Privacy Policy

PRIVACY POLICY

Last Updated: 2026-08-25

  1. About this Privacy Policy

This Privacy Policy explains how personal data is processed when you: visit the Palagus website, communicate with us, receive an invitation to Palagus, create or use a Palagus account, participate in interviews, surveys, or other feedback activities or use Palagus to analyse brands, businesses, websites, sources, and visibility in AI-generated answers.

Palagus is a business-to-business software service intended exclusively for professional users who are at least 18 years old.

In this Privacy Policy, “Palagus,” “we,” “us,” and “our” refer to the person operating Palagus as identified below.

“Personal data” means information relating to an identified or identifiable natural person.

  1. Controller and Contact Details

The controller responsible for the processing described in this Privacy Policy is:

Mohamed Heouaichi

operating under the business or product name Palagus

Hattinger Straße 305

44795 Bochum

Germany

Website: www.palagus.com

Privacy contact: support@palagus.com

Palagus is currently operated without a separately registered Palagus company. The controller named above is therefore personally responsible for determining the purposes and means of the processing described in this Privacy Policy.

Data protection officer: Maher Saidani

  1. Scope of This Privacy Policy

This Privacy Policy covers processing connected with: the public Palagus website, the Palagus beta application and waiting list, beta selection and onboarding, the Palagus web application, brand, website, competitor, source, and AI visibility analysis, customer workspaces, product feedback and user research, customer and prospective customer communication, security, administration, and internal operations.

This version does not cover: a newsletter, because the Palagus newsletter is not currently active, paid subscriptions or payment processing, because the current beta is free

Processing performed through services that have not yet been activated.

This Privacy Policy will be updated before any materially new processing activity begins.

  1. Palagus as Controller

Palagus generally acts as the controller for: website visitor data, beta application and waiting-list data, user account information, workspace administration data, product usage and security information, communications and feedback, data collected from publicly accessible online sources for Palagus’s own service purposes, information used to operate, secure, and improve Palagus.

Palagus is not intended as a general-purpose platform for processing personal data about a customer’s employees, customers, or other identifiable individuals.

Users should not upload personal data about third parties unless they have the necessary authority and a valid legal basis for doing so.

Palagus does not currently offer a separate data processing agreement under Article 28 GDPR. If future Palagus functionality involves processing personal data solely on a customer’s documented instructions, the parties’ roles and the possible need for a data processing agreement must be assessed before that functionality is provided

  1. Visiting the Palagus Website

5.1 Purposes

When you access the Palagus website, we process technical information to: deliver the website to your device, maintain website availability and performance, protect the website against misuse and attacks, identify and resolve technical problems, understand how the website is found and used, where applicable, operate application and login functionality.

5.2 Categories of data

Depending on the configuration of the website and your device, the following data may be processed: IP address, date and time of access, requested page or resource, referring page, browser type and version, operating system, device information, language and regional settings, technical identifiers, error and security information, consent preferences, information transmitted through forms.

5.3 Legal basis

The delivery, stability, and security of the website are based on our legitimate interests under Article 6(1)(f) GDPR.

Our legitimate interests are: providing a secure and functional website, protecting our systems and users, detecting misuse, resolving errors, maintaining the technical integrity of Palagus.

Where a technology requires access to or storage of information on your device and is not strictly necessary, we will request consent before activating it. The corresponding processing of personal data is based on Article 6(1)(a) GDPR.

  1. Hosting and Technical Infrastructure

Palagus currently uses the following infrastructure providers:

6.1 Amazon Web Services

Amazon Web Services is used for hosting and data storage.

Depending on the Palagus function, Amazon Web Services may process: website and application data, workspace data, technical logs, stored source content, generated analysis results and security and operational information.

6.2 Supabase

Supabase is used for: database services, user authentication, account management and file storage.

Supabase may process account information, login information, workspace information, uploaded files, product data, and related technical identifiers.

Passwords are not intended to be stored in plain text. Authentication credentials are protected using secure password hashing and related authentication safeguards.

6.3 Vercel

Vercel is used to host the Palagus website and application frontend. Vercel may process technical request information required to display and operate these services.

6.4 Browserbase

Browserbase is used for automated browser operation and website crawling. Depending on the relevant Palagus function, Browserbase may process: submitted domains and URLs, publicly accessible website content, browser requests, website metadata, screenshots, technical website information, information necessary to retrieve and analyse webpages.

6.5 Hosting regions

Palagus intends to configure the above services for processing and storage within the EU or EEA.

The location of a server alone does not necessarily exclude access or onward processing from a country outside the EEA. The actual provider contracts and configurations must therefore be reviewed.

  1. Beta Application and Waiting List

7.1 Application process

The Palagus beta is currently free.

Prospective users may apply through a form on the Palagus website. Applications are placed on a waiting list and reviewed manually. Selected applicants may receive an invitation to join the beta.

7.2 Information collected

The beta application may contain: name, business email address, company name, professional position or role, company website, optional free-text information or the reason for applying, date and time of the application, information associated with subsequent communication.

Applicants are not allowed to enter special categories of personal data, confidential information, or personal data about unrelated third parties in the free-text field.

7.3 Purposes

We use beta application data to: administer the waiting list, verify that an applicant belongs to the intended B2B, audience,understand whether an applicant is suitable for the beta, select and invite beta participants, communicate about the application, prevent misuse or duplicate applications and plan and operate the beta programme.

7.4 Legal basis

Processing necessary to respond to an application and take steps toward beta participation is based on Article 6(1)(b) GDPR.

Manual assessment, waiting-list administration, product planning, and prevention of misuse are based on our legitimate interests under Article 6(1)(f) GDPR.

Our legitimate interests include selecting suitable professional beta participants, operating an effective beta programme, and protecting limited beta capacity.

7.5 Transmission and internal management

Application details are transmitted to Palagus by email using Migadu (Mail Provider Service).

Authorised Palagus team members manually transfer the relevant application information into a locally stored Excel lists. Applications are manually reviewed. The relevant information is not stored in databases of third party service providers.

Access to the list is limited according to team members’ roles and responsibilities.

7.6 Retention

Data relating to applicants who are not invited, or who do not activate their access, is deleted from the active waiting list no later than 6 months after collection, unless: the applicant requests earlier deletion, the information is still required for an ongoing communication, a legal obligation requires longer storage or the information is required to establish, exercise, or defend legal claims.

  1. Invitations and Account Creation

8.1 Invitation process

Selected beta applicants receive an invitation by email. The invitation includes an initial password and other information required for first access.

The provider Migado is used to send invitation emails. For security reasons, users will be make aware of changing the the initial password promptly after their first login within the invitation mail.

8.2 Account information

When an account is created, we may process: name, business email address, company or organisation, professional position or role, internal account identifier, authentication information, login timestamps, IP address, browser and device information, security events, workspace membership and permissions.

8.3 Purposes and legal basis

We process this information to: create and administer the account, authenticate users, assign users to the relevant workspace, provide the Palagus beta, manage permissions, protect the account, investigate suspicious login activity,and communicate essential service information.

Processing required to create and provide an account is based on Article 6(1)(b) GDPR.

Security logging, access management, and prevention of misuse are based on our legitimate interests under Article 6(1)(f) GDPR.

  1. Customer Workspaces

Privacy is not just a policy for us—it's a fundamental promise. We continuously evaluate and enhance our data protection strategies, staying ahead of evolving technological and regulatory landscapes to provide you with a secure experience.

  1. Use of the Palagus Platform

10.1 Data entered by users

Users can provide or create: brand names, company domains and URLs, competitor names and domains, topics and Persona information, prompts (search questions), target countries and languages, documents and files, configuration and project information.

10.2 Automatically generated information

Palagus can automatically generate prompts based on information such as: a company or brand, a submitted website, defined topics, a country and one language, identified competitors and project settings.

Palagus therefore processes both manually created prompts and prompts automatically created by its systems.

10.3 Outputs stored by Palagus

Depending on the function, Palagus may store: complete prompts, complete AI-generated answers, complete conversation histories, brands and competitors mentioned in responses, rankings, visibility indicators, and other metrics, cited URLs and source references, source text or extracts, analyses, detected anomalies or patterns of the own brand or of competitors, diagnoses and recommended actions.

10.4 Purposes

This information is processed to: provide the requested Palagus functions, create and maintain the customer workspace, measure brand visibility, share of voice, position, sentiment, mentions, share of citations and other metrics in AI-generated answers, compare brands and competitors, identify sources used or cited by AI services, analyse changes over time, identify anomalies or opportunities, generate diagnoses and recommended actions, enable exports and project management, maintain the continuity of multi-turn interactions and secure and support the platform.

10.5 Legal basis

Processing necessary to provide the beta functions requested by a user is based on Article 6(1)(b) GDPR.

Security, service integrity, error analysis, and proportionate product improvement are based on our legitimate interests under Article 6(1)(f) GDPR.

Where consent is legally required for a specific optional activity, the processing is based on Article 6(1)(a) GDPR.

Palagus evaluates visibility across multiple AI search and answer environments.

Depending on the selected function, this may include services such as: ChatGPT, Google AI Overviews or AI Mode, Microsoft Copilot, Perplexity, Google Gemini, Claude, DeepSeek, other AI search, answer, or language-model services.

The availability of a particular service may change and may depend on the selected Palagus function.

11.1 Methods of access

Depending on the relevant service, Palagus may retrieve information through: official APIs, automated browser interactions, other authorised technical interfaces.

Palagus will use these methods in accordance with applicable contractual, technical, and legal requirements.

11.2 Data provided to service providers

Depending on the function, information sent to selected AI and API service providers may include: prompts and search questions,automatically generated prompts, brand and company names, domains and URLs, competitor information, brand information, topics, languages, and locations (countries), relevant publicly accessible source information and context required to generate or retrieve a response.

Users should not place personal data, sensitive personal data, confidential information, authentication credentials, or trade secrets into prompts unless this is necessary, authorised, and lawful.

11.3 Provider description

The current version of this Privacy Policy refers to these recipients collectively as selected AI and API service providers.

Before publication, Palagus will internally document: which providers are actually used, which data each provider receives, whether the provider acts as a processor or independent controller, retention periods, processing regions, international transfer mechanisms and relevant contractual restrictions.

A separate and maintained subprocessor list may be used where appropriate.

11.4 Model training

Prompts, domain names, brand name, competitor names, topics, competitor domains, fictional buyer persona descriptions and names can be used for training third-party models of different providers. Palagus does not send any personal information of users (name, last name, username, password, relation to brands) to any third party.

Palagus does not use customer workspace content to train or fine-tune AI models.

  1. Website Crawling and Public Online Sources

12.1 Crawling activities

Palagus automatically and repeatedly retrieves content from company, brand, competitor, and other relevant websites.

Depending on the selected function, Palagus may process: full webpage content, HTML or rendered content, URLs, page titles, meta descriptions, headings, text content, screenshots, publication or source information, internal and external links, structured data and schema markup, canonical tags, robots.txt information, sitemap information, HTTP status codes, availability information, page structure, performance or loading information, other technical website characteristics.

12.2 Purposes

This information may be used to: understand website content and structure, identify content relevant to AI visibility, compare a company’s website with competitor websites, detect technical or content changes, understand which sources are used in AI-generated answers, create metrics, produce analyses, diagnoses, and recommended actions, monitor changes over time and document the state of a source at the time of analysis.

12.3 Publicly accessible personal data

Public websites may incidentally contain personal data, such as: author or employee names, business roles, quotations, professional profile information,photographs, business contact details and links to professional profiles.

Palagus is not designed to profile or evaluate these individuals. Depending on the relevant function and source, such information may nevertheless be captured as part of the website or source being analysed.

Where this occurs, Palagus processes the data only to the extent relevant to the source, website, brand, or company analysis.

Palagus does not use such information to make employment, credit, eligibility, or other decisions about individuals.

12.4 Legal basis

Processing necessary to provide a customer-requested website analysis may be based on Article 6(1)(b) GDPR.

Processing publicly accessible source information for monitoring, benchmarking, source analysis, service security, and improvement may also be based on Article 6(1)(f) GDPR.

Our legitimate interests include:

providing B2B visibility analysis, understanding publicly accessible sources cited by AI systems, monitoring customer and competitor websites, identifying changes, anomalies, and optimisation opportunities and documenting sources used for professional analysis.

Where personal data is obtained from a public or third-party source, the transparency requirements of Article 14 GDPR may apply. Any exceptions or proportionate notification approach must be assessed based on the specific processing activity.

12.5 Responsible crawling

Palagus intends to retrieve only information needed for the applicable function and to operate crawling proportionately.

The technical and legal rules for each relevant source must be reviewed separately. Access to publicly available information does not automatically remove contractual, intellectual-property, database, or data-protection restrictions.

  1. Files and Third-Party Personal Data

Palagus technically allows users to upload documents or files.

Users should not upload: personal data about third parties without appropriate authority, special categories of personal data, confidential personal information, private communications, authentication credentials, information that the user is prohibited from sharing.

If a user uploads personal data, the user is responsible for ensuring that: the data was collected lawfully, the upload has a valid legal basis, the upload is compatible with the original purpose of collection, affected individuals receive any required information, the data is limited to what is necessary, the user has the required contractual and organisational authority.

Palagus is not designed for the targeted processing of health data, biometric data, political opinions, religious beliefs, trade-union membership, sexual-life data, sexual-orientation data, or other special categories of personal data.

  1. Product Analytics and Microsoft Clarity

We are using Microsoft Clarity on: the public Palagus website and the authenticated Palagus web application.

Microsoft Clarity can potentially support usage statistics, heatmaps, or session-recording functionality. The exact functions to be activated have not yet been determined.

Clarity will be only activated when under the consent of users. Session recording is enabled.

Clarity may process: IP address or derived location information, device and browser information, page and screen interactions, navigation events, interactions with interface elements, session identifiers and diagnostic information.

We configure masking to prevent passwords, prompts, uploaded content, workspace results, and other confidential customer information from appearing in recordings or heatmaps.

Where required, Clarity is activated only after consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG.

We use Google Search Console to understand how palagus.com appears and performs in Google Search. The information available through Search Console may include: search queries, impressions, clicks, average positions, landing pages, countries and devices, indexing information and website errors and technical search information. Google states that Search Console does not show all data and may omit certain low-volume queries or queries containing personal or sensitive information to protect privacy. We use this information to:maintain the discoverability of the Palagus website, identify technical indexing problems, improve website content, understand aggregated search performance.

The related processing is based on our legitimate interests under Article 6(1)(f) GDPR in maintaining and improving our business website.

  1. Cookies and Similar Technologies

Palagus may use cookies, local storage, pixels, or similar technologies.

16.1 Strictly necessary technologies

Strictly necessary technologies may be used to: maintain login sessions, authenticate users, keep the service secure, apply access permissions, store privacy preferences, prevent misuse, route requests, deliver functions expressly requested by the user.

Where access to or storage on the device is strictly necessary to provide an expressly requested digital service, consent may not be required under Section 25(2) TDDDG.

16.2 Optional technologies

Optional analytics, heatmap, session-recording, advertising, or similar technologies are activated only where the required consent has been obtained.

Under Section 25 TDDDG, storing information on or accessing information from a user’s device generally requires informed consent, except where the activity is strictly necessary for transmission or for a digital service expressly requested by the user.

Where the technology also processes personal data, the GDPR applies in addition.

16.3 Consent settings

Where a consent banner is used, users must be able to: accept or reject optional categories, make a granular choice where appropriate, change their selection, withdraw consent as easily as it was given. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Consent Provider:

  1. Communication and Meeting Arrangements

Interested parties, beta applicants, and users can contact Palagus and arrange meetings by email.

We may process: name, business email address, company, position or role, email metadata, message content, preferred meeting time, meeting subject, information voluntarily provided during communication and internal notes required for follow-up. Migadu is used for business email communication, including beta form transmission, responses to applicants, and appointment coordination. We process inquiries to respond to the sender and manage the requested communication.

The legal basis is:

Article 6(1)(b) GDPR where the communication concerns beta participation, use of Palagus, or pre-contractual measures;

Article 6(1)(f) GDPR for general business communication, documentation, follow-up, and efficient relationship management;

Article 6(1)(c) GDPR where retention is required by law.

We do not use currently use an external meeting-booking service.

  1. Beta Feedback and User Research

During the beta, Palagus may collect: general feedback, feature requests, error reports, survey responses, written notes from user interviews, product and usability observations and professional context relevant to the feedback.

Beta interviews are not audio- or video-recorded. Only written notes are created. We process this information to: understand how professional users use Palagus, identify errors and usability problems, prioritise improvements, evaluate feature demand, improve AI visibility analyses and diagnostic functions.

Processing directly connected with beta participation is based on Article 6(1)(b) GDPR.

Voluntary feedback, service improvement, and product research may also be based on our legitimate interests under Article 6(1)(f) GDPR.

Where feedback is optional, users may decline to provide it.

  1. Security and Prevention of Misuse

We implement appropriate technical and organizational measures to protect personal data and the Palagus platform against unauthorized access, loss, alteration, disclosure, and misuse.

We may monitor the use of our services where necessary to maintain platform security, detect fraudulent or abusive activity, investigate potential violations, and enforce our Terms of Service.

Users must not use Palagus to: Upload personal data of third parties without a lawful basis or appropriate authorization

Attempt to gain unauthorized access to accounts, systems, or data

Interfere with the security, availability, or functionality of the platform

Use automated methods to access or extract data in an unauthorized manner

Use the service for unlawful, fraudulent, harmful, or misleading activities

If we identify suspected misuse or a security risk, we may restrict or suspend access, investigate the activity, and take other appropriate measures to protect Palagus, its users, and third parties.

No method of electronic transmission or storage is completely secure. Therefore, while we take reasonable steps to protect information, we cannot guarantee absolute security.

  1. Recipients of Personal Data

Personal data may be disclosed to: authorised Palagus team members, AWS, Supabase, Vercel, Browserbase, Migadu, Microsoft, where Microsoft Clarity is activated, Google, in connection with Google Search Console, selected AI and API service providers, professional advisers where required, public authorities, courts or law-enforcement bodies where legally required.

Recipients receive only the information necessary for their function. Providers that determine their own purposes and means may act as independent controllers for part of their processing. This must be assessed for each provider.

  1. International Data Transfers

Palagus intends to configure its core infrastructure for EU or EEA processing.

However, some service providers or their subprocessors may be established outside the EEA or may permit access from countries outside the EEA.

Where personal data is transferred outside the EEA, Palagus will use an applicable transfer mechanism, such as:

  • an adequacy decision under Article 45 GDPR;

  • the EU-US Data Privacy Framework for a participating US recipient;

  • Standard Contractual Clauses under Article 46 GDPR;

  • supplementary contractual, technical, or organisational safeguards;

  • another mechanism permitted by Chapter V GDPR.

The EU-US Data Privacy Framework applies only to participating US organisations. Where no adequacy decision applies, appropriate safeguards such as Standard Contractual Clauses may be required. [bfdi.bund.de]

[OPEN: Complete a provider-by-provider transfer assessment before publication. Do not state that a provider is certified under the EU-US Data Privacy Framework unless the relevant legal entity and current certification have been verified.]

You may request information about the safeguards applicable to a specific transfer by contacting us.

  1. Retention and Deletion

We retain personal data only for as long as required for the relevant purpose, unless a legal obligation or legitimate need requires longer retention.

22.1 Waiting-list information

Data relating to applicants who are not invited or do not activate their account is deleted from the active waiting list no later than 12 months after collection.

22.2 Account and workspace data

Account and workspace data is retained while the account or workspace remains active and until: the user deletes the relevant project, the user deletes the information through the interface, the account is closed, the data is no longer required to provide the beta or another applicable retention period expires.

The deletion period following account closure can take up to 30 days.

22.3 Crawled content and screenshots

Website content, screenshots, metadata, and technical website information may be kept while required for monitoring, historical comparison, analysis, diagnosis, and reporting.

22.4 AI prompts, answers, and conversation histories

Prompts, answers, sources, and full conversation histories may be stored while the related project or workspace remains active.

Users can delete the related project through the Palagus interface.

22.5 Communications and feedback

Communications and beta feedback are retained for as long as needed to respond, manage the beta, document relevant decisions, improve the service, or address legal claims.

22.6 Backups

After deletion from active systems, information may remain in protected backup copies for up to 30 days.

During this period, the information is not used for ordinary operational purposes. It is deleted or overwritten through the regular backup cycle, unless retention is required by law.

  1. User Controls, Export, and Deletion

Palagus users can: delete projects and associated project data through the user interface, export their workspace data through the user interface, delete their accounts through the Palagus interface and request information about the processing of their personal data.

Exports may include, depending on the selected function: prompts, AI answers, cited sources, metrics, analyses, diagnoses, recommendations and times.

Deletion through the user interface removes the relevant content from active use, subject to temporary backup retention and legal obligations.

  1. Automated Decision-Making and Profiling

Palagus uses automated systems, including artificial intelligence, to analyse brands, companies, websites, publicly available sources, and user-provided business information. These systems may generate visibility scores, identify patterns or anomalies, and provide insights, diagnostics, and recommendations.

Palagus does not use automated processing to make decisions about individuals that produce legal effects or similarly significantly affect them. Palagus does not create profiles of individuals for employment, credit assessment, insurance, eligibility, or comparable purposes.

Any scores, classifications, insights, or recommendations generated by Palagus are provided for informational and professional decision-support purposes only. They do not constitute binding decisions and should be reviewed and evaluated by the relevant user or organisation.

If Palagus introduces processing in the future that constitutes automated individual decision-making within the meaning of Article 22 GDPR, we will provide the required information and implement appropriate safeguards, including, where applicable, the opportunity to request human intervention, express a point of view, and contest the decision.

Under Article 22 GDPR, individuals have the right not to be subject to decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significantly affect them.

  1. Users Under 18

Palagus is intended exclusively for B2B and professional users who are at least 18 years old. Palagus is not directed to children or minors. Persons under 18 must not: apply for the beta, create an account, use the Palagus service or provide personal data to Palagus.

If we learn that a person under 18 has submitted personal data, we will take appropriate steps to delete it.

  1. Your Data Protection Rights

Subject to the applicable legal requirements, you may have the following rights:

26.1 Right of access

You may request confirmation as to whether we process your personal data and obtain access to that data and related processing information.

26.2 Right to rectification

You may request correction of inaccurate personal data and completion of incomplete information.

26.3 Right to erasure

You may request deletion of your personal data where the legal requirements are met.

The right to erasure may be restricted where processing remains necessary, for example, to comply with a legal obligation or establish, exercise, or defend legal claims.

26.4 Right to restriction

You may request restriction of processing where the applicable requirements are met.

26.5 Right to data portability

Where processing is based on consent or a contract and is carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used, and machine-readable format.

26.6 Right to object

You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR.

We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is required for legal claims.

26.7 Objection to direct marketing

You may object at any time to the use of your personal data for direct marketing. If you object, we will stop using your personal data for that purpose.

26.8 Withdrawal of consent

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

26.9 Right to complain

You have the right to lodge a complaint with a data protection supervisory authority.

  1. Exercising Your Rights

To exercise your data protection rights, contact:

support@palagus.com

Please describe your request sufficiently clearly so that we can identify the relevant processing activity.

We may request proportionate information to verify your identity where necessary to protect your data from unauthorised access.

We will respond within the period required by applicable data protection law.

  1. Requirement to Provide Data

Some information is required to: review your beta application, invite you to the beta, create an account, authenticate you, assign you to a workspace, provide requested Palagus functionality, secure your account and respond to an inquiry.

If required information is not provided, we may be unable to accept the application, create the account, provide the requested function, or respond to the request.

  1. Changes to This Privacy Policy

Some information is required to: review your beta application, invite you to the beta, create an account, authenticate you, assign you to a workspace, provide requested Palagus functionality, secure your account and respond to an inquiry.

If required information is not provided, we may be unable to accept the application, create the account, provide the requested function, or respond to the request.