Semantio Platform Privacy Policy

    This document sets out the principles for the processing and protection of personal data of visitors to the website semantio.pro and users (subscribers) of the application app.semantio.pro (hereinafter collectively referred to as the "Platform").

    1. Who is the controller of your data?

    The controller of your personal data collected in connection with the use of the Platform is Brand Semantics Prosta Spółka Akcyjna with its registered office in Warsaw, at ul. Puławska 77, 02-595 Warsaw, registered under KRS number: 0001222755, using NIP number: 5214154430 (hereinafter "the Company" or "the Controller").

    For all matters related to the processing of personal data and to exercise your rights, you can contact us at the e-mail address: office@brandsemantics.eu.

    2. What data do we process, for what purpose, and on what legal basis?

    The rules for processing your data vary depending on the relationship you have with us:

    Providing data in the application registration form is a condition for concluding a service agreement (SaaS subscription). Failure to provide basic data (including payment requirements) results in the inability to open an account. In contact forms, providing data other than an email address is always optional.

    3. To whom do we transfer your data (Sub-processors)?

    The Semantio Platform is an advanced technological service. To ensure the highest quality, reliability, and analytical capabilities (including AI), we entrust data processing to specialised third parties (Sub-processors):

    • Supabase, Inc. / Vercel, Inc. – providers of the core server infrastructure (databases, code execution environments, hosting), ensuring the continuity of application operation and information storage.

    • Stripe, Inc. – certified payment service operator handling the subscription model and invoicing. Brand Semantics does not directly collect or store your payment card data.

    • LLM model providers (e.g., Google LLC, OpenAI, Anthropic) – entities providing generative artificial intelligence programming interfaces, analysing submitted messages (prompts) to create analytical reports (while adhering to policies guaranteeing that this data is not used to train public models).

    • GitHub, Inc. / Resend / Mailchimp – providers of systems for managing transactional and marketing email notifications and operational support.

    • Other companies providing us with marketing and analytical tools (based on your consent to cookies).

    Data transfers to third countries (outside the EU/EEA)
    Due to the global nature of our technology providers (including cloud service providers based in the USA), your personal data may be transferred to countries outside the European Economic Area. The Company guarantees that such transfers take place with strict protection measures. The legal basis for transfers to entities in the USA is primarily the European Commission's adequacy decision issued under the Data Privacy Framework (DPF) programme. In other cases or for entities outside the DPF framework, the transfer is secured by implementing binding Standard Contractual Clauses (SCCs) issued by the European Commission.

    4. Data Retention Period

    We store data for as long as necessary to achieve the purposes for which it was collected:

    • In the case of a SaaS agreement – for the duration of account activity, and then, if suspended, until permanent deletion. We have implemented innovative Data Wipe mechanisms on the platform, deleting monitoring history and identifiers after 90 days of non-payment. Full account deletion, if not requested by you earlier, is carried out systemically after 24 months of complete inactivity.

    • For marketing purposes (Newsletter) – until consent is withdrawn or an objection is raised. Subscriber addresses that have not opened any messages for over 18 months may be systematically removed from contact databases.

    • NOTE – Anti-Abuse Registry (Trial Abuse Registry): To protect against repeated, unlawful use of the free trial period, based on a legitimate legal interest (Article 6(1)(f) GDPR), we store unique hashes (cryptographic digests) of email addresses and Stripe payment identifiers for a period of 36 months from the moment the account is deleted. During this time, this data is used exclusively for backend verification during attempts at subsequent registration.

    5. Cookies, Cross-Domain Tracking, and Profiling

    Our Platform uses cookies (small text files) and similar technologies. Our consent management system operates across domains (Cross-Domain) within the common ecosystem of the marketing website and the application environment itself, meaning that your chosen privacy preferences are maintained when seamlessly transitioning between systems.

    We collect cookies categorised as follows:

    1. Essential cookies: Mechanisms guaranteeing basic defence against network attacks (e.g., Cloudflare CAPTCHA verification, query limiting), files maintaining secure user sessions in the application (generated by the authorisation system), and consent manager scripts. These files cannot be disabled.

    2. Statistical analytics (Google Analytics, Hotjar, Inspectlet, Islaymetrics): Collect anonymised information (based on, among other things, a truncated IP address) allowing us to understand how users navigate pages (heatmaps, number of visits), thereby improving the Platform's UX architecture.

    3. Marketing and Social Media (Meta Pixel, Google Ads, LinkedIn Insight Tag, X Pixel): Tools used for remarketing and behavioural advertising purposes. They inform global social media platforms about visits to specific areas of the Semantio Platform, allowing us to display more relevant advertisements in other parts of the Internet. The respective advertising platforms use this data for profiling, matching advertisements to profiles identified in their systems.

    4. Embedded content (e.g., YouTube): The display of videos embedded from external portals on the Semantio Platform is subject to a "placeholder" system. Until you actively consent to their playback (by clicking the activation component), we do not send any video logs to external corporations. Consent given to display a video involves the storage of tracking cookies from that portal on your device.

    How to manage cookie consents?
    You can return to the preferences expressed during your first visit at any time, modifying or rejecting individual sets of cookies. Simply click the "Manage cookies" link located in the footer of every page of our Platform. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

    Legal note on automated processing: Your personal data may be subject to profiling for the purpose of personalising marketing content sent, however, it will not be used to make decisions based solely on automated processing that could produce significant legal effects concerning you.

    6. Your Rights

    In accordance with GDPR requirements, we guarantee you the ability to exercise the following rights free of charge:

    • Right of access: You can request information about the data processed about you.

    • Right to rectification: You can update your data at any time, either through the application or by contacting us.

    • Right to erasure (right to be forgotten): If we do not have a strong, alternative legal basis for retaining them (e.g., the aforementioned fraud registry or accounting obligations).

    • Right to restriction of processing and data portability.

    • Right to object: To the processing of data based on our legitimate interest (including against the use of email for informational and offer communication or against profiling).

    • Complaint to the Supervisory Authority: You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) if you believe that our actions violate applicable legal standards.