Privacy notice

This notice covers the map check on medicalseo.company, the email you leave for the full analysis, and any email correspondence that follows.

Controller

Yan Dobromyslov, Portugal, is the controller. Privacy requests can be sent to info@medicalseo.company.

What the check collects

The check collects the website you enter and the technical anti-abuse data needed to process it. When you ask for the full analysis it also collects your email address and the services you name.

Do not submit patient information, health information, passwords, or other sensitive personal information.

Cloudflare Turnstile separately processes network, browser, and request signals to distinguish people from automated abuse. Its token is verified and is not stored in the check's record or any event log.

What the check reads and keeps

Cloudflare protects and forwards the request. The public pages of the website you enter are read, and their text is sent to OpenAI, which reads the practice's name, clinic addresses and services; the practice's name, address and phone and the search its patients make are sent to DataForSEO for Google's map at the clinic's door, the clinic's address to the US Census Bureau's geocoder to place it, and a Google model writes what the map shows from the practice's name and address, its profiles, the search and the map. For a website that gives no street address and has no Business Profile, the check reads Google's first page for its search instead: the search is sent to DataForSEO for that page, its click price and the visits Google sends the sites on it, the pages at the top are read, the domain's registration date is read from its public registry record, and a Google model says what those pages are and writes what the page shows. Your connection's address is kept only as a daily key that limits checks, and changes every day.

Enter a public website address, never a private document, an account link or an address carrying a password or a personal token.

The result can be opened for a day after the check, and the check's record leaves active storage after 30 days, or a year after you leave your email for the full analysis; restricted backups rotate out within 30 days more, and the map data DataForSEO returned stays in a local cache so a repeat check does not buy it again. An email you leave reaches Yan with the check it came from and is used only to send the analysis and answer you.

DataForSEO's policy states that API task data is retained for 365 days, and OpenAI's business terms govern its processing; a record deleted here does not delete provider records.

Purpose and legal basis

The information is used to run the check you ask for, make and send the full analysis you ask for, assess and reply to a business inquiry, administer the resulting discussion, and protect the check from abuse. The legal basis is the legitimate interest in responding to people who choose to ask and keeping the service secure under Article 6(1)(f) GDPR.

Nothing you give is added to a newsletter or used for unrelated marketing. Automated anti-abuse checks may refuse likely abuse, but they do not make a legal or similarly significant decision about a person.

Processors and international processing

The active record lives in a private local SQLite database. Proton Drive stores end-to-end encrypted backup copies. Cloudflare protects and relays the check. Google delivers the full analysis to the email you leave, from Yan's mailbox, and hosts the contact mailbox used for replies and rights requests. To make the check and the full analysis, the website you give and the services you name are read by an OpenAI model, each clinic is searched on Google's map through DataForSEO, and a Google model writes what the map shows for each clinic from the practice's name and address, its website's text, the services and the map; for a website with no street address and no Business Profile, its search is read on Google's first page through DataForSEO instead, and a Google model says what the pages there are and writes what the page shows. The check and the analysis send none of them your email address.

These providers and their subprocessors may process information outside the European Economic Area. Depending on the provider and destination, applicable safeguards include European Commission standard contractual clauses, adequacy decisions, and the EU-US Data Privacy Framework. A copy of the applicable safeguards can be requested at the address above.

Retention

The record of a request for the full analysis is deleted 12 months after it is made. It may be deleted sooner when it is invalid, a test, contains inappropriate sensitive information, is no longer needed for the stated purpose, or a valid deletion or objection request applies. If work begins, only information needed for that work moves to separately governed client records.

Technical event records contain no answers you gave and are deleted after 30 days. Google mailbox messages have no fixed automatic deletion schedule. Deleted information can remain temporarily in restricted disaster-recovery backups until the relevant backup expires; those copies are not used for ordinary operations.

Your rights

You can choose not to use the check and email instead. Depending on the circumstances, you may request access to, correction or deletion of your information, restriction of processing, or object to processing based on legitimate interests. Portability applies where its legal conditions are met. Identity may need to be verified before a request is completed.

You may also complain to Portugal's Comissão Nacional de Proteção de Dados or the data-protection authority where you live or work.

Last updated: 30 September 2026