SemperWise semperwise.com

Client Portal

Portal privacy notice

Applies to the SemperWise client portal. Last updated 9 August 2026.

1. Scope of this notice

This notice covers personal data processed through the client portal. The main privacy policy on semperwise.com covers our website and our business generally.

2. What we collect

3. Cookies

The portal sets one strictly-necessary cookie to keep you signed in, and one optional cookie if you choose "keep me signed in". There is no analytics, no advertising and no third-party tracking. You cannot turn the session cookie off and still sign in, because it is the sign-in.

4. Why we process it

To provide the services your organisation has engaged us for; to keep the portal secure and prove who did what; and to meet our legal and contractual obligations. The lawful basis is performance of a contract, and our legitimate interest in securing the service.

5. Who can see your data

Your organisation's own users, according to the role you give them, and the SemperWise personnel delivering your engagement. When our staff open your account to help you, that access is recorded in your activity log. We do not sell data and we do not share it with third parties for their own purposes.

6. Where assessments run

Assessments are executed on infrastructure operated by SemperWise, not by the portal itself. The portal holds the request and the results. Credentials for the scanning infrastructure are never stored on the portal server.

7. Retention

Assessment data is retained for the period agreed in your engagement, so that you retain the evidence auditors ask for. Audit records are retained longer where we are required to demonstrate what happened. On written request we will delete your account and associated data, except where we must keep records by law.

8. Your rights

Under the India DPDP Act and, where applicable, the GDPR, you may request access to, correction of, or erasure of your personal data, and may withdraw consent where consent is the basis. Contact info@semperwise.com; we respond within 24 business hours.

9. Security

Passwords are hashed, tokens are stored only as hashes, transport is encrypted, and every organisation's data is isolated from every other. Reports and evidence are stored outside the web root and served only after an authorisation check.


Questions about this page? Email info@semperwise.com. Back to the portal.