Last updated: 1 August 2026
This document is provided in English, which is the legally authoritative version.
This Privacy Policy explains how Semplo B.V. ("Semplo", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our website at semplo.ai and our AI employee platform (together, the "Service").
We are committed to complying with the General Data Protection Regulation (GDPR) and the Dutch implementation thereof (UAVG). If you have questions about this policy, Contact at privacy@semplo.ai.
Semplo B.V. is the data controller responsible for your personal data.
We collect personal data in the following ways:
When your customers interact with your AI employee widget, we process messages and any personal data they share (such as name, email, phone number, and appointment details) on your behalf as a data processor. You are the data controller for this data. See our Data Processing Agreement for details.
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing payments and managing subscriptions | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending transactional emails (confirmations, receipts) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Customer support and responding to enquiries | Legitimate interests (Art. 6(1)(f) GDPR) |
| Improving and developing our Service | Legitimate interests (Art. 6(1)(f) GDPR) |
| Sending product updates and marketing emails | Consent (Art. 6(1)(a) GDPR) — you may opt out at any time |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Fraud prevention and security | Legitimate interests (Art. 6(1)(f) GDPR) |
We do not sell your personal data. We share data only with the following categories of sub-processors, each under appropriate data processing agreements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (AWS Frankfurt) |
| Anthropic | AI language model processing | USA (Standard Contractual Clauses) |
| Stripe | Payment processing | USA (Standard Contractual Clauses) |
| Resend | Transactional and growth email delivery | USA (Standard Contractual Clauses) |
| Twilio | SMS delivery | USA (Standard Contractual Clauses) |
| Vercel | Application hosting and delivery | USA/EU (Standard Contractual Clauses) |
| Vapi | Voice call orchestration, including call audio and transcripts | USA (Standard Contractual Clauses) |
| Deepgram | Speech-to-text during voice calls | USA (Standard Contractual Clauses) |
| ElevenLabs | Text-to-speech for the spoken reply | USA (Standard Contractual Clauses) |
| Google / Microsoft | Calendar synchronisation, where you connect Google or Outlook | USA/EU (Standard Contractual Clauses) |
| Booking.com | Reservation synchronisation, where you connect Booking.com | EU (Netherlands) |
Where data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
| Data type | Retention period |
|---|---|
| Account and billing data | Duration of your account plus 7 years (legal/tax obligation) |
| Conversation and customer data | Duration of your account, or as configured in your settings |
| Usage and analytics data | 24 months |
| Support communications | 3 years after the last interaction |
| Marketing consent records | Until consent is withdrawn, plus 3 years |
When you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain it by law.
As a data subject in the European Economic Area, you have the following rights:
To exercise any of these rights, email us at privacy@semplo.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption at rest and in transit, access controls, and regular security reviews. Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it responsibly to security@semplo.ai.
We use cookies and similar tracking technologies on our website. For full details of what cookies we use and how to manage them, see our Cookie Policy.
Our Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, Contact at privacy@semplo.ai and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on our website at least 14 days before the change takes effect. The date at the top of this page always reflects the most recent update. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
For any questions about this Privacy Policy or to exercise your rights, Contact: