Security & privacy
Your data, your competitor monitoring – cleanly separated.
We clearly separate what is implemented today from what is planned. No invented certificates.
Implemented today
| Area | Status | Details |
|---|---|---|
| Encrypted transmission | ACTIVE | All pages are delivered exclusively over HTTPS; the browser is instructed via HSTS to always use HTTPS. |
| Login to the customer area | ACTIVE | Without a password: login link by email, valid for 20 minutes and usable only once. Session cookie only over HTTPS, not readable by scripts, not sent to other websites; automatic logout after 8 hours without use. Details in the privacy policy (section 12). |
| Export | ACTIVE | Download your data yourself in the customer area. |
| Form data | ACTIVE | Requests from the order form and the contact form are stored on our web server in a folder that cannot be accessed from outside, and are forwarded to us by email. |
| New-customer discount | ACTIVE | So that the discount is granted only once per company, we store only short values (hashes) of the tax number, website, email address and company name for a redemption – not in plain text. Details in the privacy policy (section 5). |
| IP addresses | ACTIVE | To protect against abuse, we store only a truncated hash value of the IP address with a request, not the address itself. |
| Reach measurement without cookies | ACTIVE | We count page views ourselves: without cookies, without third-party services, without stored IP addresses. No advertising or tracking cookies, no Google Analytics, no fonts or scripts from third-party servers. If your browser sends “Do Not Track” or “Global Privacy Control”, nothing is measured. Details in the privacy policy (section 8). |
| Payment data | ACTIVE | Payment by invoice and bank transfer – we do not collect card data and do not debit anything automatically. |
| AI assistant and WhatsApp | ACTIVE | The chat transmits nothing before you send a message; we log questions in shortened form, without IP address, for 30 days. WhatsApp is only linked – no scripts from WhatsApp are loaded. Details in the privacy policy (sections 10 and 11). |
| AI providers | ACTIVE | The AI providers we use are named as processors in the privacy policy (section 7). |
Planned
| Area | Status | What is planned |
|---|---|---|
| Hosting of the app | PLANNED | The future customer app and its database are to run in EU data centers; we will name the providers here once it is in operation. |
| Tenant separation | PLANNED | Every record is assigned to a customer account; access across account boundaries is to be technically ruled out. |
| Delete your account yourself | PLANNED | Delete the customer account yourself in the customer area. Until then: deletion on request by email. |
| Backups | PLANNED | Daily encrypted backups of the app database. |
| Data processing agreement (DPA) | PLANNED | A standard data processing agreement under Art. 28 GDPR for download and a published list of sub-processors. Until then: DPA on request. |
Service providers
| Service provider | What for | Note |
|---|---|---|
| Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus | Hosting of the website, server log files, form data | See privacy policy, section 2 |
| Anthropic PBC, San Francisco, USA (Claude) | Creation of the reports (AI Council), AI assistant on the website | Transfers to third countries on the basis of standard contractual clauses or the EU-US Data Privacy Framework, where applicable (section 7) |
| OpenAI Ireland Ltd., Dublin, Ireland, or OpenAI, L.L.C., San Francisco, USA (ChatGPT) | Cross-checking of the reports (AI Council) | |
| Google Ireland Limited, Dublin, Ireland, or Google LLC, Mountain View, USA (Gemini) | Decision in the event of disagreement (AI Council) |
Which data we keep separate
- Data provided by you – company, lines of business, area, contact person.
- Public web observations – competitor pages, directories, AI answers.
- Billing data – billing address, VAT ID or tax number and invoices, which we retain in accordance with commercial and tax law requirements.
- Usage data – technically necessary server log files and counts from our own reach measurement, without cookies and without ad tracking.
Data minimization
We do not keep complete copies of competitor pages permanently, but hashes, differences and structured observations. Screenshots serve as evidence and are subject to a retention period.
Found a security vulnerability?
Write to contact@semia-agent.de. The contact details for security reports are also available in machine-readable form in the file security.txt.
Questions?
Privacy requests and requests for a DPA via the contact page or by email to contact@semia-agent.de.