Skip to main content

Data protection

Privacy Policy

This policy explains the personal data BrandPresence processes when you visit the website, create or join a workspace, monitor a site, use billing, or connect supported services.

Last updated:

1. Data controller and contact

BrandPresence is operated by BalkuSoft Kft. (tax number: 27962239-2-09; company registration number: 09-09-034448), which acts as the data controller for the processing described in this policy.

Privacy, account-deletion, billing-data, and security questions may be sent to brandpresence@blksft.com. Do not send passwords, API keys, access tokens, or payment-card details.

2. Data we process

The data processed depends on how you use BrandPresence. We process information you provide, technical information generated by the service, public website evidence collected for monitoring, billing references, and information you authorize connected services to provide.

  • Account and workspace data: name, email address, organization, role, invitations, authentication events, and session records.
  • Support data: email address, organization, website, message, language, source page, campaign parameters, and bounded technical request information.
  • Customer configuration: sites, canonical origins, sitemaps, locales, prompt groups, prompt versions, brands, competitors, recommendation notes, and approvals.
  • Technical monitoring evidence: public sitemap and robots data, delivered-page metadata, HTTP results, crawl timing, findings, and finding history.
  • AI-answer monitoring evidence: prompts, samples, provider and model details, generated answers, mentions, citations, source URLs, token metadata, errors, and private artifact references.
  • Connected-service data: selected Google Search Console or Bing Webmaster properties, matched Cloudflare zones, imported performance and crawler aggregates, connection status, and encrypted credentials where required.
  • Billing data: Paddle customer, transaction, product, price, subscription, invoice, status, renewal, and portal references. BrandPresence does not store full payment-card details.
  • Security and operations data: timestamps, bounded error details, job events, browser information, and privacy-preserving IP-derived information used for access control and abuse prevention.
  • Cookie choices and, only after consent, analytics or advertising measurement data associated with this website.

3. Purposes and legal bases

We process data to provide accounts, workspaces, monitoring, evidence, recommendations, integrations, billing support, security, diagnostics, customer communication, and legal compliance.

Depending on the context, the legal basis is performance of a contract or steps requested before a contract, legitimate interests in operating and securing a business service, consent for optional measurement and connected access, or compliance with a legal obligation. Consent may be withdrawn without affecting earlier lawful processing.

4. Google Search Console data

When an authorized workspace member connects Google Search Console, BrandPresence requests the read-only Search Console scope (webmasters.readonly). The service can list available properties and import performance data for the property selected by the user.

BrandPresence may store the selected property URL, permission level, import status, clicks, impressions, click-through rate, average position, dates, queries, and pages. This data supports visible workspace evidence and recommendations. BrandPresence does not use this access to edit a website or Search Console property.

OAuth authorization codes are exchanged and not retained. Refresh credentials are encrypted at rest; access tokens are short-lived. Disconnecting removes the stored connection credential. Historical metrics already imported remain in the workspace so earlier evidence does not silently change. You may request deletion of those historical imports where legally permitted.

BrandPresence use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, or used to train a general-purpose AI model.

4A. Cloudflare AI crawler evidence

When an owner or administrator connects Cloudflare, BrandPresence requests only Zone Read, Analytics Read, and offline access. It automatically matches the exact site hostname to the unique most-specific active zone and cannot change DNS, WAF, robots.txt, zone settings, or crawler controls.

BrandPresence stores bounded normalized aggregates such as request and successful-request counts, response bytes, hourly last-seen values, daily activity, status codes, and up to 50 requested paths. It does not retain IP addresses, arbitrary headers, raw response bodies, or raw user-agent strings. Verified Bot Management detection IDs are labeled separately from spoofable user-agent matching.

OAuth authorization codes and PKCE verifiers are not retained after use. Access and refresh credentials are encrypted at rest. Disconnecting revokes authorization where possible, clears stored credentials, stops future imports, and retains historical normalized evidence unless deletion is requested and legally permitted.

5. Cookies and measurement

Strictly necessary storage supports security, sessions, checkout attribution, and remembering cookie choices. Before you choose, Google may receive limited cookieless measurement signals with analytics and advertising consent denied; optional analytics and advertising storage remains disabled until you consent.

You can reject optional categories, change your choice using the cookie-settings control, or clear browser storage. Consent records are retained for up to one year unless changed or cleared sooner.

6. Service providers and disclosures

We use providers where needed to operate BrandPresence. These may include Cloudflare for hosting, queues, and private storage; database infrastructure for application records; Paddle as merchant of record for checkout, subscriptions, taxes, invoices, and approved refunds; Google and Microsoft for connected search services and measurement; and AI providers for monitoring runs configured by customers.

We may disclose information when required by law, to protect users or the service, or during a corporate transaction subject to appropriate safeguards. We do not sell personal data.

7. International transfers and retention

Some providers may process data outside Hungary or the European Economic Area. Where required, we rely on an adequacy decision, contractual safeguards, or another lawful transfer mechanism.

We retain data only as long as needed for the service, evidence history, security, dispute handling, accounting, and legal obligations. Retention varies by record and customer status. Account, workspace, and imported evidence may be deleted on a verified request unless continued retention is legally required.

8. Security and your rights

We use tenant-scoped authorization, hashed session and one-time-code material, encrypted connector credentials, access-controlled artifact storage, bounded logs, and transport encryption. No online service can guarantee absolute security.

Subject to applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. We may verify your identity and authority before completing a request. You may complain to the Hungarian National Authority for Data Protection and Freedom of Information or another competent authority.

9. Account deletion and data export

Verified account-deletion, data-access, and portability requests may be sent to brandpresence@blksft.com. We may retain records where required for tax, accounting, fraud prevention, dispute handling, or another legal obligation.

10. Automated decision-making

BrandPresence provides evidence and recommendations for human review. We do not make decisions producing legal or similarly significant effects solely through automated processing.

11. Children and policy changes

BrandPresence is a business service and is not directed to children under 16.

We may update this policy when the service, providers, or legal requirements change. The date above identifies the current version. Material changes will be communicated through an appropriate channel where required.