Privacy Policy
Last updated: 6 October 2026
1. Who we are
Argumento Vigoroso LDA ("we", "us", "our"), trading as Aureus Virtus, operates the Aureus Virtus SEO platform (the "Platform"), available at https://aureusvirtus.com and https://app.aureusvirtus.com.
For personal data relating to our customers' end users and website visitors, we act as a data processor on behalf of our customers, who are the data controllers. For personal data relating to our own account holders and website visitors, we act as a data controller.
Controller entity: Argumento Vigoroso LDA
Registered in: Portugal
Registered address: Rua Odette de Saint-Maurice, 3L (-1), Esc. C, 1700-921 Lisboa, Portugal
Data protection contact: contact@aureusvirtus.com
EU representative: Not applicable (we are established in the EU)
2. Scope
This policy covers the Platform, its API, and https://aureusvirtus.com. It does not cover third-party websites we link to, or the third-party services our customers choose to connect.
3. Information we collect
3.1 Account information
Provided when an account is created or a user is invited: name and email address; encrypted password credentials; assigned role and organisation membership; two-factor authentication settings, where enabled.
3.2 Usage and security information
Collected automatically as the Platform is used: last login time and IP address; failed login attempt counts and account lockout state; session and device records for active sign-ins; audit records of significant actions taken in the Platform; records of calls made to third-party data providers on a customer's behalf.
3.3 Project and website information
Provided or configured by customers: website domains and project configuration; tracked keywords, target regions and languages; competitor domains selected for comparison.
3.4 Information generated by the Platform
Website crawl results, including page content, headings, metadata and technical issues found on the customer's own website; search ranking positions and history; backlink and referring-domain records; brand mention and sentiment records; reports generated by customers; conversations with the in-platform SEO assistant.
3.5 Information received from Google
Covered separately in section 4.
4. Google user data
4.1 What we access, and why
When a customer connects a Google account to a project, we request these permissions:
| Permission | What it allows | Why we need it |
|---|---|---|
| analytics.readonly | Read-only access to Google Analytics | To display website traffic, sessions, pageviews and conversions on the customer's dashboard |
| webmasters.readonly | Read-only access to Search Console | To display search impressions, clicks, click-through rate, average position, top queries and landing pages |
| openid, email, profile | Basic account identification | To show which Google account is connected, so the customer can confirm the right one is linked |
Both data permissions are read-only. The Platform cannot create, modify or delete anything in a connected Google Analytics property or Search Console account.
4.2 What we store
The email address of the connected Google account, so the customer can see which account is linked; Google access and refresh tokens, encrypted at rest; the list of Analytics properties and Search Console sites available to that account, and which one the customer selected as primary; daily snapshots of the reporting data described above, retained so that historical trends can be charted without repeatedly re-querying Google.
4.3 How we use it
Solely to provide the Platform's analytics features to the customer who connected the account: dashboards, charts, health scoring, generated reports, and grounding the in-platform SEO assistant's answers in that customer's own figures.
We do not sell Google user data, use it for advertising, use it to build profiles for advertising purposes, or use it to develop, improve or train generalised artificial intelligence or machine learning models.
4.4 Limited Use disclosure
Argumento Vigoroso LDA's (trading as Aureus Virtus) use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
4.5 Transfer to our AI provider
Where a customer uses the in-platform SEO assistant, a small set of aggregate figures derived from Google data — total sessions, clicks, impressions, click-through rate and average search position — is included in the context sent to OpenAI so that the assistant's answers reflect that customer's actual performance. Individual Search Console queries, landing page URLs and Google account credentials are not included.
OpenAI does not use data submitted through its API to train its models. This transfer is made solely to provide the requested feature to the customer, and never to develop or improve any generalised AI or ML model.
4.6 Disconnecting
A customer can disconnect a Google account from a project at any time in the Platform. Disconnecting deletes the stored tokens immediately, and the Platform stops requesting any further data from Google.
Previously retrieved reporting snapshots are retained as part of the project's historical record. To remove those as well, delete the project, or contact us at contact@aureusvirtus.com to request erasure.
Disconnecting within the Platform does not automatically remove the authorisation from your Google Account's permissions list. You can revoke it directly at https://myaccount.google.com/permissions.
5. Legal bases for processing (EU)
| Purpose | Legal basis |
|---|---|
| Providing the Platform under a contract | Performance of a contract |
| Account security, fraud prevention, audit logging | Legitimate interests |
| Service and security notification emails | Legitimate interests / performance of a contract |
| Marketing communications, where sent | Consent |
| Retaining records required by law | Legal obligation |
Where we act as a processor for a customer, that customer is responsible for establishing the legal basis for the data they upload or connect.
6. Sharing and sub-processors
We do not sell personal data. We share data only with the service providers below, only to the extent needed to operate the Platform:
| Provider | Purpose | Data involved |
|---|---|---|
| Namecheap | Application and database hosting | All Platform data |
| Google (Analytics, Search Console, Safe Browsing APIs) | Analytics retrieval; URL threat checks | Connected account data; URLs checked |
| OpenAI | In-platform SEO assistant and semantic search | Assistant conversations; aggregate project metrics (see 4.5) |
| DataForSEO | Keyword research, search volume, SERP and competitor data | Keywords and domains queried |
| Topvisor | Search ranking position tracking | Keywords, domains and target regions |
| WhoisXML | Domain ownership lookups for link-network analysis | Domains queried |
| IPinfo | IP address lookups for the phishing-detection module | IP addresses checked |
| Resend | Transactional email (verification, password reset, invitations) | Name and email address |
We may also disclose information where required by law, or to establish, exercise or defend legal claims.
7. International transfers
Platform data is hosted in the European Union. Several providers listed above operate outside the EEA, including in the United States. Where personal data is transferred outside the EEA, we rely on the EU Standard Contractual Clauses and, for providers certified under it, the EU–US Data Privacy Framework.
8. Retention
| Data | Retention |
|---|---|
| Account records | For the life of the account, then 30 days after closure |
| Google access and refresh tokens | Until the account is disconnected or the project is deleted |
| Analytics snapshots, crawl results, ranking history | For the life of the project; deleted when the project is deleted |
| Audit and security logs | 12 months |
| Assistant conversations | For the life of the account, unless deleted earlier by the user |
| Backups | 30 days |
Deleting a project removes its associated analytics, crawl, ranking and report records. Deleting an account removes the account record; contact us for erasure of any remaining associated data.
9. Security
Passwords are stored hashed, never in plain text. Google tokens are encrypted at rest. Optional two-factor authentication on user accounts. Automatic account lockout after repeated failed sign-in attempts. Role-based access control, with data separated per customer organisation. Audit logging of significant actions. Encryption in transit (HTTPS/TLS).
No system can be guaranteed completely secure. We maintain procedures for detecting and responding to personal data breaches, and will notify affected individuals and regulators where required by law.
10. Your rights
Under EU data protection law you may request access to, correction of, erasure of, or a portable copy of your personal data; object to or request restriction of processing; and withdraw consent where processing relies on it.
To exercise any of these, contact contact@aureusvirtus.com. We will respond within one month.
If your data was provided to us by one of our customers, please contact that customer directly — we will refer such requests to them and assist as required.
You may also complain to your supervisory authority. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD, https://www.cnpd.pt).
11. Cookies
The website at aureusvirtus.com uses no analytics or marketing cookies. The Platform uses only cookies strictly necessary for authentication and session security. No cookie consent banner is required for either.
12. Children
The Platform is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.
13. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be notified to account holders by email.
14. Contact
Argumento Vigoroso LDA, trading as Aureus Virtus
Argumento Vigoroso LDA
Rua Odette de Saint-Maurice, 3L (-1), Esc. C, 1700-921 Lisboa, Portugal
contact@aureusvirtus.com