SEMLY.AI PRIVACY POLICY

Administrator and DPO

  1. The administrator of personal data is Droplo Spółka z ograniczoną odpowiedzialnością based in Wałbrzych at ul. Uczniowska 16, 58-306 Wałbrzych, NIP 8863009117, REGON 383546529, registered in the National Court Register maintained by the District Court for Wrocław-Fabryczna in Wrocław, IX Economic Department, under KRS number 0000789369, hereinafter referred to as "Administrator" or "Semly".
  2. We have appointed a Data Protection Officer in the person of Paweł Kobierzewski, who can be contacted at iod@semly.ai or by mail: ul. Uczniowska 16, 58-306 Wałbrzych.
  3. The policy describes the processing of data related to the Semly website and platform, including integration with ChatGPT via MCP and the use of external AI services.

Purposes and legal bases for processing personal data

  1. We process data to provide the Semly.ai service, including account creation and management, data verification, payment processing, and executing operations requested by the user through authorized ChatGPT/MCP integration. The legal basis for processing necessary for the performance of a contract with the data subject is Article 6(1)(b) of the GDPR. We use data from client representatives and employees to manage customer relations based on the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR). Data necessary for fulfilling accounting and financial reporting obligations are processed based on Article 6(1)(c) of the GDPR.
  2. We process information necessary to ensure cybersecurity, access control, proper functioning of the platform, and its development, including system logs used for diagnostics and error handling. The basis is the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR).
  3. We process data to establish, pursue, or defend claims. The basis is the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR).
  4. We use contact data to send information about service updates, changes to the Terms of Service and Privacy Policy, and to handle technical inquiries. The basis is the legitimate interest of the Administrator in ensuring communication related to the service (Article 6(1)(f) of the GDPR).
  5. To the extent permitted by law, we process contact data for direct marketing of Semly services based on the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR). If the use of a particular communication channel requires separate consent, we obtain it before use. We limit profiling to visitors of the Semly website and use it to tailor advertisements and marketing communications to their interests. Profiling using optional cookies and similar technologies is based on consent (Article 6(1)(a) of the GDPR), which can be withdrawn in the cookie settings on the site. User command contents, responses, and articles processed by the ChatGPT/MCP integration are not used for Semly marketing or profiling.
  6. If you give separate consent, we will use contact data to send newsletters (Article 6(1)(a) of the GDPR). The use of optional cookies and similar technologies is also based on required consent. Files necessary for the operation of the site and selected user functions are described in the cookie section.

Scope of processing personal data

  1. During registration and account management, we collect identification data such as first name, last name, NIP, and REGON, contact data such as email address and phone number, company data such as name, address, and website, and billing data, including transaction history. We also process technical data related to the use of the platform, such as IP address and login time.
  2. We use the email address provided via chat on the platform to respond to inquiries, handle requests, and provide feedback.
  3. We process product data from the feed, including names, descriptions, technical parameters, and other product information. If this data concerns individuals, we process it in accordance with the GDPR.
  4. We collect IP addresses of users redirected from AI models to the client's store for traffic analysis and service usage statistics.
  5. The scope of data related to ChatGPT/MCP integration is described in the next section. In connection with visiting the website, we may also process cookie identifiers and information about how the site is used and interests, as described in the cookie section and granted consents.
  6. Providing data required for concluding and settling the contract and fulfilling legal obligations is necessary for these purposes. Other data, especially data provided for the newsletter, is provided voluntarily. Using the ChatGPT/MCP integration is voluntary; its operation requires authorization of the connection and provision of data necessary for the selected operation.

AI, ChatGPT, and MCP integrations

Integration operation

Semly allows connecting an account with ChatGPT via the MCP (Model Context Protocol). The integration enables the use of Semly functions from within ChatGPT within the granted permissions and the user's access to the account and selected brands.

Data received and shared

In connection with the use of the integration, we process:

  1. Connection and authorization data, including user account identifier, selected brands, scope of granted permissions, OAuth tokens, and information about the validity or revocation of access.
  2. Parameters of tool calls and content provided from ChatGPT to perform the task, including commands, briefs, and materials intended for creation, modification, or saving in Semly.
  3. Data returned from Semly to ChatGPT, depending on the task: information about brands, reports, monitored prompts and responses from AI systems, recommendations, articles, briefs, and available analytical data.
  4. Technical data regarding the handling of connections and tool calls, necessary for diagnostics, access control, and ensuring security.

These materials may contain personal data if they have been included in the content provided by the user or resources available in Semly. Transmitting content for storage in Semly means its retention according to the rules regarding content and account data, not solely for the duration of the connection.

Do not include passwords, API keys, authentication codes, or other access secrets in commands and content sent to tools. The connection of the account occurs during the authorization process, not by providing this data in conversation.

Purposes and recipients

We use the data to authenticate the user, verify permissions, execute requested operations, transmit results to ChatGPT, and ensure security and technical support for the integration. The legal bases are defined in the section on purposes and legal bases for processing.

Results returned by Semly tools are transmitted to OpenAI as the provider of ChatGPT. Processing in ChatGPT is also subject to the terms and privacy policies of OpenAI applicable to the service and user account.

If the task requires generating or analyzing content by an external AI system, data necessary for that task may be shared with providers of the following services:

  • OpenAI API;
  • Google Gemini API;
  • Anthropic API;
  • xAI API.

The scope of data transfer depends on the function used and may include commands, briefs, content subject to analysis or development, and context necessary to perform the task. Not every operation requires data to be shared with all listed providers.

At the user's request, articles and data necessary for their storage or publication may be transmitted to the connected WordPress or Shoper. The operation of saving or publishing requires appropriate permissions.

Hosting

The Semly database, logs, and backups are stored in Poland using the services of IQ PL Sp. z o.o., ul. Geodetów 16, 80-298 Gdańsk. External AI providers and ChatGPT may process data outside Poland and the European Economic Area, under the terms described in the data sharing section.

Permissions and revocation of access

During authorization, the user selects brands available for integration and separately grants permissions for write operations. The integration respects the user's permissions in Semly, including access restrictions for employees. Granting permissions for connection or writing is the authorization of the integration action and does not imply consent for marketing.

The user can revoke access in the Semly panel in the Settings → MCP section. Revocation of access blocks further use of the given connection.

Disconnecting the integration does not automatically delete content in Semly, materials previously transmitted to WordPress or Shoper, or earlier conversations in ChatGPT. Revocation of access and requests for data deletion are separate actions.

Marketing, profiling, and model training

Semly does not use command content, responses, or articles from users processed by the integration for Semly marketing, user profiling, or training models by Semly. Profiling of visitors to the Semly website is a separate activity described in the records regarding marketing and cookies.

The rules for data use by external AI providers result from the terms applicable to the used API, contained contracts, and service configurations. Processing in ChatGPT is subject to the rules applicable to the user account. The assurance regarding Semly practices does not constitute an assurance of all practices of these providers.

Rights regarding processed data

Under the terms and within the limits provided by the GDPR, the person whose data we process has the right to:

  1. Access personal data and receive a copy of it.
  2. Rectification or completion of data.
  3. Request deletion of data in cases specified in Article 17 of the GDPR.
  4. Request restriction of processing.
  5. Data portability provided to the Administrator when processing is carried out in an automated manner based on consent or contract.
  6. Withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
  7. Object to processing based on legitimate interest for reasons related to the particular situation of the person. In the case of direct marketing, including related profiling, an objection can be raised at any time without justification of a particular situation.
  8. Lodge a complaint with the President of the Personal Data Protection Office. Information on how to lodge a complaint can be found at uodo.gov.pl.

Requests regarding personal data can be sent to iod@semly.ai or hello@semly.ai, as well as by mail to the Administrator's address. Consent for optional cookies and similar technologies can also be withdrawn in the cookie settings on the site.

Request for data deletion

In the request, please specify the account and the scope of the request, e.g., MCP connection data, specific content, or account data. Do not send passwords or access tokens.

In case of justified doubts, we may ask for information necessary to confirm the identity of the requester. In the case of a request to delete organizational account resources, we also check the authorization to dispose of these resources.

We provide information on how the request has been handled without undue delay, generally within a month of its receipt. In the case of a complex request or a large number of requests, the deadline may be extended by an additional two months under the terms specified in the GDPR. We inform about the extension and its reasons within the first month. If deletion of specific data is not possible for legal reasons, we explain the scope and basis for their further retention.

Deleting data in Semly does not automatically delete earlier conversations in ChatGPT or materials published in WordPress or Shoper. Deleting this data requires using the functions or procedures of the relevant service. This does not limit Semly's obligations to notify recipients of the deletion of personal data if such obligations arise from the law.

For how long we process personal data

We store personal data only for as long as necessary to achieve a specific purpose:

  1. Account and service management data - for the duration of the account or service use, taking into account requests for deletion and deadlines specified below.
  2. Billing and accounting data - for periods required by applicable laws.
  3. Data processed based on consent - for the time needed to achieve the given purpose, no longer than until the consent is withdrawn, unless another legal basis requires further retention of specific data.
  4. Data used for direct marketing - until an objection is raised or the relevant consent is withdrawn, depending on the basis for processing.
  5. Data necessary to establish, pursue, or defend claims - for the period during which relevant claims may be pursued, solely to the extent necessary for that purpose.

For data related to ChatGPT/MCP integration, we apply the following terms:

  1. OAuth authorization is valid for 90 days, unless the user revokes access earlier.
  2. OAuth tokens and related connection records are deleted within 30 days of revocation or expiration of access. Revocation or expiration of access blocks further use of the connection, regardless of the record deletion deadline.
  3. Technical logs are stored for a maximum of 30 days from their creation.
  4. Security and authorization logs are stored for a maximum of 90 days from their creation. Data related to a documented incident may be stored longer, solely to the extent and for the time necessary to clarify it or establish, pursue, or defend claims.
  5. Content and business data in Semly, including reports, articles, and briefs, are stored for the duration of account use. We delete them from the main system within 30 days of receiving an effective deletion request or account closure, taking into account applicable deadlines and legal exceptions.
  6. Data remaining in backups are stored for a maximum of 90 days from their deletion from the main system.

The validity of OAuth authorization does not determine the retention period of articles, reports, or other account data. Disconnecting the integration does not automatically delete these resources.

Data remaining in backups are not used for ongoing service provision. Access to them is limited to the needs of securing and restoring the system. In the case of restoring a backup, we again apply previously executed data deletions.

If a legal obligation or the need to establish, pursue, or defend claims requires longer retention, it only includes data necessary for that purpose and the appropriate period for it. This does not automatically extend the retention of all account or integration data.

The above terms apply to data stored by Semly. Data transmitted to ChatGPT, API providers, and connected WordPress or Shoper may be subject to separate periods resulting from the rules of the relevant service and contained contracts. The periods of cookie operation are described in the cookie section.

Who we share personal data with

We share data for the purposes described in this policy and to the extent necessary to achieve them. Recipients may include:

  • hosting providers, including IQ PL Sp. z o.o., ul. Geodetów 16, 80-298 Gdańsk;
  • providers of marketing and analytical tools, to the extent appropriate for the tool and basis for processing; the use of optional cookies and similar technologies requires appropriate consent;
  • providers of email messaging tools;
  • individuals cooperating with us under civil law contracts if data transfer is necessary for the tasks performed;
  • internet service providers, e.g., Google;
  • providers of software for customer and potential customer service, including CRM tools and telephone support;
  • payment service providers, including Stripe and PayU, when you use their services to pay for Semly;
  • providers of invoicing software and entities providing accounting and bookkeeping services;
  • domain registrars, SSL/TLS certificate providers, and legal services;
  • entities providing courier or postal services if required by correspondence;
  • OpenAI as the provider of ChatGPT, receiving results returned by authorized Semly tools;
  • providers of content generation and analysis services through OpenAI API, Google Gemini API, Anthropic API, and xAI API when the function uses these services;
  • operators and providers of connected WordPress or Shoper when the user requests to save or publish content;
  • other entities providing technical services necessary for the operation of the platform and public authorities if disclosures are required by law.

Data transfer outside the European Economic Area

Using ChatGPT, external AI services, and other services described in this policy may involve transferring personal data outside the European Economic Area, particularly to the United States, despite the Semly database, logs, and backups being stored in Poland.

The basis for the transfer is determined for a specific recipient and service. It may be a relevant decision of the European Commission stating an adequate level of protection or appropriate safeguards, particularly standard contractual clauses approved by the European Commission, along with an assessment and additional protective measures if required.

In the case of using the EU–US Data Privacy Framework, we verify whether the recipient has active certification covering the relevant scope of processing. Information about the basis for a specific transfer and how to obtain a copy of the applied safeguards can be obtained at iod@semly.ai.

Security of personal data

  1. We implement technical and organizational measures appropriate to the nature of the data, purposes of processing, and risks to the individuals whose data are concerned. These measures are intended to protect data against unauthorized access, disclosure, alteration, loss, or destruction.
  2. In particular, we apply safeguards for data sets against unauthorized access, encryption of transmissions using SSL/TLS, authentication data safeguards, and access control to the panel using individual login data.
  3. Access to the integration is limited by the permissions granted and the rights of the user on the Semly account. Revocation of access prevents further use of the given connection.

Automated decisions

Profiling of visitors to the Semly website for advertising and marketing purposes is carried out under the principles described in the records regarding marketing and cookies.

The Administrator does not make decisions based solely on automated processing, including profiling, which have legal effects concerning the individual or significantly affect them in a similar way within the meaning of Article 22 of the GDPR. Content processed by the ChatGPT/MCP integration is not used for profiling visitors.

Changes to the Privacy Policy

  1. We review and update the policy in connection with changes in services, methods of data processing, or legal regulations.
  2. The current version is published on the Semly website. When published, we indicate the date of its validity.
  3. We communicate significant changes to users as part of service-related communication.

Cookie Policy

Semly uses cookies and similar technologies to ensure the operation of the site and platform, support selected functions, and - to the extent of granted consents - analytics, advertising, and profiling of visitors to the Semly website.

This part of the policy applies to websites and applications operated by Semly or on its behalf. Use of third-party services, including social media platforms, is also subject to the rules of those entities.

Consents and cookie settings

On the site, we use a consent management platform (CMP). It allows obtaining information about the cookies used and partners, granting or withdrawing consent for optional technologies, and changing previous choices.

Necessary technologies serve the operation of the site and functions selected by the user. Optional analytical, advertising, and profiling technologies are activated upon obtaining the required consent. Refusal of consent does not block the use of functions that do not require these technologies. Consent can be changed or withdrawn in the cookie settings on the site.

User command contents, responses, and articles processed by the ChatGPT/MCP integration are not used for profiling visitors to the site.

What are cookies?

Cookies are data, usually small text files, stored on the user's device. They can enable device recognition, session maintenance, and settings retention. They usually contain the source name, duration, and identifier.

Types and durations

  • Session cookies are temporary and operate for the duration of the session, according to their configuration.
  • Persistent cookies remain on the device for the period specified in their parameters or until deleted by the user.
  • First-party cookies come from Semly, while third-party cookies come from providers of used tools. This distinction is independent of the division into session and persistent cookies.

Information about the technologies used, providers, and durations is available in the cookie settings on the site. Third-party cookies are also subject to the rules of their providers.

Can cookies be associated with the processing of personal data?

Cookies and similar technologies may contain identifiers or enable the collection of information that alone or in combination with other data constitutes personal data. The scope of processing depends on the technology and purpose of its use. Not all statistical data is anonymous; if they allow identifying a person, we apply the principles of personal data protection to them.

Purposes of using first-party cookies

Depending on the type of technology and the appropriate basis for processing, we use cookies for:

  1. Authenticating the user and maintaining the session.
  2. Ensuring the operation and configuration of selected functions.
  3. Managing the affiliate program and verifying sources of visits.
  4. Creating statistics and improving the structure and operation of services.
  5. Retaining settings and adapting the site to preferences.
  6. Analyzing the way the site is used.
  7. Presenting advertisements tailored to the interests of visitors to the site, within the required consent.
  8. Ensuring the security of using the services.

Purposes of using third-party cookies and tools

  1. Analytics of site usage, e.g., Google Analytics.
  2. Presenting advertisements, including those tailored to the preferences of visitors to the site, using Google Ads, TikTok Ads, YouTube Ads, and Meta Ads.
  3. Integration with social media services such as Facebook, X, LinkedIn, Instagram, YouTube, and TikTok.
  4. Communicating with users and providing information about services, e.g., via Gleap Chat.

Optional technologies of these providers are used to the extent of consents granted by the user. Detailed information about the tools available on the site can be found in the cookie settings.

Browser settings

The user can also change the browser settings to delete or block cookies. Blocking necessary technologies may limit the operation of some functions, e.g., logging in. Instructions for managing cookies are available in the browser settings and documentation of its provider. Browser settings do not replace the ability to withdraw consent in the CMP.