legal · privacy notice
Privacy notice
What we hold, why we hold it, which AI and infrastructure providers see it, how long it stays, and how to make us delete it.
IT Master is operated from London, United Kingdom by its founder, Rodd Azad. Written questions about this document go to contact@itmaster.uk.
1. Who controls your data
IT Master, the autonomous SEO content engine at itmaster.uk, is the controller of the personal data described here. It is operated from London, United Kingdom by its founder, Rodd Azad, who is the point of contact for everything in this notice. We have not appointed a Data Protection Officer; we are not required to.
Write to contact@itmaster.uk for anything about your data, including a request to exercise the rights in section 9. Editorial corrections go to hello@itmaster.uk.
There is a second relationship worth separating. For the personal data on your website and in your own analytics — your visitors, your customers — you are the controller and we act as a processor on your instructions. We process it to research, write, publish and measure content for you, and for nothing else.
This notice is written under the UK GDPR and the Data Protection Act 2018. We do not publish a company registration number here because there is none to publish for this operation yet; we name the operator instead of printing a placeholder.
2. What we collect
Account details
Your name, email address, the billing account you belong to, your role, and the dates your record was created and changed. If you set a password we store a one-way hash of it, never the password itself. If you sign in with Google we receive your name, email address and basic profile from Google, using the standard sign-in scopes and nothing more.
Billing
Top-up amounts, currency, payment references, payment status, and the cardholder name you type at checkout. Card numbers are entered into Worldpay’s own checkout component and never reach our servers — we hold a payment session reference and the outcome, not your card.
Connected sites
The address of each site, its CMS or API credentials (encrypted at rest, per site), the content we generate and publish for it, and the performance data we read back. Where your site content or product data contains personal data — a staff biography, a customer question — it is processed as part of the content, as described above.
Connection tokens
OAuth tokens for Google Search Console, Google Analytics, Bing Webmaster Tools and Microsoft Ads, held encrypted and used only to read data for the site you connected them to and to submit URLs for indexing. You can disconnect any of them at any time, which is what revokes them.
Correspondence
Emails and messages you send us, and our replies.
Technical data
Server logs, and error reports through Sentry when something breaks — the page, browser and error diagnostics. Cloudflare sits in front of the site and sees the IP address and request metadata of traffic to it. We do not build profiles of visitors and there is no advertising or analytics tracking on our marketing pages.
Cookies
All of our cookies are strictly necessary, so there is no consent banner to click through:
itmaster_session— your signed-in session. HTTP-only, 14 days.gsc_oauth_state,ga4_oauth_state,bwt_oauth_state,msads_oauth_state,ga4_terms_site— short-lived values discarded in ten minutes (thirty for the GA4 terms hand-off) that make a connection flow safe by keeping the site you are connecting on the server side rather than in a URL.
We set no advertising, profiling or cross-site tracking cookies.
3. Why we hold it, and our lawful basis
- To provide the service — accounts, generation, publishing, measurement, support. Basis: performance of our contract with you.
- To take payment and keep financial records. Basis: contract, and legal obligation for the records tax law requires us to keep.
- To keep the service secure and working — logging, error monitoring, fraud and abuse prevention, rate limiting. Basis: our legitimate interest in a service that is not broken or abused, balanced against the small amount of data involved.
- To improve the engine — reviewing failures, pass rates and cost, and publishing aggregated statistics that identify no customer, site or article. Basis: legitimate interest.
- To send service email — top-up receipts, low balance warnings, publishing alerts, changes to these documents. Basis: contract. These are not marketing and you cannot unsubscribe from them while you hold an account.
- To send anything promotional. Basis: your consent, which you can withdraw at any time.
We do not sell personal data, and we do not share it for advertising. We do not make decisions with legal or similarly significant effects about people by automated means: the engine makes automated decisions about content — what to write, whether a draft passes — not about individuals.
4. How AI providers see your content
This is the part people most want to know, so it gets its own section. Producing an article means sending material to AI providers: your brief, the research dossier, passages retrieved from your own data, the draft itself, and the checkers’ verdicts on it. The providers we use for that are Anthropic, Google, OpenAI, Perplexity and Voyage AI, and the split of work between them is in the table below.
Two things follow from how the engine is built. Because the model that writes is never the model that checks, and every check includes a model from a different vendor than the writer, a single article is seen by more than one provider — that cross-vendor spread is the product, not an accident. And because each check gets only what it needs, no provider receives your whole account.
We reach these providers through their paid business APIs, not their consumer chat products, and we do not sell or license your content to them for any purpose other than performing the task we sent it for. Each provider handles data under its own terms; if you need the current list for a data-protection assessment of your own, ask at contact@itmaster.uk.
5. Every service we use, and what it sees
These are the third parties involved in running IT Master. Several never touch personal data at all, and the table says so rather than leaving you to guess.
| Service | What we use it for | What it sees |
|---|---|---|
| Anthropic | Writes articles (Haiku, Sonnet, Opus and Fable models by tier) and sits on the E-E-A-T and AI-tell panels. | Research dossiers, briefs, drafts and your connected-site content. |
| Google (Gemini) | Adversarial fact-check, novelty scoring, the large-context research read, the AI-tell panel, embeddings for retrieval, and image rendering. | Research dossiers, drafts, product and datasheet text, images. |
| OpenAI | Panelist on the fact-check and E-E-A-T checks; writes the prompts our image models render. | Drafts, claims under check, image briefs. |
| Perplexity | Web-grounded cross-check of factual claims on the tiers that include it. | Individual claims and search queries. |
| Voyage AI | Re-ranks passages retrieved from your own corpus before they reach a writer. | Retrieved passages and the query. |
| DataForSEO | Keyword volumes, difficulty, SERP results and People Also Ask data. | Keywords, domains and locations. No customer content. |
| Firecrawl | Reads the public competitor pages a topic has to beat. | Public URLs. No customer content. |
| Exa | Semantic search for angles competitors missed. | Search queries. No customer content. |
| Apify | Collects public forum and community discussion for research. | Search queries. No customer content. |
| Google Search Console | Reads your site's search performance and index status; submits URLs for indexing. | Your site's data, via an OAuth token you grant. |
| Google Analytics | Reads your site's traffic so we can measure what published content did. | Your site's data, via an OAuth token you grant. |
| Bing Webmaster Tools and Microsoft Ads | Search performance and keyword data for Bing. | Your site's data, via an OAuth token you grant. |
| IndexNow | Tells participating search engines a URL has changed. | Published URLs only. |
| Companies House and Police.uk | Free UK public-data APIs used as research signals. | Public lookups. No customer or personal data is sent. |
| Worldpay | Processes card payments for top-ups. | Your card details (entered directly into their component), cardholder name, email and amount. |
| Resend | Sends service email — top-up receipts, low balance warnings, publishing alerts, notices about these documents. | Your name, email address and the message. |
| Cloudflare | DNS, CDN and protection in front of our sites. | IP address and request metadata for traffic to itmaster.uk. |
| Sentry | Error monitoring, so a broken page reaches us before it reaches you. | The URL, browser and technical diagnostics of an error. |
We add or replace a provider when the pipeline changes — a better checker, a cheaper renderer, a model retired by its vendor. When that happens we update this table and its last-updated date.
6. How long we keep it
- Account details — while your account is open, and deleted within 30 days of you asking us to close it, except where a record below has to be kept.
- Billing and payment records — six years from the end of the accounting period, because UK tax law requires it.
- Connected-site content and generated articles — while the site is connected. Articles already published to your own site are yours and stay there; deleting your account here does not delete them from your website.
- OAuth tokens — until you disconnect that integration or close the account, then deleted.
- Support correspondence — up to two years, so we can pick up a thread you started last year.
- Server logs and error reports — short-lived operational data, kept in the order of weeks rather than years, and not used to profile anyone.
7. Where your data goes
We are in the United Kingdom, and so is our infrastructure. Several of the providers in the table above are in the United States or process data there — the AI providers in particular.
Those transfers rely on the UK’s approved safeguards: an adequacy decision where one covers the provider, and otherwise the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, in each provider’s data-processing terms.
8. How it is protected
- Traffic is encrypted in transit.
- Passwords are stored as one-way hashes; nobody at IT Master can read yours.
- Site credentials, payment credentials and OAuth tokens are encrypted at rest.
- Keys are per site, so one customer’s credentials cannot reach another customer’s content or corpus.
- Sessions are HTTP-only cookies re-checked against the database on every request, so disabling an account ends its sessions immediately.
- Access to production data is limited to the people who need it to run the service.
No system is perfect. If a breach happens that is likely to risk your rights and freedoms, we will tell the Information Commissioner’s Office within 72 hours where required, and tell you without undue delay.
9. Your rights
Under UK data protection law you have the right to:
- Be informed — this notice.
- Access a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have data deleted where we have no overriding reason or legal duty to keep it.
- Restrict processing while a dispute about accuracy or basis is resolved.
- Data portability — receive the data you gave us in a common machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent where consent is the basis, without affecting what happened before.
- Not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. As above, the engine’s automated decisions are about content, not people.
To exercise any of these, email contact@itmaster.uk from the address on your account, or write to us and we will verify your identity another way. We reply within one month, and will say so if a complex request needs longer. There is no charge.
If you are unhappy with how we handled it, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you told us first, but you do not have to.
10. Children, and changes to this notice
IT Master is a business service and is not intended for anyone under 18. We do not knowingly collect personal data from children.
We update this notice when what we do changes — a new provider in the table, a new kind of data, a different retention period. The version here is always the current one, and its date is at the top. If a change materially affects you we email account holders before it takes effect.
The terms of service and the refunds policy sit alongside this notice.