exeral exeral
  • About
  • Services
  • Work
  • Pricing
  • Contact
Sign in Book a call
  • About
  • Services
  • Work
  • Pricing
  • Contact
  • Sign in
  • Book a call →

Legal

Privacy Policy

Last updated June 26, 2026

Sero LLC d/b/a exeral


1. Introduction and Scope

This Privacy Policy ("Policy") explains how Sero LLC, a Florida limited liability company, doing business as "exeral" ("exeral," "we," "us," or "our") collects, uses, discloses, and protects personal information. exeral is a digital agency that builds and maintains websites and provides local search engine optimization ("SEO"), answer engine optimization ("AEO"), Google Business Profile management, reporting, review management, content, and related services for local service businesses.

This Policy applies to:

  • Website visitors — people who visit our public marketing website at exeral.io and related pages;
  • Prospects and leads — people and businesses who inquire about our services, submit our discovery form, book a discovery call, or whom we contact through our cold-outreach lead program (see Section 9);
  • Clients and their authorized representatives — businesses that engage us and the individuals who administer their accounts, use our client portal, or participate in onboarding; and
  • Clients' end users (limited) — individuals who interact with websites or systems we build and operate for our clients, where we act only as a service provider/processor.

Our role — controller vs. processor. For the personal information we collect about our own website visitors, prospects, leads, and clients, exeral acts as the controller/business (we decide why and how it is processed), and this Policy governs that processing. When we host, maintain, or operate a website, analytics property, Google account, review channel, or messaging program on behalf of a client, the personal information of that client's customers and end users is processed by us as a service provider/processor under the client's instructions. In that capacity, the client is the controller, this Policy does not govern that data, and individuals should direct privacy requests to the relevant client.

Data Processing Addendum. Our processing of personal information on behalf of a client is governed by a written Data Processing Addendum (or equivalent terms in our Master Services Agreement) that incorporates the service-provider/processor terms required by applicable law — including that we process such data only on the client's documented instructions; that we do not sell or "share" it, retain, use, or disclose it outside the direct business relationship, or combine it with other data except as permitted by law; that we delete or return it at the end of the engagement; and that equivalent obligations flow down to any subprocessors we engage.

This Policy does not apply to third-party websites, products, or services that we do not control, even if they are linked from our site or integrated with our services.


2. Categories of Personal Information We Collect

The categories below are organized to map to the categories of "personal information" defined under the California Consumer Privacy Act, as amended ("CCPA/CPRA"). Not every category is collected from every person; what we collect depends on how you interact with us.

# Category (CCPA mapping) Examples of what we collect
A Identifiers Name, business name, email address, telephone number, mailing/business address, website URL, account login identifiers, IP address, and similar identifiers.
B Customer records / contact and financial info (Cal. Civ. Code § 1798.80) Billing contact details and payment-related information processed through our payment processor. We do not store full payment card numbers (see Section 8).
C Commercial information Services purchased or considered, proposals, orders, billing history, budget range, timelines, and service preferences.
D Internet or other electronic network activity Browsing and usage data, pages viewed, referring/exit pages, clicks, device and browser type, operating system, and cookie/SDK identifiers (see our Cookie Policy, Section 11).
E Geolocation data (coarse) Approximate, city/region-level location inferred from IP address and your stated service area. We do not collect precise GPS geolocation.
F Audio / electronic information — voice recordings and transcripts Audio recordings and machine-generated transcripts of the optional AI voice onboarding interview, where you have consented to recording (see Section 4 and Section 6).
G Professional or employment-related information Your role/title at your business, business type and description, and professional details you provide during intake.
H Uploaded files and content Logos, photos, brand assets, documents, copy, and other materials you upload to us (e.g., during onboarding or through the client portal).
I Communications The contents of emails, messages, form submissions, support requests, portal messages, and notes from calls and meetings.
J Inferences Inferences we draw to provide and improve services (e.g., service-fit, lead-scoring signals for prospects, and reporting insights).

Sensitive personal information. We do not intentionally collect "sensitive personal information" as that term is defined under the CCPA/CPRA or "sensitive data" as defined under the Florida Digital Bill of Rights (e.g., government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, health, sexual orientation, immigration status, or genetic/biometric data). Please do not submit such information to us.

The audio recordings and transcripts described in Category F are collected only with your consent and are used solely for the onboarding purpose described in this Policy. We do not use voice recordings to generate a voiceprint or any other biometric identifier, and we do not use them to identify or authenticate any individual. We do not sell or "share" voice recordings or transcripts (see Sections 6 and 8).


3. Sources of Personal Information

We obtain personal information from the following sources:

  1. Directly from you — when you submit our discovery form (which may capture a partial contact record from information you have already entered, even if you do not complete and submit the form; a notice of collection is provided on the form itself), book a discovery call, communicate with us, participate in onboarding (web form or AI voice interview), upload files, or use the client portal.
  2. Automatically — through cookies, pixels, server logs, and similar technologies when you use our website (see Sections 11 and 17).
  3. From your use of our services — including, for clients who authorize it, data accessed through your connected Google properties (Google Analytics, Google Search Console, and Google Business Profile) and your publicly visible online reviews, used to deliver monitoring, optimization, and reporting (see Sections 7 and 8).
  4. From third-party data sources (business prospects only). For our cold-outreach lead program, we collect publicly available business contact information about prospective business customers — and signals about those businesses — from sources such as Google Places/Maps, online business listings, public business registries, county permit records, the U.S. Census, WHOIS records, search-engine results, and reputable third-party data vendors. This information may include a business name, business owner or contact name, business email and phone number, business address, ratings, and technology/marketing signals about the business's website. We collect this without the prospect's prior consent, as permitted by applicable law, and use it only for our own direct outreach (see Section 9). We do not knowingly collect data from sources that require us to circumvent logins, authentication, or technical access controls.

4. How We Use Personal Information

We use personal information for the following business purposes:

  • Provide and operate our services — build, host, maintain, and update client websites; deliver SEO, AEO, Google Business Profile management, content, review management and generation, citation/NAP monitoring, and reporting; provision and operate client accounts and the client portal; and process onboarding (web form and, where consented, the recorded AI voice interview).
  • Communicate with you — respond to inquiries, schedule and conduct discovery calls (including over video conferencing), send transactional and account messages, and provide support.
  • Billing and payments — process payments, manage subscriptions and invoices, and collect amounts owed.
  • Marketing and outreach — send our own marketing communications (subject to your choices and applicable law), and operate our cold-outreach lead program (see Section 9).
  • Reviews and reputation — monitor reviews; draft and, with the client's authorization, respond to reviews on the client's behalf; and solicit reviews from a client's customers via email and/or SMS where the client directs and where lawful consent and disclosures are in place (the client being responsible for obtaining that consent, see Section 10).
  • Improve and develop — analyze usage to maintain, secure, debug, and improve our website, services, and internal tools, including our AI-assisted production methods.
  • Safety, security, and legal — detect, prevent, and respond to fraud, abuse, security incidents, and unlawful activity; enforce our terms; establish, exercise, or defend legal claims; and comply with legal obligations.

AI-assisted processing. We use artificial intelligence and large language models extensively to draft website copy and content, generate consultation questions, prepare SEO/AEO drafts, conduct the AI voice onboarding interview, and assist our internal operations. AI output can contain errors and is reviewed by humans before use. AI-generated content may not be eligible for copyright protection and may not be exclusive. See Section 6.

We do not use personal information to make decisions that produce legal or similarly significant effects about you without meaningful human involvement.


5. Legal Bases (Forward-Looking)

Our services are directed to businesses and individuals in the United States. We process personal information where we have a legitimate business need, to perform a contract or take steps at your request, to comply with legal obligations, or with your consent where required (for example, the recorded AI voice interview and SMS marketing). To the extent any future state or international privacy framework requires us to identify legal bases for processing, we will update this Policy accordingly.


6. AI-Generated Content, Voice Recording, and Accuracy

AI-assisted content. Portions of the deliverables and communications we produce are generated with the assistance of AI tools. Under current U.S. Copyright Office guidance, purely AI-generated material may not be eligible for copyright protection, and we do not and cannot warrant that AI-assisted output is original, exclusive, or protectable. Clients are responsible for reviewing and approving all deliverables — including for factual accuracy and legal, regulatory, professional-licensing, medical, financial, and advertising compliance — before publication or use. AI-assisted content may contain errors, inaccuracies, or outdated information, and is provided without warranty of accuracy to the fullest extent permitted by law.

AI voice onboarding and recording consent. Our onboarding intake is offered in two modes: (a) a web form, and (b) an optional AI voice agent that conducts a spoken onboarding interview. The voice interview is recorded and transcribed by automated tools. Because Florida is an all-party consent state for the recording of private communications (Fla. Stat. § 934.03), the AI agent will disclose at the start of the call that the conversation is being conducted by an automated AI assistant and is being recorded and transcribed, and will ask for your affirmative consent. We record only if you affirmatively consent; if you decline, the interview will not be recorded (and you may use the web-form intake instead). If more than one person is on the call, consent is required from every participant. We use the recordings and transcripts only to complete onboarding and deliver our services, we do not sell or "share" them and do not use them to create any biometric identifier, and we retain them as described in Section 12.


7. Google API Limited Use Disclosure

For clients who authorize it, exeral accesses certain Google account data — Google Analytics, Google Search Console, and Google Business Profile — through Google's OAuth authorization, using the narrowest scopes (read-only where feasible) needed to deliver monitoring, optimization, and reporting.

exeral's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, this means:

  • We use Google user data only to provide and improve the user-facing reporting and optimization features for which you granted access;
  • We do not transfer, sell, or use Google user data to serve advertising (including personalized, retargeting, or interest-based advertising);
  • We do not use Google user data for credit, lending, or eligibility decisions;
  • We do not allow humans to read Google user data except (i) with your affirmative consent, (ii) for security, abuse prevention, or legal compliance, or (iii) where the data has been aggregated and anonymized for internal operations; and
  • We retain and delete Google user data as described in this Policy and our agreement with you, and you may revoke our access at any time through your Google account security settings.

8. Disclosures of Personal Information, Service Providers, and Data Sources

We distinguish between (a) service providers / processors that process personal information on our behalf under contract, and (b) data sources from which we obtain business-prospect information that those sources collected for their own purposes. We may also disclose information to professional advisors, to comply with law or legal process, to protect rights and safety, and in connection with a merger, acquisition, financing, or sale of assets (with appropriate safeguards).

8.1 Service Providers / Processors (process on our behalf)

We disclose personal information to service providers and processors that perform functions on our behalf under contracts that limit their use of the data to performing those functions and that prohibit them from using the data for their own purposes. These providers fall into the following categories:

  • Hosting, storage, database, and authentication providers — for website and application hosting, file/blob storage (including uploaded onboarding files), database services, and client-portal user authentication.
  • Customer-relationship and scheduling providers — for managing inquiries, contacts, and call scheduling.
  • Payment processor — for processing payments and managing subscriptions and invoices. Our payment processor is PCI-DSS compliant and handles card data; exeral never stores full payment card numbers.
  • Communications providers — for transactional and marketing email, SMS messaging (subject to the consent and disclosures in Sections 9 and 10), AI voice onboarding, and speech-to-text transcription.
  • AI / large language model providers — to generate and assist with copy, content, consultation questions, and drafts.
  • Google services — OAuth, Analytics, Search Console, Business Profile, Places, PageSpeed, Maps, and video meetings, handled in accordance with Section 7.
  • Analytics and cookie providers — as described in Section 11 and our Cookie Policy.

A current list of the specific subprocessors we use is available on request at privacy@exeral.io. This list may change as our vendors change.

8.2 Data Sources (from which we obtain prospect business data)

For our cold-outreach lead program (Section 9), we obtain publicly available business information from third-party data sources and data vendors. These sources collect and maintain that information for their own purposes and are not acting as our service providers when they do so; we obtain or license business records and signals from them for our own outreach use. We do not authorize, and do not rely on these sources to perform, processing on our behalf.

8.3 No Sale or Sharing

We do not sell or "share" personal information, as the terms "sell" and "share" are defined under the CCPA/CPRA (which include disclosures for monetary or other valuable consideration and disclosures for cross-context behavioral advertising). We do not engage in cross-context behavioral advertising. Because we do not "sell" or "share," no opt-out of sale/sharing is required for our current practices; however, if our practices change, we will update this Policy and provide the required opt-out mechanism, including honoring browser opt-out preference signals such as Global Privacy Control (see Section 17).


9. Cold-Prospect Notice (Lead Program)

We operate (or plan to operate) an internal program that identifies prospective business customers and sends them commercial email offering a free website audit. For this program:

  • We collect publicly available business contact information and business signals from the sources described in Sections 3(4) and 8.2, without the prospect's prior consent, as permitted by applicable law.
  • We use this information solely for our own direct outreach and related lead management. We do not sell, license, or otherwise make prospect data available to any third party. Because we use this data only for our own direct outreach and do not sell it, we do not operate as a "data broker" under the California Delete Act (Cal. Civ. Code §§ 1798.99.80 et seq.) or analogous state data-broker laws; if that ever changes, we will register and comply as required.
  • Our outreach is email only. We do not send cold SMS or place cold autodialed calls to prospects.
  • Every commercial email complies with the CAN-SPAM Act and the Florida Electronic Mail Communications Act (Fla. Stat. §§ 668.60–668.610): accurate sender, header, and routing information; a non-deceptive subject line that accurately describes the message; identification as a commercial/advertisement message where applicable; a valid physical postal address; and a working unsubscribe mechanism that we honor within ten (10) business days.
  • We maintain a permanent suppression / do-not-contact list and an opt-out flag, and we will not re-add suppressed contacts from new data feeds.

Your choices as a business contact. If you received an email from us and do not wish to be contacted, you may use the unsubscribe link in the message, or contact us at privacy@exeral.io to be removed from our outreach, suppressed from future contact, and/or have your information deleted, subject to our limited legal-retention needs. We will also process verifiable privacy requests as described in Section 13 regardless of the state in which you reside.


10. Marketing Email and SMS

Email. We send marketing email consistent with the CAN-SPAM Act and the Florida Electronic Mail Communications Act (Fla. Stat. §§ 668.60–668.610), including non-deceptive subject lines and accurate header and routing information. Every commercial email includes a clear unsubscribe mechanism and our valid physical postal address. You may opt out at any time; we honor opt-outs within ten (10) business days.

SMS (text messages). Where we offer SMS — including account or marketing texts, or review-request messages we may send on behalf of a client — we and/or the client (as applicable) obtain the consent required by the Telephone Consumer Protection Act ("TCPA") and the Florida Telephone Solicitation Act, and we comply with carrier (A2P 10DLC) requirements. Consent to receive marketing texts is not a condition of any purchase. The specific consent disclosures, program description, STOP/HELP instructions, message-frequency and rate notice, and links to the applicable Privacy Policy and Terms are presented at the point of opt-in; this Policy does not itself supply the legal basis for any SMS program.

Messages sent on a client's behalf. When SMS or email is sent to a client's customers, the client is the controller and is solely responsible for obtaining the prior express written consent and providing the disclosures required by the TCPA, the Florida Telephone Solicitation Act, CAN-SPAM, and other applicable law. In those sends, exeral acts only as a service provider/processor and relies on the client's representations and consent records.

For any messages, message and data rates may apply, message frequency varies, and you may opt out at any time by replying STOP (and reply HELP for help). Mobile opt-in data is not shared or sold to third parties for their own marketing.


11. Cookies and Tracking Technologies

Our website uses cookies and similar technologies for functionality, analytics, and performance measurement. For details about the cookies we use and your choices, please see our Cookie Policy https://exeral.io/cookies. We do not use cookies to engage in cross-context behavioral advertising. See Section 17 regarding Do-Not-Track and Global Privacy Control signals.


12. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including to provide our services, maintain accounts, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and context. As general guidance:

  • Client account and deliverable data — retained for the duration of the engagement and for a reasonable period afterward, or as set in our agreement, after which it may be returned, deleted, or anonymized.
  • Voice recordings and transcripts — retained only as long as needed to complete onboarding and support the engagement, and in any event deleted or anonymized within the duration of your engagement plus twelve (12) months, unless you ask us to delete it sooner days after onboarding is complete, except where a longer period is required to resolve a dispute or comply with law.
  • Uploaded files and assets — retained for the engagement and a reasonable wind-down period.
  • Prospect/lead data (cold program) — retained while a prospect is active in outreach and for a limited period thereafter, then deleted or anonymized; suppression-list entries are retained as needed to honor opt-outs.
  • Billing records — retained as required for tax, accounting, and legal purposes.

We may retain de-identified or aggregated information indefinitely. Where we delete data on request, certain copies may persist in backups for a limited time and as required for legal-hold, security, transaction-completion, or other lawful purposes.


13. Your Privacy Rights

The rights available to you depend on where you live and on whether applicable law currently applies to exeral. We describe the principal frameworks below and, as a matter of practice, will consider and respond to verifiable requests from individuals in any U.S. state.

13.1 Florida (Florida Digital Bill of Rights)

The substantive controller obligations of the Florida Digital Bill of Rights (Fla. Stat. §§ 501.701–501.722) apply only to entities meeting a large-revenue threshold (generally more than $1 billion in global gross annual revenue plus an additional trigger). exeral does not currently meet that threshold, so those consumer-rights obligations do not currently apply to us. Regardless of threshold, exeral affirmatively states that it does not sell sensitive personal data or biometric personal data and does not engage in targeted/cross-context behavioral advertising. If our status or practices change, we will update this Policy and provide any required notices and rights.

13.2 California (CCPA/CPRA)

If you are a California resident and the CCPA/CPRA applies, you have the right to:

  • Know/Access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
  • Delete personal information we collected from you, subject to legal exceptions;
  • Correct inaccurate personal information;
  • Opt out of sale/sharing — note that, as stated in Section 8, we do not sell or share personal information;
  • Limit the use of sensitive personal information — note that we do not collect sensitive personal information for any purpose requiring this option;
  • Data portability — receive a copy of certain information in a portable format;
  • Non-discrimination — we will not discriminate against you for exercising your rights; and
  • Use an authorized agent and, where a request is denied, to appeal that decision (see Sections 13.4–13.5).

13.3 Other U.S. States

Residents of other states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others as they take effect) may have rights to access, correct, delete, obtain a portable copy, opt out of the sale of personal data, opt out of targeted advertising, opt out of certain profiling, and to appeal a denied request. exeral may not currently meet the applicability thresholds of all such laws, but we will honor verifiable requests to the extent these laws apply to us and will otherwise consider such requests as a matter of practice.

13.4 How to Exercise Your Rights

To exercise any right, contact us at privacy@exeral.io or at the mailing address in Section 21. Please tell us which right you wish to exercise and provide enough information for us to locate your data and verify your request.

Verification. To protect your privacy, we will take reasonable steps to verify your identity before fulfilling a request, which may include matching information you provide against information we hold. We will not use information collected for verification for any other purpose. An authorized agent may submit a request on your behalf with proof of authorization and, where required, verification of your identity.

Response timeline. We will acknowledge and respond to verifiable requests within the timeframe required by applicable law (generally within 45 days, extendable by an additional 45 days where reasonably necessary, with notice to you). There is no fee for most requests unless they are excessive, repetitive, or manifestly unfounded.

13.5 Appeals

Where an applicable state privacy law provides for it — and otherwise as a matter of practice — you may appeal a decision declining to act on your request by contacting us at privacy@exeral.io with the subject line "Privacy Appeal." We will respond within the period required by applicable law and explain our decision. If your appeal is denied and the privacy law applicable to you provides an escalation avenue, you may contact the relevant regulator for your state (for example, California residents may contact the California Privacy Protection Agency or the California Attorney General).

13.6 Monitoring of Thresholds

Because our business is new and growing, we periodically reassess whether changes in our scale or practices bring us within the substantive obligations of privacy laws that currently may not apply to us — including, for example, crossing the CCPA/CPRA applicability thresholds (such as buying, selling, or sharing the personal information of 100,000 or more California consumers or households), beginning to sell prospect data (the California Delete Act and analogous data-broker laws), or processing Florida sensitive or biometric data for sale (Fla. Stat. § 501.715). If we cross an applicable threshold, we will update this Policy and implement the required notices, rights, and registrations.


14. Children's Privacy

Our website and services are intended for businesses and are not directed to anyone under 18, and we do not knowingly collect personal information from minors. Under Florida law, the personal information of consumers known to be under 18 is treated as sensitive, and we do not seek to collect it. If you believe a minor has provided us personal information, please contact us at privacy@exeral.io and we will take reasonable steps to delete it.


15. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (HTTPS/TLS), access controls and authentication for our systems and client portal, and engagement of reputable infrastructure and security vendors. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.


16. Accessibility

If you have difficulty accessing our website or need assistance, please contact us at contact@exeral.io and we will make reasonable efforts to assist. (The accessibility standard of care and related disclaimers for websites we build for clients are addressed in our Master Services Agreement, not in this Policy.)


17. Do-Not-Track and Global Privacy Control

Some browsers offer a "Do Not Track" ("DNT") signal. Because there is no common industry standard for DNT, our website does not currently respond to DNT signals. To the extent we are required to treat an opt-out preference signal such as Global Privacy Control (GPC) as a valid request to opt out of sale/sharing, we will honor it; as noted in Section 8, we do not currently sell or share personal information, so such a signal currently has no sale/sharing activity to act upon.


18. International Visitors

exeral is based in the United States, and our website and services are intended for users in the United States. We do not currently offer services to, or target, individuals in the European Union, the United Kingdom, or other jurisdictions outside the United States, and we do not undertake to comply with the EU/UK GDPR at this time. If you access our website from outside the United States, you do so on your own initiative, and your information will be processed in the United States, where data-protection laws may differ from those of your jurisdiction.


19. No Guarantee of Results

Nothing in this Policy or on our website is a promise of specific outcomes. exeral does not guarantee any particular search rankings, traffic, leads, call volume, conversions, or revenue. Search engines and AI answer engines are controlled by third parties and are outside our control. Our reports reflect only metrics we actually measured; we do not fabricate results. Marketing statements are aspirational and are not warranties.


20. Changes to This Policy

We may update this Policy from time to time. When we do, we will post the updated Policy and revise the "Last updated" date above. For material changes — particularly any change to whether we sell or "share" personal information or any new use of sensitive personal information — we will provide additional notice as required by applicable law before the change takes effect.


21. Contact Us

If you have questions about this Policy or our privacy practices, or wish to exercise your rights, contact us:

Sero LLC d/b/a exeral Attn: Privacy Email: privacy@exeral.io Mailing address: Boca Raton, Florida — full mailing address available on request at privacy@exeral.io General/legal contact: legal@exeral.io Support: contact@exeral.io Phone: contact@exeral.io Website: exeral.io


exeral exeral

Conversion-led websites and marketing for local businesses that want to be found — on Google and AI search — trusted, and hired.

Company
  • About
  • Selected work
  • Contact
Services
  • Web design
  • SEO
  • Google Business
  • Pricing
Reach us
  • contact@exeral.io
  • Book a discovery call
Legal
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • AI & messaging disclosures
© 2026 Sero LLC d/b/a exeral Remote · Built for local businesses