Legal · Legal document
How semantecseo.com uses cookies and similar technologies.
This policy covers device storage and access on semantecseo.com and direct controlled flows. The exact live inventory remains subject to a production scan, provider confirmation, and consent testing.
Operative document
Semantec SEO Cookie and Similar Technologies Policy
Reviewed 15 August 2026
Owner: Kevin Maguire trading as Semantec SEO
1. Scope and controller
This policy covers cookies, local storage, pixels, tags, device identifiers, and similar technologies used on semantecseo.com and direct flows controlled by Kevin Maguire trading as Semantec SEO.
OpenAI controls technology on ChatGPT and OpenAI domains. Stripe, Authflow.ai, and other external providers control technology on their own domains or hosted flows.
2. What cookies and similar technologies do
These technologies can maintain a session, protect a request, remember a choice, support account access, process checkout, measure performance, diagnose errors, personalise an interface, or support advertising.
The legal result depends on the purpose, timing, provider, domain, duration, user request, and whether information is stored on or read from the device.
3. Consent rule
Irish ePrivacy rules normally require consent before storing or reading information on a device. Narrow exemptions may apply where the technology is necessary to transmit a communication or provide an online service explicitly requested by the user.
Non-essential analytics, preference, marketing, advertising, tracking, and similar technology must remain blocked before consent where consent is required.
4. Consent standard
Consent must be informed, specific, freely given, and expressed through a clear affirmative action. Scrolling, silence, continued browsing, or a preselected control does not provide valid consent.
Optional categories should be off by default. Accept and reject choices should be easy to find, and withdrawal should be as easy as the original choice.
5. Technology categories
| Category | Purpose | Normal consent position |
|---|---|---|
| Strictly necessary | Security, routing, session, requested account, checkout, consent record | May be exempt when strictly necessary |
| Preferences and functionality | Remember optional display or feature choices | Consent may be required |
| Analytics and performance | Measure visitors, routes, events, diagnostics, and performance | Consent normally required under Irish DPC guidance |
| Marketing and advertising | Advertising, attribution, remarketing, or cross-site profiling | Consent required |
| External platform | Technology on ChatGPT, Stripe, Authflow.ai, or another provider domain | Provider terms and user action apply |
6. Live inventory requirement
Before publication, the live site must be scanned before any choice, after accepting each optional category, and across account, entitlement, checkout, support, and embedded-provider flows.
The final inventory must state the technology name, provider, domain, purpose, category, duration, third-party access, trigger, consent state, and verification date. Unknown providers or durations must not be published as facts.
7. Confirmed and pending provider paths
Stripe supports checkout, billing, refunds, subscriptions, and fraud controls. Authflow.ai supports access and entitlement. OpenAI controls ChatGPT and OpenAI domains.
Hosting, CMS, cache, security, analytics, diagnostics, email, support, consent, and embedded-media providers remain pending until the production environment is verified.
8. Change or withdraw your choice
The live site should provide a persistent cookie-settings control that shows current category choices and allows optional categories to be accepted, rejected, or withdrawn without unnecessary friction.
Browser controls can also block or delete storage but do not replace the site's consent mechanism. Blocking essential technology may prevent a requested account or checkout function.
9. Retention and transfers
Each inventory item must state an actual session or persistent duration. Provider location, role, subprocessor use, retention, and transfer safeguards belong in the Privacy Policy and provider register.
10. Changes and contact
The policy and inventory should be reviewed after any change to tags, embeds, providers, analytics, advertising, checkout, account access, consent management, or website architecture.
Send cookie questions or observed pre-consent activity to privacy@semantecseo.com with the URL, date, browser, technology name where known, and screenshots or network evidence that do not expose another person's data.
Official and first-party references.
The published legal document remains subject to mandatory law, the order confirmation, and current provider terms.
Current Semantec SEO Cookie Policy
First-party cookie and provider baseline.
Irish DPC cookie guidance
Official consent, exemption, and withdrawal guidance.
OpenAI Cookie Policy
Official external platform cookie source.
Use the document that owns the question.
Specific policies control their own subject and should not be replaced by a summary elsewhere.
Owned route
Cookie overview
Plain-language consent and category summary.
Open route →
Owned route
Privacy Policy
Associated personal-data processing and provider roles.
Open route →
Owned route
Provider register
External provider identity and transfer records.
Open route →
Owned route
Data retention
Consent and technology retention criteria.
Open route →
Owned route
GDPR overview
Consent withdrawal and other rights.
Open route →
Owned route
Contact
Cookie and privacy reporting route.
Open route →