lazy cats aI LLM check logo white
  • How it works
  • Features
  • Pricing
  • FAQs
  • Run your free check →
    Pay when it pays off
MENU
MENU
CLOSE
CLOSE
LEGAL

Privacy Policy & GDPR

Last updated: August 17, 2026

This Privacy Policy explains how LAZY CATS SRL ("LazyCats AI", "we", "us", "our") collects, uses, shares and protects personal data when you visit www.lazycats.ai, create an account, or use our AI visibility audit tool (the "Service"). It is written to comply with Regulation (EU) 2016/679 (the "GDPR") and applicable Romanian data protection law.

We are not a law firm, and this policy is not legal advice to you — it describes our own practices as a data controller. If you have questions about how a specific provision applies to your situation, we recommend speaking with a qualified data protection professional.

Contents

  • 1. Who we are (data controller)
  • 2. What personal data we collect
  • 3. How we use your data and our legal basis
  • 4. How long we keep your data
  • 5. Who we share your data with
  • 6. International data transfers
  • 7. Cookies and similar technologies
  • 8. Your rights under the GDPR
  • 9. How we protect your data
  • 10. Automated decision-making and profiling
  • 11. Children's privacy
  • 12. Data breach notification
  • 13. Changes to this policy
  • 14. How to contact us

1. Who we are (data controller)

The data controller responsible for your personal data is:

LAZY CATS SRL
CUI (Tax ID): 43054586
VAT ID (intra-community): RO47555687
Nr. Reg. Com.: J07/511/2020
EUID: ROONRC.J7/511/2020
Registered address: Str. Primăverii 11, Botoșani, Cod 710108, Județul Botoșani, România

We do not have a statutory Data Protection Officer, as our current scale of processing does not require one under Article 37 GDPR. For any data protection question or request, contact us at privacy@lazycats.ai — see Section 14 for details.

2. What personal data we collect

We collect different categories of data depending on how you interact with us:

a) Account data. When you create a LazyCats AI account: your name, work email address, and a securely hashed password (or, if you sign in via a third-party provider, the identifiers that provider shares with us).

b) Billing data. If you subscribe to a paid plan, our payment processor (Stripe) collects your billing name, address, and card details directly. We do not store full card numbers on our own systems — we receive only limited data back from Stripe, such as the last 4 digits of your card, billing status, and invoice history.

c) Audit input data. To run an AI visibility audit, you (or your organization) submit a website URL, domain name, and/or brand name. Where you ask us to track specific competitors, we also process the names/URLs you provide for them. This is normally business data rather than personal data, but if your website, domain, or brand name happens to be your own personal name (e.g. a personal portfolio site or sole-trader brand), it is treated as personal data under this policy.

d) Audit results. The reports our Service generates — visibility scores, citation data, and recommendations — are stored on your account so you can access your history over time.

e) Communications data. If you email us, use in-app chat, or fill out a contact/demo form, we keep the content of that correspondence and your contact details so we can respond and keep a record of the interaction.

f) Usage and technical data. Like most websites, we automatically collect some technical data when you visit our site or use the Service: IP address, browser type and version, device type, pages viewed, referring URLs, and timestamps. This is collected via server logs and, where enabled, analytics and advertising cookies (see Section 7).

g) Marketing data. If you subscribe to our newsletter or opt in to product updates, we collect your email address and track engagement (opens/clicks) so we can improve what we send you. You can unsubscribe at any time.

We do not intentionally collect special categories of data (health, religion, political opinions, biometric data, etc.), and we ask that you do not submit such data to us through support requests, forms, or the audit tool.

3. How we use your data and our legal basis

Under the GDPR, we must have a valid legal basis for every use of personal data. Here is how our main purposes map to those bases:

To create and administer your account, run audits, and deliver the Service you've signed up for — legal basis: performance of a contract (Art. 6(1)(b) GDPR).

To process payments and maintain accounting records — legal basis: performance of a contract, and compliance with legal obligations under Romanian accounting and tax law (Art. 6(1)(b) and (c) GDPR).

To respond to support requests and communicate about your account — legal basis: performance of a contract and our legitimate interest in providing good customer service (Art. 6(1)(b) and (f) GDPR).

To secure our systems, prevent fraud and abuse, and debug the Service — legal basis: legitimate interest in keeping our Service safe and reliable (Art. 6(1)(f) GDPR).

To understand aggregate usage and improve the Service — legal basis: legitimate interest (Art. 6(1)(f) GDPR), or consent where analytics cookies require it (Art. 6(1)(a) GDPR — see Section 7).

To run and measure advertising campaigns on Google, Facebook/Instagram, and TikTok — legal basis: your consent, given via our cookie banner (Art. 6(1)(a) GDPR). You may withdraw this consent at any time — see Section 7.

To send you marketing emails, product updates, or newsletters — legal basis: your consent, given when you subscribe (Art. 6(1)(a) GDPR). You may withdraw this consent at any time via the unsubscribe link in any email or by contacting us.

Where we rely on legitimate interest, we have considered that our interest does not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interest — see Section 8.

4. How long we keep your data

We keep personal data only for as long as necessary for the purposes described above:

Account and audit data: for as long as your account is active, and for up to 12 months after closure in case you wish to reactivate it, after which it is deleted or anonymized.

Billing and invoicing records: for 10 years from the end of the relevant financial year, as required by Romanian accounting law (Legea contabilității nr. 82/1991).

Support communications: up to 24 months after the last interaction, unless a longer period is needed to resolve a dispute.

Server and security logs: typically 12 months, or longer if needed to investigate a security incident.

Marketing data: until you unsubscribe or ask us to delete it, or after a prolonged period of inactivity (typically 24 months without any engagement).

Cookies: see the retention periods for each cookie listed in Section 7.

Where we no longer need personal data for these purposes, we delete or irreversibly anonymize it.

5. Who we share your data with

We do not sell your personal data. We share it only with service providers who process it on our behalf ("processors"), or where required by law. Our current sub-processors and advertising partners include:

Webflow (website hosting, forms, and our CMS) — processes data needed to serve our site and store site content.

Stripe (payment processing) — processes billing and card data to handle subscriptions and invoices.

Resend (transactional and marketing email) — processes your email address and message engagement data (opens/clicks) to send account notifications, invoices, and — where you've opted in — marketing emails.

Google (Google Analytics and Google Ads) — where you consent to analytics/advertising cookies, processes usage and technical data (Section 2(f)) and, for visitors who arrived via a Google ad, conversion data, to help us understand traffic, site performance, and ad effectiveness.

Meta Platforms, Inc. / Meta Platforms Ireland Ltd. (Facebook/Instagram Pixel) — where you consent to advertising cookies, receives limited technical and behavioral data (e.g. pages viewed, sign-ups) so we can measure and optimize ads run on Facebook and Instagram, and build retargeting/lookalike audiences. Meta acts as an independent controller for its own ad platform and may combine this data with other data it holds about you under its own privacy policy.

TikTok Inc. / TikTok Technology Limited (TikTok Pixel) — where you consent to advertising cookies, receives similar technical and behavioral data to measure and optimize ads run on TikTok and build custom audiences. TikTok acts as an independent controller for its own ad platform and processes this data under its own privacy policy.

OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), and Perplexity AI — when you run an audit, the website/domain/brand names and related prompts described in Section 2(c) are sent to these providers' APIs so we can generate your visibility report. We do not knowingly send account credentials, payment data, or other unrelated personal data to these providers.

Each processor listed above is contractually required to use the data we share only to provide their service to us (or, for our advertising partners, subject to their own platform terms and privacy policies), and to apply appropriate security measures. We may also disclose personal data where required by law, to enforce our terms, or to protect the rights, property, or safety of LazyCats AI, our users, or others.

Some pages on our site include affiliate links (for example, to third-party tools we recommend, disclosed as such). Clicking an affiliate link takes you to that third party's own site, which has its own privacy policy — we do not share your personal data with that provider by virtue of the link itself.

6. International data transfers

Several of the sub-processors and advertising partners listed in Section 5 — including Stripe, Resend, OpenAI, Anthropic, Google, Meta Platforms, TikTok, and Perplexity AI — are based in, or transfer data to, the United States, the United Kingdom, or other countries outside the European Economic Area (EEA) as part of their global infrastructure (for TikTok, this can include the US, UK, Ireland, and Singapore, per TikTok's published data practices). Where we transfer personal data outside the EEA, we rely on legally recognized safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), or the provider's participation in a recognized adequacy framework, to ensure your data continues to receive a comparable level of protection. You can contact us for more information about the specific safeguards used for a given transfer.

7. Cookies and similar technologies

We use cookies and similar technologies (including pixels and local storage) grouped into four categories, the standard classification used across the EU/EEA. Only the first category loads automatically. Everything else is switched off until you actively consent via our cookie banner, which lets you accept or decline each category independently and change your choice at any time.

a) Strictly necessary cookies

Required for the site to work. You can't opt out of these, because they don't track you for marketing purposes.

  • Webflow session / CDN cookies (provider: Webflow) — load balancing, form security (CSRF protection), and remembering basic UI state. Duration: session-length up to 1 year, depending on the specific cookie.

b) Performance & analytics cookies

Help us understand, in aggregate, how visitors use the site so we can improve it. Requires consent.

  • Google Analytics — cookies _ga, _ga_*, _gid (provider: Google LLC). Measures page views, sessions, traffic sources, and on-site behavior. Duration: up to 2 years (_ga, _ga_*), 24 hours (_gid).
  • Google Ads conversion tracking — cookie _gcl_au (provider: Google LLC). Records whether a visit resulted from a Google ad click, to report campaign performance. Duration: up to 90 days.

c) Functional cookies

Remember choices you've made so the site behaves the way you expect. Requires consent, except where a cookie is itself needed to store your consent choice.

  • Cookie-consent preference cookie (provider: LazyCats AI / our consent management tool) — remembers which cookie categories you've accepted or declined, so we don't ask again on every visit.

d) Targeting & advertising cookies

Used by us and our advertising partners to measure ad performance, build audiences, and show more relevant ads on their own platforms. Requires consent.

  • Meta (Facebook/Instagram) Pixel — cookies _fbp, fr (provider: Meta Platforms, Inc. / Meta Platforms Ireland Ltd.). Tracks page views and on-site actions (e.g. sign-ups, plan purchases) so we can measure and optimize Facebook/Instagram ad campaigns, and build retargeting/lookalike audiences. Duration: up to 90 days (_fbp), up to 180 days (fr).
  • TikTok Pixel — cookie _ttp and related click-identifier cookies (provider: TikTok Inc. / TikTok Technology Limited). Tracks page views and on-site actions to measure and optimize TikTok ad campaigns and build custom audiences. Duration: up to 13 months.
  • Google Ads remarketing (provider: Google LLC). Builds retargeting audiences based on pages you've visited, so we can show relevant ads on Google's ad network. Duration: up to 540 days.

Because Google, Meta, and TikTok each act partly as an independent controller for the data collected through their own pixels, we recommend also reviewing their privacy policies directly: Google Privacy Policy, Meta Privacy Policy, and TikTok Privacy Policy. You can manage ad personalization directly through Google's Ad Center, Meta's ad settings, and TikTok's privacy controls.

Declining performance/analytics or targeting/advertising cookies does not affect your ability to use the Service — it only means we and our advertising partners have less visibility into how you found us and how the site performs for you.

8. Your rights under the GDPR

If you are located in the EEA (or otherwise protected by the GDPR), you have the following rights over your personal data:

Right of access — ask us for a copy of the personal data we hold about you.

Right to rectification — ask us to correct inaccurate or incomplete data.

Right to erasure ("right to be forgotten") — ask us to delete your data, subject to legal exceptions (e.g. accounting records we must retain).

Right to restrict processing — ask us to limit how we use your data in certain circumstances.

Right to data portability — ask us for your data in a structured, machine-readable format, or ask us to transmit it to another provider where technically feasible.

Right to object — object to processing based on our legitimate interest, including profiling, and to direct marketing or advertising cookies at any time (which we will always honor).

Right to withdraw consent — where processing is based on consent (e.g. marketing emails, analytics or advertising cookies), withdraw it at any time via our cookie banner or by contacting us, without affecting the lawfulness of processing before withdrawal.

Right not to be subject to solely automated decision-making producing legal or similarly significant effects — see Section 10, though we do not currently engage in this type of processing.

To exercise any of these rights, contact us at privacy@lazycats.ai. We will respond within one month, as required by the GDPR (extendable by two further months for complex requests, in which case we will explain why).

You also have the right to lodge a complaint with a supervisory authority. In Romania, this is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, București, cod 010336, România
Email: anspdcp@dataprotection.ro
Phone: +40.318.059.211
Website: www.dataprotection.ro

If you are located outside Romania, you may instead contact the supervisory authority in your own EU/EEA member state.

9. How we protect your data

We apply technical and organizational measures appropriate to the risk, including: encryption of data in transit via HTTPS/TLS, hashed and salted password storage, role-based access controls limiting internal access to personal data on a need-to-know basis, and due diligence on the sub-processors listed in Section 5 before we work with them. No system is 100% secure, but we work to keep these safeguards up to date as our Service grows.

10. Automated decision-making and profiling

The AI visibility audits our Service produces are informational reports about how third-party AI models describe or cite a website or brand — they do not make automated decisions about you as an individual, and are not a form of profiling that produces legal or similarly significant effects on you personally. Our advertising cookies (Section 7) build audiences for ad targeting, but do not make automated decisions with legal or similarly significant effects either. We do not use automated decision-making in this stricter sense anywhere in the Service (for example, we do not use it to approve/deny accounts or set individualized pricing).

11. Children's privacy

Our Service is intended for businesses and professionals, and is not directed at, or knowingly used to collect data from, individuals under 16. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will delete it promptly.

12. Data breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ANSPDCP within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly, without undue delay, and explain the nature of the breach and the steps we are taking.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our Service, or the law. We will update the "Last updated" date at the top of this page, and where changes are material, we will make a reasonable effort to notify active account holders (for example, by email) before they take effect.

14. How to contact us

For any question about this policy, or to exercise your data protection rights, contact us at:

LAZY CATS SRL
CUI: 43054586 · VAT ID: RO47555687
Str. Primăverii 11, Botoșani, Cod 710108, România
Email: privacy@lazycats.ai

We aim to respond to all privacy-related requests within one month.

Based in Europe. Delivering globally.
AI visibility for your brand — on ChatGPT, Claude, Gemini and Perplexity.
Status: All systems operational

Product

How it worksFeaturesPricingFree Audit

Resources

BlogGlossaryFAQsFeature requests

Company

AboutContact

Legal

Terms and Conditions
Privacy Policy & GDPR
LazyCatsBot
© 2019–2026.
LazyCats® is a Registered Trademark.
All rights reserved.
Secure payments via