Trust · Trust disclosure
The provider register separates Semantec SEO responsibilities from external platform responsibilities.
This register identifies confirmed providers involved in ChatGPT delivery, payment, and access, and explains why a provider's role, data, location, retention, and contract must be checked separately.
Verified facts and boundaries.
These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.
Provider roles depend on the processing activity.
The term subprocessor should be used only when the contractual and legal role has been confirmed. A company can act as a processor for one activity and an independent controller for another.
This register therefore describes the public operational role and directs readers to the provider's own terms. The Privacy Policy should state the final role, data categories, purpose, retention, transfer, and legal basis.
Confirmed public providers.
| Provider | Public role | Data or activity | Primary external source |
|---|---|---|---|
| OpenAI / ChatGPT | Hosts ChatGPT and executes GPT interactions | Account, conversation, files, output, model and platform data under OpenAI terms | OpenAI privacy, terms, data controls, and GPT documentation |
| Stripe | Payment processing | Payment method, transaction, fraud, billing and refund records according to role | Stripe privacy and service documentation |
| Authflow.ai | Access and entitlement support | Account, authentication, entitlement and subscription-state data according to role | Authflow.ai contractual and privacy documentation |
| Semantec SEO | Product, site, support, access decision, and direct record owner | Company-controlled website, account, support, billing, privacy and product records | Semantec SEO Privacy Policy |
Providers not yet confirmed should not be guessed.
Hosting, analytics, consent management, email, diagnostics, support, file storage, and other operational services should be listed only after the live configuration, contract, data flow, and public notice are checked.
A generic category can identify the type of provider in the Privacy Policy, but a public register should not invent a vendor name or role.
What to record for each provider.
- Legal and trading name
- Service and processing purpose
- Controller, processor, or independent role by activity
- Personal-data categories and data subjects
- Hosting or processing location where relevant
- International transfer mechanism
- Retention and deletion terms
- Security and incident obligations
- Contract owner and review date
- Public privacy and service links
Provider changes.
A new provider or material change should be assessed before use. The review should cover purpose, necessity, access, data minimisation, security, privacy, international transfers, retention, user notice, and exit.
The Privacy Policy, cookie inventory, security overview, legal terms, and operational documentation should be updated when the change affects their statements.
User choice and external routes.
Following a link to ChatGPT, Stripe, Authflow.ai, or another provider can place the user under that provider's terms, privacy notice, cookies, and controls. Semantec SEO does not control the external domain.
Ask privacy@semantecseo.com which party likely holds a record if the correct route is unclear.
Check the controlling first-party and official sources.
These routes support the current public statement. External platform and legal sources remain subject to their own updates.
Semantec SEO Privacy Policy
Current first-party provider and data-flow baseline.
GPTs in ChatGPT
Official OpenAI GPT and external API boundary.
OpenAI Europe Privacy Policy
Official OpenAI privacy and retention source for EEA users.
Move to the page that owns the next question.
Each route has a separate job so company, product, trust, legal, and compliance information does not collapse into one promotional page.
Owned route
Data privacy overview
Controller and platform boundaries by interaction.
Open route →
Owned route
Privacy Policy
Purposes, bases, recipients, transfers, retention, and rights.
Open route →
Owned route
Security overview
Provider and user security responsibilities.
Open route →
Owned route
Cookie overview
Third-party domains and device storage.
Open route →
Owned route
Data retention
Provider and category retention criteria.
Open route →
Owned route
Contact
Provider, privacy, and support questions.
Open route →