Privacy Policy

AEO-REX Ltd · Last updated: 19 April 2026 · Effective date: 19 April 2026

Plain English summary: We only collect the information we need to provide our services, deliver your AI Visibility Reports, and run our business. We don't sell your data. We use trusted third parties (like Stripe for payments) who meet UK GDPR standards. You have legal rights over your data and can contact us at any time to exercise them.

1. Who we are

AEO-REX Ltd ("we", "us", "our", "AEO-REX") is a limited company registered in England and Wales.

We are the "data controller" for the personal information you share with us through our website, tools, and services.

2. What this policy covers

This policy explains how we collect, use, store, and protect your personal information when you:

3. What information we collect

3.1 Information you give us directly

WhenWhat we collect
Free AI scanner / assessmentYour name, business name, website URL, email address, phone number (optional), business type, revenue band, and stated concerns
Purchasing a serviceBilling name, business name, billing address, email, and payment details (processed by Stripe, see section 6)
Contacting usAny information you include in your message, including name, email, and message content
Using our dashboard toolsBusiness names, website URLs, competitor URLs, and search queries you enter

3.2 Information we collect automatically

When you use our website, we may collect limited technical information including your IP address, browser type, device type, referring website, pages viewed, and time spent on pages. This is used for security, diagnostics, and understanding how people use our site. We use analytics tools which set cookies on your device, see section 9.

3.3 Information from third parties

To deliver AI Visibility Reports, we collect publicly available information about your business from sources including AI platforms (ChatGPT, Perplexity, Claude, Google AI Overviews, Microsoft Copilot), Google Search, directory listings, Wikidata, Crunchbase, Reddit, Trustpilot, and Google Business Profile. We do not access anything behind authentication without your explicit consent.

If you connect third-party accounts (Google Search Console, Google Analytics, Google Ads, YouTube) to our dashboard, we access only the data you authorise. We do not store credentials; these connections use OAuth via the providers' own authentication systems.

4. How we use your information (and our legal basis)

Under UK GDPR we must have a lawful basis for processing your data. Here is what we do and why:

What we doWhyLegal basis
Deliver your AI Visibility ReportTo fulfil the service you requested or purchasedContract / legitimate interest
Process paymentsTo take payment for our servicesContract
Reply to your enquiriesTo answer your questions and provide supportLegitimate interest
Send service-related emails (report delivery, invoices, account updates)To fulfil our contract with youContract
Improve our website and servicesTo make what we offer betterLegitimate interest
Comply with legal obligations (tax records, etc.)Required by lawLegal obligation
Send marketing emails (if applicable)To tell you about our servicesConsent (you can withdraw at any time)

5. What we don't do

6. Who we share your data with

We only share your data with trusted service providers who help us run our business. Each is contractually required to protect your data and use it only for the purposes we specify.

ProviderPurposeLocation
StripePayment processing and invoicingIreland / USA (UK-adequate)
Email service providerSending service and marketing emailsUK / EU / USA
Website hosting providerRunning our website and toolsUK / EU
Cloud storage providersSecurely storing reports and business recordsUK / EU
Analytics providersUnderstanding website usageUK / EU / USA
AI platforms (read-only queries)Checking your public AI visibilityUSA / global
HMRC, accountants, professional advisorsLegal, tax, and compliance obligationsUK

We may also disclose your information if required by law, court order, or to protect our legal rights.

7. International data transfers

Because we work with clients worldwide and use some service providers based outside the UK (for example, Stripe and some AI platforms), your data may be transferred outside the UK. When this happens, we rely on one or more of the following safeguards:

You can ask for a copy of the safeguards we use at any time by emailing us.

8. How long we keep your data

Type of dataRetention period
Client records and reports7 years after the end of our business relationship (HMRC requirement)
Payment and transaction records7 years (HMRC requirement)
Free scanner submissions (non-clients)24 months, then deleted
Enquiries that don't become clients24 months, then deleted
Marketing email listsUntil you unsubscribe or 24 months of inactivity
Website analyticsUp to 26 months

9. Cookies and tracking

Our website uses cookies and similar technologies. We use three types:

You can manage your cookie preferences through the cookie banner on our website or by adjusting your browser settings. Blocking essential cookies may prevent parts of the site from working.

10. Your legal rights

Under UK GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, email shanazbegum@aeo-rex.com. We will respond within one month.

11. How we protect your data

We use appropriate technical and organisational security measures including encrypted connections (HTTPS), secure password policies, access controls, regular backups, and reputable hosting and payment providers. No system is 100% secure, but we take your data seriously.

If we ever experience a data breach that affects your rights, we will notify the ICO within 72 hours and notify affected individuals where legally required.

12. Children's data

Our services are intended for business owners aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, please contact us and we will delete it.

13. Complaints

If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the UK supervisory authority:

14. Changes to this policy

We may update this policy from time to time. When we make significant changes, we will update the "last updated" date at the top and, where appropriate, notify clients by email. We recommend reviewing this page periodically.

15. Contact us

For any privacy-related questions:

© 2026 AEO-REX® · Company Reg: 17018571 · Registered trademark. Registered April 2026.