Legal
Privacy Notice
Last updated 21 August 2026
Frida Consulting AB, trading as CitedGiraffe, is the data controller for the personal data described here.
1. Who we are
Frida Consulting AB ("we", "us"), a company registered in Sweden, trades as CitedGiraffe and operates citedgiraffe.com. We are the data controller for personal data processed through the service: we decide what data is collected and why, and we are accountable for it. For the content and website data you feed into your workspace, we act as processor on your instructions.
Privacy questions: privacy@citedgiraffe.com.
2. What we collect, why, and on what basis
- Account data — name, email address, login credentials (stored hashed), organisation name. Used to create and secure your account and provide the service. Basis: performance of our contract with you.
- Workspace and site data — the domains you scan, brand and business details, keywords, prompts, articles, connected publishing destinations and API keys. Used to deliver scans, plans, generation and publishing. Basis: contract.
- Support messages — the content of emails and in-app messages you send us. Used to answer you and improve the product. Basis: contract and legitimate interests.
- Usage and telemetry — pages viewed, features used, job runs, errors and performance data. Used for reliability, abuse prevention and product improvement. Basis: legitimate interests.
- Device and connection data — IP address, browser and device identifiers, timestamps. Used for security, fraud prevention and rate limiting. Basis: legitimate interests and legal obligation.
- Marketing preferences — if you opt in to product emails. Basis: consent, which you can withdraw at any time.
Payment card details are never collected or seen by us — they are handled by Paddle, our Merchant of Record.
3. Who we share data with
- Service providers and subprocessors — hosting and database infrastructure, AI model providers used for generation and visibility measurement, email delivery, error monitoring and support tooling. They may only process data on our instructions.
- Merchant of Record — Paddle.com, for the sale of subscriptions, payments, subscription management, invoicing, tax compliance and billing support.
- Professional advisers — legal, accounting and audit, where necessary.
- Authorities — where we are legally required to disclose, or to protect our rights or others' safety.
- Acquirers — in connection with a merger, acquisition or sale of assets, subject to this notice.
We do not sell personal data.
4. International transfers
Some of our providers process data outside the EEA/UK, including in the United States. Where that happens we rely on adequacy decisions where available, or on the European Commission's Standard Contractual Clauses (and the UK Addendum) together with additional technical and organisational safeguards such as encryption in transit and at rest.
5. Retention
We keep account and workspace data for as long as your account is active. After termination, workspace content is retained for 30 days for export and then deleted or anonymised. Anonymous scans are retained for up to 12 months. Billing and tax records are kept as long as Swedish law requires (currently seven years). Logs and telemetry are kept for up to 12 months. We delete or anonymise personal data when it is no longer needed for the purpose it was collected for.
6. Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing is based on consent. Email privacy@citedgiraffe.com and we will respond within one month. If you are unhappy with our response you can complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
7. Security
We apply appropriate technical and organisational measures: encryption in transit (TLS) and at rest, encrypted storage of third-party refresh tokens, hashed passwords and hashed API keys, row-level tenant isolation in the database, least-privilege access controls, and monitoring and logging of administrative activity. No system is perfectly secure, but we review these measures regularly and will notify you and the regulator of a qualifying breach as required by law.
8. Cookies
We use essential cookies and local storage only, to keep you signed in, maintain your session, remember your selected workspace and protect against abuse. These are required for the service to function and are set on the basis of our legitimate interest in providing it. We do not use advertising or cross-site tracking cookies. Paddle may set cookies necessary for checkout when you make a purchase. You can clear or block cookies in your browser settings, but signing in will stop working.
9. Children
CitedGiraffe is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
10. Changes
We will post updates to this notice on this page and, for material changes, notify you in the app or by email. See also our Terms & Conditions and Refund Policy.