Trust · Trust disclosure
Personal data is kept only for a defined purpose, legal obligation, security need, or dispute period.
This schedule explains the retention criteria for website, account, billing, support, security, privacy, and provider-related records controlled or received by Semantec SEO.
Verified facts and boundaries.
These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.
Retention is category-specific.
A single period does not fit every record. Semantec SEO links retention to the purpose, legal basis, contract, account state, security need, tax or accounting duty, dispute period, consent status, and whether the record is needed to protect another person.
When a record is no longer needed, it should be deleted, anonymised, or retained only in a restricted form where a legal or evidential reason remains.
Current retention criteria.
| Record category | Retention criterion | Deletion or review trigger |
|---|---|---|
| Website and diagnostic logs | Period proportionate to operation, security, fraud prevention, and troubleshooting | Log purpose expires or security window closes |
| Account and entitlement records | Active access plus the period needed for account closure, dispute, fraud, and legal obligations | Account closes and residual obligations expire |
| Billing and transaction records | Statutory tax, accounting, consumer, chargeback, and dispute requirements | Applicable retention duty and dispute period expire |
| Support communications | Until the issue is resolved plus a reasonable follow-up or dispute period | Issue closes and no continuing obligation remains |
| Privacy and rights requests | As needed to respond, verify compliance, and handle complaint or legal risk | Compliance and limitation needs expire |
| Security reports and incident records | As needed to investigate, remediate, demonstrate control, and prevent recurrence | Risk and evidential need expire |
| Marketing preferences | Until withdrawal, objection, suppression need, or inactivity review | Consent withdrawn or purpose ends |
| Cookie consent records | As needed to demonstrate the choice and apply it | Consent expires, changes, or the record is no longer needed |
ChatGPT and external-provider retention is separate.
OpenAI controls retention for ChatGPT account, conversation, file, memory, training, and Temporary Chat records under its own terms and settings. Semantec SEO does not set those platform periods.
Stripe, Authflow.ai, hosting, email, and other confirmed providers may retain records under their own legal and service obligations. The provider register and Privacy Policy should identify the relevant role and source.
Legal hold and restricted retention.
Deletion may be delayed where a record is needed for a legal obligation, fraud prevention, security investigation, consumer dispute, tax or accounting requirement, defence of a claim, or protection of another person's rights.
A legal hold should be limited to the relevant record, reason, owner, and duration. It should not become indefinite general retention.
Backups and derived records.
A deleted record may remain temporarily in protected backups until the backup cycle replaces it. Backup access should be restricted and restoration should not silently return deleted data to active use.
Aggregated or irreversibly anonymised information may be retained when it no longer identifies a person. Pseudonymised data remains personal data when re-identification is reasonably possible.
Request deletion or clarification.
Email privacy@semantecseo.com with the record or account, date range, and request. Deletion rights are subject to the GDPR conditions and exceptions explained in the rights overview and Privacy Policy.
Check the controlling first-party and official sources.
These routes support the current public statement. External platform and legal sources remain subject to their own updates.
Semantec SEO Privacy Policy
Current first-party processing and retention record.
OpenAI Europe Privacy Policy
Official OpenAI retention principles for EEA users.
Irish DPC guidance
Official Irish data-protection guidance and accountability sources.
Move to the page that owns the next question.
Each route has a separate job so company, product, trust, legal, and compliance information does not collapse into one promotional page.
Owned route
Privacy Policy
Detailed processing and retention criteria.
Open route →
Owned route
GDPR overview
Deletion, restriction, access, objection, and complaint rights.
Open route →
Owned route
Provider register
External provider roles and separate retention sources.
Open route →
Owned route
Data rights process
Request intake, verification, search, review, and response.
Open route →
Owned route
Cookie overview
Consent records and device-storage boundaries.
Open route →
Owned route
Contact
Privacy and data-handling contact route.
Open route →