Nalza reads your website, your search data and the connected accounts you approve, then drafts changes you review. This page says exactly what that means for your data.
Last updated 25 August 2026.
Nalza is an SEO and AI-search platform operated from Mississauga, Canada. In this policy "we" means Nalza and "you" means the account holder. Reach us through the contact page for anything on this page, including deletion requests.
We use it to score your site, track your rankings and AI citations, draft fixes, and — only where you approve each change — apply those fixes to your site or your Google Business Profile. We do not sell your data, and we do not use your data to train AI models.
We use these processors, each for one job:
Nalza's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read access to Search Console and Analytics so we can show your own performance, and access to your Business Profile so we can show it and — only on your explicit, per-field approval — publish wording you have reviewed. We do not transfer this data to anyone except as described above, do not use it for advertising, and do not allow humans to read it except where you ask us for support, where the law requires it, or for security investigations.
Nothing is published without you approving it. The connector collects only the changes you have approved, applies them, and reports back what actually landed. It refuses a change if the page moved since you reviewed it. You can disconnect your site at any time, which revokes the token at both ends.
We keep your data while your account is open, because the product's value is the history — score trends, ranking movement and what changed when. Ask us and we will delete your account and its data; disconnecting a Google account removes its tokens immediately. Encrypted backups are kept off-site and roll off on their own schedule, so deleted data can persist in a backup for a short period after removal.
Traffic is encrypted in transit. Connection tokens are stored hashed. Access to production is limited to the people who operate the service. No system is perfect, and we would rather say that plainly than promise otherwise.
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Depending on where you live you may have additional rights under laws such as PIPEDA, the GDPR or the CCPA. Ask through the contact page and we will act on it.
If we change how we handle your data we will update this page and its date. If the change is material we will tell you in the app rather than hoping you re-read this page.