New-customer offer: 20% off for the first 3 months – with the code RivalEyeGo1 · order by 31 December 2026.See pricing

Privacy policy

This English translation is provided for convenience. The German version is the legally binding one.

1. Controller

SEMIA, owner Samir Gassara, Wolfhager Straße 341, 34128 Kassel, Germany
Email: contact@semia-agent.de · Phone: +49 (0) 155 1038 9104
See also the imprint.

2. Visiting the website

When you visit the website, technically necessary data (IP address, time, page requested, browser) is processed in server log files by our hosting provider Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. This data is technically necessary and is not merged with other data sources. Legal basis: Art. 6(1)(f) GDPR (secure and stable operation). The log files are deleted automatically once the technically necessary period has expired. A data processing agreement under Art. 28 GDPR is in place with the hosting provider.

3. Fonts

This website does not load any fonts from third-party servers. It uses the system fonts installed on your device or fonts delivered locally from our server.

4. Contact and order forms

We process information from forms (company, website, area, lines of business, name, email, phone; in the order form also the billing address, VAT ID or tax number and any promo code entered) in order to handle your request and to set up the subscription. Legal basis: Art. 6(1)(b) GDPR. The information is stored on our server at the hosting provider (see section 2) and forwarded to us by email. After you submit a form, we send an automatic confirmation of receipt to the email address provided. We delete the information as soon as the request has been dealt with and no statutory retention obligations remain. To protect against abuse, we store a pseudonymized short value (hash) of your IP address with every request, not the IP address itself, and limit the number of requests per hour (Art. 6(1)(f) GDPR).

If you arrive via an ad or a link with campaign information in the address, we store this information with your request – as described in section 9 under “campaign source”. So that you do not have to retype anything after an error message, your browser remembers your entries until you close the tab (session storage of the browser). This temporary storage remains on your device.

5. Subscription, invoice and new-customer discount

For the subscription we process the information from the order form, including the billing address and your company’s VAT ID or tax number. We need them to issue invoices and to show the value-added tax correctly (Art. 6(1)(b) and (c) GDPR). Payment is currently made by invoice and bank transfer; no online payment service provider is used. We do not collect card data. We create invoices automatically, send them to you by email as a PDF and show them to you in the customer area. We retain invoice data in accordance with commercial and tax law requirements (up to 10 years).

Verification of the VAT ID: We verify VAT identification numbers from EU member states via the VAT Information Exchange System (VIES) of the European Commission. For this purpose we transmit the number and the country to this service. Legal basis: Art. 6(1)(c) and (f) GDPR (correct invoicing).

New-customer discount – protection against multiple use: We grant the new-customer discount only once per company. To check this, when an order is placed with a promo code we compare the tax number, the domain of the website, the email address and its domain as well as the company name and postal code with earlier orders. For this we store short values (hashes) of this information for every redemption, formed with a secret key; the short values do not contain the information in plain text. We keep them even after a cancellation or after the deletion of the customer account so that the discount is not granted again. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing misuse of the discount).

6. Monitoring of public data (RivalEye service)

To provide the service, we process publicly accessible information about competitors (websites, directories, review signals). Insofar as personal data (e.g. the names of owners in an imprint) is processed in the course of this, this is done on the basis of Art. 6(1)(f) GDPR (legitimate interest in market monitoring); we limit ourselves to what is necessary and do not store complete copies of pages permanently.

7. AI services

To create the reports we use AI providers as processors: Anthropic PBC, San Francisco, USA (Claude); OpenAI Ireland Ltd., Dublin, Ireland, or OpenAI, L.L.C., San Francisco, USA (ChatGPT); Google Ireland Limited, Dublin, Ireland, or Google LLC, Mountain View, USA (Gemini). We transmit the observation data needed for the analysis and your company details. Transfers to third countries take place on the basis of standard contractual clauses or the EU-US Data Privacy Framework, where applicable. How the AI Council is used in the free Competitor Check and which data it receives there is described in section 9.

We also use Claude by Anthropic for the AI assistant on the website (see section 10) and when you ask your agent questions in the customer area. In the customer area we transmit your question, the conversation history and the necessary information from your current report for this purpose.

8. Reach measurement without cookies

We measure ourselves how our website is used – without cookies, without third-party services and without user profiles. This website does not set any advertising or tracking cookies and does not use Google Analytics. The only cookie on the website is set by the customer area after you log in; it is technically necessary (see section 12).

What we count: page views with the page requested, the domain of the website you come from, the language and the device class (phone, tablet or desktop); campaign information from the address (utm_source, utm_medium, utm_campaign – for click identifiers from Google or Facebook only whether one was present); in addition individual events: clicks on buttons and contact links, forms started and submitted (without their content), videos started, the scroll depth and the approximate time spent on the page.

No storage of the IP address: So that we do not count visitors twice on the same day, we form a short value (hash) from the IP address and the browser identifier with a secret random value that changes daily. We do not store the IP address itself. We delete the short values of a day on the following day; after that only counts remain. For the measurement we store nothing on your device, and we do not recognize you on another day.

Objection via browser signal: If your browser sends the signal “Do Not Track” (DNT) or “Global Privacy Control” (GPC), the measurement does not take place – nothing is transmitted in that case.

Purpose and legal basis: We want to understand which pages and which advertising lead to inquiries, and to improve the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a data-minimizing reach measurement). You can object to the processing (Art. 21 GDPR) – most easily via the browser signal.

Recipients and storage period: The counts are stored on our server at the hosting provider (see section 2). We do not pass them on to third parties. We delete counts after 25 months.

Session storage of the browser: For convenience functions the website uses the session storage of your browser – for form entries, the chat history, a running Competitor Check and so that a notice window appears only once. This information remains on your device and disappears when you close the tab. We do not set cookies for this.

Local storage in the online report: In the online report your browser remembers in its local storage which competitors you have shown or hidden. This information remains on your device, is not transmitted to us and stays there until you delete the website data in your browser.

9. Free Competitor Check

When you use the free Competitor Check, we process:

  • your entries: the address of your website, up to three competitor websites, your email address and your statement that you are inquiring on behalf of a business;
  • the results of the check: the information found publicly on the websites entered (e.g. the page title, whether there is an imprint link) and the points and actions calculated from it as well as the texts the AI Council writes from it;
  • the campaign source: if you arrive via an ad or a link with campaign information in the address (utm_source, utm_medium, utm_campaign, utm_content, utm_term), we store this information with your request – and also whether the address contained a click identifier from Google or Facebook (gclid, fbclid), but not the identifier itself. The page reads the information only from the current address; we do not set any cookies for this and store nothing on your device;
  • your IP address only as a short value: to protect against abuse and to limit the number of checks, we store a short value (hash) of your IP address formed with a secret key, not the IP address itself.

Purpose: to create the report you requested and send it to you, to answer your request and follow-up questions, to prevent abuse and – via the campaign source – to see which advertising and which links lead to inquiries. Providing your email address is necessary; otherwise we cannot send you the report.

Legal basis: Art. 6(1)(b) GDPR for the report you requested; Art. 6(1)(f) GDPR for the protection against abuse and the limiting of requests (legitimate interest in secure operation and in nobody having reports sent to other people’s addresses) and for the campaign source (legitimate interest in measuring the success of our advertising without cookies and without user profiles). For our daily statistics we count checks per campaign without email and IP addresses.

Queue and confirmation by email (double opt-in): If a lot of checks are running, your request waits briefly in a queue on our server. After the check we send you an email with a confirmation link. After you have confirmed the request via this link – and not before – the AI Council deliberates on the results (see below), then we create the PDF and send it to your address. The report ends with brief information about the RivalEye subscription; we do not send you any further promotional emails. A copy of the report or a short version of it goes to us so that we can answer follow-up questions.

Retrieval of the websites entered: For the check, RivalEye retrieves the public pages of the websites entered at most once per check – robots.txt (also with or without “www.” and that of the address to which a homepage redirects), the homepage (alternatively over http:// or with or without “www.”), a redirect test from http to https, llms.txt and the sitemap (for a sitemap index, up to 2 sub-sitemaps of the same domain) – and respects the robots.txt in doing so (how to recognize these requests). If these pages contain personal data, such as the names of owners, we evaluate them only insofar as this is necessary for the checks; we do not store complete copies of pages. So that further checks with the same website do not retrieve it again, we briefly cache the result per website (the information found, not a copy of the page): it is reused for at most 6 hours and then deleted during the next automatic cleanup. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the market monitoring requested).

AI Council in the check: After your confirmation, three AI services write and check the texts of your report (summary, assessments and actions): Claude by Anthropic writes the draft, ChatGPT by OpenAI checks it, and if there are objections Gemini by Google decides. The AI services do not change points, measured values or ranking. For this we transmit to them only measured data of the websites entered and the results calculated from it: addresses of the websites, points, findings and the information found publicly there, such as page title, page description and main heading. We do not transmit email addresses or IP addresses – neither yours nor any that appear on the websites; they are filtered out before transmission. The AI services do not retrieve the websites themselves.

Recipients: Anthropic PBC, San Francisco, USA (Claude); OpenAI Ireland Ltd., Dublin, Ireland, or OpenAI, L.L.C., San Francisco, USA (ChatGPT); Google Ireland Limited, Dublin, Ireland, or Google LLC, Mountain View, USA (Gemini). They process the data on our behalf as processors (Art. 28 GDPR). We base transfers to the USA on the EU-US Data Privacy Framework (adequacy decision of the EU Commission, Art. 45 GDPR) insofar as the recipient is certified under it, otherwise on standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR). Legal basis: Art. 6(1)(b) GDPR (the report you requested) and, insofar as the measured data contains information about third parties, Art. 6(1)(f) GDPR (legitimate interest in the market monitoring requested). If the AI Council’s daily quota has been reached or a service does not respond, you receive the rule-based report; the PDF then says so.

Storage period: Unconfirmed requests become invalid after 48 hours and are then deleted during the automatic cleanup, which runs at least once a day. We store confirmed requests with their results for 30 days and then likewise delete them during this cleanup; in the first 7 days after confirmation you can retrieve the report again via the link. We do not store the PDF itself; it is generated anew from the stored results each time it is retrieved (without asking the AI services again). The campaign source is deleted with the request; the daily counts per campaign do not contain any personal data. We treat the confirmed request (email address, websites entered, result in short form, campaign source) and our copy of the report like other requests (see section 4). The short values used to limit requests are deleted automatically after the blocking period has expired.

Hosting and email: All data is stored on our server at the hosting provider (see section 2). The emails are sent via its mail server. The check does not use cookies; the reach measurement from section 8 applies to the page. We do not add your email address to any newsletter.

10. AI assistant on the website (chat)

On the website you can ask the RivalEye assistant questions. It is an AI assistant, not a human – this is also stated in the chat window. As long as you do not send a message, nothing is transmitted. You do not need an account.

Data processed: your message, the last messages of the conversation (so that the answer fits the history), the language and the page on which you use the chat. Please do not enter any sensitive data in the chat, for example health data, passwords or bank details.

Recipient: For the answer we transmit this information to Anthropic PBC, San Francisco, USA (Claude). Anthropic processes it on our behalf as a processor (Art. 28 GDPR). What is stated in section 7 applies to the transfer to the USA. If the AI service is not reachable or the daily quota has been reached, the assistant answers from a fixed list of answers; nothing goes to Anthropic in that case.

Storage period: Your browser stores the history only for the open tab (session storage). On our server we log for each question the time, the language, the page and the question in shortened form (at most 300 characters); we make email addresses and phone numbers in it unrecognizable. We do not store your IP address or a session identifier with it. We delete these logs after 30 days. To protect against abuse we limit the number of messages; for this we use a short value (hash) of your IP address, which is deleted after the blocking period has expired.

Purpose and legal basis: We answer your questions about RivalEye and see which questions are asked frequently in order to improve the website. Legal basis: Art. 6(1)(b) GDPR insofar as a contract or its initiation is concerned; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering inquiries quickly).

11. Contact via WhatsApp

On the website you will find links to WhatsApp. These are simple links: we do not embed any scripts from WhatsApp, and as long as you do not click a link, no data is transmitted to WhatsApp. If you click a link, you leave our website and open WhatsApp. The terms of service and the privacy policy of WhatsApp apply to the use of WhatsApp. The provider for users in Europe is WhatsApp Ireland Limited, Dublin, Ireland, a company of the Meta group. In the process WhatsApp processes, among other things, your phone number and usage data, also in countries outside the EU.

If you write to us via WhatsApp, we process your phone number, your profile name and the content of your messages in order to answer your request. Legal basis: Art. 6(1)(b) GDPR insofar as a contract or its initiation is concerned; otherwise Art. 6(1)(f) GDPR. Please do not send us any sensitive data via WhatsApp. We delete the history as soon as your request has been dealt with and no statutory retention obligations exist. If you do not wish to use WhatsApp, you can reach us by email, by phone or via the contact form.

12. Customer area and login

In the customer area you see your reports, invoices and settings. Logging in works without a password.

Login link by email: You enter your email address. If it is stored with us as a customer address, we send you a login link. It is valid for 20 minutes and for one login only; after clicking it, you confirm the login with a button. The response on the website is the same for every address – so it does not reveal whether an address is stored with us. We store the link only as a short value (hash) and delete it during the automatic cleanup once it has been expired or used for one day.

Session cookie: After you log in, our server sets a technically necessary cookie named “re_sid”. It contains only a random session identifier, is transmitted only over HTTPS, cannot be read by scripts and is not sent to other websites. It has no expiry date; your browser deletes it when you close the browser. On the server the login ends after 8 hours without use, at the latest 7 days after the login and immediately when you log out. For the session we store on the server your customer number, a short value of your email address and the times of the login and of the last use; the server deletes session files that are no longer used after 12 hours during its regular cleanup. Without a login we do not set any cookies.

Log: We store the time of your last login and log logins and logouts, the opening of reports and invoices, and data exports – without IP address. We delete these entries after 365 days; if your contract ends, we delete them together with your customer data 30 days after the end of the contract.

Protection against abuse: So that nobody requests login links in bulk, we limit the number of links per IP address and per email address per hour. For this we store only short values (hashes) formed with a secret key and the times of the requests, not the IP address itself. We delete these counters during the regular cleanup as soon as they are older than 48 hours.

Downloading your data yourself: In the customer area you can download your stored data as a file at any time (export). We currently delete your customer account on request by email.

Legal basis: Art. 6(1)(b) GDPR (access to your customer area as part of the contract) and Art. 6(1)(f) GDPR for the protection against abuse and the log (legitimate interest in secure operation). The session cookie is strictly necessary for the customer area you have requested (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); consent is not required for it.

13. Your rights

Access, rectification, erasure, restriction, data portability, objection (Art. 15–21 GDPR) and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), e.g. with the Hessian Commissioner for Data Protection and Freedom of Information, P.O. Box 3163, 65021 Wiesbaden, Germany, datenschutz.hessen.de. Requests to contact@semia-agent.de.

14. Date of this version

1 October 2026