Legal
Privacy Policy
Last updated June 1, 2026.
This Privacy Policy explains how Sema ("Sema", "we", "us", "our") collects, uses, discloses, and protects personal information when you visit our website, create an account, or use our products and services. We are committed to processing personal data lawfully, fairly, and transparently in accordance with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000 and its rules, and, where applicable, the EU/UK GDPR.
1. Who we are
- Sema operates a semantic-layer platform for enterprise AI analytics. For personal data you provide to us directly (for example, when you sign up or contact us), Sema acts as the data fiduciary / controller.
- For data within the databases you connect to Sema, you (our customer) are the data fiduciary / controller and Sema acts as a data processor on your behalf under our Data Processing Addendum.
2. Information we collect
- Account information you provide, such as name, work email, company, role, and password (stored only as a salted hash).
- Billing information processed by our payment partner; we do not store full card numbers.
- Usage, log, and device data such as IP address, browser type, pages viewed, and feature interactions, collected via server logs, cookies, and similar technologies.
- Content you submit, including questions you ask, glossary edits, and the schema and sample values Sema reads from the data sources you connect to operate the product.
- Communications you send us, including support requests and enquiry-form submissions.
3. How we use information
- To provide, secure, personalise, and improve the product, including authentication, billing, support, and product analytics.
- To communicate with you about your account, security notices, service changes, and — where you have consented or as otherwise permitted by law — product updates.
- To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
4. Legal bases & consent
- We process personal data on the basis of your consent, the performance of a contract with you, our legitimate interests in operating and securing the service, and compliance with legal obligations.
- Where we rely on consent (for example, for certain marketing communications or cookies), you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Cookies & tracking
- We use strictly necessary cookies to run the site and, with your consent where required, analytics cookies to understand usage.
- You can control cookies through your browser settings; disabling some cookies may affect functionality.
6. Sharing & disclosure
- We share information with subprocessors who help us operate the service (see our Subprocessors page), under written contracts imposing confidentiality and data-protection obligations.
- We may disclose information to comply with applicable law, lawful requests by public authorities, or to protect the rights, safety, and security of Sema, our users, and the public.
- In the event of a merger, acquisition, or asset sale, personal data may be transferred subject to this Policy.
- We do not sell your personal data.
7. International transfers
- Personal data may be processed in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as standard contractual clauses and transfer only to jurisdictions permitted under applicable law, including the DPDP Act.
8. Data retention
- We retain personal information for as long as your account is active or as needed to provide the service, and thereafter only as required to meet legal, tax, accounting, or security obligations.
- Audit and evidence records may be retained for up to seven years to support compliance and dispute resolution, after which they are deleted or irreversibly anonymised.
9. Security
- We implement reasonable security safeguards including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, network isolation, secret encryption, and append-only audit logging.
- No method of transmission or storage is completely secure; we continually review and improve our safeguards.
10. Your rights
- Subject to applicable law, you may have the right to access, correct, update, and erase your personal data, to obtain a summary of processing, to nominate another individual to exercise your rights in case of death or incapacity, and to grievance redressal.
- To exercise these rights, email privacy@semalayer.com. We will verify your identity and respond within the timeframes required by law.
11. Children
- Sema is not directed to children. We do not knowingly process the personal data of children without verifiable parental consent as required by the DPDP Act. If you believe a child has provided us personal data, contact privacy@semalayer.com.
12. Grievance & Data Protection Officer
- Grievance Officer (India, DPDP Act, 2023): reachable at grievance@semalayer.com. We acknowledge grievances promptly and resolve them within the statutory period.
- You also have the right to lodge a complaint with the Data Protection Board of India.
13. Changes to this Policy
- We may update this Policy from time to time. Material changes will be notified via the product or email. The 'last updated' date above reflects the latest revision.
14. Contact
- Questions about this Policy? Email privacy@semalayer.com.

