- Home
- Privacy Policy
Privacy Policy
This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
Last updated: September 1, 2026 · Effective date: September 1, 2026
This document applies to orlandoseocompany.net and to services provided by Orlando SEO Company. If you have questions about anything here, contact [email protected] — we would rather explain it than have you guess.
Introduction and scope
Orlando SEO Company (“we”, “us”, “our”) operates the website at orlandoseocompany.net and provides search engine optimisation, content, web design and related digital marketing services. This Privacy Policy describes how we handle personal information when you visit our website, contact us, request an audit, subscribe to our newsletter, or engage us as a client.
This policy applies to information collected through this website and through the business relationships that arise from it. It does not apply to third-party websites we link to, to the websites of our clients, or to information you provide directly to third-party platforms such as Google or Meta under their own terms.
For the purposes of data protection law, the data controller is Orlando SEO Company, 121 S Orange Ave, Suite 1500, Orlando, FL 32801. Questions about this policy can be sent to [email protected].
Information we collect
Information you give us directly
- Contact and audit request data: your name, business email address, telephone number, website URL, the service you are interested in, and any message you choose to include.
- Newsletter data: your email address and, where you provide it, your first name.
- Client onboarding data: billing contact details, business address, tax identifiers where required for invoicing, and the names and email addresses of colleagues you ask us to work with.
- Correspondence: the content of emails, call notes, meeting recordings where you have consented to recording, and messages exchanged through shared workspaces.
Information we receive when you use the site
- Technical data: IP address, browser type and version, operating system, device type, screen dimensions, referring URL and time zone setting.
- Usage data: pages viewed, time on page, scroll depth, links and buttons clicked, forms started and completed, and the search terms you enter in our on-site search.
- Cookie and local storage data: identifiers and preferences as described in our Cookie Policy. Our forms also save a draft of your entries in your own browser’s local storage so you do not lose work if the page reloads; that draft never leaves your device and is deleted when the form is submitted.
Information we access on your behalf as a client
When you engage us, you may grant us access to analytics, search console, advertising, CMS, call tracking or e-commerce platforms that contain personal information about your own customers. We access these only to perform the services, we act on your instructions in respect of that data, and we do not use it for any other purpose. Where required, we will enter into a data processing agreement setting out those obligations formally.
Information we do not want
Please do not send us special category data (health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sexual orientation), payment card numbers by email, or login credentials in plain text. If you send such information unsolicited, we will delete it and ask you to resend through an appropriate channel.
How and why we use your information
We use personal information for the following purposes, relying on the legal bases indicated where the GDPR or similar laws apply:
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to enquiries and preparing audits | Contact data, website URL, message content | Legitimate interests; steps preparatory to a contract |
| Delivering contracted services and support | Contact, onboarding, correspondence and platform data | Performance of a contract |
| Invoicing, accounting and tax records | Billing and transaction data | Legal obligation; performance of a contract |
| Sending our newsletter | Email address, first name | Consent (withdrawable at any time) |
| Measuring and improving our website | Technical and usage data, analytics cookies | Consent for optional analytics cookies; legitimate interests for aggregate server logs |
| Security, fraud prevention and abuse detection | IP address, server logs, form submission metadata | Legitimate interests; legal obligation |
| Defending legal claims and enforcing agreements | Any relevant records | Legitimate interests; legal obligation |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not engage in automated decision-making that produces legal effects concerning you.
Cookies, analytics and tracking
Our website uses a small number of essential cookies and local storage entries required for the site to function — remembering your cookie choice, storing your form draft on your own device, and security protections. These cannot be switched off without breaking the site.
Optional analytics cookies help us understand which pages are useful and where visitors struggle. These are only set if you accept them in our cookie banner, and you can change your mind at any time by clearing site data in your browser. Full details, including categories, purposes and retention, are in our Cookie Policy.
We honour Global Privacy Control signals where your browser sends them, and we do not attempt to circumvent browser privacy settings, tracking protection or ad blockers.
Who we share information with
We share personal information only where necessary, and only with the following categories of recipient:
- Service providers (processors) who host our website, deliver our email, process payments, manage our CRM, host shared documents and provide analytics. Each is bound by contract to process data only on our instructions and to maintain appropriate security.
- Professional advisers — accountants, auditors, insurers and lawyers — where they need the information to advise us.
- Authorities where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims.
- A successor entity in the event of a merger, acquisition or sale of assets, subject to the protections in this policy continuing to apply.
We never share client performance data or account access with other clients, and we do not publish identifiable client results without written permission. Case studies on this website are published either with consent or in anonymised form.
International transfers
We are based in the United States, and some of our service providers process data in the United States and other countries. If you are located in the United Kingdom, the European Economic Area or Switzerland, this means your personal information may be transferred outside your jurisdiction.
Where we make such transfers we rely on an appropriate safeguard — typically the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider’s certification under the EU-US Data Privacy Framework — together with supplementary technical and organisational measures such as encryption in transit and at rest. You may request information about the specific safeguard used for a particular transfer.
How long we keep information
| Record type | Retention period |
|---|---|
| Enquiry and audit request data (no engagement) | 24 months from last contact, then deleted |
| Client records and correspondence | 7 years after the end of the engagement |
| Invoices and accounting records | 7 years, as required by applicable tax law |
| Newsletter subscription data | Until you unsubscribe, plus 12 months to honour your opt-out |
| Server logs | 90 days, then deleted or aggregated |
| Analytics data | 14 months maximum, in aggregated form |
| Form drafts in your browser | Stored on your device only; removed on submission or when you clear site data |
Where we no longer need information but cannot delete it immediately (for example because it exists in a backup), we isolate it from active use until deletion occurs in the ordinary backup cycle.
Your rights
If you are in the EEA, UK or Switzerland
You have the right to: request access to your personal information; request correction of inaccurate data; request erasure; request restriction of processing; object to processing based on legitimate interests; receive your data in a portable format; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your national supervisory authority.
If you are a California resident
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use, disclose and sell or share; to access and receive a copy of it; to request deletion; to request correction; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no “Do Not Sell or Share” action needed — but you may still submit a request confirming this.
If you are a Florida resident
Under the Florida Digital Bill of Rights, where applicable to us, you have rights to confirm processing, access, correct, delete and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale of personal data and certain profiling. We do not conduct targeted advertising or sell personal data.
How to exercise a right
Email [email protected] with “Privacy request” in the subject line and tell us which right you wish to exercise. We will acknowledge within 10 business days and respond substantively within 30 days (or 45 days where permitted, with notice to you). We may need to verify your identity before acting — usually by confirming control of the email address associated with the data. An authorised agent may act on your behalf with written authorisation.
Exercising these rights is free. We may charge a reasonable fee or decline only where a request is manifestly unfounded or excessive, and we will explain our reasoning if so.
How we protect information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold, including:
- TLS encryption for all data in transit to and from this website;
- encryption at rest for stored records held with our primary service providers;
- role-based access control, so staff access only what their role requires;
- mandatory multi-factor authentication on all business accounts and client platform access;
- a password manager with unique credentials for every system;
- documented offboarding that revokes access on the day a staff member or contractor leaves;
- regular review of third-party processor security posture.
No method of transmission or storage is completely secure. If we become aware of a personal data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required and inform affected individuals without undue delay, describing what happened, what data was involved and what steps we are taking.
Children’s privacy
Our services are directed at businesses, and our website is not intended for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
Third-party links and embedded content
This website links to third-party sites, including social media profiles and the websites of clients and publishers. We are not responsible for their privacy practices, and we encourage you to read their policies. Where we embed third-party content, that provider may receive your IP address and set its own cookies; we describe any such embeds in our Cookie Policy.
Changes to this policy
We may update this policy to reflect changes in our practices, technology or legal obligations. The “last updated” date at the top of this page always reflects the current version. Where a change materially affects your rights, we will provide prominent notice on this website and, where we hold your email address and the change requires it, by email. Continued use of the website after an update constitutes acceptance of the revised policy.
Contact us
Questions, requests or complaints about privacy can be addressed to:
Orlando SEO Company
121 S Orange Ave, Suite 1500, Orlando, FL 32801
Email: [email protected]
Telephone: (929)-566-4655
If you are not satisfied with our response, you may complain to your local data protection authority. In the UK that is the Information Commissioner’s Office; in the EEA it is your national supervisory authority; in California, the California Privacy Protection Agency or the Attorney General’s office.
Need something clarified?
We are happy to explain any part of this document in plain language, or to provide it in an alternative format on request.