Privacy policy
1. Data controller
| Field | Value |
|---|---|
| Company | MDigital Sp. z o.o. |
| Address | ul. Nowowiejska 77b, 05-850 Pogroszew-Kolonia, Poland |
| Tax ID (NIP) | 1182300026 |
| Statistical ID (REGON) | 540879468 |
| Company register (KRS) | 0001155016 |
| Data protection contact | [email protected] |
The controller of personal data processed in connection with the use of semantichub.app is the company named in the table above (the "Operator"). The Operator has not appointed a Data Protection Officer — none of the conditions requiring a mandatory DPO under Article 37 GDPR is met (the processing is not carried out by a public authority, does not consist of regular and systematic large-scale monitoring, and does not involve large-scale processing of special categories of data). For all matters concerning the protection of personal data, including exercising the rights described in the "Your rights" section, please contact the Operator at the address given in the table above.
2. Roles: controller and processor
The Operator acts in two distinct roles, depending on whose data is being processed.
- Account and usage data (email address, name, and the other data described in "What data we process") — for this data the Operator is the controller within the meaning of Article 4(7) GDPR and independently decides on the purposes and means of processing.
- Article content contributed by the customer within the goals and portals the customer has configured — for this data the Operator acts solely as a processor, processing it on the customer’s documented instructions; the customer remains the controller. This arrangement is governed by a separate agreement: Data Processing Agreement (DPA).
3. What data we process
In connection with creating and maintaining an account, we process the following data:
| Data category | Source / notes |
|---|---|
| Email address | login and contact channel |
| Name | profile data |
| Avatar address | profile data |
| Job title | profile data |
| Interface language | user preference |
| Time zone | user preference |
| Password hash | we never store the password itself in plain text |
| Email verification marker | confirmation that the mailbox is controlled by the user |
| Plan and subscription status | scope of the service billed to the account |
| Stripe identifiers | attached to the account for future billing purposes — see the note below |
| Session data | stored separately, used to handle authentication |
| Second authentication factor (2FA) data | if enabled by the user |
| API tokens | if the user has generated a programmatic access token |
A separate category is the content of publicly available articles fetched from portals the customer has configured within their goals, together with the articles’ metadata (e.g. source URL, publication date, portal name). Articles may contain personal data of third parties (e.g. authors, quoted individuals) — for this data the Operator acts as a processor, as described in "Roles: controller and processor" above.
4. Purposes and legal bases
| Purpose of processing | Legal basis |
|---|---|
| Providing the service (creating and maintaining an account, delivering the service’s functionality) | Article 6(1)(b) GDPR — necessary for the performance of a contract |
| Security, abuse detection and application error monitoring | Article 6(1)(f) GDPR — the Operator’s legitimate interest in keeping the service secure and operational |
| Billing and tax/accounting obligations | Article 6(1)(c) GDPR — a legal obligation to which the Operator is subject |
| Usage analytics (Umami and Microsoft Clarity) | Article 6(1)(a) GDPR — consent, given through the cookie consent banner |
5. Recipients and sub-processors
Data is disclosed only to entities necessary for providing the service, under data processing agreements or their own confidentiality obligations.
| Entity | Role | Location |
|---|---|---|
| H88 S.A. (cyberFolks) | application server hosting | Poland |
| Cloudflare, Inc. | proxy, web application firewall, DNS, backup storage (R2) | United States / global infrastructure |
| OpenRouter, Inc. | gateway to the language models used by the pipeline | United States |
| Resend, Inc. | transactional email delivery (system emails) | United States |
| Brave Software, Inc. | Brave Search API — source discovery (research) module | United States |
| Microsoft Ireland Operations Limited | Microsoft Clarity — service usage analytics | Ireland / Microsoft Azure infrastructure |
The full list of sub-processors, with the transfer basis for each, is published at: List of sub-processors.
6. Transfers outside the EEA
Some of the recipients listed above are located outside the European Economic Area. Data is transferred to them on the following bases:
| Recipient | Location | Transfer basis |
|---|---|---|
| Cloudflare, Inc. | United States | Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF) |
| OpenRouter, Inc. | United States | Standard Contractual Clauses (SCC) |
| Resend, Inc. | United States | Standard Contractual Clauses (SCC) and the Data Privacy Framework (DPF) |
| Brave Software, Inc. | United States | Standard Contractual Clauses (SCC) |
| Microsoft Ireland Operations Limited | Ireland / Microsoft Azure infrastructure | transfer to an entity in the EEA; Microsoft uses SCCs for onward transfers to Microsoft Corporation in the United States |
The language models used by the processing pipeline (including Mistral Nemo, DeepSeek V4 Flash, a text embedding model, and GPT-4o-mini) are reached exclusively through the sub-processor OpenRouter, Inc., which routes requests onward to the underlying model providers: Mistral AI (France), DeepSeek (China), and OpenAI (United States, within the OpenRouter relationship described above).
Database backups are stored in a Cloudflare R2 bucket for which the backup repository does not indicate a specific geographic jurisdiction. The Operator does not represent that backups are processed in any single specified country — the transfer takes place within the Cloudflare, Inc. relationship described in the table above, on the basis of Standard Contractual Clauses and the Data Privacy Framework.
7. Where we process data
The application server is hosted by H88 S.A. (cyberFolks) in Poland. The Operator also maintains its own supporting infrastructure, likewise located in Poland:
- the LiteLLM language model proxy (llm.kmagdziarz.pl)
- the Langfuse model-call observability system (lu.kmagdziarz.pl)
- the Umami traffic analytics (umami.kmagdziarz.pl)
- the Bugsink error tracker (errors.kmagdziarz.pl)
These systems are not separate sub-processors — they are the Operator’s own infrastructure — but are disclosed as processing locations.
8. Logs and observability
The application server keeps standard technical logs necessary for diagnosing failures and detecting abuse.
Application errors are recorded in Bugsink, running on the Operator’s own infrastructure in Poland, with personal data collection disabled ("sendDefaultPii: false") and transaction tracing disabled ("tracesSampleRate: 0"). Bugsink stores nothing on the user’s device.
9. Bring your own model keys
The service allows a customer to connect their own API key for a chosen language model provider (BYOK — bring your own key) instead of using the Operator’s default configuration.
The key is encrypted at rest using Fernet with a key derived through a KDF with domain separation, and is further protected by tenant isolation (row-level security) at the database level. Once saved, the key is never returned in plain text — neither through the interface nor through the API.
10. Retention periods
- Account data — kept until the account is deleted by the user or the agreement is terminated; deletion follows a request sent to the Operator’s contact address.
- Database backups — the restic mechanism runs a backup daily, rotating the five most recent snapshots, corresponding to roughly a five-day window.
- Server logs — the retention period is currently being determined and will be stated in the next version of this policy.
The retention period for Langfuse logs (observability of prompt and response content) is described in "Logs and observability" above.
11. Your rights
A data subject has the following rights under the GDPR:
- right of access to their data and to obtain a copy of it (Article 15 GDPR)
- right to rectification of inaccurate or incomplete data (Article 16 GDPR)
- right to erasure ("the right to be forgotten", Article 17 GDPR)
- right to restriction of processing (Article 18 GDPR)
- right to data portability in a structured, commonly used format (Article 20 GDPR)
- right to object to processing based on legitimate interest (Article 21 GDPR)
- right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal — applies to processing based on consent, e.g. analytics
These rights are exercised on request sent to [email protected]. The Operator responds without undue delay, as a rule within one month of receiving the request.
A data subject also has the right to lodge a complaint with the supervisory authority — the President of the Polish Data Protection Authority (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland — if they consider that the processing of their data infringes data protection law.
12. Automated decisions
The service does not subject users to automated decision-making, including profiling, that produces legal effects concerning them or similarly significantly affects them (Article 22 GDPR).
The system generates content based on article clusters and a goal configuration set by the customer — this is a tool-like operation on data contributed by the customer, not profiling of the service’s users.
13. Cookies
The rules for storing information on the user’s end device (cookies, localStorage) and how consent is managed are described in a separate document: Cookie policy.
14. Changes to this policy
The Operator may amend this policy, in particular in connection with a change in the scope of data processed, the list of sub-processors, or applicable law. The Operator will notify users of material changes in advance, through a notice within the service or an email sent to the address associated with the account, indicating the effective date of the change. The current version and effective date are always shown in the header of this document.