Best AEO Agency (“Company,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit bestaeoagency.com or engage our services. Please read it carefully. If you disagree with its terms, please discontinue use of our Site.
1. Overview & Scope
This Policy applies to information collected through our website, contact forms, email communications, service agreements, and any other interaction with Best AEO Agency. It covers personal data we process as a data controller (information you provide to us directly) and, where applicable, as a data processor (information processed on behalf of our clients).
We operate in compliance with applicable U.S. privacy law — including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) — and, where applicable, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Data Controller
For the purposes of applicable data protection law, the data controller is:
For EU/EEA or UK residents, where GDPR applies, you may contact our privacy team with data subject requests at the email above. We respond to all requests within 30 days (or 45 days where permitted by applicable law).
3. Information We Collect
A. Information You Provide Directly
- Contact form submissions: name, email address, phone number, practice name, message content
- Strategy session requests: practice details, goals, budget range, current marketing situation
- Service agreements: billing information, business name, address, authorised contacts
- Communications: emails, attachments, and any information you send us
B. Information Collected Automatically
- Usage data: pages visited, time on site, referring URL, click paths
- Device data: IP address, browser type and version, operating system, screen resolution
- Analytics data: session duration, bounce rate, conversion events — collected via Google Analytics 4
- Advertising data: ad interaction data via Google Ads and Meta Pixel, including click IDs (gclid, fbclid)
C. Information From Third Parties
- Business information from public directories and LinkedIn
- Referral information from partners or colleagues who recommend our services
- Advertising platform data (Google Ads, Meta) related to campaign performance
We do not knowingly collect sensitive personal information such as Social Security numbers, government IDs, precise geolocation data, or health information beyond what is strictly necessary to deliver agreed services under a signed BAA.
4. How We Use Your Information
We use your information to:
- Respond to enquiries and schedule strategy sessions
- Provide, manage, and improve our marketing services
- Process payments and manage billing
- Communicate about your account, deliverables, and campaign performance
- Send service-related notices (invoices, policy updates, contract renewals)
- Send marketing communications where you have opted in or where we have a legitimate interest — you may opt out at any time
- Analyse website usage to improve the user experience and conversion performance
- Comply with legal obligations and enforce our Terms
- Detect and prevent fraud, abuse, or security threats
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
5. Legal Basis for Processing (GDPR)
For individuals in the European Economic Area (EEA) or United Kingdom, we process personal data on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): Processing necessary to perform a service agreement or to take steps at your request before entering into one.
- Legitimate interests (Art. 6(1)(f)): Analytics, fraud prevention, direct marketing to existing clients, and service improvement — where our interests are not overridden by your rights.
- Consent (Art. 6(1)(a)): Marketing communications to non-clients and certain cookie categories. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): Where processing is required by applicable law (e.g., tax records, HIPAA documentation).
8. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements:
- Prospect enquiry data: 24 months from last contact, or until you request deletion
- Client data: Duration of service agreement plus 7 years (to satisfy tax and accounting obligations under IRS guidance)
- Payment records: 7 years per applicable tax law
- Website analytics data: 14 months (Google Analytics 4 default retention)
- Marketing opt-out records: Indefinitely (to honour your opt-out)
You may request earlier deletion of your personal data subject to our legal retention obligations. See Section 17 for how to submit a request.
9. Security
We implement administrative, technical, and physical safeguards designed to protect your information against unauthorised access, disclosure, alteration, or destruction, including:
- TLS/HTTPS encryption for all data in transit
- Access controls and role-based permissions for internal data access
- Encrypted storage for sensitive client data
- Regular security reviews and vendor assessments
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you in accordance with applicable law (e.g., within 72 hours under GDPR, or as required by applicable U.S. state breach notification laws).
For U.S. state breach notification obligations, we follow the requirements of the applicable state data breach notification laws.
10. Healthcare Data & HIPAA
Best AEO Agency is not a Covered Entity under the Health Insurance Portability and Accountability Act (HIPAA), but may act as a Business Associate where we process Protected Health Information (PHI) on behalf of a healthcare client. In such cases:
- A signed Business Associate Agreement (BAA) is required before any PHI is shared with us;
- We process PHI only as specified in the BAA and for no other purpose;
- We implement the safeguards required by the HIPAA Security Rule;
- We report any known breach of unsecured PHI to the Covered Entity as required by the HIPAA Breach Notification Rule.
We do not use PHI for marketing, advertising targeting, or any purpose beyond performing contracted services. Advertising campaigns for healthcare clients are structured to avoid transmitting PHI to advertising platforms in accordance with HHS HIPAA guidance on online tracking technologies.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) (Cal. Civ. Code §1798.100 et seq.), grants you the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions (legal obligations, fraud prevention, etc.).
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing:We do not sell or share personal information for cross-context behavioural advertising as defined under CPRA. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise your rights, contact us at privacy@bestaeoagency.com. We will respond within 45 days. We may need to verify your identity before processing your request. You may designate an authorised agent to submit requests on your behalf.
For more information on California privacy rights, visit the California Attorney General’s CCPA page.
12. EEA/UK Rights (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, the GDPR (or UK GDPR as applicable) grants you the following rights under Articles 15–22:
- Right of access (Art. 15): Obtain confirmation of whether we process your data and a copy of it.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your data (“right to be forgotten”) where no legal basis for retention applies.
- Right to restrict processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
- Rights related to automated decision-making (Art. 22): We do not make automated decisions with legal or similarly significant effects.
To exercise these rights, email privacy@bestaeoagency.com. You also have the right to lodge a complaint with your local supervisory authority:
13. Children's Privacy
Our Site and services are directed to business professionals and are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13 in compliance with the Children’s Online Privacy Protection Act (COPPA). If we become aware that we have collected personal information from a child under 13, we will delete it promptly. If you believe we may have collected such information, please contact us at privacy@bestaeoagency.com.
14. Third-Party Links & Services
Our Site may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before providing any personal information. Key third-party services we use and their policies:
- Google Privacy Policy — Analytics, Ads, Search Console
- Meta Privacy Policy— Facebook & Instagram Ads
- Formspree Privacy Policy — contact form processing
- Vercel Privacy Policy — website hosting
15. International Data Transfers
We are based in the United States. If you are located outside the U.S., your information is transferred to and processed in the U.S., which may not have data protection laws equivalent to those in your country.
For transfers from the EEA or UK, where applicable, we rely on:
- EU Standard Contractual Clauses (SCCs) for transfers from the EEA;
- UK International Data Transfer Agreements (IDTAs) or addenda for transfers from the UK;
- The EU-U.S. and UK-U.S. Data Privacy Framework where applicable.
Contact us at privacy@bestaeoagency.com for more information on transfer mechanisms.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy on this page with a revised “Last updated” date and, where required by law or where the change is significant, notify you by email or a prominent notice on the Site.
Your continued use of the Site after changes are posted constitutes acceptance of the revised policy. We encourage you to review this page periodically.
17. Contact & Data Requests
For privacy questions, data subject requests, to exercise your rights, or to report a privacy concern:
Privacy Officer — Best AEO Agency
Phoenix, Arizona, United States
Email: privacy@bestaeoagency.com
Response time: within 30 days (45 days for complex requests). We may verify your identity before processing data access or deletion requests. For urgent matters, please indicate “URGENT PRIVACY REQUEST” in your subject line.
For Terms of Service questions, see our Terms & Conditions.