Privacy & Security
Last updated: May 16, 2026
Scope: this privacy policy applies to the useof Sero, the applications, website, connections, and services offered by Sero.
Trust is at the heart of everything we do at Sero. We want you to work, create connections, and use data with confidence—without worrying about what happens to your data behind the scenes. Your data remains yours. In this privacy policy, we clearly explain which personal data and Google user data we process, why we do so, how long we retain data, with whom we may share data, and which choices and rights you have.
This policy also applies to data we receive when you sign in with Google via OAuth or when you add Google connections to Sero, such as Google Analytics, Google Search Console, or other Google services that you actively connect yourself.
1. Who is responsible for your data?
Sero is responsible for processing personal data within Sero, unless otherwise stated in a specific situation. This privacy policy is intended to serve as Sero’s dedicated privacy policy and should be published on an HTML or rich-text web page on a domain owned or verified by Sero.
We don’t make privacy more complicated than necessary. That’s why we process only the data needed to keep Sero working properly, securely, and reliably.
2. What data do we process?
Depending on how you use Sero, we may process the following categories of personal data:
account details, such as your name, email address, account ID, and profile photo;
login and authentication data;
data you enter, upload, connect, or generate within Sero;
data from connections that you activate yourself, such as statistics or property data from Google Analytics or Google Search Console;
technical data, such as IP address, browser type, device and session data, log files, and security information;
communication data, such as when you contact us;
billing and administrative data, where applicable.
We don’t collect more data than necessary for the purposes for which it is processed. We don’t store anything “just in case” if it isn’t needed for the operation, security, or support of Sero.
3. Google OAuth and Google User Data
Sero uses Google OAuth 2.0 to let users sign in securely and add Google connections to Sero themselves. Examples include connections with Google Analytics, Google Search Console, or other Google services supported within Sero.
You decide whether to add a Google connection. Without your consent, we do not request access to your Google Account or Google services. When you create a connection, Google shows you which permissions or scopes are requested. Sero uses these permissions only for the features for which you activate the connection.
3.1 What Google Data Do We Collect When You Log In with Google?
When you sign up or log in through Google, we may receive and process the following Google user data:
your first and last name;
your email address;
your profile picture, if available;
your unique Google Account ID, where necessary to securely link your Sero account to your Google login.
We use this data to verify your identity, create your account, or allow you to sign in securely.
3.2 Which Google data do we process through Google connections?
If you voluntarily add a Google connection in Sero, we may—depending on the connection selected and the scopes you approve—retrieve or process data from that Google service. Examples include:
Google Analytics account information, properties, data streams, reports, metrics, traffic data, conversions, and performance indicators;
Google Search Console sites, verified properties, search performance, search queries, pages, impressions, clicks, positions, and technical indexing or performance data;
basic data needed to show which Google account or property is connected to Sero;
access and refresh tokens needed to make the connection work technically, to the extent provided by Google and for as long as the connection is active.
The exact data depends on the connection you activate and the scopes you authorize. Sero requests only the scopes needed for the functionality you use. If a connection requires read-only access, we do not request write access.
3.3 Examples of Google OAuth Scopes
Depending on the functionality used, Sero may request access to scopes such as:
openid, email, and profile for secure sign-in and basic profile information;
Google Analytics scopes, such as scopes for reading Analytics accounts, properties, and report data;
Google Search Console scopes, for example, for reading Search Console sites and search performance;
other Google API scopes needed for future or additional connections within Sero.
When additional scopes are needed, we request separate consent through Google OAuth. We use Google data only for the function you consented to.
3.4 How Do We Use Google User Data?
We use Google user data only to provide, secure, and improve Sero for you as a user. Specifically, we use this data for the following purposes:
verifying your identity;
to create your account or let you sign in securely;
linking your Sero account to your Google login;
to enable Google connections you choose within Sero;
displaying linked Google data clearly in dashboards, reports, analyses, or workflows within Sero;
to provide insights, recommendations, or automations based on the data you connect;
preventing technical errors, misuse, unauthorized access, and security incidents;
to provide support when you contact us about your account or connections.
We do not use Google user data for purposes other than providing, securing, supporting, or improving Sero’s user-facing functionality.
3.5 What Do We Not Use Google User Data For?
We never sell Google user data. We also do not use Google user data for:
targeted advertising;
personalized advertising;
retargeting;
interest-based advertising;
selling data to data brokers;
transfers to information brokers or data resellers;
creditworthiness assessments;
loan or financing purposes;
building external databases outside Sero’s functionality;
training, enriching, or improving third-party AI models.
Google user data is not used for advertising purposes and is not transferred to third parties for advertising, data brokerage, or reselling purposes.
3.6 Sharing Google User Data
We do not share Google user data with third parties, except when strictly necessary to provide, secure, or support Sero, or when we are legally required to disclose data.
Examples of parties that may process data on our behalf include:
hosting and infrastructure providers;
security and monitoring services;
authentication or account management providers;
support or administrative systems, where necessary;
AI or analytics providers that provide functionality within Sero solely on our behalf, when necessary for a feature you use.
These parties may process data only according to our instructions, for the agreed purposes, and subject to appropriate contractual and security obligations. We do not allow these parties to sell Google user data or use it for their own advertising, reselling, or AI training purposes.
3.7 Google API Services User Data Policy
Sero’s use and transfer of information received through Google APIs complies with the Google API Services User Data Policy, including the Limited Userequirements. This means, among other things,that we use Google user data only for permitted, user-facing functionality within Sero and not for prohibited purposes such as advertising, selling data, or training third-party AI models.
3.8 Storage and Retention Periods for Google User Data
We retain Google user data for as long as your Sero account remains active or as long as necessary for the purposes described in this privacy policy.
For Google connections:
we retain basic connection data for as long as the connection remains active;
we retain access tokens and refresh tokens only for as long as necessary to keep the integration working;
We retain retrieved reporting or analytics data for as long as necessary to operate dashboards, reports, analytics, support, security, or administration within Sero;
when you remove a connection, we stop retrieving new data through that connection.
When you delete your account or ask us to delete your data, we delete the Google login data and Google connection data associated with your account, unless we need to retain certain data longer due to legal obligations, security, dispute resolution, or administrative reasons.
Active account data is generally deleted within 30 days after a valid deletion request. Data in backups is overwritten or deleted within the normal backup cycles, unless longer retention is legally required.
3.9 Revoking Google Access
You can revoke Sero’s access to your Google account at any time through your Google account’s security settings. You can manage this through:
https://myaccount.google.com/permissions
You can also remove or reconnect specific connections within Sero, if available. After revoking or removing a connection, Sero can no longer retrieve new data through that Google connection unless you grant permission again.
Revoking Google access does not automatically remove all previously processed data from your Sero account. If you want your account or personal data deleted, please contact us using the contact details in this policy or use the deletion options within Sero, if available.
4. How Do We Use Personal Data?
We process personal data for the following purposes:
providing and operating Sero;
creating, managing, and securing user accounts;
enabling connections that you add yourself;
displaying dashboards, reports, analyses, and insights within Sero;
providing support and customer service;
personalizing the user experience within the application;
improving the performance, reliability, and security of Sero;
preventing fraud, misuse, and unauthorized access;
complying with legal obligations;
administration, billing, and contract management, where applicable.
We process personal data only when we have a valid legal basis, such as performing a contract, obtaining consent, complying with a legal obligation, or pursuing our legitimate interest in securing and improving our services.
5. Secure EU servers
All our servers are located within the European Union, primarily in the Netherlands. This means your data is protected under a strong European privacy framework, including the General Data Protection Regulation (GDPR).
If data is processed outside the European Economic Area, we ensure appropriate safeguards, such as standard contractual clauses, additional security measures, or other mechanisms permitted under the GDPR.
6. We Don’t Share Data Unless Necessary for Sero
We never share sensitive information with third parties for commercial sales, advertising, or data resale. In some cases, certain vendors need to process data to keep Sero running properly, for example for hosting, security, monitoring, authentication, support, or technical infrastructure.
In those cases, we share only what is necessary. Your data remains yours, and parties that process data on our behalf may not use that data for their own purposes.
7. Full GDPR Compliance
Sero operates in accordance with the GDPR. We enter into appropriate agreements with processors, as required under Article 28 of the GDPR. These agreements state, among other things, that processors may process data only according to our instructions and must implement appropriate technical and organizational measures.
We process personal data according to the principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
8. AI Processing and No Model Training
Sero may use AI functionality and AI providers to deliver the service. For example, this may include summarizing, analyzing, or structuring information within features you use.
We enter into data processing agreements or comparable data protection agreements with our AI providers. These agreements require providers to process data only according to our instructions and to implement appropriate security measures.
User data, including Google user data, may not be used to train, enrich, or improve third-party AI models unless you expressly and separately grant permission to do so. By default, your data is not used for model training.
Your data remains your data.
9. Encryption and Privacy
We take appropriate technical and organizational measures to protect personal data and Google user data against loss, misuse, unauthorized access, disclosure, alteration, and destruction.
Our security measures include:
hosting on secure servers within the European Union, primarily in the Netherlands;
encryption of data in transit, where possible, using TLS/HTTPS;
encrypted storage for sensitive data where appropriate;
access restrictions based on the need-to-know principle;
limited internal access to functional systems;
logging, monitoring, and security checks;
regular security audits and checks;
backups and recovery procedures;
contractual security obligations with processors.
We design Sero with privacy and data protection at its core, in line with privacy by design and privacy by default as referred to in Article 25 of the GDPR.
10. Retention periods
We do not retain personal data longer than necessary for the purposes for which it was collected, unless a longer retention period is legally required or permitted.
In general:
account data is retained for as long as your account remains active;
data from active integrations is retained for as long as necessary to provide the integration and associated features;
support and communications data is retained for as long as necessary to handle your request and for administrative purposes;
billing data is retained in accordance with statutory record-keeping requirements;
security logs are retained for as long as necessary for security, monitoring, and incident investigation;
deleted data may remain temporarily in backups until the backup cycle expires.
When a retention period expires, we securely delete or anonymize the data.
11. Data Deletion
At Sero, you remain in control of your data as much as possible. You can request the deletion of your personal data, Google connections, or your entire Sero account.
After a valid deletion request, we delete your data unless we need to retain certain data due to legal obligations, security, disputes, or legitimate administrative purposes.
Deletion requests can be submitted via: [email protected]
If your Sero account is linked to Google login, we also delete the Google login data associated with your Sero account when your account is deleted. If you have added Google connections, we also delete the associated connection data and stop retrieving new data.
12. Your Rights
Under the GDPR, depending on the circumstances, you have the following rights:
right to access your personal data;
the right to correct inaccurate data;
right to delete data;
right to restrict processing;
right to data portability;
right to object to certain processing activities;
the right to withdraw consent when processing is based on consent;
the right to lodge a complaint with the Dutch Data Protection Authority.
You can submit a request via [emailprotected]. We may ask you to verify your identity before fulfilling your request.
13. No Sale of Personal Data
We do not sell personal data or Google user data. We do not provide personal data to third parties for advertising purposes, data brokerage, data resale, credit assessments, lending or financing purposes, or similar purposes.
14. Children
Sero is not intended for use by children under the age at which they may independently consent to the processing of personal data under applicable law. If we discover that we have processed a minor’s personal data without valid consent, we will delete that data where necessary.
15. Changes to this privacy policy
We may update this privacy policy from time to time, for example when our services, integrations, legal requirements, or data processing practices change. The most current version is always available on this dedicated privacy policy page.
If we materially change how we use Google user data or other personal data, we will clearly inform users, for example by email, in-app notification, or a notice on our website. Where legally required, we will request consent again.
16. Contact
For questions about this privacy policy, privacy rights, or the processing of personal data, you can contact:
SeroEmail:
[email
protected]Website: https://sero.tech
Address: Herengracht 231, 1016BG, Amsterdam