Legal

Privacy Policy (GDPR)

Last updated:

1. Who we are

AIRank is a GEO/AEO consultancy operated by AIRANK S.R.L., the controller of your personal data under the GDPR. Administrator: Dragoș Mihai Drăgoi.

Company details

Company name
AIRANK S.R.L.
Unique Registration Code (CUI)
55587736
Registration date
15 September 2026
Trade register number
J2026054397002
European Unique Identifier (EUID)
ROONRC.J2026054397002
Share capital
RON 500
VAT
Not a VAT payer

Registered office (no walk-in hours): Str. Verzișori nr. 6, bl. D, ap. B118, Sector 4, București, 040301.

Contact: dragos@airank.ro · contact page

2. What data we collect and why

The contact form and the homepage form

What: Contact form: name, email address, message and, optionally, your website address. Homepage form: your email address only.

Why: We reply to your request and discuss a possible collaboration. We send no newsletter and do not add your address to any mailing list without your explicit consent.

Legal basis: Consent (Art. 6(1)(a) GDPR) and legitimate interest (Art. 6(1)(f) GDPR).

Free mini-audit (/en/free-ai-audit/)

What: The address of the website analysed, your email address, your phone number (optional), your IP address, a unique request code (token) and the results of the audit generated for your website.

Why: We generate and send you the report you asked for. Your IP address and email address are also used to limit requests to one audit per 24 hours per address, so the service is not abused. After the report, we may send you a single follow-up email to ask whether you need any clarification.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) for generating the requested report, limiting abuse and the follow-up email; consent (Art. 6(1)(a) GDPR) for the phone number, which is optional.

How it works: Your request reaches an automated workflow (n8n, our own server), and the list of requests and their results are kept in a Google Sheet through Google Apps Script; the report is emailed from a Google account. Your website is analysed on our own infrastructure. Public technical data about the site may be sent to third-party services for interpretation and measurement (a language model through OpenRouter, Google CrUX/PageSpeed, Ahrefs). Your email address and phone number are NOT sent to those services.

Professional contact details of the companies we approach (prospects)

What: Trade name, web domain, professional contact email and phone, city, industry, plus public technical observations about the website (search result positions, missing SEO elements, presence in AI search answers).

Where from: Exclusively from public sources — the contact page a company publishes on its own website, the public Google Business profile and public search engine results. We do not buy address lists and we do not collect data from private sources.

Why: We write to you once, with a concrete observation about your company’s website, to offer a service that fixes exactly that. We send at most one follow-up message.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR), within the meaning of Recital 47. We documented the balancing test in a written assessment (LIA), available on request.

How to stop: Reply STOP to any message from us, or write to the address in section 6. We stop immediately and permanently, without asking for reasons. We keep only your address on a suppression list, precisely so that you are not contacted again.

What we do NOT do: We do not track whether you opened a message (no tracking pixel), we do not build behavioural profiles, we make no automated decisions that affect you and we do not process special categories of data.

This section is the notice required by Art. 14 GDPR, for the case where the data was not obtained directly from the data subject.

Bookings and messages through external services (Cal.com, WhatsApp)

What: If you book a discovery call through Cal.com or message us on WhatsApp, the details you enter there (usually name, email or phone number, booking time, message content) are processed by that service under its own policy, and we receive what you send us.

Legal basis: Steps taken at your request before a possible collaboration (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f) GDPR).

Web traffic data (Plausible Analytics)

What: Anonymised visits, pages viewed, traffic source, device (generalised), country.

Why: We learn how the site is used so we can improve it. Plausible is cookieless and does not collect personally identifiable data.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). No consent is needed, because there are no tracking cookies.

Web traffic data (Google Analytics 4) — only if you accept

What: Visits, pages viewed, traffic source, device, country — via the _ga and _ga_<container id> cookies.

Why: Additional traffic statistics alongside Plausible, for reporting.

Legal basis: Consent (Art. 6(1)(a) GDPR). The script does NOT load and no cookie is set until you press "Accept" in the banner shown on your first visit. You can withdraw consent at any time from "Cookie preferences" (footer).

3. Who receives your data

We do not sell your personal data and do not pass it to third parties for commercial purposes. We use providers that process data on our behalf or at your request. Each provider describes its own processing, including where data is stored, in its own policy, linked below.

  • n8n (our own server) — receives the form submissions and runs the mini-audit workflow.
  • Google (Workspace/Gmail, Apps Script, Sheets) — keeps the list of audit requests and their results, sends the emails and hosts the company mailbox. policies.google.com
  • Netlify — hosts and delivers the website; processes technical connection data such as the IP address. netlify.com
  • Plausible Analytics — anonymised traffic statistics. plausible.io
  • Google Analytics (Google Ireland Limited) — additional traffic statistics, only if you choose to accept from the consent banner. policies.google.com
  • Cal.com — booking discovery calls, if you choose that route. cal.com
  • WhatsApp (Meta) — conversations, only if you message us on WhatsApp. whatsapp.com

To interpret the mini-audit we may also use a language-model service (OpenRouter), Google CrUX/PageSpeed and Ahrefs; they receive public technical data about the site analysed, not your email address or your phone number.

4. How long we keep your data

Contact form data is kept until the end of the business relationship or until you ask for deletion. Plausible traffic data is kept for 12 months and then deleted automatically.

Google Analytics 4 data (if you accepted) is kept according to the settings in the Google Analytics property; the _ga/_ga_<container id> cookies can be deleted at any time manually from your browser or by withdrawing consent from "Cookie preferences".

Mini-audit requests (website address, email, phone, IP address, results) are kept for 12 months after the audit, unless a commercial relationship follows, and are then deleted; deletion is carried out periodically.

Professional contact details of the companies we approach are deleted 12 months after the last contact, unless a commercial relationship arises. The one exception: if you asked us not to contact you again, we keep your address permanently on a suppression list — deleting it would lead to exactly what you asked us to avoid, a new approach.

5. Local storage in your browser

The mini-audit widget saves in your browser (localStorage), for at most 24 hours, a request identifier, the address of the website analysed, the email address you entered and the audit deadline. We use them only so you can return to the result if you reload the page; nothing is sent elsewhere from this storage. You can delete them at any time from your browser settings.

We only use cookies for Google Analytics 4, opt-in, only if you press "Accept" in the consent banner — Plausible remains cookie-free. Details: cookie policy (in Romanian).

6. Your GDPR rights

Access — you can ask for a copy of the data we hold about you.
Rectification — you can ask for incorrect data to be corrected.
Erasure — you can ask for your data to be deleted (“the right to be forgotten”).
Objection — you can object to processing based on legitimate interest.
Portability — you can ask for your data in a structured format.
Withdrawing consent — where processing is based on consent, you can withdraw it at any time, without affecting the processing carried out before.
Complaint — you can lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).

To exercise your rights: dragos@airank.ro. We reply within 30 days at most.

7. Changes to this policy

We may update this policy from time to time. The date of the latest change is shown at the top. We recommend checking it periodically.