' data processing terms, which incorporate the EU Standard Contractual Clauses. Requests routed through OpenRouter may be served by model hosts in the United States, China, or Sweden; the full list and transfer mechanisms are maintained at /legal/sub-processors.
Yes. Connected platform credentials, such as WordPress Application Passwords and Shopify OAuth tokens, are stored encrypted and can be revoked at the connected service or disconnected in the app. The same applies to every other service you can connect, including a Gmail or Outlook account, Slack, and Cloudflare.
No. When you connect Google Search Console, Google Analytics 4, Google Ads, or Google Tag Manager, we use that access only to read your data, you can revoke it at any time, and we never share your data with Google for advertising purposes.
Infrastructure runs on AWS. AI model providers are Anthropic, OpenAI, and Google, plus OpenRouter, a gateway that routes some AI tasks to a fixed allowlist of model hosts with training denied, and additional AI engines used by the AI Visibility feature. SEO data comes from a specialist provider in the EU, payments are processed by Stripe, and authentication runs on AWS Cognito. The full current list, with purposes and transfer mechanisms, is maintained at /legal/sub-processors.
Billing address and payment method details are processed by Stripe, which is PCI-DSS Level 1 certified. We never store raw card numbers on our own servers.
7 years, in line with New Zealand tax record-keeping requirements and exceeding the five-year minimum under UAE Federal Decree-Law No. 32 of 2021 (Commercial Companies Law).
Your account data (name, email, usage history, AI agent outputs) is retained for the lifetime of your account. When you cancel, your account is auto-closed 90 days after cancellation. Data is then deleted within 30 days of closure. Billing records specifically are the exception: those are retained for 7 years regardless of closure, because we're required to under UAE commercial and tax law.