1. Roles under privacy law
- For platform accounts, leads, vendor lookup visitors, watch lists and vendors, SemantiqWall (the operator, ZapBrabo Technology) is the controller.
- For data that customers' AI agents send to the decision API (subjects, resources, parameters) and data in customers' repositories, the customer is the controller and SemantiqWall is the processor (operator under LGPD), acting on the customer's instructions.
- The Founder is the privacy contact (encarregado) at contato@semantiqwall.com.
2. Data inventory
The inventory is derived from the database schema and reviewed at least once a year and whenever a feature adds data.
| Data set | Content | Class | Role |
|---|---|---|---|
| User accounts | Name, e-mail, optional phone (for approvals), language, time zone, last login, bcrypt password hash, encrypted MFA secret and recovery codes | Confidential (secrets: Restricted) | Controller |
| Memberships and sessions | Role per organization; session with IP address, browser user agent, encrypted payload | Confidential | Controller |
| Customer configuration | Organization name and logo, agents, tools, channels, credential references (name, provider, scopes - never the secret), catalog, policies, API key hashes | Confidential | Processor |
| Agent decisions and approvals | Operation, action, subject and resource identifiers and destination as sent by the customer's agent; parameters masked before storage (tax IDs, e-mails, phones and card numbers masked; secret fields removed; long text cut); decision and reason | Confidential | Processor |
| Response checks | Verdict and issues found; the checked text is not stored, only its hash and length | Confidential | Processor |
| Cases, reports, repository analysis (Raio-X) and remediation proposals | Findings, excerpts and proposed changes of the customer's code; uploaded archives are deleted after analysis and GitHub read tokens are used once and not stored | Restricted | Processor |
| Audit log | Actor, action, subject, context, IP address, user agent, UTC time | Confidential | Controller (platform) / Processor (tenant) |
| Leads (site forms) | Name, e-mail, company, WhatsApp number, agent count range, message, domain, language, salted IP hash | Confidential | Controller |
| Vendor lookups and vendor profiles | Domain and tax ID searched, integrations chosen, public signals collected from the vendor's public website, salted IP hash of the requester | Public signals: Public; lookup record: Internal | Controller |
| Vendor verification | Vendor's answers to the 12 criteria, evidence files, reviewer notes | Confidential | Controller |
| Watch lists and verification requests | Name, company, e-mail (used only after confirmation), vendors followed, alerts, message to the vendor, salted IP hash | Confidential | Controller |
| Cookies | Session, XSRF-TOKEN (CSRF protection), sw_locale (language), sw_lista (private watch-list link) |
Internal | Controller |
| Backups | Full database dump | Same as the highest class inside (Restricted) | Both |
Classes: Public - may be published. Internal - low harm if disclosed. Confidential - customer or personal data; access limited to the customer and the operator. Restricted - secrets, customers' source code and evidence files; never leaves production except through the owning customer or an approved subprocessor.
No sensitive personal data (as defined in LGPD art. 5, II) is intentionally collected. Customers are told not to send it to the decision API (policy 11).
3. Data flows and location
| Where | What | Location |
|---|---|---|
| Hostinger VPS | Everything above (database, files, logs, backups) | Datacenter location to be confirmed with Hostinger |
| Resend | Transactional e-mails (recipient address, content) | Region sa-east-1 (São Paulo) |
| GoDaddy Titan | Mailbox contato@semantiqwall.com | To be confirmed |
| GitHub | SemantiqWall source code; for customers who install the GitHub App, pull requests in their repositories | United States |
| AI provider (Anthropic), only when enabled | Case title, severity and evidence text (truncated), agent name, purpose, tools and actions for triage; up to 4 files of the customer's code for remediation proposals | United States |
| Meta WhatsApp Cloud API, only when enabled (currently disabled) | Approver phone number and approval message | Meta infrastructure |
All transfers use TLS. International transfers (to the US) rely on the mechanisms of LGPD art. 33, primarily standard contractual clauses, with the supplier's data processing terms (policy 09).
4. Privacy by design and by default
- Collect the minimum: masking of agent parameters, hashes instead of text for response checks, salted IP hashes on public forms, credential references instead of secrets.
- Watch-list e-mails are used only after the person confirms them; every alert e-mail has an unsubscribe link.
- No advertising, no third-party analytics and no tracking cookies on the site or panel.
- New features that add personal data, a new subprocessor or a new AI use require a check against this policy before release (policy 03).
5. Data protection impact assessment
A DPIA (RIPD under LGPD) is done before processing that may create high risk: new categories of personal data, sending customer data to a new subprocessor or AI provider, large-scale monitoring, or automated decisions about people. It records the purpose, legal basis, data, risks, safeguards and the Founder's decision. Commitment: first DPIA for the AI triage and remediation features (owner: Founder, target 2026-12-31).
6. Retention
| Data | Kept for |
|---|---|
| Customer organization data | While the contract is active; after termination, available for export for 30 days, then deleted within 90 days (backups roll over afterwards) |
| Audit log | Life of the organization, then up to 5 years as evidence (policy 04) |
| User accounts | While the user is a member; deleted with the organization or on request |
| Leads | 24 months after the last contact |
| Vendor lookup records | 24 months; public vendor profiles while the vendor is listed |
| Vendor verification answers and evidence | While the verification is valid and 12 months after |
| Watch lists and requests | Until the person deletes them or unsubscribes; lists with no activity for 24 months are deleted |
| Application access records (sign-ins, with IP address and time) | At least 6 months (Marco Civil art. 15): they are kept in the append-only audit trail, which is not purged, so in practice they stay for the life of the account and the audit-log period above (policy 04) |
| Application error log | 14 days (policy 04) |
| Web server (Caddy) access log | Retention not yet configured; commitment in policy 04 (owner: Founder, target 2026-10-15) |
| Backups | 14 days on the server; 30 days off-site once in place (policy 06) |
Status: these periods are adopted by this policy, but automatic deletion is not in place today; data is deleted manually on request. Commitment: scheduled purge jobs for each row above except the audit log, plus the audit log procedure in policy 04 (owner: Founder, target 2026-12-31). In place: full organization data export in JSON for owners and administrators (Organization page).
7. Deletion and disposal
- Data is deleted from the database with standard deletes; it disappears from backups when those backups expire.
- Uploaded vendor evidence files live on the server disk; removing them together with their records is part of the purge commitment in section 6.
- Physical media are Hostinger's; their media sanitization practice is to be obtained (policy 09).
8. Data subject requests
- Anyone can ask to confirm, access, correct, anonymize, port or delete their data, or to learn with whom it was shared, by writing to contato@semantiqwall.com. Watch-list owners can also delete items and unsubscribe themselves.
- We verify identity using the e-mail on file (a reply from that address or a confirmation link) before acting.
- We answer within 15 days (LGPD); US residents' requests under state laws are answered within the same 15 days and never later than 45 days.
- When we are the processor, we forward the request to the customer (controller) within 5 business days and help them answer.
- Each request and its outcome are logged in the security register.
9. Law enforcement and government requests
- We disclose data only when legally required: a court order, or, for registration data only, a request from an authority with legal power to ask for it (Marco Civil art. 10).
- Each request is checked for validity and scope; overly broad requests are challenged or narrowed.
- When customer data is requested, we tell the customer first unless the law or the order forbids it, so they can respond.
- Every request, the legal basis and what was disclosed are recorded in the security register.
10. Production data outside production
Production data is not copied to development or test. Any exception needs written approval (policy 00), masking before use and deletion afterwards.