Privacy notice: SeoPageForge AI sales assistant

Last updated:

This notice explains how SeoPageForge processes personal data when our AI sales assistant contacts you by email or when you reply to it. It covers business email sent by our AI assistant from an address at mg.seopageforge.com, for example our current test identity “SeoPageForge Test Assistant” <controlled-test@mg.seopageforge.com>.

Do not want further emails? Use the unsubscribe option your email program shows for our message, or reply to our message with just the word unsubscribe. Either way your address is blocked from further messages straight away. How opting out works.

1. Who is responsible

The controller of your personal data is:

SeoPageForge is a trade name of Hensen Software Services B.V.
Malta 30
2721 HL Zoetermeer
The Netherlands
Chamber of Commerce (KvK) number: 42046093
Email: privacy@seopageforge.com

You can contact us at this address about anything in this notice, including to exercise your rights. A person, not the AI assistant, handles privacy requests.

2. How the AI assistant works

3. What data we process

We do not intend to process special categories of personal data. Please do not send them to us.

4. Where the data comes from

We obtain your business contact details from an address your organisation publishes itself for business enquiries (for example on its own website), from information you gave us yourself, or, with your consent, from an introduction by someone you know. A person at SeoPageForge enters each address and records its source and the reason we may contact you. Your replies and delivery events come from you and from our email provider.

Our systems do not send email to addresses collected by automated scraping.

5. Purposes and lawful basis

Purpose Lawful basis (GDPR Article 6)
Contacting you about business services SeoPageForge offers (AI automation and custom software), and following up on your replies Legitimate interest in business-to-business outreach, Article 6(1)(f). We have weighed our interest in offering our services to businesses against your interests: we only write about services relevant to your company, keep messages few and clearly identified, and honour every opt-out immediately. Article 11.7 of the Dutch Telecommunications Act requires prior consent for unsolicited commercial email. Without your consent, we only write to an address that your organisation, or you when acting as a professional or sole trader, has itself published for receiving business messages, such as a contact address on your own website. Every message identifies us, gives our postal address and offers a free way to opt out.
Continuing a conversation you started or asked for, or preparing a quote you requested Legitimate interest, Article 6(1)(f), or, where you yourself are the prospective customer, steps at your request before entering into a contract, Article 6(1)(b)
Respecting opt-outs: keeping a blocking record so we never email you again Legal obligation, Article 6(1)(c), and legitimate interest, Article 6(1)(f)
Delivering email reliably, processing delivery events and bounces, and protecting our systems against misuse Legitimate interest, Article 6(1)(f)
Keeping records of who approved what, so we can show we acted properly Legitimate interest and accountability, Articles 5(2) and 6(1)(f)

Where we rely on legitimate interest, you can object at any time (see section 10). An objection to direct marketing is always honoured.

6. Who receives the data

We do not sell your data. We share it only with these service providers, who process it on our behalf:

Our own application, database and the AI assistant runtime run on a server that SeoPageForge owns and operates itself in the Netherlands. No hosting provider processes this data. The database and the blocking list are stored on that server. The credentials for our email provider and our platform services are held in our password manager, 1Password, and are only loaded into the server’s memory while a service runs. The AI assistant has no direct access to the credentials, the database or the blocking list.

We may disclose data where the law requires it, for example to a court or regulator.

When you open this page, Cloudflare processes your IP address to deliver it. The page sets no cookies and uses no analytics.

7. Transfers outside the EEA

Mailgun processes our email data in its EU region. Our own server is in the Netherlands. Some providers listed above may process or access data outside the European Economic Area: the AI model providers (OpenAI, and for the fallback model Nous Research and Upstage), Cloudflare, and Mailgun, whose support staff and sub-processors may access EU-region data from outside the EEA (Mailgun Technologies is a US company in the Sinch group). For transfers to the United States by Mailgun (support and sub-processor access), Cloudflare and OpenAI (OpenAI Ireland Limited may transfer data to OpenAI group companies in the US), the providers rely on the European Commission’s Standard Contractual Clauses and, where they are certified, the EU–US Data Privacy Framework, as set out in their data processing terms. No personal data of real recipients is sent to the fallback model route (Nous Research and Upstage). Before that changes, we will confirm the safeguards for that route and update this notice, or remove the fallback. You can ask us for a copy of the relevant safeguards.

8. How long we keep it

Data Retention
Copy of a sent message stored by Mailgun 72 hours
Incoming replies stored by Mailgun Up to 3 days
Mailgun delivery logs and event data According to our Mailgun plan (currently 5 days)
Your email address on Mailgun’s own blocking lists after a hard bounce, complaint or opt-out recorded by Mailgun For as long as the block must be honoured
Your email address in our blocking list after an opt-out, complaint or hard bounce For as long as we must honour the block, so that we never contact you again
Record of when and how an opt-out arrived (contains no email address) As long as the related block exists
Email address, company, contact basis, business notes, sent messages, replies and delivery events in our own database 24 months after our last contact with you. Deletion is currently done by hand: we check at least once a year, so a record may remain up to 12 months longer before it is deleted.
Working notes the AI assistant keeps on our server about conversations Deleted together with the other data about the conversation (see above)
Approval and audit records Kept for as long as our system runs, to show that we acted properly. These records are designed not to contain your email address or message text.

If you ask us to erase your data, we delete it except for the minimum needed to keep you on our blocking list, unless you ask us to remove that too and understand we may then be unable to prevent future contact.

9. Opting out

You can stop further emails in any of these ways:

An opt-out through the unsubscribe option, or a reply as described above that answers our message in the same email conversation, takes effect immediately and automatically, without review by the AI assistant. We do not send a confirmation email. Any other opt-out request, such as a reply that only suggests you want to stop, a request sent as a new email rather than a reply to ours, or an email to our privacy address, is reviewed by a person, who blocks your address where appropriate.

Messages already approved but not yet sent to you are stopped as well. The only exception is a message whose sending had already started at the moment your opt-out arrived: that single message may still be delivered, but no further message follows it.

10. Your rights

Under the GDPR you have the right to:

To use a right, email us at the address in section 1. We answer within one month, and may ask you to confirm you control the email address concerned.

11. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). You can also complain to the authority in the EU country where you live or work.

12. Security

We protect your data with technical and organisational measures, including:

13. Changes to this notice

We update this notice when our processing changes. The date at the top shows the latest version.