Trust · Trust disclosure
Exercise GDPR rights with the controller that holds the record.
This page explains the rights request route for personal data controlled by Semantec SEO, the one-month general response period, identity verification, external-platform boundaries, and the right to complain to a supervisory authority.
Verified facts and boundaries.
These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.
Send the request to the controller that holds the record.
Semantec SEO handles requests concerning personal data it controls, including direct website, account, entitlement, support, billing, privacy, and business records it receives or creates.
OpenAI controls ChatGPT account, chat, file, memory, training, and platform records. Stripe, Authflow.ai, or another provider may control separate records. One interaction can therefore require more than one request route.
Rights that may apply.
| Right | Purpose | Important qualification |
|---|---|---|
| Be informed | Receive clear information about processing | The Privacy Policy should identify purposes, bases, recipients, retention, transfers, and rights |
| Access | Confirm processing and receive a copy | The rights and freedoms of others may limit disclosure |
| Correction | Correct inaccurate or complete incomplete data | The request should identify the relevant record and correction |
| Deletion | Request erasure in eligible circumstances | Legal duties, claims, security, and other exceptions may apply |
| Restriction | Limit eligible processing while an issue is checked | The controller may retain the record while limiting other use |
| Portability | Receive eligible data in a structured format | Applies only to specified automated processing based on consent or contract |
| Object | Object to certain processing | The result depends on the lawful basis and compelling grounds |
| Withdraw consent | Stop consent-based processing | Withdrawal does not make earlier lawful processing unlawful |
| Complain | Raise a matter with a supervisory authority | The Irish DPC is the national supervisory authority for Semantec SEO |
What to include.
- Your name and contact route
- The account email or identifier concerned
- The right you want to exercise
- The relevant service, page, transaction, or date range
- Enough context to locate the record
- A preferred response format where relevant
Identity verification must be proportionate.
Semantec SEO may ask for information needed to confirm identity or authority when there is reasonable doubt. The request should use the least intrusive method suitable for the risk.
Do not send a passport, driving licence, password, authentication code, or full payment-card number unless a proportionate request and secure route have been provided.
Timing and extensions.
The general GDPR deadline is without undue delay and within one month of receipt. The period may be extended by up to two further months where the request is complex or numerous, with notice and reasons given within the first month.
A request for clarification should not be used to delay a response unnecessarily. A controller may charge a reasonable fee or refuse a manifestly unfounded or excessive request only where the legal conditions are met.
Response, refusal, and complaints.
The response should explain the action taken. If a request is refused or restricted, the controller should state the reason and the available complaint or judicial route where required.
You may complain to the Irish Data Protection Commission or another competent supervisory authority. Raising the matter with Semantec SEO first may help clarify the record, but it is not a condition that removes the right to complain.
Check the controlling first-party and official sources.
These routes support the current public statement. External platform and legal sources remain subject to their own updates.
Semantec SEO GDPR Notice
Current first-party rights and controller record.
Irish DPC rights guidance
Official overview of GDPR rights.
Irish DPC access guidance
Official access, portability, and one-month response guidance.
Move to the page that owns the next question.
Each route has a separate job so company, product, trust, legal, and compliance information does not collapse into one promotional page.
Owned route
Privacy Policy
Detailed processing purposes, bases, recipients, retention, and transfers.
Open route →
Owned route
Data rights process
Internal intake, verification, search, review, and response standard.
Open route →
Owned route
Data retention
Retention criteria and deletion boundaries.
Open route →
Owned route
Provider register
External platform and provider roles.
Open route →
Owned route
Contact
Privacy and support routes.
Open route →
Owned route
OpenAI data controls
External ChatGPT data controls and privacy routes.
Open route →