Cookie choices at Semantec SEO: what runs, when consent is needed, and how to change it.
This Cookie Policy explains how Semantec SEO and its service providers use cookies and similar technologies on semantecseo.com. It also separates the website from external services such as Authflow.ai, Stripe, and ChatGPT.
A final public policy needs an exact inventory of names, providers, domains, purposes, expiry periods, third-party access, and consent behaviour. The current draft records confirmed provider roles and keeps unverified technology behind a release gate.
- Controller: Kevin Maguire trading as Semantec SEO
- Privacy contact: privacy@semantecseo.com
- Non-essential technology waits where consent is required
- ChatGPT uses OpenAI’s separate cookie controls
Cookie Path Finder
Choose the interaction that brought you here.
Website delivery and consent state
Start with the domain and the organisation that controls it.
This policy covers storage and access technology used on semantecseo.com and direct account or checkout flows controlled by Semantec SEO. It does not control technology on an external site after the visitor leaves this domain.
Controller details
- Trading name
- Semantec SEO
- Legal person
- Kevin Maguire
- Address
- Central Park, Clane, Ireland
- Privacy email
- privacy@semantecseo.com
- Support email
- support@semantecseo.com
What this policy must separate
Semantec SEO can explain technology used on its website and in flows it controls. The policy must also make these boundaries visible:
- Authflow.ai supports account access and entitlement.
- Stripe supports checkout, billing, and fraud controls.
- OpenAI controls cookies on ChatGPT and OpenAI domains.
- Hosting, analytics, diagnostics, email, support, and consent providers must be named from the live register before publication.
Consent applies to storage or access, not only to personal data.
Irish ePrivacy rules normally require consent before a site stores information on or reads information from a device. A narrow exemption can apply to communication technology and technology strictly necessary for a service the user explicitly requested.
Block before choice
Do not load non-essential analytics, preference, marketing, pixels, tags, or similar technology before the required choice.
Use a real action
Do not treat scrolling, silence, continued browsing, or a preselected control as consent.
Give a clear choice
State each purpose plainly, keep optional categories off by default, and make rejection and acceptance easy to find.
Allow withdrawal
Keep a visible cookie-settings route and apply a changed choice without forcing the user to search for it.
Category labels do not decide the legal result by themselves.
The purpose, timing, provider, domain, duration, and user request decide whether a technology is exempt or needs a choice.
Strictly necessary
Limited to technology needed for a requested service or communication.
- Secure session
- Traffic routing
- Requested account access
- Consent choice record
Preferences and functionality
Remembers optional choices or adds a feature that is not essential on first load.
- Saved interface choice
- Long-term preference
- Optional chat or media
- Personalisation
Analytics and performance
Measures visitors, paths, events, diagnostics, or feature use.
- Page views
- Traffic source
- Feature event
- Performance measurement
Marketing and advertising
Supports advertising, remarketing, campaign attribution, or cross-site profiling.
- Ad audience
- Remarketing
- Cross-site signal
- Campaign attribution
Provider roles are partly known. Exact cookie records still need a live scan.
The public table must contain the exact name, provider, domain, purpose, duration, category, and third-party access state for every active cookie or similar technology. The records below are a release register, not a final claim that each item is currently set.
8 of 8 inventory records shown
| Item or family | Provider and domain | Category | Purpose | Expiry | Verification state |
|---|---|---|---|---|---|
| Consent preference recordCookie or local-storage record | Consent manager: confirm current providersemantecseo.com or the confirmed consent-provider domain | Strictly necessary | Store and apply the visitor's cookie choices. | Confirm from the production scan | Pending live scan |
| Website session, delivery, or security technologyCookie, session identifier, or similar technology | Hosting, CMS, caching, or security provider: confirmsemantecseo.com and any confirmed infrastructure domain | Strictly necessary | Deliver pages, route traffic, protect requests, or maintain a secure session. | Confirm from the production scan | Pending live scan |
| Authentication and entitlement sessionAuthentication, session, entitlement, or security technology | Authflow.aiConfirm the domains used by the live sign-in and paywall flow | Strictly necessary when account access is requested | Authenticate the user, maintain session continuity, and check access status. | Confirm from the live Authflow.ai flow and provider record | Provider confirmed; exact inventory pending |
| Checkout and fraud-control technologyCookie, local storage, URL tracking, or device/fraud signal | StripeStripe and checkout domains used by the live integration | Strictly necessary during requested checkout, subject to purpose review | Process payment, maintain checkout state, protect the transaction, and reduce fraud. | Confirm from the live checkout and Stripe's current inventory | Provider confirmed; exact inventory pending |
| Analytics and performance measurementCookie, pixel, tag, local storage, or similar identifier | No provider confirmed for publicationPending | Analytics | Measure page use, route use, feature use, or performance. | Pending | Blocked until inventory and consent are confirmed |
| Marketing or advertising technologyCookie, pixel, tag, device identifier, or similar technology | No provider confirmed for publicationPending | Marketing | Advertising, remarketing, campaign attribution, or cross-site profiling. | Pending | Not approved |
| Embedded media or social technologyEmbedded player, social widget, pixel, or local storage | No embedded provider confirmedDepends on any future embed | Functional, analytics, or marketing depending on purpose | Display or measure third-party content. | Pending if an embed is added | No current inventory entry confirmed |
| ChatGPT and OpenAI platform cookiesCookies and similar technologies controlled by OpenAI | OpenAIchatgpt.com, openai.com, and other OpenAI service domains | External platform | Account, security, service functionality, consent, analytics, preferences, and other OpenAI purposes. | See OpenAI's current cookie inventory | External policy |
No inventory record matches those filters.
Account, payment, and ChatGPT technology sit in different provider paths.
Semantec SEO
Controls the website purpose, consent design, account purpose, subscription purpose, and the records it directly receives.
- Website and consent state
- Direct support and privacy contact
- Provider and inventory register
Authflow.ai
Supports account access, paywall, authentication, entitlement, and related technical events.
- Exact cookie names pending
- Domains and duration pending
- Role and transfer details pending
Stripe
Supports payment, checkout state, fraud controls, subscription events, refunds, and billing activity.
- Scan the exact checkout
- Record hosted or embedded domains
- Separate necessary and optional purposes
OpenAI and ChatGPT
Control technology used after the visitor follows the external MIRENA product link to ChatGPT.
- Separate domain
- Separate cookie controls
- Separate privacy terms
The policy needs a live route back to cookie settings.
The standalone draft uses an integration hook. It does not pretend to change consent when no consent manager is connected.
What the production control should do
- Show the current category state.
- Allow optional categories to be accepted or rejected separately.
- Apply withdrawal without unnecessary friction.
- Keep non-essential technology blocked after rejection.
- Record the policy and consent version tied to the choice.
- Reopen from a persistent footer or policy control.
Browser settings can also block or delete cookies, but they operate outside the site’s own consent record. Blocking required account or checkout technology may stop that requested function.
Each record needs a duration and a provider-access statement.
Session and persistent technology
A session cookie normally ends with the browser session. A persistent cookie remains for a stated period or until deletion. The public inventory must state the actual duration, not only the words session or persistent.
When a third party can access a cookie or similar identifier, that access must also be stated.
Transfers and provider records
Provider location, role, subprocessor use, retention, and transfer safeguards belong in the provider register and the Privacy Policy. Cookie wording should match those records rather than repeat a vague international-users clause.
Complete the evidence checks before this draft becomes the live notice.
This checklist is a review aid inside the draft. A checked box does not replace a legal or technical record.
0 of 10 release checks complete
Cookie Policy FAQ
What are cookies and similar technologies?
Cookies are small files or records stored on or read from a device. Similar technologies can include local storage, pixels, tags, software development kits, device identifiers, and other methods that store or access information.
Which cookies need consent in Ireland?
Consent is normally required before storing or accessing information on a device. A narrow exemption can apply when the technology is strictly necessary to transmit a communication or provide an online service the user explicitly requested.
Do analytics cookies require consent?
The Irish Data Protection Commission states that analytics cookies require consent. The Semantec SEO analytics inventory and provider must therefore be confirmed and blocked before consent where that rule applies.
Can I use the website after rejecting non-essential cookies?
General website access should not depend on accepting optional analytics or marketing technology. Some requested functions, such as account access or checkout, may need narrowly scoped session or security technology to work.
How do I change or withdraw my cookie choice?
Use the cookie-settings control provided on the live site. Withdrawal should be available as readily as the original choice. Browser controls can also delete or block stored data, but they do not replace the site's consent control.
What happens when I open MIRENA in ChatGPT?
You leave semantecseo.com and use an external OpenAI service. OpenAI controls cookies and similar technologies on ChatGPT and OpenAI domains under its own cookie and privacy policies.
What happens during Stripe checkout?
Stripe may use cookies and similar technologies for checkout state, transaction security, authentication, fraud controls, and other purposes described in its policy. The exact Semantec SEO checkout flow must be scanned and recorded.
How often should the cookie inventory be checked?
Check it before publication, after any change to providers, tags, embeds, account access, checkout, analytics, advertising, or the consent manager, and at a scheduled interval. Update the policy when the live inventory changes.
Does the Semantec SEO cookie control change browser settings?
No. A site consent tool controls the technologies configured through that tool. Browser settings can separately block or delete cookies across websites.
Who can I contact about cookies or privacy?
Contact privacy@semantecseo.com. The controller details and privacy-request route also appear in the Semantec SEO Privacy Policy.
Contact Semantec SEO or the Irish Data Protection Commission.
Semantec SEO privacy contact
Kevin Maguire trading as Semantec SEO
Central Park, Clane, Ireland
Irish supervisory authority
Data Protection Commission
6 Pembroke Row
Dublin 2, D02 X963, Ireland