Privacy Policy
Last updated: July 31, 2026
GetCited (“GetCited”, “we”, “us”, or “our”) operates getcited.marketingand related AI answer-engine optimization services (the “Service”). This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over it. It is written to comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) for users in India, and with the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”) for users elsewhere. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect the following categories of information:
- Account & contact data: name, work email, company name, company size, and password (hashed) when you sign up, book a demo, or submit a form.
- Billing data: billing address and payment details, processed by our payment processor (Razorpay for India, and Stripe/equivalent for other regions) — we do not store full card numbers on our servers.
- Client & domain data: the website domains, content, and brand/competitor information you connect to the Service for audits, monitoring, and content generation.
- Usage data: log data, device/browser type, IP address, pages visited, and interactions with the Service, collected via cookies and analytics tools.
- Third-party integration data: data from services you connect (e.g. Google Search Console, CMS platforms, social accounts) limited to what is needed to deliver the Service.
2. How We Use Your Information
- To provide, operate, and maintain the Service, including audits, monitoring, and reports.
- To process payments and manage subscriptions.
- To communicate with you about your account, updates, and support requests.
- To send marketing communications, where permitted, with an option to opt out at any time.
- To monitor, improve, and secure the Service, including fraud and abuse prevention.
- To comply with legal obligations.
3. Legal Basis for Processing (GDPR)
Where GDPR applies, we process personal data on the basis of: performance of a contract (to deliver the Service you signed up for), your consent (e.g. marketing emails, non-essential cookies), legitimate interests (e.g. product security and improvement), and compliance with legal obligations.
4. Consent & Notice (DPDP Act)
Where the DPDP Act applies, we collect and process personal data only for the specified, lawful purposes described in this policy, based on your free, informed, and specific consent (or another legal ground recognized under the DPDP Act, such as performance of a contract). You may withdraw consent at any time, as easily as it was given, by contacting us using the details in Section 11 — withdrawal does not affect processing carried out before withdrawal.
6. International Data Transfers
Your data may be processed and stored in countries other than your own, including the United States and India, where our infrastructure and service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers out of the EEA/UK, and comply with cross-border transfer requirements under the DPDP Act.
7. Data Retention
We retain personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed for these purposes, we delete or anonymize it.
8. Your Rights
Depending on your location, you may have the right to: access the personal data we hold about you; correct or update it; request erasure; withdraw consent; object to or restrict certain processing; request a copy of your data in a portable format; and file a grievance or complaint with a supervisory authority (in India, the Data Protection Board; in the EU/UK, your local data protection authority; in California, the California Privacy Protection Agency).
To exercise any of these rights, contact us at the email address in Section 11. We will respond within the timeframe required by applicable law.
10. Data Security
We use industry-standard technical and organizational measures — including encryption in transit, access controls, and row-level security on our database — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email, and the “Last updated” date above will reflect the latest revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
For any questions, requests, or grievances regarding this Privacy Policy or your personal data, contact us at hello@getcited.marketing.