The controller of your personal data within the meaning of Art. 4 point 7 of the GDPR is:
Visomedia Konrad Grodecki
ul. Trzebowiańska 9, 54-153 Wrocław
Tax ID (NIP): PL89427870
Email: info@sempuls.com
Phone: +48 518 080 457
Hereinafter referred to in this Policy as the "Controller" or "Sempuls". Sempuls is a SaaS platform for do-it-yourself SEO and AEO (Answer Engine Optimization), available at sempuls.com.
For matters related to the processing of personal data, you can contact the Controller by writing to info@sempuls.com with "GDPR" in the subject line, or by mail to the registered office address. We respond within 30 days of receiving your request.
We collect the following categories of personal data:
We process data for the following purposes and on the following legal bases (GDPR):
| Purpose of processing | Legal basis | Retention period |
|---|---|---|
| Providing the Sempuls service (contract) | Art. 6(1)(b) GDPR — performance of a contract | Duration of the account + 3 years |
| Invoicing and accounting | Art. 6(1)(c) GDPR — legal obligation | 5 years from the end of the tax year |
| Marketing of our own services (email) | Art. 6(1)(f) GDPR — legitimate interest | Until consent is withdrawn or you object |
| Analytics and product improvement | Art. 6(1)(f) GDPR — legitimate interest | 2 years |
| Establishing and defending legal claims | Art. 6(1)(f) GDPR — legitimate interest | Until the limitation period expires (usually 3 years) |
| System security and abuse detection | Art. 6(1)(f) GDPR — legitimate interest | 12 months (logs) |
To provide the service, we use the providers (sub-processors) listed below, to whom we entrust the processing of your data. Each provider is bound by data processing agreements (DPAs) that ensure GDPR compliance:
| Provider | Purpose | Processing location |
|---|---|---|
| SeoHost.pl (Poland) | Application hosting and database | EU (Poland) |
| Google LLC / Google Ireland Ltd. | OAuth Search Console, Business Profile API, Maps Geocoding API, Gemini AI | EU / USA (mechanism: Standard Contractual Clauses) |
| DataForSEO LLC | Data on SERP rankings, keywords, AI Overview, Local Finder | USA (SCC) |
| Anthropic PBC | AI content generation (Claude models) — descriptions, GMB posts, AEO audits | USA (SCC) |
| OpenAI / Perplexity / Groq (optional) | Checking citations in AI answers (AI Citations) | USA (SCC) |
| Payment provider (Stripe / PayU / Przelewy24) | Processing subscription payments | UE / USA (SCC) |
| SMTP provider (outgoing mail) | Sending transactional emails and notifications | UE |
We do not sell your data. We do not share it with third parties for marketing purposes.
Some providers (Google, DataForSEO, Anthropic, OpenAI) are based in the USA. Data is transferred to these entities on the basis of the Standard Contractual Clauses adopted by European Commission decision 2021/914, and in Google's case additionally on the basis of the Data Privacy Framework (EC decision of July 10, 2023). We apply additional technical measures (encryption in transit with TLS 1.3) and organizational measures (data minimization).
Under the GDPR, you have the following rights:
To exercise these rights, write to info@sempuls.com. We respond within 30 days.
Sempuls uses cookies and similar technologies (localStorage, sessionStorage). We divide them into three categories:
ai_share_sess), CSRF token, remembered selected project. The application does not work without them. Legal basis: legitimate interest — operating the service.You can change your consents at any time in the site footer ("Cookie settings") or in your browser settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Sempuls uses AI algorithms (including Claude models from Anthropic and Gemini from Google) to generate SEO content suggestions, AEO audits, Google Business Profile descriptions, and recommendations. These processes do not make decisions that produce legal effects concerning you or significantly affect your rights — they are only suggestions that you decide to implement or reject. We do not use automated profiling within the meaning of Art. 22 of the GDPR.
We apply the following protection measures:
Despite exercising due care, no system is 100% secure. In the event of a personal data breach, we will report it to the President of the UODO within 72 hours and notify the affected individuals if the breach may result in a high risk.
Providing data when registering an account is voluntary, but necessary to create an account and use Sempuls. Without an email address and password, we cannot create an account. Without invoice details, we cannot issue a billing document required by tax law.
Sempuls connects to your Google accounts only at your explicit request, using the OAuth 2.0 protocol. We never ask for your Google account password and have no access to it. You can disconnect the integration at any time.
| Permission (OAuth scope) | What we use it for |
|---|---|
| Google Search Console webmasters.readonly | Read-only access to search statistics for your verified sites: clicks, impressions, CTR, average position, queries, and URLs. We show this data in your dashboard, in reports, and in the keyword tracking module. |
| Google Analytics 4 analytics.readonly | Read-only access to statistics from your GA4 property: sessions, users, traffic sources, conversions. The data is used to show the results of your SEO efforts in the dashboard and in reports for you and your clients. |
| Google Ads adwords | Read-only access to your Google Ads accounts and the accounts you manage through a manager account (MCC): account list, campaign names and statuses, costs, impressions, clicks, conversions, and conversion value. We show this data in your dashboard (Ads module) and in reports so you can compare the results of paid campaigns with your SEO results. Sempuls does not create, change, or delete campaigns, budgets, or Google Ads account settings. |
| Google Business Profile business.manage | Managing your Google Business Profile at your command: reading profile data, statistics, and reviews, and publishing posts and updates that you approve in Sempuls. |
| Sign in with Google openid, userinfo.email, userinfo.profile | Creating and authenticating your Sempuls account: email address, full name, and profile picture. |
We only request the permissions necessary for the features you use. Integrations are independent — you can connect only the services you choose.
Sempuls's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:
We store OAuth tokens in the database in encrypted form and use them solely to regularly fetch data for your projects. We save data retrieved from Search Console and Analytics so we can show changes over time (ranking history, traffic trends).
You can disconnect an integration at any time in your project settings in the Sempuls dashboard — the token is then revoked and data fetching stops immediately. Independently of this, you can revoke the app's access directly in your Google account at myaccount.google.com/permissions.
We delete historical data retrieved from Google services when you delete the project or account in Sempuls, no later than within 30 days. You can request account deletion at any time by contacting us at the address given in the "GDPR contact" section.
We may update the Policy in the event of legal or technical changes, or changes to the service we provide. We will announce any material change by e-mail to registered users at least 14 days in advance. The current publication date is shown at the top of this page.