Last updated: 29 April 2026
This privacy notice describes how MOMENTUM TECHNOLOGY ARENA SRL(“Xygnius”, “we”, “us”) processes personal data in connection with the Xygnius SEO and AI-visibility platform available at xygnius.com and its subdomains (the “Service”).
Controller details.
For requests under the EU General Data Protection Regulation (“GDPR”) or the Romanian Law no. 190/2018, contact the privacy address above. We respond within one month of receipt and may extend by up to two further months for complex requests (Art. 12(3) GDPR).
We process the following categories of personal data:
We do not knowingly collect special categories of personal data (Art. 9 GDPR — health, religion, biometric data, etc.). Do not submit such data through the Service.
We rely on different lawful bases depending on the activity:
We do not sell personal data. We share it only with vetted sub-processors that act on our written instructions under an Article 28 GDPR data-processing agreement (DPA):
| Processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Subscription billing & payment processing | EU (IE) → US | SCCs + DPA |
| Vultr Holdings, LLC | VPS hosting & persistent storage | EU (region of choice) | SCCs + DPA |
| Cloudflare, Inc. | DNS, DDoS protection, edge caching | Global edge | SCCs + DPA |
| Resend, Inc. | Transactional email delivery | US | SCCs + DPA |
| Sentry (Functional Software, Inc.) | Error and performance monitoring | US (EU residency available on request) | SCCs + DPA |
| PostHog, Inc. | Product analytics — only if “Analytics” cookie consent is given | US (EU residency available) | SCCs + DPA, opt-in only |
| OpenRouter (OpenRouter LLC) | AI-model API gateway — relays prompts to selected LLM providers (e.g. Anthropic, Google) for content generation, audits, and AI-visibility checks | US | SCCs; LLM providers operate under their own zero-retention API terms |
| fal.ai | AI image generation (Quick Ad creative pipeline) | US | SCCs |
| DataForSEO | Keyword and SERP data lookups | US | SCCs |
| Google LLC (OAuth, GA4, Search Console, Merchant Center) | Authentication and OAuth-connected reporting integrations — only if you connect them | US | SCCs + DPA |
Where a sub-processor is located outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplementary technical measures (encryption in transit and at rest), and the corresponding processor's DPA. We can supply the relevant transfer-impact assessment summaries on written request.
AI providers and your prompts. Content you submit to AI-powered features (blog generator, AI visibility checks, schema generator, brand voice extraction, etc.) is forwarded through OpenRouter to the model provider you or the platform have selected. We use models that operate under zero-retention API agreements, meaning the provider does not train its models on your inputs. We do not log full prompt bodies on our side beyond what is needed to render the result in your account.
We use a small number of cookies and equivalent storage technologies. The full list, their purposes, retention, and provider is in our Cookie Policy. You can change your choices at any time via the “Manage cookies” link in the footer or under Settings.
Our primary infrastructure is hosted in the European Economic Area. Some sub-processors listed in §4 are based in the United States or operate global edge networks. For those transfers, we rely on:
We keep personal data only for as long as we need it for the purpose it was collected, or as required by law:
Under the GDPR you can exercise the following rights free of charge, once per reasonable period:
To exercise any right, email [email protected]. We may need to verify your identity before responding.
We do not use personal data to make decisions producing legal or similarly significant effects on you within the meaning of Article 22 GDPR. AI-generated outputs (blog drafts, audit recommendations, ad copy, visibility scores, etc.) are advisory tools for you — they do not determine access to credit, employment, or essential services.
AI outputs may be inaccurate, biased, or incomplete. Always review them before publishing or relying on them in business decisions. See §8 of our Terms of Service for the full disclaimer.
We apply technical and organisational safeguards proportionate to the risk:
Despite these measures, no service can be guaranteed entirely secure. We will notify affected users and the relevant supervisory authority without undue delay if a personal-data breach is likely to result in a risk to their rights and freedoms (Art. 33–34 GDPR).
The Service is intended for business users and is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe a child has registered for an account, contact us and we will delete the data.
We may update this notice when our processing changes or the law requires it. Material changes will be notified by email and surfaced in-app at least 14 days before they take effect. The “last updated” date at the top of the page always reflects the current version.
Questions, requests, or complaints under this notice: [email protected]. Postal correspondence: MOMENTUM TECHNOLOGY ARENA SRL, Strada Caius Marcius Coriolan 29, București, Romania.