Semsem
← Back to Home

Semsem Privacy Policy

Last updated: July 27, 2026

Semsem (“Semsem,” “we,” “us,” or “our”) provides a software platform for veterinary clinics to manage patients, appointments, medical records, billing, and inventory (the “Service”). This Privacy Policy explains what personal data we collect, how we use it, and the choices you have in compliance with the Saudi Personal Data Protection Law (PDPL).

This Policy applies to:

1. What we collect

  • Account and clinic data: Name, email, phone number, clinic name and address, role/permissions, and authentication data.
  • Patient and medical data: Pet name, species, breed, age, owner contact details, appointment history, medical records, vaccination records, and attachments.
  • Billing and payment data: Subscription plan, billing cycle, invoice history. Card payment details are processed directly by our payment processor, Moyasar; Semsem does not store full card numbers.
  • Usage data & Communications: Log data, interactions with the AI copilot feature, and emails sent through the platform.

2. How we use data

We process data strictly to provide the Service: managing records, processing subscription payments, sending transactional emails, providing the AI copilot feature, and maintaining security through audit logs.

3. Data Hosting and Subprocessors

To ensure compliance with local data residency requirements, Semsem’s core databases and file storage are securely hosted on Google Cloud Platform infrastructure located within the Kingdom of Saudi Arabia (Dammam region).

We use the following third-party service providers (subprocessors):

ProviderPurpose
Google Cloud / FirebaseDatabase hosting and authentication (Hosted in KSA).
VercelApplication hosting.
MoyasarPayment processing.
ResendTransactional email delivery.
OpenRouterAI copilot feature.

Note: Semsem utilizes an automated anonymization layer that filters out identifiable personal data before any prompts are transmitted to OpenRouter.

4. Data retention and Security

We retain clinic and patient data for as long as the account is active. Upon account closure, data is retained for 30 days to facilitate export or recovery, after which it is securely deleted. We implement strict, industry-standard security measures, including HTTPS encryption, role-based access control, and multi-tenant database isolation to protect all health-adjacent data.

5. Your rights

Under the PDPL, data subjects have the right to access, correct, delete, and request portability of their data.

  • Clinic staff: Can exercise these rights via in-app settings or by contacting us.
  • Patient owners: Must contact their respective veterinary clinic directly to exercise their privacy rights, as the clinic controls the data.

6. Contact us

For privacy-related inquiries, contact: [email protected]