Privacy Policy
Sembot Sp. z o.o. — services sembot.com, css.sembot.com, sembot.eu. We explain what personal data we collect, why and on what basis, whom we entrust it to, and what rights you have.
Version 1.0 · effective 6 July 2026This Policy explains what personal data we collect, for what purpose and on what legal basis, whom we entrust it to, and what rights you have. It applies to visitors to our services, people filling in forms, and users of the product.
1. Data controller
The controller of your personal data is Sembot Sp. z o.o., ul. Juliusza Słowackiego 24/1101, 35-060 Rzeszów, Poland, registered in the National Court Register (KRS) under number 0000781855, VAT ID PL8133810819 (the „Controller" or „we").
Sembot Sp. z o.o.
ul. Juliusza Słowackiego 24/1101, 35-060 Rzeszów, Poland
KRS 0000781855 · VAT ID PL8133810819
E-mail: [email protected] · phone (+48) 17 789 1 333
We have not appointed a Data Protection Officer. For all data protection matters you can contact us at [email protected].
2. Scope and mapping of services
This Policy covers the entire Sembot ecosystem — the CSS service website, the product, and related services. As this is a single document for different areas, below we indicate which processing relates to which area:
| Area / service | What happens with the data | Main legal basis |
|---|---|---|
| css.sembot.com — form | Contact and acquisition of a sales lead | Actions on request / consent |
| Services — cookies / analytics | Measurement and marketing via cookies | Consent (ePrivacy) |
| Product (sembot.com / sembot.eu) — account | Registration and account management, service provision | Contract performance (Art. 6(1)(b)) |
| All services — security | Protection against spam and abuse | Legitimate interest |
Some support activities are carried out with the involvement of Sembot group companies, including the London office (United Kingdom) — see sections 4 and 5.
3. Purposes, legal bases and retention periods
| Purpose | Data categories | Legal basis | Retention period |
|---|---|---|---|
| Contacting a person who left their details, to provide information and present an offer (at their request) | name, e-mail, phone, acquisition source, message content | Art. 6(1)(b) (actions at the person's request); contact requested by leaving details — in line with the Electronic Communications Law (PKE) | Lead activity; if no interaction, 12 months from last contact → deletion/anonymisation |
| Own marketing (sales contact, offers) — e-mail / phone | e-mail, phone, identifiers | Art. 6(1)(a) (consent); for the e-mail/phone channel — consent under the PKE. Use of the services is not conditional on marketing consent (Art. 7(4)). | Until consent is withdrawn or objection raised; if inactive — no longer than 12 months from last interaction → deletion/anonymisation |
| Use of the service and account management | e-mail, password (hash), company data, billing data | Art. 6(1)(b) (contract performance) | Duration of the contract/account + limitation period for claims |
| Security and integrity of the form (protection against spam and abuse) | IP address, user agent, technical logs | Art. 6(1)(f) (legitimate interest: security) | 3–6 months |
| Measurement and marketing via cookies | online identifiers, activity data — see Cookie Policy | Art. 6(1)(a) (consent) in conjunction with Art. 5(3) ePrivacy | According to the lifetime of individual cookies |
| Statistics and analysis (after anonymisation) | anonymised data (no identification) | Not applicable — after anonymisation this is not personal data | Indefinitely, in anonymised form |
| Legal obligations (e.g. handling requests, accounting) | data necessary to fulfil the obligation | Art. 6(1)(c) | As required by law (e.g. 5 years for accounting records) |
4. Data recipients and processors
We entrust data to trusted providers acting on our behalf under data processing agreements; we also share it with group companies for the purpose of handling enquiries:
| Recipient / role | Function | Location / transfer |
|---|---|---|
| OVH | Hosting (dedicated servers) | FR / DE / PL — EU |
| Cloudflare, Inc. | CDN, TLS termination, bot protection (Turnstile) | USA — DPF + SCC |
| Amazon Web Services (Frankfurt) | Intermediary for transmitting form data | Data in the EU; AWS Inc. (USA) — DPF/SCC |
| Google (Workspace / Gmail) | Handling and lead notifications | USA / IE — DPF + SCC |
| Google (Ads, Analytics) | Measurement and marketing (with consent) | USA — DPF + SCC |
| Microsoft (Clarity) | Behaviour analysis: heatmaps and session recordings (with consent) | USA — DPF + SCC |
| Sembot group companies, including the London office (UK) | Handling enquiries and support | United Kingdom — EU adequacy decision |
We do not sell your personal data.
5. Transfers outside the EEA
Some recipients are located outside the European Economic Area. Transfers take place with appropriate safeguards in place:
| Country / recipient | Transfer basis |
|---|---|
| USA — Google, Microsoft, Cloudflare, AWS | Adequacy decision — EU-US Data Privacy Framework (for certified entities) and standard contractual clauses (SCC) as a fallback mechanism |
| United Kingdom — London office / group | EU adequacy decision for the United Kingdom (valid until 27 December 2031) |
You can obtain a copy of the safeguards applied (e.g. the text of the SCC) or information on certification by contacting us at [email protected]. The certification status under the Data Privacy Framework can be checked on the official list (dataprivacyframework.gov).
6. Your rights
You have the right to: access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and to withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)).
You also have the right to lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
7. Automated decision-making and profiling
Within our services we do not make decisions based solely on automated processing, including profiling, that would produce legal or similarly significant effects on you (Art. 22 GDPR). Automation and AI features operating inside the product — if they concern you — are described in a separate product notice.
8. Is providing data mandatory
Providing data is not a statutory obligation; it is voluntary. The consequence of not providing it depends on the purpose:
- Data necessary to provide the service (e.g. e-mail address): providing it is a condition for using the service and managing an account.
- Data marked as optional (e.g. phone number, message content): entirely voluntary; not providing it does not affect access to the service.
- Marketing consents: voluntary and independent of using the service. Lack of consent does not limit access to the service or its features.
9. Changes to this Policy
We may update this Policy (e.g. due to changes in law, technology or the scope of processing). The current version is always available at sembot.com/pl/privacy-policy/, together with the version number and effective date.
For material changes — concerning the purposes of processing, legal bases, categories of recipients or the manner of exercising your rights — we will inform you with appropriate notice in a manner adequate to the channel (account holders and people who have given consent — by e-mail or an in-product message; others — via a clear notice on the service). If a change concerns processing based on consent, we will ask for it to be given again to the extent necessary.
10. Contact
For data protection matters:
E-mail: [email protected]
Phone: (+48) 17 789 1 333