Huntair logo
FeaturesPlansFAQContact usLearn
login Sign inTry for free
English·Italiano Courtesy translation. The Italian version is legally binding.

Privacy Policy — Huntair

Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.

Version 1.0 — effective from [●●/●●/2026]

Courtesy translation. This English version is provided for convenience only. The legally binding version is the Italian one, available by selecting Italiano at the top of this page. In case of any discrepancy, the Italian version prevails.


1. Data controller

The data controller is LEAF S.r.l. Semplificata ("LEAF S.r.l.s."), with registered office at Via Vincenzo Pacifici 17, 00019 Tivoli (RM), Italy, and operating office at Via Etruria 41, 00183 Rome, Italy, Tax Code and VAT number 15954051007, REA RM-1626132, e-mail privacy@huntairseo.com, certified e-mail (PEC) leafsrlsemplificata@pec.it ("LEAF" or the "Controller").

For any request concerning personal data you can write to privacy@huntairseo.com.

LEAF has not appointed a Data Protection Officer (DPO), as the legal requirements for doing so are not met.

2. Our approach: transparency and control

Huntair is a professional SEO and GEO analysis tool: we work on websites, brands and domains. For your account we collect only the data strictly necessary to let you register, pay (if you choose a paid plan) and use the Platform.

To understand how the website and the Platform are used, improve them and offer you relevant content and offers, we may use statistical analysis, measurement, customer journey and marketing tools, including third-party tools, and carry out profiling activities. These processing operations take place always and only with your prior consent, given through the cookie banner and the account settings, and may be refused or withdrawn at any time without any consequence on your use of the Service. Furthermore:

  • we do not sell your data to third parties;
  • we do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you (Article 22 GDPR);
  • we do not process special categories of data (Article 9 GDPR) or data of minors. The Service is reserved for adult professionals;
  • non-technical tools are activated only after your consent and are listed, with their providers and durations, in the Cookie Policy (huntairseo.com/legal/cookie), which supplements this notice.

3. What data we process, why, and on what legal basis

3.1 Account data

Data Purpose Legal basis Retention
E-mail address, password (stored only as a cryptographic hash, never in plain text), username, date of acceptance of the Terms, e-mail verification status Creation and management of the account, authentication, identity verification, service communications (e-mail verification, password reset, analysis completion notifications), performance of the Terms Performance of a contract (Art. 6.1.b) For the entire life of the account and up to 30 days after closure, subject to legal obligations
Optional profile data: first name, last name, company, country, time zone, biography, profile picture, colour/logo/text for report personalisation Personalisation of the experience and of exported reports Performance of a contract (Art. 6.1.b). Providing this data is optional and at your discretion As above
Identifier from the external provider (Google, Microsoft, Facebook, LinkedIn, GitHub, Apple), name and e-mail returned by the provider Social login ("Sign in with…") Performance of a contract (Art. 6.1.b) As above
TOTP secret and hashed backup codes (only if you enable two-factor authentication) Account security Performance of a contract (Art. 6.1.b) and legitimate interest in security (Art. 6.1.f) Until MFA is disabled or the account is closed
Date of last access, failed login attempt counter Security, prevention of abusive access Legitimate interest (Art. 6.1.f) Same as the account

3.2 Security data and technical logs

Data Purpose Legal basis Retention
IP address associated with login attempts (failed and successful) and with rate limiting Prevention of brute-force attacks, abuse and fraud; Platform security Legitimate interest (Art. 6.1.f) in the security of the Service Rate limit counters are automatically deleted within 24 hours; hosting infrastructure application logs are kept for a maximum of 7 days
Technical server logs (date/time, requested endpoint, outcome, any errors) Operation, diagnostics and security Legitimate interest (Art. 6.1.f) Maximum 7 days

3.3 Billing and payment data

Data Purpose Legal basis Retention
Company name, VAT number, billing address, Stripe customer and subscription identifiers, subscription status, card network and last 4 digits, next renewal date Management of the subscription, credits, invoices and tax obligations Performance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) 10 years from the invoice for tax data (Art. 2220 Italian Civil Code); the rest for the life of the account

Full payment card details never pass through our systems and we do not store them: they are collected and processed directly by Stripe Payments Europe Ltd., an independent controller for its own payment activities, whose privacy notice is available at stripe.com/privacy.

3.4 Newsletter and commercial communications

Data Purpose Legal basis Retention
E-mail, first and last name (if provided) Sending the newsletter and communications about news and updates to the Platform, only if you ticked the relevant box at registration or in the settings Consent (Art. 6.1.a), which can be withdrawn at any time from the account settings or from the link at the bottom of every e-mail Until consent is withdrawn

Communications strictly necessary for the service (e-mail verification, password reset, security alerts, analysis completion notifications, billing, changes to the Terms) are not newsletters and are sent regardless of consent, on the basis of the contract.

3.5 Data you enter into the Platform ("User Content")

To work, Huntair processes what you decide to analyse: URLs and domains, brand name, product/service descriptions, "personas", competitors, custom prompts and questions, PDF documents you upload, texts you submit to the plagiarism checker or the article generator, and aggregated data from the Google Analytics 4 and Google Search Console properties you choose to connect to a project (for the connection we store an encrypted access token, revocable at any time).

This data, as a rule, concerns websites and companies, not natural persons. However:

  • we ask you not to enter third-party personal data (for example names of people in prompts, documents containing personal data, customer lists) unless strictly necessary;
  • if you do, you act as an independent Controller of such data and assume full responsibility for having a suitable legal basis and for having informed the data subjects. LEAF processes it exclusively as a technical tool, on your instruction, for the time needed to produce the output, and does not use it for any purpose of its own. For Business and Enterprise customers who need it, a Data Processing Agreement (DPA) under Article 28 GDPR is available on request;
  • remember that User Content is transmitted to the AI model providers and third-party services listed in Section 5 for processing. Do not enter information you do not want to reach those providers.

Legal basis: performance of a contract (Art. 6.1.b). Retention: for the life of the project or the account; you can delete projects and analyses yourself at any time.

3.6 Team member data

If a Team Leader invites you to a team, we process your e-mail (provided by the Leader) to deliver the invitation and, once accepted, your account data as in Section 3.1. The Team Leader is responsible for having informed you of this Privacy Policy. You can leave the team at any time.

3.7 Data collected through the contact form

The "Contact" form on the website does not send data to our servers: filling it in opens your e-mail client with a pre-filled message, which you decide whether to send. The data you send us by e-mail (name, e-mail, subject, message) is processed to respond to your request (legitimate interest, Art. 6.1.f, or pre-contractual measures, Art. 6.1.b) and kept for the time needed to handle it and in any case no longer than 24 months.

3.8 Browsing and usage data (analytics and customer journey)

Data Purpose Legal basis Retention
Aggregated and pseudonymised technical data on the use of the Platform collected directly by our systems, without non-technical cookies and without third-party tools: pages and features used, product events (e.g. analysis started, report exported), errors, device and browser type, country derived from the IP Internal statistics, Service improvement, detection of malfunctions, security Legitimate interest (Art. 6.1.f) in understanding and improving our product; you can object at any time 26 months, then only in aggregated form
Data collected through third-party web analytics tools (currently Google Analytics 4): cookie or device identifiers, pages visited, traffic source, interactions, conversion events (registration, upgrade), approximate location, technical characteristics Measuring the audience, understanding how the website and Platform are used, optimising content, campaigns and conversion paths Consent (Art. 6.1.a) given through the cookie banner, withdrawable at any time 14 months at individual user level, then only aggregated data
Customer journey and product analytics data: sequence of actions taken on the website and in the Platform (visit, registration, onboarding, project creation, feature use, upgrade, drop-off), session recordings and heatmaps with automatic masking of text fields, associated with a pseudonymous identifier or, for registered users, with your account Understanding where users encounter difficulties, improving the experience and onboarding, measuring the effect of changes, personalising in-app messages and service communications Consent (Art. 6.1.a) through the cookie banner and/or account settings, withdrawable 24 months

The tools actually in use, their providers, the cookies set and their durations are listed in the Cookie Policy, which is updated whenever a tool is added or removed.

3.9 Profiling and personalised marketing

With your specific and separate consent, we may analyse the data referred to in Sections 3.1, 3.3 (limited to plan and subscription status), 3.4 and 3.8 to build a profile of your preferences, interests and usage patterns (for example: most-used features, industry, team size, customer lifecycle stage, propensity to upgrade) in order to:

  • (a) send you personalised commercial communications by e-mail or in-app notifications;
  • (b) show you relevant content, suggestions and offers within the Platform;
  • (c) define audience segments for advertising campaigns on third-party platforms (for example Google Ads, Meta, LinkedIn), including through pixels, conversion tags and custom audience lists built on pseudonymised identifiers (hashed e-mail), including lookalike audiences.

Legal basis: consent (Art. 6.1.a), withdrawable at any time from the account settings, the cookie preferences panel or by writing to privacy@huntairseo.com; withdrawal does not affect your use of the Service. Retention: profiling data for 12 months from collection; data used for marketing for 24 months from the last interaction, unless withdrawn earlier. Profiling does not produce decisions with legal effects and does not change the prices or conditions of the Service applied to you.

3.10 Commercial communications to customers (Art. 130, paragraph 4, Italian Privacy Code)

If you are already our customer, we may send communications to the e-mail address you provided about services similar to those you have already purchased (new features, updates, upgrade offers), even without consent, on the basis of legitimate interest (Art. 6.1.f) and within the limits of Article 130, paragraph 4, of the Italian Privacy Code. You can object at any time, free of charge, from the link at the bottom of every e-mail or from the account settings; we will no longer write to you for this purpose.

3.11 Data we do NOT collect

We do not collect biometric data, health data or other special categories, data of minors, precise geolocation (GPS), and we do not buy data from data brokers. Third-party sources are limited to the login providers you choose to use and, within the limits of the consent given, to the analytics and advertising platforms listed in the Cookie Policy.

4. Cookies and similar technologies

The website and the Platform use cookies, browser local storage (localStorage), pixels, tags and SDKs (collectively, "cookies"), divided into four categories:

Category What it does Consent
Technical / necessary Login session, security, interface preferences, storage of cookie choices Not required (Art. 122 Italian Privacy Code; Italian Data Protection Authority Guidelines of 10 June 2021)
Statistics / analytics Measurement of the audience and of the use of the website and the Platform (e.g. Google Analytics 4) Required
Experience / customer journey Session recording, heatmaps, A/B testing, support chat, onboarding personalisation Required
Marketing / profiling Conversion pixels, remarketing, custom audiences, offer personalisation Required

The technical cookies currently in use are:

Name Type Purpose Duration
huntair_session Technical cookie, HttpOnly, Secure, SameSite=Strict Maintaining the authenticated login session 12 hours
theme, sidebar state, active project localStorage (not sent to the server) Remembering interface preferences Until deleted by the User
Banner preference cookie Technical cookie Remembering your cookie choices 6 months

How consent works. On first access a banner appears allowing you, with buttons of equal prominence, to accept all cookies, reject all or customise your choices by category. Until you make a choice, only technical cookies are set; closing the banner without making a choice is equivalent to refusal. You can change or withdraw your choices at any time from the "Cookie preferences" link in the footer. The banner is shown again after 6 months or in case of relevant changes. We keep proof of the consent given (date, choices, version of the notice).

The complete and up-to-date list of cookies and non-technical tools, with providers, durations, purposes and links to their respective privacy notices and opt-out mechanisms, is contained in the Cookie Policy (huntairseo.com/legal/cookie). The addition or removal of tools falling within the categories described above is documented in the Cookie Policy and does not require an amendment to this notice.

Fonts. The pages load typefaces from Google Fonts; on that occasion your browser transmits your IP address to Google LLC's servers.

5. Recipients of the data: providers and processors

We do not sell your data. To provide the Service and for analytics and marketing purposes (the latter only with your consent) we rely on providers that process data on our behalf and on our instructions as Processors (Art. 28 GDPR), or that act as independent Controllers or Joint Controllers limited to their own service:

Provider Role What it processes Location / transfer
Heroku (Salesforce, Inc.) Application hosting, European Union region All data in transit on the application, technical logs EU; US parent company (DPF / SCC)
MongoDB Atlas (MongoDB, Inc.) Database All account and project data [●cluster region, e.g. AWS eu-west-1]; US parent company (DPF / SCC)
Stripe Payments Europe Ltd. Payments and invoicing (independent controller for payment data) Payment data, e-mail, billing data Ireland / USA (DPF / SCC)
Twilio SendGrid Sending transactional e-mails and newsletters E-mail, name, content of e-mails USA (DPF / SCC)
OpenAI, L.L.C. AI models (analysis, recommendations, content generation, agent) User Content sent for processing (URLs, texts extracted from websites, prompts, documents). No account data. API use: data is not used to train models under the provider's API terms USA (DPF / SCC)
Anthropic, PBC AI models (as above) As above USA (DPF / SCC)
Google LLC / Google Ireland Ltd. Gemini AI models; PageSpeed Insights API; Google Analytics 4 and Search Console APIs; Google login; Google Fonts User Content sent to the models; analysed URLs; aggregated data from connected GA4/GSC properties; Google profile data for login; IP for fonts Ireland / USA (DPF / SCC)
Google Ireland Ltd. — Google Analytics 4, Google Tag Manager, Google Ads Web analytics, conversion measurement, remarketing and custom audiences. Only with your consent. Processor for GA4; independent controller for Google Ads Cookie/device identifiers, pages visited, events, traffic source, approximate location, hashed e-mail for custom audiences Ireland / USA (DPF / SCC)
Customer journey, product analytics and session replay tools (for example Microsoft Clarity, Hotjar, PostHog, Mixpanel, HubSpot; the current list is in the Cookie Policy) Session recording with field masking, heatmaps, funnels, segmentation, in-app messages. Only with your consent. Processors Pseudonymous or account identifier, events and action sequences, technical data EU / USA (DPF / SCC)
Advertising platforms (for example Meta Platforms Ireland, LinkedIn Ireland, Google Ads) Conversion pixels, remarketing, custom and lookalike audiences. Only with your consent. Joint controllers or independent controllers for their own purposes Cookie identifiers, conversion events, hashed e-mail Ireland / USA (DPF / SCC)
Perplexity AI, Inc. AI models (brand visibility in answer engines) Prompts and brand name USA (SCC)
SerpApi, LLC Search results data (keyword position, volumes) Keywords, domain, reference country. No account data USA (SCC)
ScraperAPI Retrieval of geolocated web pages URLs of analysed websites. No account data USA (SCC)
Microsoft, Meta (Facebook), LinkedIn, GitHub, Apple Identity providers, only if you choose to sign in through them (independent controllers for their own service) Profile data returned by the provider (identifier, name, e-mail) EU / USA (DPF / SCC)
GitHub / Microsoft Code repository and CI (no user data) — —
Advisers (accountant, lawyers), authorities Legal compliance Tax data; data requested by the authority Italy

The up-to-date list of providers is available on request at privacy@huntairseo.com.

6. Transfers of data outside the European Union

Some providers are established in the United States or transfer data there. In such cases the transfer takes place on the basis of an adequacy decision of the European Commission (EU-U.S. Data Privacy Framework, for certified providers) or of the Standard Contractual Clauses approved by the Commission (Art. 46.2.c GDPR), supplemented where necessary by additional measures. You can request a copy of the safeguards adopted by writing to privacy@huntairseo.com.

7. How long we keep the data

Retention periods are indicated for each category in Section 3. In summary: account and project data remain as long as the account is active and are deleted or anonymised within 30 days of closure; tax data for 10 years; security logs for a few days; newsletter data until consent is withdrawn; web analytics data for 14 months at individual level; customer journey and marketing data for 24 months; profiling data for 12 months. Encrypted backup copies may persist for a further maximum period of 30 days before being overwritten.

Free accounts inactive for more than 12 months may be closed and the related data deleted, after notice by e-mail.

8. Security

We adopt technical and organisational measures appropriate to the risk, including: encryption in transit (TLS), passwords stored exclusively as hashes (bcrypt), optional two-factor authentication, HttpOnly/SameSite=Strict session cookies, verification and reset tokens stored as hashes, role- and team-based access control, login attempt limiting, separate production environments and access restricted to authorised personnel.

No system is entirely secure. In the event of a personal data breach that poses a risk to your rights, we will inform you as provided for in Article 34 GDPR.

9. Your rights

Under Articles 15–22 GDPR you have the right to:

  • access your data and obtain a copy;
  • rectify inaccurate or incomplete data (much of it can be edited directly from your profile);
  • obtain erasure ("right to be forgotten"), within the limits of legal obligations;
  • obtain restriction of processing;
  • receive your data in a structured, commonly used format (portability);
  • object to processing based on legitimate interest and, at any time and without having to give reasons, to processing for direct marketing purposes, including related profiling (Art. 21.2 GDPR);
  • withdraw consent at any time (newsletter, analytics, customer journey, profiling, marketing), without affecting processing already carried out, from the account settings, the "Cookie preferences" panel or by writing to privacy@huntairseo.com;
  • not be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you (we do not make any; the profiling referred to in Section 3.9 takes place only with your consent and has no such effects);
  • lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the authority of your State of residence.

You can exercise your rights by writing to privacy@huntairseo.com from the e-mail address associated with your account. We will respond within 30 days, extendable in the cases provided for by law. We may ask you to confirm your identity.

Account closure. You can close your account by writing to privacy@huntairseo.com from the address associated with the account: the data will be deleted as indicated in Section 7.

10. Nature of the provision of data

Providing an e-mail and password (or your identity through an external provider) and accepting the Terms are necessary to create the account: without them it is not possible to use the Service. Billing data is necessary only for paid plans. All other data (profile, newsletter, connections to external services) is optional and failure to provide it results at most in the inability to use the specific feature. Consent to analytics, customer journey, profiling and marketing is always optional: refusing or withdrawing it does not in any way limit access to the Service or its features.

11. Minors

The Service is reserved for adults acting for professional purposes. We do not knowingly collect data from minors under 18. If you believe a minor has provided us with data, write to us and we will delete it.

12. Changes to this notice

We may update this Privacy Policy to reflect changes to the Service, providers or legislation. The current version is always published at huntairseo.com/legal with its effective date. In the event of material changes we will notify you by e-mail or with a notice in the Platform. Continued use of the Service after publication constitutes acknowledgement of the updated notice; where a change requires new consent, we will expressly ask for it. The introduction, replacement or removal of tools and providers falling within the categories and purposes already described in Sections 3.8, 3.9 and 4 is documented in the Cookie Policy and in the list of providers and does not constitute a material change to this notice.

13. Language

This notice is drawn up in Italian. Any translations are provided for convenience only; in case of discrepancy the Italian version prevails.


LEAF S.r.l. Semplificata — Via Vincenzo Pacifici 17, 00019 Tivoli (RM), Italy — VAT 15954051007 — REA RM-1626132 — privacy@huntairseo.com — leafsrlsemplificata@pec.it

Last updated: [●●/●●/2026]

Terms and Conditions Privacy Policy Cookie Policy Cookie preferences
© 2026 LEAF srls. All rights reserved