Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains how Surgbly collects, uses, shares, stores, and protects information when you use Surgbly's website, application, dashboards, APIs, reports, integrations, Auto-Fix features, Influence Plans, exports, and related services (the “Service”).
1. Who We Are
Surgbly is operated by Yash Amin ([email protected]) and Vishvam Amin ([email protected]), based in Ahmedabad, Gujarat, India.
Privacy contact: [email protected]
Surgbly may act as a processor for customer website, analytics, and client data, and as a controller for account, billing, security, and marketing data.
2. Information We Collect
Account information, organization and site information, site crawl data, search/analytics data (GSC, GA4), SEO/AEO/GEO monitoring data, CMS and integration credentials, Fix Pack and deployment data, AI prompts and generated outputs, usage analytics, billing information, marketing site data, security/audit logs, and support communications. We do not intentionally collect sensitive personal data.
3. How We Collect Information
Directly from you, from integrations you authorize, through crawling and monitoring jobs, from third-party data providers, via cookies and telemetry, from our billing provider, and from public/customer-authorized sources.
4. Purposes and Legal Bases
Each data category is mapped to a purpose (account creation, diagnosis, deployment, billing, security, support) and a legal basis (contract necessity, legitimate interest, legal obligation, or customer instruction). We do not sell personal data and do not use customer website content to train Surgbly-owned models.
5. AI and LLM Data Handling
Surgbly sends bounded customer content to AI/LLM providers (OpenAI, Anthropic, Perplexity, Google/Gemini) to classify issues, draft Fix Packs, and generate reports. We do not opt customer content into provider training.
6. CMS Credential and Token Handling
Credentials are encrypted at rest and in transit, scoped to the connected site, never returned to the browser, and never exposed to AI systems. Connection, rotation, and revocation events are logged.
7. Auto-Fix, Deployment, and Rollback Data
Before snapshots, proposed diffs, approvals, deployment attempts, verification results, and rollback records are retained to support rollback, support, and dispute resolution.
8. Data Retention
Raw crawl snapshots: 30–90 days. Fix/deployment rollback evidence: 12-month baseline. Billing, audit, and security records are kept as required by law. Deletion requests purge customer content while preserving only legally required records.
9. Data Export and Portability
Reports, audit logs, findings, deployment history, and configuration can be exported through the app or by support request, subject to identity verification.
10. User Rights
Access, correction, deletion, portability, objection, restriction, consent withdrawal, marketing opt-out, and the right to complain to a regulator. Contact [email protected]; baseline response target is 30 days.
12. Marketing Communications
Service, security, billing, and legal notices are sent regardless of marketing preferences. Marketing emails can be unsubscribed via the footer.
13. International Transfers
Data may be processed in India, the US, the EEA, and the UK, using SCCs, the UK IDTA, and provider DPAs where required.
14. Security Measures
Managed authentication, tenant isolation, encryption in transit and at rest, scoped integration access, audit logging, read-before-write snapshots, and rollback workflows. No system can be guaranteed secure.
15. Breach Notification
Customer notice without undue delay, targeting no later than 72 hours after confirming a reportable incident, consistent with DPDP Rule 7 and GDPR Article 33.
16. Children's Data
The Service is for business use and not directed to children.
17. Agency and Client Data
Agencies are responsible for their own client authorization and for providing required notices to clients and their users.
18. Public Website Content
Surgbly may crawl public website content, which can still contain personal data. Customers are responsible for their sites' compliance.
19. Changes to This Policy
Material changes are communicated through the app, email, or website before taking effect.
20. Contact
[email protected]
Operated by Yash Amin ([email protected]) and Vishvam Amin ([email protected])
Ahmedabad, Gujarat, India