GDPR Rights at Semantec SEO | Requests, Timing and Complaints
GDPR · Rights and requests

GDPR rights at Semantec SEO: what you can ask, where to send it, and what happens next.

This notice explains how to exercise data-protection rights in relation to personal data controlled by Kevin Maguire trading as Semantec SEO.

The detailed record of data categories, purposes, lawful bases, providers, retention, and transfers belongs in the Privacy Policy. Cookie and device-storage choices belong in the Cookie Policy.

  • Privacy email: privacy@semantecseo.com
  • General deadline: one month
  • Requests are generally free
  • Last updated: 20 July 2026

GDPR Rights Request Planner

Create a request email in your browser.

Local tool

The tool does not send or store the form values. Do not add passwords, full card details, or identity documents. Send identity material only after a proportionate request through an appropriate route.

SubjectGDPR access request
Record routeSemantec SEO


              

Useful details to include

    Scope and controller

    Start with the organisation and the records it controls.

    This page covers rights requests addressed to Semantec SEO. External platforms may control their own account, chat, payment, or device records.

    Use the controller that holds the record

    One interaction can involve more than one organisation. The request should go to the party that controls the record you need.

    • Semantec SEO: website, direct account, entitlement, support, privacy, subscription, and billing records it receives or controls.
    • OpenAI: ChatGPT account, chat, file, and platform records controlled under OpenAI’s privacy terms. An enabled action, app, or external API can create a separate route.
    • Stripe and Authflow.ai: payment or access providers may hold separate platform records. The Privacy Policy records the current roles and data flow.
    Your rights

    GDPR gives people rights over personal data, subject to stated conditions.

    The right that applies depends on the processing, lawful basis, record, and reason for the request.

    01

    Be informed

    Receive clear information about the controller, purposes, bases, recipients, retention, transfers, and rights.

    02

    Access

    Ask if personal data about you is processed and request a copy with the related information.

    03

    Correction

    Ask for inaccurate personal data to be corrected and incomplete data to be completed where appropriate.

    04

    Deletion

    Ask for eligible personal data to be deleted. Legal duties and other exceptions may limit the right.

    05

    Restriction

    Ask for eligible processing to be limited while an accuracy, lawfulness, or objection issue is checked.

    06

    Portability

    Receive eligible data in a structured, commonly used, machine-readable form.

    07

    Object

    Object to eligible processing. Direct marketing use must stop when a valid objection applies.

    09

    Automated decisions

    Receive protection from certain solely automated decisions with legal or similarly significant effects.

    10

    Complain

    Raise a concern with a competent supervisory authority, including the Irish Data Protection Commission where applicable.

    Request handling

    A rights request should move through a clear, recorded path.

    Identity checks should protect the data without asking for more information than the request needs.

    01

    Send the request

    Email the privacy contact or use the planner. Name the right, account, service part, and useful date range.

    02

    Check identity if needed

    Extra information may be requested only when there are reasonable doubts about identity.

    03

    Locate the records

    Search the approved systems and contact relevant providers when their records are involved.

    04

    Apply the right

    Provide the data or action, or explain any legal condition, exception, limit, fee, or refusal.

    05

    Close or complain

    Record the response. A person may contact a competent supervisory authority if the concern remains.

    1month, as the general deadline

    Response timing and cost

    Action should be taken without undue delay and within one month after receipt.

    A permitted extension of up to two further months may apply for a complex or numerous request. Notice and reasons must be given within the first month.

    Requests are generally free. A reasonable fee or refusal may apply to a manifestly unfounded or excessive request, with the burden on the controller.

    Lawful bases

    The legal basis belongs to the processing activity, not the page label.

    The detailed processing matrix sits in the Privacy Policy. These are the bases most likely to appear in the current Semantec SEO service.

    C

    Contract

    Account access, paid service delivery, subscription administration, and support connected with the service.

    L

    Legitimate interests

    Security, fraud controls, diagnostics, service administration, support, and dispute handling after a balancing check.

    O

    Legal obligation

    Tax, accounting, regulatory, rights-request, incident, and lawful disclosure duties.

    A

    Consent

    Optional cookies, optional marketing, and other processing that needs a freely given, specific, informed, and clear choice.

    Data and platform paths

    Send the request to the party that controls the record.

    The public MIRENA product runs in ChatGPT. Website, access, billing, and support records can follow different paths.

    Interaction Likely controller or route Typical records Useful next action
    Browse semantecseo.com Semantec SEO Website, device, consent, security, and permitted analytics records Build a Semantec SEO request
    Use account access or entitlement Semantec SEO, supported by Authflow.ai Identifiers, access status, authentication events, and session records Check the provider record
    Pay or manage a subscription Semantec SEO for records it receives; Stripe for separate Stripe records Subscription, invoice, refund, dispute, transaction, and payment-platform records Read Stripe privacy information ↗
    Use MIRENA in ChatGPT OpenAI for ChatGPT platform data; Semantec SEO for direct action, API, support, or other received data ChatGPT account, prompts, chats, files, output, actions, and external API data where used Read OpenAI GPT privacy information ↗
    Contact support or privacy Semantec SEO Contact details, messages, attachments, issue history, and request records Email privacy
    Receive optional marketing Semantec SEO and its current communication provider Email, preference, consent, unsubscribe, and suppression records Withdraw consent or object
    Retention, transfers, and privacy contact

    Exact records and provider safeguards belong in the Privacy Policy.

    This notice keeps the rights route clear and links to the detailed processing record.

    Retention and international transfers

    Personal data should not stay longer than needed for the stated purpose, subject to tax, accounting, security, dispute, and other legal duties.

    When a provider processes data outside the European Economic Area, the applicable route may use an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.

    Read the detailed Privacy Policy →

    Privacy contact and DPO status

    Kevin Maguire is identified here as the controller and privacy contact. Requests should use privacy@semantecseo.com.

    This notice identifies Kevin Maguire as the controller and privacy contact. No separate statutory Data Protection Officer is identified on this page.

    Complaints

    You may raise a concern with Semantec SEO or a competent supervisory authority.

    The Irish Data Protection Commission asks people to set out the concern clearly and recommends contacting the controller first where practical.

    Irish Data Protection Commission

    You may also complain to another competent supervisory authority in the place of habitual residence, work, or the alleged infringement where GDPR allows.

    Data Protection Commission
    6 Pembroke Row
    Dublin 2, D02 X963
    Ireland
    Related privacy pages

    Use the page that owns the question.

    This separation keeps rights, data flows, cookie choices, and paid-service terms from becoming one long policy.

    Data processing

    Privacy Policy

    Data categories, purposes, lawful bases, providers, retention, transfers, security, and platform boundaries.

    Read the Privacy Policy →
    Device storage

    Cookie Policy

    Cookie names, providers, purposes, durations, consent rules, account access, payment technology, and choice controls.

    Read the Cookie Policy →
    Paid access

    Subscription Terms

    Account responsibility, payment, renewal, cancellation, access, output limits, and service changes.

    Read Subscription Terms →
    Submitted material

    Acceptable Use

    Material that should not be submitted, misuse controls, account protection, and service limits.

    Read Acceptable Use →
    Common questions

    GDPR request FAQ

    Who is the data controller for this notice?

    Kevin Maguire trading as Semantec SEO is identified as the controller for personal data where Semantec SEO decides why and how it is processed. The contact address is Central Park, Clane, Ireland, and privacy requests should use privacy@semantecseo.com.

    How do I make a GDPR request?

    Use the rights request planner on this page or email privacy@semantecseo.com. State the right, the account or email concerned, the part of the service used, and a date range where useful. Do not send a password or full payment-card details.

    How quickly should Semantec SEO respond?

    Where GDPR applies, the general deadline is without undue delay and within one month after receipt. A permitted extension of up to two further months may apply when a request is complex or numerous, with notice and reasons given within the first month.

    Are GDPR requests free?

    Requests and responses are generally free. A reasonable fee or refusal may be possible for a request that is manifestly unfounded or excessive, especially when repetitive. The controller must be able to support that decision.

    Will I need to provide identification?

    Only when there are reasonable doubts about identity and extra information is needed to protect the data from unauthorised disclosure. Do not send identity documents unless Semantec SEO asks through an appropriate route.

    Can the MIRENA GPT builder read my individual ChatGPT conversation?

    OpenAI states that GPT builders cannot view individual conversations through the standard GPT builder interface. This does not cover information sent through an enabled action, app, external API, support message, or another direct channel.

    Where do I request ChatGPT account or chat data?

    Use OpenAI's privacy and data-control routes for ChatGPT account, chat, file, and platform records controlled by OpenAI. Contact Semantec SEO only for data it receives or controls directly, such as support, access, billing, or enabled action records.

    Is Kevin Maguire described as a Data Protection Officer?

    This notice identifies Kevin Maguire as the controller and privacy contact. It does not identify a separate statutory Data Protection Officer. A DPO role and contact details will be published if a formal appointment is made.

    Can I complain to the Irish Data Protection Commission?

    Yes. You may raise the concern with Semantec SEO first and may complain to the Irish Data Protection Commission or another competent supervisory authority where GDPR permits.

    Does this notice replace the Privacy Policy or Cookie Policy?

    No. This page owns GDPR rights, request timing, identity checks, and complaint routes. The Privacy Policy owns the detailed processing matrix, providers, retention, and transfers. The Cookie Policy owns device storage, consent, and cookie controls.

    Official references

    Read the regulation and regulator material directly.

    EU law

    Regulation (EU) 2016/679

    The official GDPR text, including Articles 12 to 22, 37, and 77.

    Open EUR-Lex ↗

    Make a clear request without sending more data than needed.

    Build the template, check the route, remove unnecessary detail, and send it to the controller that holds the record.