← Back to home

Semantiks Global Privacy Notice

1. Scope

This Notice applies to personal data collected through or in connection with:

This Notice does not replace a separate employee, candidate, contractor, vendor, or jurisdiction-specific notice that Semantiks may provide for a particular relationship. It also does not govern a Customer’s independent collection and use of personal data through an AI agent or other Customer-controlled channel.

2. Who is responsible for your personal data

Semantiks Inc.

Semantiks Inc., a corporation organized under the laws of the State of Delaware, with its business address at 1111B S Governors Ave STE 91260, Dover, Delaware 19904, United States (“Semantiks,” “we,” “us,” or “our”), is responsible for the personal data covered by this Notice when it operates the websites, administers accounts, contracts for the platform, bills Customers, conducts sales and marketing, or otherwise determines the purposes and means of processing.

3. Definitions

TermMeaning
Authorized Useran individual authorized by a Customer to access the Console or Services.
Customera business or other organization that purchases, evaluates, configures, or uses the Services.
Customer Datadata, content, prompts, messages, conversations, audio, transcripts, files, records, instructions, configurations, and other information submitted to or processed by the Services on behalf of a Customer.
End Useran individual who interacts with an AI agent, messaging channel, workflow, or digital experience made available by or for a Customer.
Personal Datainformation relating to an identified or identifiable natural person.
Sensitive Personal Datapersonal data that is legally treated as sensitive or that presents heightened risk, including data concerning health, biometrics, genetics, race or ethnicity, religion, political views, trade-union affiliation, sex life or sexual orientation, or comparable protected information.
Servicesthe Semantiks agentic customer-experience platform, Console, APIs, AI agents, integrations, implementation, support, and related services.
Service Providera vendor, person in charge, processor, or subprocessor that processes personal data on behalf of Semantiks or a Customer.

4. Personal data we collect

The categories below describe the types of personal data Semantiks may collect. The data actually collected depends on your relationship with Semantiks, the features used, the Customer’s configuration, and applicable law.

4.1 Sensitive, financial, and regulated data

Semantiks does not require Sensitive Personal Data for ordinary website, sales, or account administration. The Services are configurable, however, and a Customer or End User may submit sensitive, financial, health, biometric, employment, or other regulated information. Customers must not submit or instruct Semantiks to process such data unless the processing is authorized by law, covered by the applicable contract and Data Processing Addendum, supported by appropriate notices and consents, and approved for the relevant Semantiks use case.

Where applicable law requires express consent or another heightened authorization for Sensitive Personal Data, financial data, biometric data, or other regulated information, Semantiks or the applicable Customer will obtain the required authorization unless a legal exception applies.

5. When Semantiks acts for itself and when it acts for a Customer

5.1 Semantiks as responsible party or controller

Semantiks generally determines the purposes and means of processing for website visitor data, sales and prospect data, account and Authorized User data, billing and contract-administration data, Semantiks marketing data, product-security data, and support records used to operate and improve Semantiks’ own business.

5.2 Semantiks as person in charge or processor

When Semantiks processes Customer Data to provide the Services under a Customer’s instructions, the Customer ordinarily acts as the controller or responsible party and Semantiks acts as the processor, service provider, contractor, or person in charge, as applicable. Semantiks may use approved affiliates and third-party subprocessors. The applicable Customer agreement and Data Processing Addendum govern that processing.

End Users should direct questions or requests concerning Customer Data to the Customer that made the AI agent or digital channel available. If Semantiks receives such a request, it may identify or refer the individual to the relevant Customer and will assist the Customer as required by contract and applicable law. Semantiks will not independently determine the outcome of a Customer Data request unless legally required or authorized by the Customer.

6. Purposes for which Semantiks uses personal data

6.1 Primary and necessary purposes

6.2 Secondary or optional purposes

Where permitted by law, Semantiks may use business contact, interaction, and preference data for optional purposes such as newsletters, event invitations, product announcements, commercial prospecting, customer stories, surveys, and other marketing. These activities are not required to receive the core Services. You may opt out at any time using the unsubscribe mechanism in the communication or by contacting the Privacy Office.

Where applicable law distinguishes optional marketing or secondary purposes from purposes necessary to provide the Services or administer the relationship, Semantiks will provide an appropriate method to refuse or withdraw consent to those optional purposes.

6.3 De-identified and aggregated data

Semantiks may generate statistical, aggregated, or de-identified data to operate, secure, benchmark, analyze, and improve the Services and its business. Semantiks will take reasonable measures designed to prevent such data from being used to identify an individual or Customer and will not attempt to re-identify it except to test the effectiveness of de-identification or as required by law.

6.4 Legal bases where applicable

Where a law requires Semantiks to identify a legal basis for processing, Semantiks relies as appropriate on performance of a contract or steps requested before entering a contract; compliance with legal obligations; legitimate interests in operating, securing, improving, and marketing the Services, provided those interests are not overridden by individual rights; consent; and other lawful bases recognized by applicable law.

7. Artificial intelligence, model providers, and automated processing

The Services use artificial-intelligence and machine-learning technologies to interpret requests, retrieve information, generate responses, summarize conversations, classify intent, route work, assist agents, recommend actions, and perform other Customer-configured workflows. Inputs, contextual data, and outputs may be processed by Semantiks systems and approved model, embedding, speech, or infrastructure providers.

Unless a Customer expressly authorizes otherwise in writing, Semantiks will not use Customer Data or End-User conversations to train generalized artificial-intelligence models made available to other customers or to third parties. Semantiks may use de-identified and aggregated operational data as described in this Notice, and may use Customer Data to provide, secure, troubleshoot, and improve the Customer’s own Services in accordance with the Customer agreement and Data Processing Addendum.

Where a Customer supplies its own model-provider account or API key, the Customer may have a direct contractual relationship with that provider. The provider’s processing, retention, and training practices may be governed by the Customer’s agreement with the provider. Semantiks will transmit data to the selected provider as instructed by the Customer and as necessary to operate the configured service.

AI-generated outputs may be inaccurate, incomplete, or non-unique. Customers are responsible for configuring appropriate disclosures, testing, human review, escalation, and safeguards, particularly where an output may affect legal rights, access to services, employment, credit, health, insurance, housing, or another significant interest.

Depending on applicable law, individuals may have rights relating to profiling or solely automated processing that produces legal or similarly significant effects. Semantiks does not use account, website, or marketing data to make such decisions about individuals. Customer-configured uses of Customer Data are governed by the Customer’s instructions and privacy obligations. See Section 13.

8. Cookies and similar technologies

Semantiks and its providers may use cookies, local storage, pixels, software development kits, and similar technologies to provide authentication, remember preferences, secure the websites and Services, understand usage, measure performance, and, where permitted, support marketing. Categories may include:

A separate Cookie Policy and cookie-preference center should identify the specific technologies, providers, purposes, and retention periods in use. Disabling necessary cookies may prevent parts of the websites or Services from functioning. You may manage non-essential technologies through the cookie-preference center and, where applicable, your browser settings.

9. How Semantiks discloses personal data

Semantiks may disclose personal data only as reasonably necessary for the purposes described in this Notice, subject to contractual, organizational, and technical safeguards. Recipients may include:

9.1 Processors, service providers, and third parties

Some recipients process personal data solely on Semantiks’ or a Customer’s documented instructions as processors, service providers, contractors, persons in charge, or subprocessors. Other recipients may act as independent controllers or third parties for their own legally permitted purposes. Semantiks uses contractual restrictions and other safeguards appropriate to the recipient’s role and the nature of the disclosure.

Where applicable law requires consent or another transfer mechanism, Semantiks will use the required mechanism. Withdrawing or refusing an authorization may prevent Semantiks from providing a requested feature where the disclosure is operationally necessary, but Semantiks will explain the relevant consequence when required.

10. International processing

Semantiks is based in the United States and provides Services internationally. Customer Data is stored and processed in the United States, across Google Cloud Platform and Amazon Web Services regions located in the United States. Personal data may additionally be accessed from other countries where Semantiks, its Customers, personnel, affiliates, or Service Providers operate. Those countries may have privacy laws different from those in your location. Semantiks uses contractual, technical, and organizational safeguards appropriate to applicable law, which may include data-processing agreements, standard contractual clauses, and supplementary safeguards.

For Customer Data, the locations and safeguards applicable to processing are further addressed in the Customer agreement, Data Processing Addendum, subprocessor documentation, and any agreed data-residency terms.

11. Retention and deletion

Semantiks retains personal data only for as long as reasonably necessary for the purposes described in this Notice, the applicable Customer agreement, legal and regulatory requirements, dispute resolution, security, fraud prevention, and enforcement of rights. Retention is determined by the type of data, the relationship, the sensitivity and risk of the data, the Customer’s configuration, and applicable limitation periods.

When data is no longer necessary, Semantiks will delete, de-identify, or block it as appropriate, subject to legal retention requirements and technical limitations of backup systems.

12. Security and confidentiality

Semantiks maintains administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the Services and risk, safeguards may include access controls, least-privilege permissions, encryption in transit and at rest, logging, monitoring, secure development practices, vulnerability management, incident response, vendor diligence, personnel confidentiality obligations, and security training.

No system can be guaranteed to be completely secure. Customers and Authorized Users are responsible for maintaining the confidentiality of credentials, configuring access appropriately, using supported authentication controls, and promptly reporting suspected unauthorized access.

If Semantiks confirms a security incident affecting personal data, it will investigate, mitigate, and provide notifications to Customers, individuals, or authorities where required by applicable law and the Customer agreement.

13. Your rights and choices

Depending on applicable law and the context in which Semantiks processes your data, you may have rights to access, correct, update, delete or cancel, object to, restrict, or obtain information about processing; withdraw consent; limit use or disclosure; opt out of marketing; and complain to a competent authority. Rights are subject to legal exceptions and verification requirements.

13.1 How to submit a privacy request

Describe the right you wish to exercise, the personal data or account involved, and information reasonably necessary to locate the records. Semantiks may request proportionate information to verify identity, authority, and jurisdiction. Do not send unredacted government-identification documents by ordinary email unless Semantiks specifically provides a secure method.

13.2 United States state privacy rights

Where an applicable U.S. state privacy law applies, residents may have rights to know or access personal data, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of certain sales, targeted advertising, sharing, or profiling. Semantiks will not discriminate against an individual for exercising an applicable privacy right. Authorized agents may submit requests where permitted by law, subject to verification.

Semantiks does not sell personal data for monetary consideration. If Semantiks uses advertising or analytics technologies in a manner treated as “sharing,” “targeted advertising,” or a “sale” under applicable law, Semantiks will provide the required notice and opt-out mechanism, including recognition of legally required browser-based opt-out preference signals where applicable.

13.3 EEA, United Kingdom, and Switzerland

Where applicable, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and object to certain direct marketing or processing based on legitimate interests. Individuals may also lodge a complaint with their local supervisory authority. Where Semantiks relies on consent, withdrawal does not affect processing completed before withdrawal. Where Semantiks relies on legitimate interests, individuals may request information about the relevant balancing considerations.

13.4 Mexico and other jurisdictions

Individuals in Mexico and other jurisdictions may have rights of access, rectification or correction, cancellation or deletion, opposition or objection, limitation, consent withdrawal, and complaint to a competent authority. Semantiks will respond within the period required by the law that applies to the verified request. For requests governed by Mexican law, this may include ARCO rights and the statutory response and implementation periods.

13.5 Requests involving Customer Data

If your request concerns a conversation, transaction, CRM record, or other Customer Data processed for a Semantiks Customer, identify that Customer in your request. Semantiks may refer the request to the Customer because the Customer ordinarily determines how that data is used. Semantiks will support the Customer as required by law and contract.

13.6 Marketing, optional purposes, and consent

You may unsubscribe from marketing emails using the link in the message or contact the Privacy Office to object to optional marketing purposes, limit use or disclosure, or revoke consent where applicable. Revocation does not affect processing already lawfully completed and may not apply where processing is required to perform a contract or comply with law.

13.7 Complaints and appeals

You may contact the Privacy Office so Semantiks can attempt to resolve the issue. Where applicable law provides a right to appeal a denied privacy request, the response will explain how to appeal. You may also contact the privacy, consumer-protection, or data-protection authority with jurisdiction over your complaint.

14. Children and minors

The Semantiks websites and business account Services are not directed to children. Semantiks does not knowingly collect personal data directly from children for its own marketing or account-administration purposes. A Customer must not deploy the Services for a child-directed use case or knowingly process children’s data through the Services unless the Customer has obtained any required parental authorization, implemented age-appropriate notices and safeguards, and obtained Semantiks’ prior written approval where required by the Customer agreement.

15. Third-party services and Customer channels

The Services may connect with third-party websites, messaging platforms, model providers, CRMs, payment systems, social networks, and other services. Their independent privacy practices are governed by their own notices and agreements. A Customer’s use of a third-party integration may cause personal data to be transmitted to that provider under the Customer’s instructions.

16. Changes to this Notice

Semantiks may update this Notice to reflect changes in law, corporate structure, technology, products, or processing practices. Semantiks will post the updated Notice and revise the “Last updated” date. Where a change materially expands the use of personal data, adds a purpose that requires consent, introduces a transfer requiring consent, or otherwise requires additional notice or consent, Semantiks will provide the legally required notice and obtain consent through an appropriate mechanism before applying the change.

17. Contact information

Questions, complaints, privacy requests, and requests to limit use or disclosure may be directed to: