Legal information

Privacy Policy

Sembot Sp. z o.o. — services sembot.com, css.sembot.com, sembot.eu. We explain what personal data we collect, why and on what basis, whom we entrust it to, and what rights you have.

Version 1.0 · effective 6 July 2026
ℹ️ This English version is a convenience translation. In case of any discrepancy, the Polish version prevails and is legally binding.

This Policy explains what personal data we collect, for what purpose and on what legal basis, whom we entrust it to, and what rights you have. It applies to visitors to our services, people filling in forms, and users of the product.

1. Data controller

The controller of your personal data is Sembot Sp. z o.o., ul. Juliusza Słowackiego 24/1101, 35-060 Rzeszów, Poland, registered in the National Court Register (KRS) under number 0000781855, VAT ID PL8133810819 (the „Controller" or „we").

Sembot Sp. z o.o.

ul. Juliusza Słowackiego 24/1101, 35-060 Rzeszów, Poland

KRS 0000781855 · VAT ID PL8133810819

E-mail: [email protected] · phone (+48) 17 789 1 333

We have not appointed a Data Protection Officer. For all data protection matters you can contact us at [email protected].

2. Scope and mapping of services

This Policy covers the entire Sembot ecosystem — the CSS service website, the product, and related services. As this is a single document for different areas, below we indicate which processing relates to which area:

Area / serviceWhat happens with the dataMain legal basis
css.sembot.com — formContact and acquisition of a sales leadActions on request / consent
Services — cookies / analyticsMeasurement and marketing via cookiesConsent (ePrivacy)
Product (sembot.com / sembot.eu) — accountRegistration and account management, service provisionContract performance (Art. 6(1)(b))
All services — securityProtection against spam and abuseLegitimate interest

Some support activities are carried out with the involvement of Sembot group companies, including the London office (United Kingdom) — see sections 4 and 5.

3. Purposes, legal bases and retention periods

PurposeData categoriesLegal basisRetention period
Contacting a person who left their details, to provide information and present an offer (at their request) name, e-mail, phone, acquisition source, message content Art. 6(1)(b) (actions at the person's request); contact requested by leaving details — in line with the Electronic Communications Law (PKE) Lead activity; if no interaction, 12 months from last contact → deletion/anonymisation
Own marketing (sales contact, offers) — e-mail / phone e-mail, phone, identifiers Art. 6(1)(a) (consent); for the e-mail/phone channel — consent under the PKE. Use of the services is not conditional on marketing consent (Art. 7(4)). Until consent is withdrawn or objection raised; if inactive — no longer than 12 months from last interaction → deletion/anonymisation
Use of the service and account management e-mail, password (hash), company data, billing data Art. 6(1)(b) (contract performance) Duration of the contract/account + limitation period for claims
Security and integrity of the form (protection against spam and abuse) IP address, user agent, technical logs Art. 6(1)(f) (legitimate interest: security) 3–6 months
Measurement and marketing via cookies online identifiers, activity data — see Cookie Policy Art. 6(1)(a) (consent) in conjunction with Art. 5(3) ePrivacy According to the lifetime of individual cookies
Statistics and analysis (after anonymisation) anonymised data (no identification) Not applicable — after anonymisation this is not personal data Indefinitely, in anonymised form
Legal obligations (e.g. handling requests, accounting) data necessary to fulfil the obligation Art. 6(1)(c) As required by law (e.g. 5 years for accounting records)

4. Data recipients and processors

We entrust data to trusted providers acting on our behalf under data processing agreements; we also share it with group companies for the purpose of handling enquiries:

Recipient / roleFunctionLocation / transfer
OVHHosting (dedicated servers)FR / DE / PL — EU
Cloudflare, Inc.CDN, TLS termination, bot protection (Turnstile)USA — DPF + SCC
Amazon Web Services (Frankfurt)Intermediary for transmitting form dataData in the EU; AWS Inc. (USA) — DPF/SCC
Google (Workspace / Gmail)Handling and lead notificationsUSA / IE — DPF + SCC
Google (Ads, Analytics)Measurement and marketing (with consent)USA — DPF + SCC
Microsoft (Clarity)Behaviour analysis: heatmaps and session recordings (with consent)USA — DPF + SCC
Sembot group companies, including the London office (UK)Handling enquiries and supportUnited Kingdom — EU adequacy decision

We do not sell your personal data.

5. Transfers outside the EEA

Some recipients are located outside the European Economic Area. Transfers take place with appropriate safeguards in place:

Country / recipientTransfer basis
USA — Google, Microsoft, Cloudflare, AWSAdequacy decision — EU-US Data Privacy Framework (for certified entities) and standard contractual clauses (SCC) as a fallback mechanism
United Kingdom — London office / groupEU adequacy decision for the United Kingdom (valid until 27 December 2031)

You can obtain a copy of the safeguards applied (e.g. the text of the SCC) or information on certification by contacting us at [email protected]. The certification status under the Data Privacy Framework can be checked on the official list (dataprivacyframework.gov).

6. Your rights

You have the right to: access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and to withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)).

You also have the right to lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.

7. Automated decision-making and profiling

Within our services we do not make decisions based solely on automated processing, including profiling, that would produce legal or similarly significant effects on you (Art. 22 GDPR). Automation and AI features operating inside the product — if they concern you — are described in a separate product notice.

8. Is providing data mandatory

Providing data is not a statutory obligation; it is voluntary. The consequence of not providing it depends on the purpose:

  • Data necessary to provide the service (e.g. e-mail address): providing it is a condition for using the service and managing an account.
  • Data marked as optional (e.g. phone number, message content): entirely voluntary; not providing it does not affect access to the service.
  • Marketing consents: voluntary and independent of using the service. Lack of consent does not limit access to the service or its features.

9. Changes to this Policy

We may update this Policy (e.g. due to changes in law, technology or the scope of processing). The current version is always available at sembot.com/pl/privacy-policy/, together with the version number and effective date.

For material changes — concerning the purposes of processing, legal bases, categories of recipients or the manner of exercising your rights — we will inform you with appropriate notice in a manner adequate to the channel (account holders and people who have given consent — by e-mail or an in-product message; others — via a clear notice on the service). If a change concerns processing based on consent, we will ask for it to be given again to the extent necessary.

10. Contact

For data protection matters:

E-mail: [email protected]

Phone: (+48) 17 789 1 333

Have questions? Let's talk.

Most stores and agencies get started on their own in a few minutes. If you'd rather talk first, leave your details. We'll get back to you within 24 business hours, with no sales pressure.

We'll get back to you within 24 business hours. No sales pressure.