Legal

Privacy Policy

Last updated: September 2026

1. Introduction

Visibilio Ltd. ("Visibilio", "we", "us", or "our") is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable EU data protection laws.

This policy covers both of our properties:

  • The website at visibilio.ai — our public marketing site and Content Hub.
  • The application at app.visibilio.ai — the Visibilio content operating system, available to customers under a subscription.

Where a section applies to only one of the two, it says so. Section 4 deals specifically with data we receive from Google APIs on your instruction.

2. Data Controller

Visibilio Ltd.
Alexander Malinov 31 Blvd.
Sofia 1729, Bulgaria
EU VAT: BG208031576
team@visibilio.ai

For personal data contained in content and analytics that a customer connects to the application, Visibilio acts as a processor and the customer is the controller. Our data processing agreement governs that relationship.

3. Information We Collect

Information You Provide Directly

  • Name, email address, and company name when you submit contact forms
  • Communication data when you correspond with us
  • Email address when you subscribe to our newsletter
  • Account details when you register for the application — name, work email address, organisation, and authentication credentials
  • Content you create, upload, or publish through the application
  • Billing and company details where you hold a paid subscription

Information Collected Automatically

  • Browser type and operating system details
  • Usage patterns and pages visited
  • IP addresses (anonymised where possible)
  • Country-level location data
  • Application event logs — sign-in times, feature usage, and errors, used to operate and secure the service

Cookies

We use cookies as described in Section 10 of this policy.

4. Google User Data

The application can connect to Google services on your instruction, so that Visibilio can report on how your content performs in Google Search and on your website. This section explains exactly what that involves. It applies only to app.visibilio.ai, and only once you have connected a Google account.

4.1 Connecting is optional and always your choice

Visibilio never accesses a Google account unless you explicitly connect one through Google's own OAuth consent screen. You see the exact permissions requested before you approve them, and you can disconnect at any time (see Section 4.7). The rest of the application works without a Google connection.

4.2 What we access

We request read-only access. We do not request permission to modify, create, or delete anything in your Google account.

Google serviceWhat we readWhy
Google Search Console Search performance data for the properties you select — queries, impressions, clicks, click-through rates, average positions, and indexed URLs To show which of your pages and topics earn visibility in Google Search, and to recommend what to publish next
Google Analytics Aggregated traffic and engagement reports for the properties you select — sessions, page views, acquisition channels, and engagement metrics To connect published content to the traffic and engagement it produces
Google account basics Your name, email address, and profile picture, where you sign in with Google To create and identify your Visibilio account

We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service.

4.3 How we use it

We use Google user data solely to provide and improve the user-facing features described above and visible in the application's interface. Specifically, we use it to render your reports and dashboards, to generate content recommendations for you, and to diagnose faults you report to us.

We do not:

  • Sell Google user data, or transfer it to advertising platforms, data brokers, or information resellers
  • Use it for advertising, remarketing, credit assessment, or lending purposes
  • Use it to build profiles of individuals unrelated to the service you asked us to provide
  • Use it to develop, improve, or train generalised artificial intelligence or machine learning models
  • Allow humans to read it, except in the narrow cases set out in Section 4.5

4.4 How we store it

Google user data is encrypted in transit using HTTPS/TLS and encrypted at rest. Access tokens are held in encrypted storage and are never exposed to the browser or written to logs. We retain Google user data only while your connection is active, and we cache report data no longer than necessary to keep the application responsive.

When you disconnect a Google account or close your Visibilio account, we delete the associated tokens immediately and remove the cached Google data within 30 days.

4.5 How we share it

We do not share Google user data with third parties, except:

  • Infrastructure providers who host or process the data strictly on our behalf under contract, listed in Section 7
  • Where you direct us to, for example when you export a report
  • Where the law requires it, or where it is necessary to investigate a security incident or prevent fraud or abuse

Our staff do not read your Google user data unless you give affirmative agreement for us to view specific data (for example, when you ask us to investigate a support issue), it is necessary for security purposes, it is required by law, or the data has been aggregated and anonymised for internal operations.

4.6 Limited Use disclosure

Visibilio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.7 How to revoke access

You can disconnect Google at any time, in either of two ways:

Revoking access stops all future data collection immediately. To have data already collected deleted, contact us at team@visibilio.ai.

5. How We Use Your Data

  • Providing the application and its features to you (contract performance)
  • Responding to inquiries (legitimate interest or contract performance)
  • Service improvement through analytics (legitimate interest)
  • Securing the service and preventing abuse (legitimate interest)
  • Marketing communications (consent or legitimate interest)
  • Newsletter delivery (consent-based)
  • Billing and account administration (contract performance)
  • Legal compliance (legal obligation)

6. Automated Decision-Making

The application uses AI models to generate content drafts and recommendations. These are suggestions for you to review, edit, and approve. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

7. Data Sharing

We work with the following service providers:

  • Cloudflare — form processing, hosting, security
  • Vercel — application hosting
  • Supabase — application database and authentication
  • Resend — email delivery
  • Google Analytics — website analytics
  • Microsoft Clarity — session recording, heatmaps
  • Meta Pixel — marketing analytics

Each provider operates under their own privacy policy and data protection standards, and processes data on our instructions under a written agreement. We do not sell personal data.

8. International Data Transfers

When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including adequacy decisions, Standard Contractual Clauses, or other approved transfer mechanisms.

9. Data Retention

As a rule, we keep customer data for as long as the customer relationship lasts, and then delete it. Where a period is fixed by law, or by a commitment we have made to a third party, that period governs instead. The table below states, for each category, either the period or the criterion we use to determine it.

Data TypeRetention Period
Account and content dataFor the duration of the customer relationship, then 90 days
Google access tokensDeleted immediately on disconnection or account closure
Cached Google Search Console and Analytics dataKept while the connection is active; deleted within 30 days of disconnection or account closure
Application event logs12 months
Billing and accounting recordsFor the period required by Bulgarian accounting and tax law, which outlives the customer relationship
Contact form submissions3 years
Google Analytics data26 months
Microsoft Clarity data30 days
Marketing dataUntil consent withdrawn
Newsletter subscription dataUntil unsubscribe

Two categories are deliberately shorter than the relationship. Google user data is deleted when you disconnect the account, even if you remain a customer, because the Google API Services User Data Policy requires it and because our access exists only to serve a connection you chose to make. Event logs age out at 12 months because keeping security logs indefinitely creates risk rather than reducing it.

One category is deliberately longer. We cannot delete invoices and accounting records at the end of the relationship, because Bulgarian law requires us to keep them.

10. Cookies & Tracking Technologies

Essential Cookies

CookiePurposeDuration
Session IDSession managementSession
CSRF TokenSecuritySession
vis_langRemembers your language choice1 year

Analytics Cookies

CookiePurposeDuration
_gaGoogle Analytics2 years
_ga_*Google Analytics1 year
_clckMicrosoft Clarity1 year
_clskMicrosoft Clarity1 day

Marketing Cookies

CookiePurposeDuration
_fbpMeta Pixel3 months
_fbcMeta Pixel3 months

You can manage cookies through your browser settings. Instructions are available for Chrome, Firefox, Safari, and Edge in their respective help documentation.

11. Your Rights Under GDPR

Under GDPR you have the right to:

  • Access copies of your personal data
  • Rectification of inaccurate information
  • Erasure (the "right to be forgotten")
  • Restriction of processing
  • Data portability in machine-readable format
  • Object to legitimate interest processing
  • Withdraw consent at any time

To exercise any of these rights, contact us at team@visibilio.ai. We will respond within one month, extendable by two additional months for complex requests.

12. Security Measures

We implement appropriate technical and organisational measures to protect your data, including HTTPS/TLS encryption for data in transit, encryption at rest, secure data storage with role-based access controls, regular security assessments, and staff training on data protection.

While we strive to protect your data, no method of transmission over the Internet is 100% secure.

13. Children's Privacy

Our website and services are not directed at individuals under the age of 16.

14. Third-Party Links

Our website may contain links to external sites. We are not responsible for the privacy practices or content of third-party websites.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Where a change materially affects how we handle Google user data, we will notify connected users before it takes effect. Your continued use of our website and services after changes are posted constitutes acceptance of the updated policy.

16. Supervisory Authority

You have the right to lodge a complaint with the Bulgarian supervisory authority:

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
Sofia 1592, Bulgaria
cpdp.bg

You may also contact the supervisory authority in your country of residence within the EU.

17. Contact Us

Visibilio Ltd.
Alexander Malinov 31 Blvd.
Sofia 1729, Bulgaria
team@visibilio.ai