Legal · Legal document
How Semantec SEO processes personal data across the website, account, payment, support, and privacy routes.
This policy identifies the controller, data categories, purposes, lawful bases, providers, international transfers, retention criteria, rights, security, complaints, and the separate ChatGPT boundary.
Operative document
Semantec SEO Privacy Policy
Reviewed 15 August 2026
Owner: Kevin Maguire trading as Semantec SEO
1. Controller and contact
Kevin Maguire trading as Semantec SEO, Central Park, Clane, Ireland, is the controller for personal data where Semantec SEO determines why and how it is processed.
Privacy and data-rights requests should be sent to privacy@semantecseo.com. Product, account, billing, and cancellation support should be sent to support@semantecseo.com.
2. Scope and separate controllers
This policy covers personal data received or created through semantecseo.com, direct MIRENA access and entitlement, billing, support, privacy requests, security reports, and business communications controlled by Semantec SEO.
OpenAI controls ChatGPT account, chat, file, memory, training, and platform records under its own privacy terms. Stripe, Authflow.ai, and other providers may act as processors or independent controllers depending on the activity.
3. Personal data categories
Semantec SEO may process contact and identity details, account and entitlement information, subscription and billing records, support and privacy correspondence, website and device data, consent choices, security and fraud signals, business relationship information, and material you choose to send directly.
Semantec SEO should not receive full payment-card details from Stripe. Do not send passwords, authentication codes, secret keys, health data, legal secrets, or unnecessary sensitive personal data.
4. Purposes and lawful bases
| Purpose | Typical data | Lawful basis or role |
|---|---|---|
| Provide account and MIRENA access | Identity, email, entitlement, subscription status, access events | Contract and legitimate interests in secure delivery |
| Process payments and refunds | Billing identity, transaction, tax, refund and dispute records | Contract, legal obligation, and legitimate interests |
| Answer support and business messages | Contact details, message, relevant account or project context | Contract, steps at request, and legitimate interests |
| Operate and secure the website | IP, device, logs, security and diagnostic events | Legitimate interests and legal obligation where applicable |
| Manage privacy and legal requests | Identity, request, correspondence, evidence and response | Legal obligation and legitimate interests |
| Send required service notices | Account and contact details | Contract and legitimate interests |
| Send optional marketing | Contact and preference data | Consent or another lawful basis identified at collection |
| Establish or defend claims | Relevant account, transaction, communication and security records | Legitimate interests and legal claims |
5. MIRENA conversations in ChatGPT
OpenAI states that GPT builders cannot view individual conversations users have with their GPTs through the standard builder interface. Semantec SEO may receive information that a user sends directly through support or another disclosed route.
The confirmed Authflow entitlement action sends an email address and fixed paywall identifier to check active access; the current public record states that it does not send conversation prompts, drafts, uploaded files, or generated outputs. Any material change requires policy review.
6. Providers and recipients
Confirmed public providers include OpenAI for ChatGPT, Stripe for payment processing, and Authflow.ai for access and entitlement. Hosting, email, analytics, diagnostics, consent, support, and other providers must be verified from the live environment before final publication.
Data may also be disclosed to professional advisers, authorities, courts, regulators, acquirers, or other parties where required by law, necessary to protect rights, or connected to a legitimate business transaction with suitable safeguards.
7. International transfers
Some providers may process data outside Ireland or the European Economic Area. The applicable transfer mechanism may include an adequacy decision, standard contractual clauses, or another lawful safeguard.
The final provider register should identify provider legal entities, locations, roles, transfer mechanisms, and public privacy links. A generic provider category is not enough for final publication.
8. Retention
Personal data is kept only as long as needed for the purpose, contract, legal obligation, tax or accounting duty, security, fraud prevention, dispute, claim, consent record, or protection of another person's rights.
Category-level criteria are published in the Data Retention page. OpenAI and other providers control separate retention under their own terms.
9. Your rights
Where GDPR applies, you may have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint.
Requests are generally handled without undue delay and within one month, subject to lawful extension, identity verification, the rights of others, and applicable exceptions. The GDPR overview explains the process.
10. Cookies and similar technologies
The Cookie Policy governs storage or access on a device through semantecseo.com and direct flows controlled by Semantec SEO. Non-essential technology must not load before consent where consent is required.
OpenAI controls technology on ChatGPT and OpenAI domains. Stripe, Authflow.ai, and other provider domains have separate policies.
11. Security
Semantec SEO uses organisational and technical measures proportionate to the records and risks it controls, including access restriction, data minimisation, provider controls, incident handling, and secure payment and account providers.
No system is risk-free. The Security Overview states the public control boundary and does not claim unsupported certification or assurance.
12. Children
The service is not directed to children. Users must meet the age, account, and consent requirements in applicable law and OpenAI terms.
Do not provide children's personal data unless a lawful, authorised, necessary, and suitable route has been confirmed.
13. Changes and contact
The canonical policy applies from its effective date. Semantec SEO will review it after material changes to the product, providers, data flows, purposes, law, or user rights.
Questions, rights requests, complaints, and corrections should be sent to privacy@semantecseo.com. You may also complain to the Irish Data Protection Commission or another competent supervisory authority.
Official and first-party references.
The published legal document remains subject to mandatory law, the order confirmation, and current provider terms.
Current Semantec SEO Privacy Policy
First-party controller, provider, and data-flow baseline.
Irish DPC transparency guidance
Official transparency requirements.
OpenAI Europe Privacy Policy
Official external ChatGPT privacy and retention terms.
Use the document that owns the question.
Specific policies control their own subject and should not be replaced by a summary elsewhere.
Owned route
Data privacy overview
Plain-language controller and platform boundaries.
Open route →
Owned route
GDPR overview
Rights, timing, verification, and complaints.
Open route →
Owned route
Data retention
Category-level retention criteria.
Open route →
Owned route
Cookie Policy
Device storage, consent, inventory, and providers.
Open route →
Owned route
Provider register
Confirmed provider roles and missing evidence.
Open route →
Owned route
Data rights process
Operational request and response standard.
Open route →