Privacy Policy
Sulvo Europe OÜ, an Estonia-based company, is the controller for personal information it uses to operate this website, handle business inquiries and signup, and administer its own Services. This policy explains the information we process, its purposes, recipients, retention and your choices. Roles for data processed through publisher advertising services depend on the activity and applicable service or data-processing arrangements.
At Sulvo, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected, recorded, stored and deleted by sulvo.com and how we use it. If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us through email at privacy@sulvo.com.
Personal information includes information about an identified or identifiable person, such as contact details, account information, IP addresses, browser or device identifiers and information that can identify a person when combined with other data. Aggregate statistics are different from identifiable or pseudonymous source data. This policy covers the website, inquiries, public diagnostic integrations and account-based Services; the sections below distinguish their data flows.
Sulvo in ChatGPT
When you use the Sulvo plugin in ChatGPT or Codex, our server receives the website domain you ask about, the best email when you provide one, any site category and traffic or revenue figures you choose to share, and the diagnostic settings for your request. It checks only public website information, such as the homepage, sampled content pages, ads.txt, robots.txt, public advertising configuration files, and HTTPS certificates. We use these inputs to produce the diagnostic you request.
We return the diagnostic results to OpenAI so they can be shown in ChatGPT or Codex. Railway, our hosting provider, processes requests on our behalf. If you request a PageSpeed check, we send the public page URL to Google's PageSpeed Insights service. We do not send your traffic or revenue figures to that service.
The diagnostic tools process your inputs and results in temporary memory while answering your request. They do not save those diagnostic inputs or completed diagnostic results to a database or disk. When you provide the best email, we keep that email and the site as a review lead. Technical access and error logs are covered by the Data Retention section below and may include request metadata or error details.
We do not sell these inputs or results. If no email is already available, the plugin asks for the best email. We keep that email and the site as a review lead. You can skip the email and the diagnostic still runs. The plugin does not ask for your name or password, and it does not require or access a Sulvo account. You choose whether to provide optional traffic or revenue figures. For privacy questions or to exercise the data rights described in this policy, contact privacy@sulvo.com.
Copies of your requests and results in ChatGPT or Codex are handled by OpenAI under its applicable privacy policy and service terms. You can manage your ChatGPT conversations through OpenAI's data controls. OpenAI Privacy Policy.
Website diagnostics, inquiries and signup
The email-based diagnostic on sulvo.com is separate from the ChatGPT plugin. It collects a domain and work email, creates a publisher inquiry or signup lead in Sulvo's signup and Surge systems, and runs public checks. An Account Manager can contact you about the requested findings and onboarding. A submitted email starts the process; an approved account requires later completion and review.
Signup and service follow-up can be sent through SendGrid and other providers used for that service. Website forms can also include a name, message and referral or campaign information relevant to your request. Requested follow-up and administrative messages are separate from optional promotional marketing; use the applicable unsubscribe controls or contact us if you want a follow-up to stop. Your information is retained under the category-specific criteria in Data Retention.
What personal information do we collect from the people that visit our blog, website or app?
When you browse the website, our infrastructure processes request information such as IP address, browser or user-agent information, requested pages, referrer information and request times to deliver, secure and operate the site. A language preference may be stored. With your saved choices, optional analytics, advertising and visitor-identification tools may also process browser identifiers, page interactions and referral information. See Cookies and tracking for purposes, providers and controls. Cloudflare also provides the separate cookieless performance measurement described below.
What personal information do we collect from users when using or registering on our site?
When you request a website diagnostic, contact us or begin signup, we collect the information you provide, such as a website domain, work email, name, message and relevant business details. A website diagnostic starts an inquiry or signup lead; it does not by itself create a completed, approved account. We use the information to respond, provide findings and progress the requested relationship.
Completing an account application can require further identity, business, contact and account information and credentials. Approved account services may process property configuration, reporting, payment and support information relevant to that service. Signup handoffs can include encoded referral or campaign information where applicable; encoding is not encryption. Only include information needed for the request and do not send credentials through public diagnostic tools.
Why do we collect this information?
We process information to deliver and secure the website, answer requests, provide diagnostics, progress signup and administer agreed Services. Optional analytics helps measure website use; optional advertising and visitor-identification supports measurement, audience matching and business outreach when allowed by your choices and applicable law. Required and optional purposes have different legal bases and controls.
When do we collect information?
Information is processed when your browser requests the site, when you save preferences, when an enabled optional tool records an interaction, or when you submit a diagnostic, inquiry, application or account action. Account-based advertising services also process information from approved properties under their applicable arrangements.
How do we use your information?
We may use the information we collect from you when you register, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:
- To deliver, secure and troubleshoot the website and Services.
- To respond to requested diagnostics, inquiries and support.
- To create and assess signup leads, progress applications and administer approved accounts.
- To configure and provide agreed advertising, recovery, reporting or inventory services.
- To use optional website analytics, advertising measurement and visitor identification according to saved choices and applicable law.
- To meet legal, accounting, security, dispute and contractual obligations.
How do we protect visitor information?
Browsing, optional tracking and voluntarily submitted requests involve different information. We use appropriate safeguards for the purpose and risk, including access controls and encrypted web connections. A diagnostic or contact form asks for personal contact information; passive browsing and the ChatGPT diagnostic tools do not require a Sulvo account.
How do we protect user information?
We use technical and organizational safeguards appropriate to the information and processing, including controls on access and HTTPS connections where personal information is transmitted through our web services. No system can guarantee perfect security. Keep account credentials private and report suspected unauthorized access through the available support or privacy contacts.
Cookies and tracking
Cookies and similar browser storage can maintain preferences or recognize a browser over time. Optional tools may use pseudonymous identifiers even where the reports shown to us are aggregated. Our website separates optional identifier-based analytics from optional advertising and visitor identification. Those tags remain off until an applicable choice is saved; the site remains usable when you reject them. Required delivery, security, language and consent records and separate cookieless technical performance measurement are described below.
Your website privacy choices
Use Privacy choices to accept all optional categories, reject them or choose analytics and advertising separately.
Google Tag Manager is enabled only when both optional categories are allowed because its configured tags can cover both purposes.
A supported Global Privacy Control signal overrides an advertising or visitor-identification grant on this browser. Analytics remains a separate choice.
Changing your choices can reload the page to stop previously loaded optional tags and remove known accessible first-party tracking cookies and storage.
The choices are saved in this browser for 180 days after your last save, unless removed sooner. Expired, invalid or unavailable preference storage does not grant optional tracking. You can reopen Privacy choices at any time. Browser settings can also remove cookies or block third-party storage. These controls apply to optional website tags installed by Sulvo; essential request handling, security and the separate Cloudflare performance service are not disabled by that toggle.
Revoking a choice stops future optional website tracking through these controls; it cannot undo data already sent or delete a provider's third-party or HttpOnly cookies from another domain. You can use your browser's controls and the provider's controls for those records, and contact our privacy team for applicable data rights. Declining optional tags does not prevent public diagnostics or requested contact responses.
Website storage and recipient inventory
This inventory describes current website categories and observed identifier examples. A provider may change an identifier or its configuration; browser limits can shorten cookie lifetimes, and browser local storage can remain until the provider or you remove it. The actual cookie expiry and provider settings determine a particular identifier's lifetime. Related provider information is linked below.
Google Analytics cookie information. Apollo privacy information.
Cookieless technical performance measurement
Cloudflare may inject a performance beacon at its network edge to measure page loading and browser performance. Cloudflare describes this service as using ephemeral page-performance information rather than browser cookies, local or session storage or persistent user fingerprinting, and discarding source IP at its nearest edge before core storage. This is separate from Google Analytics, Apollo and advertising-identifier tags controlled through our Privacy choices. The website toggle does not configure Cloudflare's network-edge settings. Cloudflare's provider settings, documentation and applicable law govern that separate measurement.
Cloudflare performance and privacy information.
Third Party Disclosure
Information is disclosed to recipients for the purposes described in this policy and the relevant service. Infrastructure and security providers include Cloudflare and Google Cloud; the ChatGPT diagnostic server uses Railway. Website inquiry and signup data is processed by Sulvo's signup and Surge account/lead systems and relevant operational providers, including SendGrid for applicable signup and service follow-up email. Optional website tags can send identifiers and interaction information to Google analytics or advertising services, Apollo and advertising or identifier partners, according to saved choices. Recipients may act as processors, independent controllers or other recipients depending on the processing and applicable agreements.
Optional advertising and visitor-identification disclosures can be treated as sale or sharing under some privacy laws depending on the recipient's use and the arrangement, including sharing for cross-context behavioral advertising under California law. Reject or disable the advertising category through Privacy choices to opt out of the website identifier-based advertising and visitor-identification tags we install. We honor supported Global Privacy Control for that category. Necessary service processing and information you direct us to disclose for your requested service are separate from optional advertising. The ChatGPT diagnostic tools' treatment of inputs and results is described in their own section above.
We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others' rights, property, or safety. Examples of how we may disclose data for legal reasons include (a) as part of a merger, sale of company assets, financing or acquisition of all or a portion of our business by another company where customer information will be one of the transferred assets, (b) as required by law, for example, to comply with a valid subpoena or other legal process; when we believe in good faith that disclosure is necessary to protect our rights, or to protect your safety; to investigate fraud or to respond to government request.
We may use aggregate or de-identified information for measurement and service improvement where appropriate. Collection of a browser identifier is not automatically anonymous or de-identified processing. We do not describe identifiable source data as anonymous simply because a report contains totals.
Third party links
Occasionally, at our discretion, we may include or offer third party products or services on our website. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
Google services may be involved in optional website analytics, advertising measurement or ad delivery, according to website choices and service settings. Google Tag Manager can load configured tags and does not itself define every tag's data use. Google advertising identifiers and account-linked settings are distinct from aggregate reports. The optional diagnostic PageSpeed request is described in the Sulvo in ChatGPT section.
Google privacy and data-use information
The website can use Google Analytics and Google advertising technology such as Google Ad Manager through enabled tags or advertising partners. The particular services and identifiers depend on the relevant configuration; this policy does not equate every Google advertising request with AdSense.
For Google’s privacy policy, please visit https://policies.google.com/privacy.
Responsibilities for publisher and visitor data
For our own website, inquiries and account administration, Sulvo determines its purposes and means as a controller. Data roles for advertising, reporting or other publisher services depend on the actual activity and agreement. Where Sulvo processes data on a publisher's behalf, the applicable data-processing agreement describes instructions, scope, duration, security, subprocessing, assistance and return or deletion. Other activities or advertising recipients may involve controller roles. Contact the privacy team for the agreements and recipient details relevant to your service; accepting the public Terms is not blanket consent for every purpose.
General Data Protection Regulation ("GDPR")
Sulvo Europe OÜ is established in Estonia. GDPR applies to personal-data processing within its scope, including processing in the context of our EU establishment. Rights and obligations depend on the processing and applicable law, not only on whether an account lists an EU or EEA residence.
The legal basis depends on the purpose. Responding to a requested inquiry, preparing a signup or providing an agreed service can rely on steps toward or performance of a contract where applicable. Security, fraud prevention and appropriate business administration can rely on legitimate interests after considering individual rights. Optional tracking or other activities requiring consent use the applicable consent; legal obligations apply to required accounting, compliance or disclosures. Accepting Terms, requesting a diagnostic or starting signup is not blanket consent to unrelated marketing or tracking. You can withdraw an applicable consent without affecting earlier lawful processing.
Under GDPR, you have the following rights regarding your personal data: (a) Right of access: to request a copy of your personal data; (b) Right to rectification: to request correction of inaccurate data; (c) Right to erasure: to request deletion of your personal data, subject to legal retention requirements; (d) Right to restriction of processing: to request that we limit our processing of your data under certain circumstances; (e) Right to data portability: to receive your personal data in a structured, commonly used, and machine-readable format; (f) Right to object: to object to processing based on legitimate interests, including direct marketing; (g) Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise rights or reach our privacy team, contact privacy@sulvo.com. We respond without undue delay and, for GDPR requests, within one calendar month of receipt. Where the law permits an extension because of complexity or the number of requests, we may take up to two additional months and will explain the extension within the first month. We may request proportionate information needed to verify a request. You may complain to the Estonian Data Protection Inspectorate or another competent supervisory authority, and seek applicable judicial remedies.
California Online Privacy Protection Act of 2003 (CalOPPA)
Where California online privacy requirements apply, this policy describes information collected through the website, its purposes, recipients and privacy choices. You may browse without creating a Sulvo account, although necessary request information is processed and optional tags depend on your choices. Diagnostic, contact and signup submissions contain the information you choose to provide. Material policy changes are addressed in the Changes section.
California privacy information
For requests about California privacy rights or applicable disclosures for direct marketing, contact privacy@sulvo.com.
Does our site allow third party behavioral tracking?
When optional advertising and visitor-identification is allowed, third parties may process browser identifiers and activity for advertising measurement, matching and related purposes. The collection, recipients and controls are described in Cookies and tracking and Third Party Disclosure. Rejecting that category or using supported Global Privacy Control prevents those website tags from starting through our controls.
Children Online Privacy Protection Act ("COPPA") of 1998
When it comes to the collection of personal information from children under 13, the Children’s Online Privacy Protection Act (COPPA) of 1998, as amended puts parents in control. The Federal Trade Commission, the nation's consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. Sulvo does not specifically market its products and services to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without parental consent, we will promptly delete that information. Additionally, for California residents under 16 years of age, we will not sell or share personal information without affirmative authorization as required by the CCPA/CPRA.
Fair Information Practices
The Fair Information Practices (FIP) are a set of standards governing the collection and use of personal data and addressing issues of privacy and accuracy. There should be limits to the collection of personal data and any such data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.
As an individual user, under the FIP, you have the right to (a) obtain from a the Sulvo’s Privacy Officer, confirmation of whether or not the data controller has data relating to you; (b) to have communicated to you data relating to you within a reasonable time; at a charge, if any, that is not excessive; in a reasonable manner; and in a form that is readily intelligible to you; (c) to be given reasons if a request made under (a) and (b) is denied, and to be able to challenge such denial; and to challenge data relating to you and, (d) if the challenge is successful to have the data erased, rectified, completed or amended.
Personal data breaches
We assess and document personal-data breaches and take appropriate measures. Where GDPR Article 33 applies, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals' rights and freedoms; a delayed notice explains the delay. Where GDPR Article 34 applies and a breach is likely to result in a high risk, we inform affected individuals without undue delay through appropriate channels, subject to the statutory exceptions and safeguards. If we act as a processor, we notify the relevant controller without undue delay. Other applicable notification duties are handled under the relevant law.
We also agree to the individual redress principle, which requires that individuals have a right to pursue legally enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or a government agency to investigate and/or prosecute non-compliance by data processors.
California Civil Code Section 1798.83 permits Users of the Program that are California residents to request certain information regarding our disclosure of the information you provide through the Program to third parties for their direct marketing purposes. To make such a request, please contact us at the following address: privacy@sulvo.com.
Cookie and browser-storage categories
Required preferences store the language and your privacy choices, and security providers may use necessary cookies where configured. Optional identifier-based analytics can use Google Analytics cookies such as _ga and _ga_* to recognize browser activity. Optional advertising and visitor-identification can involve Apollo, Google advertising services and partners reached through demand.supply, including identifier providers such as ID5; observed examples include apolloAnonId, _pubcid, _cc_id, panoramaId and cto_bundle. Provider settings and browser limits affect which identifiers are used and how long they last. These identifiers are not described as anonymous merely because they lack a name.
California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA")
Where the CCPA applies, California residents have rights regarding personal information covered by that law. Optional advertising or visitor-identification disclosures may qualify as sale or sharing depending on the recipient's purpose and arrangement. Use Privacy choices to opt out of the website tags in that category; supported Global Privacy Control signals take precedence for that browser. An opt-out does not require a Sulvo account or payment and does not prevent access to public diagnostic tools.
As a California resident, you have the right to: (a) Right to Know: request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information; (b) Right to Delete: request the deletion of personal information we have collected from you, subject to certain exceptions; (c) Right to Correct: request the correction of inaccurate personal information; (d) Right to Opt-Out: direct us not to sell or share your personal information; (e) Right to Non-Discrimination: not be discriminated against for exercising any of your CCPA/CPRA rights.
To exercise these rights, contact us at privacy@sulvo.com. We apply identity verification where required for access, correction or deletion requests; opting out of website advertising through Privacy choices does not require account sign-in. We handle authorized-agent requests and applicable browser preference signals under the relevant law. We do not discriminate for exercising applicable privacy rights. Child-data safeguards and any applicable age-based authorization requirements are described below.
Data Retention
Retention depends on the type of information, its purpose, ongoing activity and applicable legal, accounting, security or dispute obligations. Inquiry and signup-lead records are stored to handle the request, progress onboarding and follow up; they do not currently have a single published automatic-expiry period. Account data is kept for administration of the relationship and applicable continuing obligations. Removing an active account can leave archived account, user, domain or configuration records; account closure is not a guarantee that every copy is permanently erased within thirty days. You can request access, correction, deletion or restriction, subject to lawful exceptions. Active raw advertising/request-log partitions in our Cloudflare BigQuery log tables currently expire after seven days; other hosting, application, support, security and activation records have different service configurations and purposes, so there is no universal ninety-day log rule. Cookie and browser-storage lifetimes follow the inventory below and provider or browser settings; permission from a saved local privacy choice expires 180 days after its last save, with expired records cleared when the site next checks them. ChatGPT diagnostic inputs and completed results are not saved by the diagnostic tools as described above. We assess whether retained identifiable information is still necessary and delete or de-identify it when no longer needed, subject to obligations and any lawful hold. Backup or archived copies may follow their own retention cycles and legal requirements.
International Data Transfers
Sulvo's controller is established in Estonia, while its cloud-hosted infrastructure and providers can process information in the United States and other countries. Website asset storage and raw advertising-log infrastructure include US locations, and Cloudflare operates a global network. This policy does not promise that all or most personal information is processed within the EU or EEA. For transfers subject to GDPR restrictions, the relevant lawful mechanism and safeguards depend on the provider and relationship, such as an applicable adequacy decision or appropriate contractual safeguards. Contact privacy@sulvo.com for recipient, location and safeguard information relevant to your processing, including how to obtain available details or copies.
Automated Decision-Making
We use automated diagnostics, quality, eligibility, security and invalid-traffic checks. Scores or flags can inform access or property decisions and the handling of advertising activity. Some account block states can be reviewed or reinstated by staff; automated status fields can also reflect earlier workflows. We do not promise that automation can never affect an account relationship or that every flag has already received human review. Contact your Account Manager, support or privacy@sulvo.com to ask about a result, challenge inaccurate data or request relevant human review. Where applicable law restricts solely automated decisions with legal or similarly significant effects, the permitted basis and required safeguards, including available intervention and challenge rights, apply.
Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles. For EU/EEA residents, this does not affect your rights under GDPR or applicable local data protection laws, including your right to lodge a complaint with your local supervisory authority.
Applicability of this Privacy Policy
This Privacy Policy is strictly limited to Sulvo Services and has no effect on any other privacy policy(ies) that may govern the relationship between you and us in other contexts.
Changes to this Privacy Policy
We publish updates on this page with their publication or effective dates and retain a link to the earlier version below. Material changes to processing are explained before they apply where the law requires notice or a new choice. We may use available account or contact channels as well as website notices. A policy update does not itself obtain consent for a new optional purpose; we ask for the applicable choice when consent is required. Review the current policy when using a new service or changing your preferences.
Contacting Us
If there are any questions regarding this Privacy Policy you may contact us using the information below.
Email: privacy@sulvo.com
Effective Date: October 3rd, 2026
Last Updated: October 6th, 2026
Earlier privacy policy published before this overall revision