Privacy Policy
Last Updated: January 23, 2026
GDPR Compliant • German Jurisdiction (BGB/HGB)
Introduction & Legal Information
This Privacy Policy ("Policy") is issued by SEO Service ("we," "us," "our," or "Data Controller"), a German-based sole proprietor operating the automated backlink marketplace at backlink-market.com (the "Site" or "Service"). We are committed to complying with the General Data Protection Regulation (GDPR/DSGVO), the German Telemedia Act (TMG), and all applicable data protection laws.
This Policy explains how we collect, use, process, disclose, and safeguard your personal information when you visit our website, use our services, integrate our WordPress plugin, or interact with our automated marketplace platform.
Data Controller & Contact Information
Data Controller:

Contact for Privacy Inquiries:
Response Time: Within 30 days (as per GDPR Article 15)
Data Protection Officer:
1. Information We Collect (GDPR Article 13-14)
1.1 Information You Provide Directly
When you register, create an account, purchase services, or contact us, we collect:
- • Account Information: Name, email address, phone number, company name
- • Billing Information: Billing address, payment method, transaction history, invoice data
- • Website Data: Website URLs, domain information for backlink placement
- • Communications: Messages, support requests, and correspondence with our team
1.2 WordPress Plugin Data Collection
Our WordPress plugin (installed on publisher websites) operates with minimal data collection and processes data server-side only:
- • No Client-Side Tracking: The plugin does not track visitor behavior or collect personal data from website visitors
- • Server-Side Injection Only: The plugin performs server-side injection of approved backlinks without storing visitor information
- • Publisher Data: We collect publisher website URL, plugin configuration, and approval status for marketplace operations
1.3 Third-Party SEO Data Providers
To verify website quality and ensure marketplace integrity, we obtain SEO metrics from third-party data providers. This data includes:
- • Domain & Link Metrics: Domain authority scores, backlink counts, referring domains, and link quality indicators
- • Traffic & Engagement Data: Estimated website traffic, visitor engagement metrics, and global/regional rankings
- • SEO Performance Indicators: Organic keyword rankings, search visibility scores, and content quality assessments
Data Transmitted: We submit only website URLs (domain names) to obtain these metrics. No personal user data (names, emails, payment information) is shared with external providers.
Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR) for quality assurance, fraud prevention, and ensuring fair marketplace operations.
Data Processing Location: Third-party data providers may process information outside the European Union. Where applicable, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions to ensure GDPR compliance.
1.4 Automatically Collected Information
When you visit our Site or use our services, we automatically collect:
- • Device Information: IP address, browser type, operating system, device model, unique device identifier
- • Browsing Information: Pages visited, click patterns, time spent on page, referral source, exit page
- • Connection Information: Timestamps, request/response data, bandwidth used
1.5 Cookies & Tracking Technologies (GDPR Article 82 - Consent)
We use cookies and similar technologies for the following purposes:
Essential Cookies
Required for Site functionality (authentication, security, user preferences). No consent required.
Functional Cookies
Enhance user experience and remember your preferences. Requires explicit consent.
Analytics Cookies
Track Site usage patterns to improve services. Third-party processors may be involved. Requires explicit consent.
Marketing Cookies
Enable targeted advertising and marketing campaigns. Requires explicit prior consent.
You can control cookie settings through your browser or our cookie management tool. Withdrawal of consent does not affect the legality of prior processing.
2. How We Use Your Information (GDPR Article 6 - Legal Basis)
We process your personal data based on the following legal grounds:
2.1 Performance of Contract (Article 6(1)(b))
- • Creating and maintaining your account
- • Processing transactions and payments
- • Delivering purchased services and backlink placements
- • Providing customer support and troubleshooting
- • Sending transaction confirmations and invoices
2.2 Legitimate Interests (Article 6(1)(f))
- • Improving and optimizing our services based on usage analytics
- • Detecting and preventing fraud, abuse, and unauthorized access
- • Marketplace quality assurance and seller/publisher verification
- • Understanding user behavior to enhance platform features
- • Monitoring compliance with our Terms of Service
2.3 Explicit Consent (Article 7)
- • Marketing communications and newsletters (opt-in)
- • Promotional campaigns and special offers
- • Non-essential cookie placement
- • Third-party data sharing (where applicable)
2.4 Legal Obligation (Article 6(1)(c))
- • Compliance with German tax and accounting requirements
- • Anti-money laundering (AML) and Know Your Customer (KYC) verification
- • Responding to legal requests from authorities
- • Fulfilling data retention obligations
3. Data Security (GDPR Article 32)
We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
Technical Safeguards:
- • Encryption in Transit: All data transmission secured with TLS 1.2+ encryption (HTTPS)
- • Encryption at Rest: Sensitive data encrypted with industry-standard algorithms
- • Database Security: Regular security audits and penetration testing
- • Access Control: Role-based access control (RBAC) with multi-factor authentication (MFA)
Organizational Measures:
- • Staff Training: All employees receive mandatory data protection and GDPR training
- • Data Processing Agreements: Binding DPAs with all third-party processors
- • Incident Response: 72-hour data breach notification protocol (GDPR Article 33)
- • Privacy by Design: Data minimization principles applied to all services
Infrastructure Location:
Our website and infrastructure are hosted on servers located in the United States. This means your personal data may be transferred to and processed in the US. We have implemented Standard Contractual Clauses (SCCs) and appropriate technical safeguards to ensure GDPR-compliant protection of your data during international transfer and storage.
4. Data Retention (GDPR Article 5(1)(e))
We retain your personal information for as long as necessary to provide our services, fulfill legal obligations, resolve disputes, and enforce our agreements.
Account & Billing Data
Retained for the duration of your account plus 7 years (German tax law requirements - HGB § 257)
Transaction Records
Retained for 10 years (German statutory requirement for commercial records)
Marketing & Consent Data
Retained until withdrawal of consent or account deletion
Log Data & Analytics
Retained for 13 months unless longer retention is legally required
Cookies
Essential cookies retained for session duration; functional/analytics cookies retained per user consent settings
You may request deletion of your data at any time. To submit a deletion request, please email us. We will comply with your request within 30 days, unless legal obligations require longer retention. Contact details are provided in Section 12.
5. Your Privacy Rights (GDPR Articles 15-22)
Under GDPR, you have the following rights regarding your personal data. To exercise any of these rights, please contact us using the email address provided in Section 12. We will respond within 30 days (extensible by two months for complex requests).
Right of Access (Article 15)
You have the right to request access to your personal data and receive a copy in a structured, commonly used, and machine-readable format (portability). This includes information about the purposes of processing, recipients, and retention periods.
Right to Rectification (Article 16)
You have the right to request correction of inaccurate or incomplete personal data. We will update your information without undue delay and inform affected third parties where applicable.
Right to Erasure (Article 17 - "Right to Be Forgotten")
You may request deletion of your personal data under certain circumstances, including when data is no longer necessary, consent is withdrawn, or processing is unlawful. Exception: We may retain data if legally required or necessary for contract performance.
Right to Restrict Processing (Article 18)
You can request limitation of processing (rather than deletion) while we verify accuracy or legality of processing. During restriction, we only store data; we do not actively process it.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance. We will provide this within 30 days in formats such as JSON, CSV, or XML.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests, including direct marketing. Upon receipt, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent (Article 7(3))
If processing relies on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal. You can manage cookie preferences or unsubscribe from marketing communications via your account settings.
Rights Related to Automated Decision-Making (Article 22)
We do not use automated decision-making (including profiling) that significantly affects you. If we introduce such processing in the future, you will have the right to obtain human intervention, express your point of view, and challenge the decision.
Right to Lodge a Complaint
You have the right to lodge a complaint with your national data protection authority if you believe our processing violates GDPR. The competent authority for Germany is the Bundesbeauftragte für Datenschutz und Informationsfreiheit (BfDI).
6. Third-Party Links and External Services
Our Site may contain links to third-party websites and integrate services from external providers. We are not responsible for the privacy practices of those external sites and services. We strongly encourage you to review their respective privacy policies before providing personal information. Our Privacy Policy applies solely to data collected through backlink-market.com.
7. Third-Party Data Sharing & Data Processors
We may share your personal data with the following categories of recipients under appropriate safeguards:
Data Processors (Third Parties Acting on Our Behalf)
- • Payment Processors: Stripe, PayPal, and other PCI-compliant payment gateways (data: billing information, transaction data)
- • Email Service Providers: For transactional and marketing communications (data: email address, communication content)
- • Analytics Providers: To understand user behavior and improve services (data: device info, browsing patterns - anonymized where possible)
- • API Providers: Ahrefs, Majestic, SimilarWeb (data: website URLs for quality verification)
- • Cloud Infrastructure Providers: For data hosting and backup (data: all personal data encrypted in transit and at rest)
All processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance and restrict their use of data to our instructions only.
Data Controllers (Independent Use)
- • Publishers: Your website URL and approval status may be visible to other marketplace participants for matching purposes
- • Legal Authorities: We may disclose data if legally required (court order, law enforcement request, regulatory compliance)
Marketing & Affiliate Partners
We share aggregated, anonymized data (not personally identifiable) with marketing partners to improve targeted campaigns. You will not be identified from this data.
8. International Data Transfers (GDPR Chapter V)
Our primary data storage is on European servers compliant with GDPR. However, certain third-party providers (particularly Ahrefs, Majestic, and SimilarWeb APIs) may process data internationally.
Safeguards for International Transfers
- • Standard Contractual Clauses (SCCs): Binding agreements approved by the EU Commission
- • Adequacy Decisions: Only transfer to countries with adequate protection levels
- • Binding Corporate Rules (BCRs): For corporate group entities
Right to Object
You have the right to object to international transfers of your personal data. Please contact us for more information about applicable safeguards.
9. Special Categories of Data (GDPR Article 9)
We do not intentionally collect or process special categories of personal data (sensitive data) such as:
- • Racial or ethnic origin
- • Political opinions or affiliations
- • Religious or philosophical beliefs
- • Trade union membership
- • Genetic or biometric data
- • Health or medical information
If you inadvertently provide such information, please notify us immediately using the privacy contact email provided in Section 12 so we can delete it.
10. Children's Privacy
Our services are not directed to individuals under the age of 18 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from minors. If we become aware that a minor has provided information, we will delete it immediately without undue delay. Parents or guardians who believe their child has provided information should contact us using the privacy email address provided in Section 12.
11. Data Processing Agreements (DPA)
If you are a publisher or business customer acting as a data controller, and we process data on your behalf as a processor, we maintain a Data Processing Addendum (DPA) compliant with GDPR Article 28. This DPA details:
- • Subject matter and duration of processing
- • Nature and purpose of processing
- • Types of personal data and categories of data subjects
- • Your obligations and rights as controller
To request a copy of our Standard DPA, please contact our Data Protection Officer using the email address provided in Section 12.
12. Contact Us & Privacy Requests
To exercise any GDPR rights, request information about our data processing, or report a privacy concern, please contact us:
General Privacy Inquiries:
Response Time: Within 30 days (per GDPR Article 12(3))
Data Protection Officer:
For DPA requests and compliance inquiries
Company Address:

Business Hours:
Available 24/7 via email for urgent data breach notifications
13. Data Protection Impact Assessment (DPIA)
We conduct regular Data Protection Impact Assessments (DPIAs) to identify and mitigate risks to data subjects. If you believe our processing poses high risk to your rights and freedoms, you may request access to our DPIA using the contact information in Section 12 with the subject line "DPIA Request" and describe your specific concerns. We will review your request and provide relevant information to the extent permitted by data protection law and our obligation to protect other data subjects' information.
14. Data Breach Notification (GDPR Article 33-34)
In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34. For security concerns, please contact us using the security email address available upon request.
15. Supervisory Authority & Legal Jurisdiction
Applicable Law: This Privacy Policy is governed by German law (DSGVO, TMG, BGB, HGB) and interpreted according to EU law.
Competent Supervisory Authority: If you believe we have violated your GDPR rights, you may lodge a complaint with the competent data protection authority:
Federal Data Protection Commissioner (BfDI)
Bundesbeauftragte für Datenschutz und Informationsfreiheit
Husarenstrasse 30
53117 Bonn, Germany
Phone: +49 (0) 228 977 0
Email: poststelle@bfdi.bund.de
Website: www.bfdi.bund.de
Jurisdiction: Any legal disputes arising from this Privacy Policy are subject to the exclusive jurisdiction of the German courts where our company is registered. However, you retain the right to lodge a complaint with your national data protection authority.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our data practices, legal requirements, or other operational reasons. We will:
- • Post the updated policy on this page with a new "Last Updated" date
- • For material changes, provide 30 days' notice before the policy takes effect
- • Notify registered users via email of significant changes affecting their data rights
Your continued use of the Site or services after policy updates constitutes your acceptance of the revised Privacy Policy. We encourage you to review this policy regularly to stay informed about how we protect your data.
17. Summary of Legal Basis
For your reference, here is a summary of how we process your data under GDPR:
Contract Performance (Article 6(1)(b))
Account management, service delivery, payments, support
Legitimate Interests (Article 6(1)(f))
Marketing, analytics, fraud prevention, platform optimization
Legal Compliance (Article 6(1)(c))
Tax records, KYC/AML, law enforcement cooperation
Explicit Consent (Article 7)
Marketing communications, non-essential cookies, optional services