Privacy Policy
Version 1.0. Protecting your privacy is critically important to us. This Privacy Policy explains how KB Media GmbH ("Pantra", "we", "us", or "our") collects, uses, and discloses information about you when you use our website pantra.io and our SEO, Security & GEO audit services (the "Service"). By accessing or using our Service, you acknowledge that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described herein. This Policy complies with the Swiss Federal Act on Data Protection (DSG/nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR).
Last updated: April 15, 2026
1. Data controller
The data controller responsible for your personal information is:
KB Media GmbH
Im Feld 9
6212 St. Erhard, Schweiz
Email: info@kb-media.ch
Website: pantra.io
For questions about this Privacy Policy or to exercise your rights, contact us at info@kb-media.ch.
2. Information we collect
We collect the following categories of information:
Identifiers. Name, email address, account name, and similar identifiers — collected when you register or sign in via Google OAuth.
Usage & Technical Data. IP address (anonymised), browser type, operating system, pages visited, referrer URL, and timestamps — collected automatically when you visit pantra.io.
Audit Data. The domain URLs you submit for scanning and the publicly available data retrieved from those domains (HTML, headers, robots.txt, sitemaps, JavaScript bundles). This data relates to your website, not to you personally.
Search Console Data. If you voluntarily connect your Google Search Console account, we access your keyword rankings, impressions, clicks, and indexing status — read-only, solely for display in your Pantra dashboard.
Commercial Information. Records related to your subscription, including plan type, billing period, and invoice address — processed by our payment provider Paddle.
Communications. Emails and messages you send us, including support requests.
3. How we use your information
We use your information for the following purposes, based on the indicated legal basis:
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and operating the Service (audits, fix-prompts, daily security monitoring, GEO monitoring, SEO strategy) | Art. 6(1)(b) — Contract |
| Processing payments via Paddle | Art. 6(1)(b) — Contract |
| Sending weekly scan reports and account notifications | Art. 6(1)(b) — Contract |
| Improving and expanding our Service | Art. 6(1)(f) — Legitimate interest |
| Detecting and preventing fraud or abuse | Art. 6(1)(f) — Legitimate interest |
| Complying with legal obligations (accounting, tax) | Art. 6(1)(c) — Legal obligation |
| Marketing communications (only with your consent) | Art. 6(1)(a) — Consent |
4. Third-party service providers
To provide our Service, we share data with the following trusted third parties. All providers are contractually bound to handle your data securely and only for the specified purposes.
Infrastructure
- Supabase Inc. (USA) — database hosting and backend infrastructure. Your account and scan data is stored on Supabase servers. supabase.com/privacy
- Vercel Inc. (USA) — hosting of the Pantra web application. Vercel processes technical access data. vercel.com/legal/privacy-policy
Payment
- Paddle.com Market Ltd. (United Kingdom) — Merchant of Record for all payments, invoicing, and global tax compliance (VAT/MWST). We do not store full payment card details. paddle.com/legal/privacy
AI services
To generate fix-prompts and run GEO monitoring, domain URLs and publicly available website data are sent to the following AI providers. No personal account data is transmitted.
| Provider | Country | Purpose |
|---|---|---|
| Anthropic (Claude API) | USA | Fix-prompt generation |
| OpenAI (GPT API) | USA | GEO monitoring |
| Perplexity AI | USA | GEO monitoring |
| Google (Gemini API, PageSpeed API) | USA | Content generation, performance checks, GEO monitoring |
Privacy policies: anthropic.com/privacy · openai.com/privacy · perplexity.ai/privacy · policies.google.com/privacy
Authentication & Search Console
- Google LLC (USA) — Google OAuth for sign-in (name, email, profile picture). Google Search Console API for keyword and indexing data (optional, read-only, requires your explicit authorisation). policies.google.com/privacy
- Resend Inc. (USA) — transactional email delivery (scan reports, account notifications). resend.com/legal/privacy-policy
5. International data transfers
Some of our service providers are located in the United States or other countries outside Switzerland and the EU. We ensure that all international data transfers are carried out on the basis of appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and recognised by the Swiss FDPIC, or adequacy decisions where applicable.
6. Data retention
We retain your data only as long as necessary for the purposes described in this Policy or as required by law:
| Data type | Retention period |
|---|---|
| Account and profile data | Duration of subscription + 30 days after cancellation |
| Scan results and findings | 12 months |
| Payment records | 10 years (Swiss legal requirement) |
| Server logs | 30 days |
| Google Search Console data | Until you disconnect the integration |
After these periods, data is securely deleted or anonymised.
7. Data security
We implement appropriate technical and organisational measures to protect your information, including:
- Encrypted transmission via HTTPS (TLS 1.3)
- Encrypted storage of sensitive data
- Role-based access controls
- API keys processed exclusively server-side — never exposed in the frontend
- Row Level Security enforced on all Supabase tables
- Regular security reviews
No security system is impenetrable. In the unlikely event of a data breach affecting your rights and freedoms, we will notify you and the relevant authorities as required by law.
8. Cookies
Pantra uses only technically necessary cookies for:
- Session management (login state)
- CSRF protection
- User preferences (e.g. language)
We do not use tracking cookies, advertising cookies, Facebook Pixel, Hotjar, or Google Analytics. No third-party behavioural tracking takes place on pantra.io.
9. Google Search Console integration
When you connect your Google Search Console account, you grant Pantra read-only access to your Search Console data. We use this data solely to display insights in your Pantra dashboard. We do not share your Search Console data with any third party. You can revoke access at any time in Settings or directly via your Google account at myaccount.google.com/permissions.
10. AI-assisted processing
Pantra uses AI services to analyse publicly available website data and generate fix recommendations, SEO strategies, and blog articles. Only domain URLs and publicly accessible website content are transmitted to AI providers — no personal account data. No automated decisions with legal or similarly significant effects are made based on your personal data.
11. Your rights
Under Swiss DSG and EU GDPR, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — request that we limit processing of your data
- Data portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests, including direct marketing
- Withdrawal of consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at info@kb-media.ch. We will respond within 30 days.
You also have the right to lodge a complaint with the competent supervisory authority:
Switzerland:
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Feldeggweg 1, 3003 Bern
edoeb.admin.ch
EU (if applicable): The supervisory authority of your country of residence.
12. Third-party links
Our Service may contain links to third-party websites or services that we do not own or control. We are not responsible for the privacy practices of these third parties and encourage you to review their privacy policies.
13. Business transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the relevant third party. We will notify you via email and/or a prominent notice on our Service before your data is transferred and becomes subject to a different privacy policy.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post any changes on this page. For significant changes, we will provide prominent notice (e.g. by email or in-app notification). The date at the top of this page indicates when it was last updated. Continued use of the Service after changes take effect constitutes your acceptance of the updated Policy.
15. Contact
KB Media GmbH
Im Feld 9
6212 St. Erhard, Schweiz
info@kb-media.ch
pantra.io