Legal · Privacy

Privacy Policy

In plain language. Short version: we don't sell your data, we don't train models on it, and you can delete it whenever you like.

1. Data controller

CS Digital Wonders LLC ("SemAgent", "we") — operator of semagent.ai. Contact: [email protected]

2. Data we collect

3. Purposes and legal bases

Contract performance (service delivery, account and billing), legitimate interest (security, abuse prevention, product analytics), consent (memory/personalization, marketing) and legal obligation — under Turkish KVKK and aligned with GDPR principles.

4. Your data never trains models

Your knowledge base, chats and agent tasks are never used to train any AI model. Conversation context is routed through our own AI gateway to enterprise, no-training endpoints (Anthropic, OpenAI, Google, Together AI).

5. Sharing

We do not sell personal data. We share only as needed to run the service: AI providers (response generation), Stripe (payments), hosting (Contabo, Germany/EU), Cloudflare (CDN/TLS), Resend (transactional email), Soniox/ElevenLabs (Voice AI plans only), and authorities where legally required. Full list: Sub-processors.

6. Retention

Account data: for the life of your account, purged within 30 days of deletion. Conversations: per your tenant settings, deletable anytime. Memory: until you delete it or withdraw consent. Usage logs: up to 12 months. Billing records: as required by tax law.

7. Security

Tenant-isolated architecture, AES-256/Fernet secret encryption, HTTPS/TLS, password hashing, 2FA and role-based access, restricted production access, HA infrastructure with backups and monitoring. Details: Trust Center.

8. Your rights

You may request access, correction, deletion, information about transfers, object to automated analysis, and claim damages for unlawful processing (KVKK art. 11; GDPR-equivalent rights honored). Write to [email protected] — we respond within 30 days. Memory data can also be viewed and deleted directly in your panel.

9. International transfers

Data is primarily hosted in the EU (Germany). Some AI providers and sub-processors are US-based; such transfers are covered by contractual safeguards.

10. Cookies & tracking

We use strictly necessary cookies to maintain your session and for security. For aggregate visit statistics we may use privacy-friendly, cookieless measurement such as Cloudflare Web Analytics. We do not use third-party advertising trackers and do not build advertising profiles. You can manage cookie preferences in your browser; blocking strictly necessary cookies may break some functionality.

11. Controller/processor roles (B2B)

We are the data controller for your account and billing data. For the end-user (customer) data you process through the widget or agent, you are the controller and we act only as a processor on your instructions. We sign a KVKK/GDPR-aligned Data Processing Agreement (DPA) with enterprise customers.

12. Children's privacy

The Service is not directed at anyone under 18 and we do not knowingly collect personal data from children. If we learn we have processed a child's data without a lawful basis, we delete it without undue delay.

13. Changes & contact

Updates are published on this page; material changes are notified by email. Questions: [email protected]

Last updated: July 8, 2026