Privacy Policy

Skip to main content

  1. MIRENA
  2. Legal
  3. Privacy Policy

Legal · Legal document

How Semantec SEO processes personal data across the website, account, payment, support, and privacy routes.

This policy identifies the controller, data categories, purposes, lawful bases, providers, international transfers, retention criteria, rights, security, complaints, and the separate ChatGPT boundary.

Operative document

Semantec SEO Privacy Policy

Version 2.0
Reviewed 15 August 2026
Owner: Kevin Maguire trading as Semantec SEO

1. Controller and contact

Kevin Maguire trading as Semantec SEO, Central Park, Clane, Ireland, is the controller for personal data where Semantec SEO determines why and how it is processed.

Privacy and data-rights requests should be sent to privacy@semantecseo.com. Product, account, billing, and cancellation support should be sent to support@semantecseo.com.

2. Scope and separate controllers

This policy covers personal data received or created through semantecseo.com, direct MIRENA access and entitlement, billing, support, privacy requests, security reports, and business communications controlled by Semantec SEO.

OpenAI controls ChatGPT account, chat, file, memory, training, and platform records under its own privacy terms. Stripe, Authflow.ai, and other providers may act as processors or independent controllers depending on the activity.

3. Personal data categories

Semantec SEO may process contact and identity details, account and entitlement information, subscription and billing records, support and privacy correspondence, website and device data, consent choices, security and fraud signals, business relationship information, and material you choose to send directly.

Semantec SEO should not receive full payment-card details from Stripe. Do not send passwords, authentication codes, secret keys, health data, legal secrets, or unnecessary sensitive personal data.

4. Purposes and lawful bases

Primary processing purposes
Purpose Typical data Lawful basis or role
Provide account and MIRENA access Identity, email, entitlement, subscription status, access events Contract and legitimate interests in secure delivery
Process payments and refunds Billing identity, transaction, tax, refund and dispute records Contract, legal obligation, and legitimate interests
Answer support and business messages Contact details, message, relevant account or project context Contract, steps at request, and legitimate interests
Operate and secure the website IP, device, logs, security and diagnostic events Legitimate interests and legal obligation where applicable
Manage privacy and legal requests Identity, request, correspondence, evidence and response Legal obligation and legitimate interests
Send required service notices Account and contact details Contract and legitimate interests
Send optional marketing Contact and preference data Consent or another lawful basis identified at collection
Establish or defend claims Relevant account, transaction, communication and security records Legitimate interests and legal claims

5. MIRENA conversations in ChatGPT

OpenAI states that GPT builders cannot view individual conversations users have with their GPTs through the standard builder interface. Semantec SEO may receive information that a user sends directly through support or another disclosed route.

The confirmed Authflow entitlement action sends an email address and fixed paywall identifier to check active access; the current public record states that it does not send conversation prompts, drafts, uploaded files, or generated outputs. Any material change requires policy review.

6. Providers and recipients

Confirmed public providers include OpenAI for ChatGPT, Stripe for payment processing, and Authflow.ai for access and entitlement. Hosting, email, analytics, diagnostics, consent, support, and other providers must be verified from the live environment before final publication.

Data may also be disclosed to professional advisers, authorities, courts, regulators, acquirers, or other parties where required by law, necessary to protect rights, or connected to a legitimate business transaction with suitable safeguards.

7. International transfers

Some providers may process data outside Ireland or the European Economic Area. The applicable transfer mechanism may include an adequacy decision, standard contractual clauses, or another lawful safeguard.

The final provider register should identify provider legal entities, locations, roles, transfer mechanisms, and public privacy links. A generic provider category is not enough for final publication.

8. Retention

Personal data is kept only as long as needed for the purpose, contract, legal obligation, tax or accounting duty, security, fraud prevention, dispute, claim, consent record, or protection of another person's rights.

Category-level criteria are published in the Data Retention page. OpenAI and other providers control separate retention under their own terms.

9. Your rights

Where GDPR applies, you may have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint.

Requests are generally handled without undue delay and within one month, subject to lawful extension, identity verification, the rights of others, and applicable exceptions. The GDPR overview explains the process.

10. Cookies and similar technologies

The Cookie Policy governs storage or access on a device through semantecseo.com and direct flows controlled by Semantec SEO. Non-essential technology must not load before consent where consent is required.

OpenAI controls technology on ChatGPT and OpenAI domains. Stripe, Authflow.ai, and other provider domains have separate policies.

11. Security

Semantec SEO uses organisational and technical measures proportionate to the records and risks it controls, including access restriction, data minimisation, provider controls, incident handling, and secure payment and account providers.

No system is risk-free. The Security Overview states the public control boundary and does not claim unsupported certification or assurance.

12. Children

The service is not directed to children. Users must meet the age, account, and consent requirements in applicable law and OpenAI terms.

Do not provide children's personal data unless a lawful, authorised, necessary, and suitable route has been confirmed.

13. Changes and contact

The canonical policy applies from its effective date. Semantec SEO will review it after material changes to the product, providers, data flows, purposes, law, or user rights.

Questions, rights requests, complaints, and corrections should be sent to privacy@semantecseo.com. You may also complain to the Irish Data Protection Commission or another competent supervisory authority.

Sources

Official and first-party references.

The published legal document remains subject to mandatory law, the order confirmation, and current provider terms.

Semantec SEO
Current Semantec SEO Privacy Policy

First-party controller, provider, and data-flow baseline.

Open source →

Irish Data Protection Commission
Irish DPC transparency guidance

Official transparency requirements.

Open source →

OpenAI
OpenAI Europe Privacy Policy

Official external ChatGPT privacy and retention terms.

Open source →