Privacy Policy
Effective date: August 8, 2026
Last updated: August 8, 2026
Version: 1.0
1. Who We Are and What This Covers
This Privacy Policy explains how Gotham Ventures, LLC, a California limited liability company doing business as Strategent (“Strategent”, “we”, “us”, “our”) collects, uses, shares, and protects personal data in connection with the Strategent platform, including the Strategent Console, our audit and diagnostic reports, APIs, and any related websites or services (collectively, the “Service”).
This policy applies to visitors to our marketing website; account holders and authorized users of the Strategent Console; client contacts at organizations that engage us for audits, diagnostics, or advisory work; and individuals whose personal data incidentally appears in websites, documents, or other content we analyze on a client’s instruction.
This policy does not apply to third-party websites we analyze or link to, or to our clients’ own privacy practices. When we analyze a client’s web property, that client remains responsible for the personal data published on it.
By accessing or using the Service, you acknowledge the practices described here.
2. Our Role: Controller vs. Processor
If you are an individual whose data appears in a client’s content and you want it corrected or removed, contact that client (the controller) directly. If you contact us, we will forward the request and support the client’s response.
3. Information We Collect
We collect the following categories of information.
3.1 Information you provide
Account information — name, work email, password credentials (stored as salted hashes), organization name, role or job title, time zone, and account preferences.
Client and engagement information — company details, points of contact, domains and properties in scope, competitor sets, target markets, and scope-of-work parameters.
Uploaded content — documents, exports, research materials, brand guidelines, content drafts, keyword lists, analytics exports, and other files you choose to submit for processing.
Access credentials and connected accounts — where you choose to connect third-party systems (for example Google Search Console, Google Analytics, a CMS, or a commerce platform), we receive OAuth tokens and the data scopes you authorize. We request read-only scopes wherever the integration supports them.
Communications — support tickets, email correspondence, meeting notes, and feedback you send us.
Billing information — billing contact, address, tax identifiers, and invoice history. Full payment card numbers are handled by our payment processor and never stored on our systems.
3.2 Information we collect automatically
Usage information — pages and features accessed, reports generated, queries run, timestamps, session duration, and interaction events.
Technical information — IP address, browser type and version, operating system, device identifiers, screen dimensions, referring URL, and language settings.
Security and audit logs — authentication events, permission changes, API calls, rate-limit events, and administrative actions.
Cookies and similar technologies — see Section 12.
3.3 Information we collect from third parties and public sources
Because the Service performs search, AEO, and technical-visibility analysis, we also collect information that is not submitted directly by you:
Crawled website content — HTML source, rendered DOM, structured data, headings, metadata, internal and external link graphs, images, robots and sitemap files, and page performance measurements from URLs you authorize us to scan. This content may incidentally contain personal data — author names, staff bios, testimonials, contact details, or reviews — that the site owner has published.
Search, AI-assistant, and citation visibility data — how a domain or brand surfaces in search results and AI-generated answers, including snippets and citation sources.
Third-party enrichment and analytics data — aggregated ranking, backlink, traffic-estimate, and competitive data from commercial data providers.
Business contact data — publicly available professional contact details used for outbound business communications, where permitted by applicable law.
3.4 What we do not want
Please do not upload special-category data (health information, biometric data, precise geolocation of individuals, government identifiers, financial account numbers, or data about children) unless we have specifically agreed to it in writing under an appropriate contract. If you upload such data without agreement, you do so as controller and at your own risk, and we may delete it.
4. Authorization to Scan and Crawl
You may only submit a domain, URL, or property for analysis if you own it or have documented authorization from the owner. By submitting a target, you represent and warrant that you have that authority.
Our crawler:
Identifies itself with a documented user agent (StrategentBot/1.0) and a contact URL.
Respects robots.txt directives and applies conservative rate limits by default.
Collects only publicly accessible content — it does not attempt to bypass authentication, paywalls, CAPTCHAs, or access controls.
Does not perform intrusive security testing, vulnerability exploitation, or penetration testing.
Authenticated or staging-environment crawls are performed only with the site owner’s explicit written permission and credentials supplied through a secure channel.
5. How We Use Information
We use personal data to:
Provide the Service — create and administer accounts, run scans, generate diagnostics, produce reports, and deliver deliverables.
Process content and generate AI-assisted outputs — analyze uploaded and crawled content to produce scores, findings, prioritized recommendations, and drafted content.
Support and communicate — respond to requests, send service notices, and share changes to terms or security.
Bill and administer — process invoices, manage subscriptions, and maintain financial records.
Secure the Service — detect abuse, prevent fraud, enforce rate limits, investigate incidents, and maintain audit trails.
Improve the Service — analyze aggregated usage patterns, diagnose defects, and develop features. Where practicable this is done using aggregated or de-identified data.
Market responsibly — send business communications about our services, subject to your consent where required and always with an opt-out.
Comply with law — meet legal, tax, accounting, and regulatory obligations, and establish or defend legal claims.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, as amended.
6. Legal Bases for Processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
Delivering the Service to an account holder or client — Performance of a contract.
Billing and account administration — Performance of a contract; legal obligation.
Security, abuse prevention, and audit logging — Legitimate interests (protecting the Service and its users).
Product improvement and aggregated analytics — Legitimate interests (improving a service you use).
Crawled content containing incidental personal data — Legitimate interests of the client and of Strategent in analyzing publicly published content.
Direct marketing to business contacts — Legitimate interests, or consent where required.
Non-essential cookies and analytics — Consent.
Responding to legal process — Legal obligation.
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 11.
7. AI and Automated Processing
The Service uses large language models and other machine learning systems to analyze content and generate findings, summaries, scoring, and recommendations.
Purpose limitation. Content you submit, and content we crawl on your instruction, is processed solely to deliver the analysis and outputs you requested.
No training on your content. We do not use client content, uploaded documents, or crawled client data to train or fine-tune our own models, and we contract with AI providers under terms that exclude our submissions from their model training. Current AI subprocessors are listed in Section 8.
Retention at the provider. AI providers may retain submissions briefly for abuse monitoring under their own terms. We select zero-retention or short-retention configurations where offered.
Human oversight. Outputs are reviewed by our team before being delivered as a formal audit or recommendation. Console-generated outputs available on demand may not be individually reviewed.
Accuracy. AI-generated outputs can be incomplete or incorrect. They are informational and do not constitute legal, financial, medical, or professional advice. You remain responsible for reviewing and validating any output before relying on or publishing it.
No consequential automated decisions. We do not use automated decision-making that produces legal or similarly significant effects on individuals within the meaning of Article 22 GDPR.
8. How We Share Information
We share personal data only as described here.
8.1 Subprocessors and service providers
We engage vendors under written contracts that require confidentiality, security safeguards, and processing limited to our instructions.
Cloud hosting and storage — running the Service and storing data.
AI model providers — generating analysis and drafted content.
Search and web data providers — ranking, backlink, and visibility data.
Analytics — product usage measurement.
Email and communications — transactional and support email.
Payments and billing — invoicing and subscription management.
Error monitoring and logging — reliability and debugging.
CRM and support tooling — managing client relationships and tickets.
A current list of named subprocessors is available on request at legal@strategent.com. Clients under a Data Processing Agreement may subscribe to advance notice of new subprocessors.
8.2 Within your organization
Reports, findings, and account activity may be visible to other authorized users, administrators, and billing contacts on your account or workspace.
8.3 With clients and their delegates
If you are a contact at a client organization, we may share correspondence, findings, and technical recommendations with that client’s team and its designated developers or agencies as needed to complete the engagement.
8.4 Legal and safety
We may disclose information where we believe in good faith it is necessary to comply with law, valid legal process, or a governmental request; to enforce our terms; or to protect the rights, property, or safety of Strategent, our users, or the public. Where legally permitted, we will notify the affected client before disclosing their data.
8.5 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will provide notice before your data becomes subject to a materially different privacy policy.
8.6 Aggregated and de-identified data
We may publish or share benchmarks, industry statistics, and research derived from aggregated or de-identified data that cannot reasonably be used to identify you, your organization, or a specific client property. We do not attempt to re-identify such data.
9. International Data Transfers
We operate primarily from California, United States and use subprocessors in multiple countries, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organizational measures. A copy of the relevant transfer mechanism is available on request.
10. Data Retention
We retain personal data only as long as necessary for the purposes described, then delete or de-identify it.
Account information — life of the account, then 90 days after closure.
Uploaded content and crawled page data — life of the engagement, then 12 months, unless the client requests earlier deletion.
Audit reports and deliverables — 24 months, so clients can track change over time.
Usage and analytics data — 24 months, then aggregated.
Security and audit logs — 12 months.
Billing and tax records — 7 years, as required by law.
Support communications — 24 months.
Marketing contact data — until opt-out, then a suppression record only.
Clients may request earlier deletion at any time; deletion requests are honored within 30 days, subject to legal retention requirements. Backups are encrypted, rotate on a 35-day cycle, and deleted data is purged from backups on that schedule.
11. Your Rights
Depending on where you live, you may have some or all of the following rights:
Access — obtain a copy of the personal data we hold about you.
Rectification — correct inaccurate or incomplete data.
Erasure — request deletion, subject to legal exceptions.
Restriction — limit how we process your data in certain circumstances.
Portability — receive your data in a structured, machine-readable format.
Objection — object to processing based on legitimate interests, including profiling.
Withdraw consent — where processing is based on consent, without affecting prior processing.
Non-discrimination — we will not deny service, charge different prices, or provide a different quality of service because you exercised your rights.
Opt out of sale or sharing — we do not sell or share personal data, but you may confirm this with us at any time.
Limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond providing the Service.
How to exercise
Email legal@strategent.app with your request and enough information for us to locate your records. We will verify your identity before acting, respond within 30 days (extendable by a further 60 days for complex requests, with notice), and will not charge a fee for reasonable requests.
Authorized agents
California residents may use an authorized agent, who must provide written permission and proof of identity.
Complaints
EEA and UK residents may lodge a complaint with their local supervisory authority. We ask that you contact us first so we can try to resolve the matter.
12. Cookies and Similar Technologies
Strictly necessary — authentication, session integrity, load balancing, and security. Consent is not required.
Functional — remembering preferences, saved filters, and language. Consent is required where required.
Analytics — understanding feature usage and performance. Consent is required where required.
Marketing — attribution for our own campaigns. Consent is required.
You can manage non-essential cookies through our cookie banner or preference center, and control all cookies through your browser settings. Blocking strictly necessary cookies may break parts of the Service.
We honor Global Privacy Control (GPC) signals as a valid opt-out request where legally required. We do not currently respond to browser “Do Not Track” signals, as no common standard exists.
13. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:
Encryption in transit (TLS 1.2+) and at rest (AES-256).
Role-based access control and least-privilege provisioning.
Multi-factor authentication for administrative and production access.
Network isolation, secrets management, and audited infrastructure changes.
Centralized logging, monitoring, and alerting.
Vendor security review before onboarding subprocessors.
Periodic access reviews, backup testing, and annual third-party penetration testing.
A documented incident response plan with defined severity levels and escalation paths.
No system can be guaranteed completely secure. If a breach affects your personal data, we will notify affected users and, where required, the relevant supervisory authority — without undue delay and within 72 hours of becoming aware, where the GDPR applies. Report suspected vulnerabilities to security@strategent.com.
14. Children’s Privacy
The Service is a business tool intended for users aged 18 and over. We do not knowingly collect personal data from children under 16. If we learn we have collected such data, we will delete it promptly. Contact legal@strategent.com if you believe a child has provided us personal data.
15. Third-Party Links and Analyzed Websites
Reports and Console views may link to third-party websites, including sites we analyze on your behalf. We do not control those sites and are not responsible for their privacy practices. Reviewing a site in an audit is not an endorsement of it.
16. Your Responsibilities as a Client
If you submit content or authorize scans, you are responsible for:
Having a lawful basis and the necessary authority to provide that data to us.
Providing any required notices to, or obtaining consent from, the individuals whose data you submit.
Not submitting special-category data outside an agreed contract.
Keeping your credentials secure and managing user access on your account.
Reviewing AI-generated outputs before publishing or acting on them.
17. Changes to This Policy
We may update this policy as the Service or the law changes. We will update the “Last updated” date and, for material changes, provide at least 30 days’ notice by email or in-product notice before the change takes effect. Prior versions are available on request. Continued use after the effective date constitutes acceptance.
18. Contact
Gotham Ventures, LLC
General privacy inquiries: legal@strategent.app
Security reports: security@strategent.app
We aim to acknowledge privacy inquiries within 5 business days.