Privacy Policy

Version 1.0. Protecting your privacy is critically important to us. This Privacy Policy explains how KB Media GmbH ("Pantra", "we", "us", or "our") collects, uses, and discloses information about you when you use our website pantra.io and our SEO, Security & GEO audit services (the "Service"). By accessing or using our Service, you acknowledge that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described herein. This Policy complies with the Swiss Federal Act on Data Protection (DSG/nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR).

Last updated: April 15, 2026

1. Data controller

The data controller responsible for your personal information is:

KB Media GmbH
Im Feld 9
6212 St. Erhard, Schweiz
Email: info@kb-media.ch
Website: pantra.io

For questions about this Privacy Policy or to exercise your rights, contact us at info@kb-media.ch.

2. Information we collect

We collect the following categories of information:

Identifiers. Name, email address, account name, and similar identifiers — collected when you register or sign in via Google OAuth.

Usage & Technical Data. IP address (anonymised), browser type, operating system, pages visited, referrer URL, and timestamps — collected automatically when you visit pantra.io.

Audit Data. The domain URLs you submit for scanning and the publicly available data retrieved from those domains (HTML, headers, robots.txt, sitemaps, JavaScript bundles). This data relates to your website, not to you personally.

Search Console Data. If you voluntarily connect your Google Search Console account, we access your keyword rankings, impressions, clicks, and indexing status — read-only, solely for display in your Pantra dashboard.

Commercial Information. Records related to your subscription, including plan type, billing period, and invoice address — processed by our payment provider Paddle.

Communications. Emails and messages you send us, including support requests.

3. How we use your information

We use your information for the following purposes, based on the indicated legal basis:

PurposeLegal basis (GDPR)
Providing and operating the Service (audits, fix-prompts, daily security monitoring, GEO monitoring, SEO strategy)Art. 6(1)(b) — Contract
Processing payments via PaddleArt. 6(1)(b) — Contract
Sending weekly scan reports and account notificationsArt. 6(1)(b) — Contract
Improving and expanding our ServiceArt. 6(1)(f) — Legitimate interest
Detecting and preventing fraud or abuseArt. 6(1)(f) — Legitimate interest
Complying with legal obligations (accounting, tax)Art. 6(1)(c) — Legal obligation
Marketing communications (only with your consent)Art. 6(1)(a) — Consent

4. Third-party service providers

To provide our Service, we share data with the following trusted third parties. All providers are contractually bound to handle your data securely and only for the specified purposes.

Infrastructure

  • Supabase Inc. (USA) — database hosting and backend infrastructure. Your account and scan data is stored on Supabase servers. supabase.com/privacy
  • Vercel Inc. (USA) — hosting of the Pantra web application. Vercel processes technical access data. vercel.com/legal/privacy-policy

Payment

  • Paddle.com Market Ltd. (United Kingdom) — Merchant of Record for all payments, invoicing, and global tax compliance (VAT/MWST). We do not store full payment card details. paddle.com/legal/privacy

AI services

To generate fix-prompts and run GEO monitoring, domain URLs and publicly available website data are sent to the following AI providers. No personal account data is transmitted.

ProviderCountryPurpose
Anthropic (Claude API)USAFix-prompt generation
OpenAI (GPT API)USAGEO monitoring
Perplexity AIUSAGEO monitoring
Google (Gemini API, PageSpeed API)USAContent generation, performance checks, GEO monitoring

Privacy policies: anthropic.com/privacy · openai.com/privacy · perplexity.ai/privacy · policies.google.com/privacy

Authentication & Search Console

  • Google LLC (USA) — Google OAuth for sign-in (name, email, profile picture). Google Search Console API for keyword and indexing data (optional, read-only, requires your explicit authorisation). policies.google.com/privacy

Email

5. International data transfers

Some of our service providers are located in the United States or other countries outside Switzerland and the EU. We ensure that all international data transfers are carried out on the basis of appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the Swiss FDPIC, or adequacy decisions where applicable.

6. Data retention

We retain your data only as long as necessary for the purposes described in this Policy or as required by law:

Data typeRetention period
Account and profile dataDuration of subscription + 30 days after cancellation
Scan results and findings12 months
Payment records10 years (Swiss legal requirement)
Server logs30 days
Google Search Console dataUntil you disconnect the integration

After these periods, data is securely deleted or anonymised.

7. Data security

We implement appropriate technical and organisational measures to protect your information, including:

  • Encrypted transmission via HTTPS (TLS 1.3)
  • Encrypted storage of sensitive data
  • Role-based access controls
  • API keys processed exclusively server-side — never exposed in the frontend
  • Row Level Security enforced on all Supabase tables
  • Regular security reviews

No security system is impenetrable. In the unlikely event of a data breach affecting your rights and freedoms, we will notify you and the relevant authorities as required by law.

8. Cookies

Pantra uses only technically necessary cookies for:

  • Session management (login state)
  • CSRF protection
  • User preferences (e.g. language)

We do not use tracking cookies, advertising cookies, Facebook Pixel, Hotjar, or Google Analytics. No third-party behavioural tracking takes place on pantra.io.

9. Google Search Console integration

When you connect your Google Search Console account, you grant Pantra read-only access to your Search Console data. We use this data solely to display insights in your Pantra dashboard. We do not share your Search Console data with any third party. You can revoke access at any time in Settings or directly via your Google account at myaccount.google.com/permissions.

10. AI-assisted processing

Pantra uses AI services to analyse publicly available website data and generate fix recommendations, SEO strategies, and blog articles. Only domain URLs and publicly accessible website content are transmitted to AI providers — no personal account data. No automated decisions with legal or similarly significant effects are made based on your personal data.

11. Your rights

Under Swiss DSG and EU GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data (subject to legal retention obligations)
  • Restriction — request that we limit processing of your data
  • Data portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interests, including direct marketing
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at info@kb-media.ch. We will respond within 30 days.

You also have the right to lodge a complaint with the competent supervisory authority:

Switzerland:
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Feldeggweg 1, 3003 Bern
edoeb.admin.ch

EU (if applicable): The supervisory authority of your country of residence.

12. Third-party links

Our Service may contain links to third-party websites or services that we do not own or control. We are not responsible for the privacy practices of these third parties and encourage you to review their privacy policies.

13. Business transfers

In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the relevant third party. We will notify you via email and/or a prominent notice on our Service before your data is transferred and becomes subject to a different privacy policy.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post any changes on this page. For significant changes, we will provide prominent notice (e.g. by email or in-app notification). The date at the top of this page indicates when it was last updated. Continued use of the Service after changes take effect constitutes your acceptance of the updated Policy.

15. Contact

KB Media GmbH
Im Feld 9
6212 St. Erhard, Schweiz
info@kb-media.ch
pantra.io