Privacy Policy | Semantec SEO and MIRENA
Privacy · Semantec SEO and MIRENA

Privacy at Semantec SEO: what is collected, who processes it, and what you can do.

This Privacy Policy covers personal data handled by Semantec SEO when you browse the website, contact support, access an account, pay for MIRENA, or make a privacy request. It also explains that the public MIRENA product runs in ChatGPT, where OpenAI’s separate terms, privacy notice, retention rules, and data controls apply.

Semantec SEO should only describe data it actually receives or controls. Any provider, retention, transfer, cookie, action, or API detail that has not been checked remains blocked for publication.

  • Dedicated privacy contact
  • ChatGPT platform split made clear
  • Payment details separated from account access
  • Final legal approval still required

Privacy Path Finder

Choose what you are doing to see the data path that applies.

Working tool
Current path 1 of 7

Website and device data

Data

Purpose

Lawful basis or role

Provider or platform

What you can do

Read the detailed part

1 · Scope and controller

Start with the organisation and the processing it controls.

This policy applies to the Semantec SEO website, direct account and access records, billing information received by Semantec SEO, support and privacy communications, and other personal data for which Semantec SEO decides the purpose and means.

What this policy does not replace

Some services process personal data under their own terms and notices. This includes ChatGPT/OpenAI for the ChatGPT platform and Stripe for parts of payment processing. Authflow.ai also supports access and paywall activity.

Semantec SEO must still explain the data it receives from those services, the roles each party holds, the purpose, the basis, the retention rule, and any international transfer.

The current provider and data-flow register remains a publication gate.

2 · Processing matrix

Personal data should be tied to a purpose, basis, recipient, and retention rule.

The table below converts the current policy into activity-level records. Items marked for confirmation must be checked against the live website, provider contracts, account flow, payment flow, GPT configuration, and internal records before publication.

Interaction Personal data Purpose Basis or role Recipients or platforms Retention
Browse the Semantec SEO website IP address; browser and device type; operating system; pages viewed; referring URL; timestamps; session or interaction data; diagnostic and security logs; cookie or similar-technology identifiers Deliver the website; maintain security; diagnose faults; measure performance; remember permitted preferences; understand site use Legitimate interests for essential operation, security, diagnostics, and service administration; consent for non-essential cookies or analytics where required Hosting and infrastructure provider; analytics or diagnostics provider; consent-management provider Confirm session-log, security-log, analytics, and cookie retention periods before publication
Contact Semantec SEO or request support Name; email address; company name; message content; support history; account context; files, URLs, screenshots, or other material voluntarily supplied Answer enquiries; provide account, product, billing, or workflow support; maintain an issue record; resolve disputes; protect the service Contract where support relates to paid access; legitimate interests for general enquiries, service administration, and dispute handling; legal obligation where applicable Email or communications provider; support tool; authorised Semantec SEO personnel Confirm support-ticket and email retention schedule
Create, access, or secure a MIRENA account or entitlement Account identifiers; email address; login or authentication data; session data; authentication events; access entitlement; subscription status; technical security data Create and manage access; authenticate users; maintain secure sessions; detect suspicious activity; enforce access rules Contract for account and paid-access delivery; legitimate interests for security, fraud prevention, and platform integrity Authflow.ai; hosting or infrastructure providers; authorised Semantec SEO personnel Confirm active-account, cancelled-account, authentication-event, and security-log periods
Purchase or manage a subscription Name; email; billing address where collected; transaction amount and date; subscription status; invoice, refund, dispute, and tax records; limited payment-method details received from the payment provider Process payment; manage subscriptions; issue invoices and refunds; prevent fraud; keep tax and accounting records; handle billing disputes Contract for billing and subscription delivery; legal obligation for tax and accounting records; legitimate interests for fraud prevention and dispute management Stripe; Authflow.ai; accounting, tax, banking, or professional advisers where applicable Confirm accounting, tax, refund, chargeback, and subscription-history periods
Use MIRENA inside ChatGPT Prompts; chat messages; uploaded topics, URLs, drafts, sitemaps, files, screenshots, and datasets; generated outputs; ChatGPT account and usage data handled by OpenAI Run the requested MIRENA workflow inside ChatGPT and return an output OpenAI determines its own lawful bases for ChatGPT platform processing. Semantec SEO needs a separate lawful basis only for any content it actually receives through enabled actions, external APIs, support, or another direct channel OpenAI/ChatGPT; any action or external API recipient enabled in the current GPT configuration ChatGPT retention and training choices depend on the user's plan and data controls; confirm whether Semantec SEO receives or retains any content through actions or external APIs
Receive service, product, or marketing communications Name; email address; subscription or account context; communication preference; unsubscribe record; message-delivery or engagement data if collected Send service and billing notices; answer support matters; send optional product or marketing updates Contract or legitimate interests for necessary service communications; consent or another locally permitted basis for optional marketing Email or communications provider Confirm suppression-list and marketing-contact periods
Protect the website, accounts, billing, and MIRENA access IP address; authentication events; access logs; device and session data; suspected misuse, fraud, abuse, or security-event records Prevent unauthorised access, fraud, abuse, and security threats; investigate incidents; enforce legal and acceptable-use rules Legitimate interests in service security and abuse prevention; legal obligation where incident, regulatory, or enforcement duties apply Authflow.ai; Stripe; hosting and security providers; advisers; authorities where lawfully required Confirm security-event, abuse-monitoring, and incident-record periods
Make a privacy or data-rights request Name; contact details; request type; account identifiers; correspondence; limited verification information; response and completion record Verify the requester where necessary; locate relevant data; answer and document the request; meet legal obligations Legal obligation; legitimate interests in protecting personal data from unauthorised disclosure and maintaining an audit record Authorised Semantec SEO personnel; relevant processors; legal or privacy advisers where required Confirm rights-request and verification-record periods
Meet tax, accounting, legal, regulatory, or dispute obligations Account, billing, transaction, support, contract, complaint, security, and dispute records relevant to the obligation Keep legally required records; answer lawful requests; establish, exercise, or defend legal claims; resolve complaints and disputes Legal obligation; legitimate interests in establishing, exercising, or defending legal claims Accountants; legal advisers; auditors; insurers; regulators; courts; public authorities Confirm statutory and limitation periods by record type
3 · MIRENA and ChatGPT

MIRENA’s public product path runs in ChatGPT.

A person using MIRENA in ChatGPT also uses OpenAI’s service. Prompts, files, account activity, and generated output may be processed by OpenAI under the terms, privacy notice, retention settings, and data controls attached to that person’s ChatGPT plan.

OpenAI states that GPT builders cannot view individual conversations through the standard GPT builder interface. This does not cover data sent through an enabled action, app, or external API. The live MIRENA configuration must be checked and each recipient must be named.

Training depends on the ChatGPT plan and settings

Consumer-plan conversations may be used for model improvement depending on the user’s data-control choice. Business, Enterprise, and Edu data is not used for training by default.

Review ChatGPT data controls ↗

Actions and external APIs need a separate record

If MIRENA sends part of an input to an action, app, or external API, the recipient, fields, purpose, role, location, retention, and privacy notice must be stated here.

What not to submit

Do not submit passwords, full payment-card details, legal secrets, health records, regulated personal data, or client-confidential material unless authorised and suitable for the platform and workflow.

4 · Providers and recipients

Name each provider and state what it receives.

The current policy names Authflow.ai and Stripe but uses generic labels for hosting, email, analytics, diagnostics, and support. A publishable notice needs a current provider register.

Provider or category Role in the service Data involved Draft status
OpenAI / ChatGPT External platform where the public MIRENA GPT currently runs Prompts, files, account data, usage data, and generated output handled under OpenAI terms and account controls Platform confirmed
Confirm actions, apps, and external API recipients
Authflow.ai Account access, paywall, authentication, entitlement, and related access flows Account identifiers, authentication data, session data, access status, and technical events Details to confirm
Legal entity, role, DPA, locations, retention, and privacy link
Stripe Payment processing, billing, subscriptions, refunds, and fraud controls Payment and transaction data, billing details, device or fraud signals, and subscription activity Provider confirmed
Map exact fields, roles, retention, and transfer terms
Hosting and infrastructure Website delivery, storage, network operation, security, and logs Technical, device, session, content, and security data as required by the service Name before publication
Email and support Contact, support, service notices, billing help, and privacy requests Contact details, messages, attachments, issue history, and delivery data Name before publication
Analytics, diagnostics, and consent Optional measurement, fault finding, performance, and cookie choices Identifiers, page activity, device data, consent state, and diagnostics Inventory before publication
5 · Data collected by activity

Data collection changes with the interaction.

Website data

Technical and device information, page activity, referrals, cookies, consent state, diagnostics, and security logs may be created when the site is loaded or used.

Contact and support data

Contact details, messages, account context, and voluntary attachments are used to answer the request and maintain an issue record.

Account and access data

Authflow.ai supports identifiers, sessions, authentication events, entitlement, and access security.

Billing data

Stripe and Authflow support payment, subscription, invoice, refund, fraud, and dispute flows. Exact fields received by Semantec SEO must be recorded.

Communication data

Service notices may be needed for account or billing administration. Optional marketing needs a lawful basis and an unsubscribe route.

Security and abuse data

Authentication, IP, session, access, fraud, misuse, and incident records may be used to protect the service and investigate threats.

Data received from providers

Semantec SEO may receive account, payment, entitlement, fraud, security, or support data from current providers. Each source and field must be recorded.

Optional versus required data

Account and billing data may be required to provide paid access. Marketing is optional. Missing required data can prevent account creation, payment, support, or a rights response.

6 · Retention

Retention needs a category-level rule.

Personal data should not remain longer than needed for its stated purpose, subject to tax, accounting, security, dispute, and legal duties. The exact periods below remain a publication gate.

Record typeRetention reasonAction before publication
Account and accessWhile access is active, then for a defined closure and security periodConfirm active, cancelled, dormant, and deleted-account periods
Authentication and security eventsFor account protection, abuse review, and incident investigationConfirm standard logs, flagged events, and incident-record periods
Billing, tax, refunds, and disputesFor contract, accounting, tax, fraud, and claims obligationsSet periods by Irish tax, accounting, payment, and limitation requirements
Contact and supportFor the open issue and a defined follow-up or dispute periodConfirm email and support-ticket periods
Marketing preferencesUntil opt-out or withdrawal, with a minimal suppression record afterwardsConfirm provider and suppression-record period
Website analytics and cookiesBy cookie, identifier, consent state, and analytics purposePublish exact names and durations in the cookie record
Privacy requestsLong enough to answer, prove completion, and manage complaintsConfirm request, verification, and response-record periods
MIRENA chats and files in ChatGPTControlled by the user’s ChatGPT account, plan, chat settings, and OpenAI retention rulesConfirm any separate data received by Semantec SEO through actions or APIs
7 · International transfers

Provider location and transfer mechanism must be visible.

Personal data may be processed outside Ireland or the European Economic Area when a provider, subprocessor, platform, or support service operates elsewhere.

Before publication, Semantec SEO should map each destination and state the relevant protection, such as an adequacy decision, Standard Contractual Clauses, an applicable Data Privacy Framework certification, or another lawful mechanism.

OpenAI / ChatGPT

Link the current regional privacy notice and record the relevant platform entity for the user.

Stripe

Map the Stripe entities, processing roles, DPA, subprocessors, and transfer terms used by the current account.

Authflow.ai

Confirm the contracting entity, locations, subprocessors, DPA, and transfer route.

Other providers

Do the same for hosting, email, support, analytics, diagnostics, and consent tools.

8 · Security

Security controls should be proportionate and accurately described.

Semantec SEO should use technical and organisational controls suited to the data and risk. Public wording can describe access control, authentication, provider review, secure transmission, backups, logging, incident response, and least-privilege access without exposing sensitive defensive detail.

Access control

Limit personal-data access to people and providers who need it for an approved task.

Account security

Use secure authentication, session protection, and suspicious-event review for controlled access.

Provider checks

Review contracts, DPAs, roles, subprocessors, security information, retention, and transfer terms.

Incident response

Maintain an internal process for investigation, containment, notification decisions, and record keeping.

Data minimisation

Request and keep only the information needed for the stated purpose.

No absolute promise

No internet service can promise complete security. The notice should state that boundary without weakening the actual controls.

9 · Your privacy rights

You may have rights over personal data about you.

Depending on the law and context, these may include access, correction, deletion, restriction, objection, portability, consent withdrawal, and rights connected to solely automated decisions. A right may be subject to legal conditions and exceptions.

01

Access

Ask if personal data is processed and request a copy with related processing information.

02

Correction

Ask for inaccurate data to be corrected and incomplete data to be completed where appropriate.

03

Deletion

Ask for eligible data to be deleted. Legal, tax, security, billing, dispute, or claims duties may limit the request.

04

Restriction

Ask for processing to be limited in the circumstances set by applicable law.

05

Object

Object to eligible processing, including some processing based on legitimate interests.

06

Portability

Request eligible data in a structured, commonly used, machine-readable form.

07

Withdraw consent

Withdraw consent for future consent-based processing without affecting earlier lawful processing.

08

Complain

Raise a concern with Semantec SEO and complain to a competent supervisory authority.

Privacy Request Planner

This tool creates an email template in your browser. It does not send or store your details.

Open in email Download all templates


          

Where GDPR applies, the general response deadline is without undue delay and within one month. A permitted extension of up to two further months may apply for complex or numerous requests, with notice given within the first month. Identity checks should be proportionate.

10 · Complaints

You can raise a privacy concern with Semantec SEO or a supervisory authority.

Irish Data Protection Commission

The Data Protection Commission is Ireland’s data-protection authority. Its current public contact address is 6 Pembroke Row, Dublin 2, D02 X963, Ireland. The DPC asks people to use its online contact route for complaints and states that concerns should normally be raised with the controller first.

11 · Cookies and marketing

Optional tracking needs a clear choice.

Strictly necessary cookies may support security, account access, session integrity, payment flow, and core site operation. Optional analytics, preference, advertising, or similar technologies may need prior consent depending on the visitor and law.

The live cookie banner, tag inventory, default state, categories, provider names, identifiers, and durations must match the cookie policy and this notice.

Necessary cookies

Used for site operation, security, authentication, session state, or payment flow where needed.

Optional cookies

Used only after the required choice has been recorded.

Marketing messages

Optional marketing must have a lawful basis and a working unsubscribe route.

Your choices

Read the Cookie Policy or withdraw from marketing through an unsubscribe link or the privacy contact.

12 · Automated decisions, children, and changes

Three publication statements need a confirmed operational position.

Automated decisions

This draft does not claim that Semantec SEO makes solely automated decisions with legal or similarly significant effects. Confirm the real position before publication. MIRENA output is working material and needs human review.

Children

The current policy says the website and MIRENA are not directed to people under 18 and that known child data will be reviewed. Confirm age gates, checkout controls, and the response process.

Policy changes

Use a real effective date, record material changes, give extra notice where the change materially affects people, and keep prior versions where appropriate.

14 · Common privacy questions

Privacy Policy FAQ

Who is the data controller?

The current site names Semantec SEO as controller. The legal person or entity behind that trading name and its business address must be added before this draft is published. Privacy requests should use privacy@semantecseo.com.

Can the MIRENA GPT builder read my individual ChatGPT conversation?

OpenAI states that GPT builders cannot view individual conversations through the standard GPT builder interface. This does not cover data sent through an enabled action, app, external API, support message, or another direct channel. The current MIRENA configuration must be checked before publication.

Can OpenAI use my MIRENA conversation to improve its models?

That depends on the ChatGPT plan and the user's data-control choices. Consumer-plan content may be used when model improvement is enabled. Business, Enterprise, and Edu data is not used for training by default. Users should review current OpenAI data controls.

What should I avoid submitting to MIRENA?

Do not submit passwords, full card details, health records, legal secrets, client-confidential material, regulated personal data, or other sensitive information unless you are authorised and the service and platform are suitable for that use.

Does Semantec SEO store my full payment-card number?

The published service description says Stripe handles payment processing. This draft assumes full card details are handled directly by Stripe, but the exact fields Semantec SEO receives must be confirmed before publication.

How long does Semantec SEO keep personal data?

The current notice gives a general necessity test. A publishable version should state category-level periods or precise criteria for account, billing, support, security, marketing, cookie, and rights-request records.

How do I make a privacy request?

Email privacy@semantecseo.com or use the request planner on this page. Describe the request, the email or account concerned, and the date range. Do not send a password or full card details.

How quickly will a GDPR request be answered?

Where GDPR applies, the general deadline is without undue delay and within one month. A permitted extension of up to two further months may apply for complex or numerous requests, with notice given within the first month.

Can I complain to a data-protection authority?

Yes. You can raise the matter with Semantec SEO first and may complain to the Irish Data Protection Commission or another competent supervisory authority where applicable.

Are optional analytics cookies used before consent?

The current cookie policy says non-essential cookies should wait for consent where required. The live banner, tags, default state, and cookie inventory must be tested before this draft is published.

Does MIRENA make automated decisions about me?

MIRENA creates SEO workflow output. This draft does not claim that Semantec SEO makes solely automated decisions with legal or similarly significant effects. The operational position must be confirmed before publication.

Is the service intended for children?

The current policy says Semantec SEO and MIRENA are not directed to people under 18. The product age rule, checkout controls, and response process should be checked before publication.

Contact Semantec SEO about privacy

Email privacy@semantecseo.com for a rights request, policy question, provider question, cookie concern, or complaint. Use support@semantecseo.com for product and billing help. Add the controller’s confirmed legal identity and postal address before publication.