Last updated 2026-09-28
This policy explains how SemantiqWall handles personal data on its website, its public vendor lookup and its platform (web panel and API). It is written to meet Brazil's General Data Protection Law (LGPD) and the US state privacy laws that apply to us.
1. Who we are
SemantiqWall is operated by:
ZapBrabo Technology
Goiânia, Goiás, Brazil
Privacy contact (encarregado / data protection officer): contato@semantiqwall.com. Security vulnerabilities: see our responsible disclosure policy.
2. When we are the controller and when we are not
- We are the controller of the data described in section 3 about people who visit our site, use the vendor lookup, follow vendors, apply for vendor verification, ask us to contact them, or hold an account on the platform.
- When a customer's AI agents send data to our decision API, or a customer asks us to analyze its code, the customer is the controller and we act as its processor, following its instructions. If you are a customer's end user, please send requests about that data to the customer; if you write to us, we will forward your request to them.
3. Data we collect
| Where | Data |
|---|---|
| Platform accounts | Name, e-mail, optional phone number (for approval messages), language and time zone, role in the organization, password (stored only as a hash), multi-factor authentication secret and recovery codes (stored encrypted), last login |
| Security records | IP address, browser user agent and time of logins, failed logins and other security-relevant actions (audit log); session data |
| Platform content sent by customers | Agent, tool and policy configuration; for each agent action: the operation, the identifiers of the subject and resource, the destination, and the parameters masked before storage (tax IDs, e-mails, phone and card numbers masked; passwords, tokens and other secret fields removed); approvals; cases and reports; excerpts of customers' code in repository analyses and fix proposals |
| Contact and analysis requests on the site | Name, e-mail, company, WhatsApp number, how many AI agents you use, your message, domain, language, and a salted hash of your IP address |
| Public vendor lookup | The domain and company ID you search, the integrations you select, a salted hash of your IP address; and public information found on the vendor's own website (for example whether it publishes a privacy policy, a company ID or a security contact) |
| "My vendors" watch lists and verification requests | Name, company, e-mail (used only after you confirm it), vendors you follow and their alerts, the message you ask us to show a vendor, a salted hash of your IP address |
| Vendor verification program | Answers to our criteria, evidence files and reviewer notes, and the platform account data of the vendor's representatives |
| Messages to our mailbox | Whatever you write to us |
We do not ask for sensitive personal data (health, religion, biometrics and the like) and we ask customers not to send it through the API.
4. Cookies
We use only cookies needed for the site to work. We do not use advertising, analytics or tracking cookies, and we do not load third-party scripts.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in; its content is encrypted | Ends after a period of inactivity |
| XSRF-TOKEN | Protects forms against cross-site request forgery | Same as the session |
| sw_locale | Remembers your language (Portuguese or English) | 1 year |
| sw_lista | Opens your private "My vendors" list on this browser | 1 year |
5. Why we use data and on what legal basis
| Purpose | LGPD legal basis (art. 7) |
|---|---|
| Provide the platform to customers and their users | Performance of a contract (V) |
| Account security, audit trail, fraud and abuse prevention | Legitimate interest (IX); exercise of rights in legal proceedings (VI) |
| Keep application access records (sign-ins with IP address and time) for at least 6 months, as required by the Marco Civil da Internet (art. 15) | Legal obligation (II) |
| Answer contact and analysis requests | Steps prior to a contract at your request (V) |
| Run the public vendor lookup and publish results about companies | Legitimate interest (IX) |
| Send vendor alerts to your e-mail | Consent (I), given when you confirm your e-mail; withdraw at any time with the unsubscribe link |
| Run the vendor verification program | Performance of a contract (V) |
Where we rely on legitimate interest, we have weighed it against your rights and keep only the minimum. You can object (section 9).
6. Who we share data with
We do not sell personal data. We share it only with the service providers below, who process it on our behalf, and with authorities when the law requires it.
| Provider | What for | Data |
|---|---|---|
| Hostinger | Hosting of our servers | All data we hold |
| Resend | Sending e-mails (watch-list confirmation and alerts) | Your e-mail, name and the message |
| GoDaddy (Titan Mail) | Our mailbox contato@semantiqwall.com | Messages you send us |
| GitHub | Our code hosting; for customers who install our GitHub App, reading the files they allow and opening pull requests | Customer code and pull request content |
| Anthropic (only when the optional AI features are enabled) | Explaining security cases and proposing code fixes | Case summary and evidence text, agent description, up to 4 of the customer's code files |
| Meta WhatsApp (only if enabled; currently disabled) | Approval messages | Approver's phone number and the approval message |
We also disclose data when required by a court order or by an authority with legal power to request it, after checking the request (see our data protection policy). If the company is sold or merged, data may pass to the successor under this policy.
7. International transfers
Our servers are operated by Hostinger; the datacenter location is informed on request. Some providers (GitHub, Anthropic and possibly others above) are in the United States. When personal data leaves Brazil, we rely on the mechanisms of LGPD art. 33, mainly standard contractual clauses in the providers' data processing terms.
8. How long we keep data
| Data | Kept for |
|---|---|
| Customer organization data | While the contract is active; then available for export for 30 days and deleted within 90 days |
| Audit log | While the organization exists and up to 5 years afterwards, as evidence |
| Accounts | While you are a member of an organization |
| Contact and analysis requests | 24 months after the last contact |
| Vendor lookup records | 24 months |
| Vendor verification answers and evidence | While the verification is valid and 12 months after |
| Watch lists | Until you delete them or unsubscribe; deleted after 24 months without activity |
| Application access records (sign-ins with IP address and time) | At least 6 months; they are kept in the audit trail, so in practice for as long as the audit log above |
| Application error logs | 14 days |
| Web server access logs | Retention period not yet configured; we are setting it to between 6 and 12 months |
| Backups | Up to 30 days |
Some of these deletions are still done manually while automatic deletion is being built.
9. Your rights
Under the LGPD you can ask us to: confirm whether we process your data; give you access; correct it; anonymize, block or delete unnecessary or unlawful data; port it to another provider; delete data processed with your consent; tell you with whom we shared it; tell you what happens if you refuse consent; and withdraw consent. You can also object to processing based on legitimate interest and ask for review of decisions made solely by automated means. You may complain to the ANPD (gov.br/anpd).
US residents (for example under the California Consumer Privacy Act, as amended) have the right to know what personal information we collect, use and disclose; to access and receive a copy; to correct it; to delete it; to opt out of its sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for using these rights. You may use an authorized agent.
How to ask: write to contato@semantiqwall.com. We confirm your identity using the e-mail address we have on file before acting, and we answer within 15 days. If we refuse, we explain why and you can reply to appeal; the Founder reviews appeals personally. For data we hold as a processor, we forward your request to the customer.
For US state-law purposes, in the last 12 months we collected these categories: identifiers (name, e-mail, phone, IP address); professional information (company); internet activity (security logs); account credentials (used only to sign you in). We collect them from you, from the organization that added you as a member, and from public websites of vendors. We disclose them only to the providers in section 6, for the business purposes in section 5.
10. Do Not Sell or Share, and Global Privacy Control
SemantiqWall does not sell personal information and does not share it for cross-context behavioral advertising. We have no advertising or analytics trackers. We honor the Global Privacy Control (GPC) signal: a browser that sends it is treated as a valid request to opt out of sale and sharing; since we do neither, nothing else changes for you. We do not use sensitive personal information to infer characteristics about you.
11. Security
We protect data with mandatory multi-factor authentication, encryption in transit (HTTPS), encryption of authentication secrets, hashing of passwords and API keys, isolation between customer organizations, masking of agent parameters and an append-only, tamper-evident audit trail. Our security policies, including what is not yet in place, are published in the Trust Center. If an incident puts your data at risk, we will notify you and the authorities as the law requires.
12. Children
SemantiqWall is a business service and is not intended for people under 18. We do not knowingly collect data from children or adolescents; if we learn we did, we delete it.
13. Automated decisions
The platform decides whether a customer's AI agent may perform an action, following rules the customer configures. These are decisions about agent actions, not assessments of people. Optional AI features only suggest; a person always decides.
14. Changes to this policy
We publish changes here with a new date. If a change is material, we tell platform users by e-mail before it takes effect.