Privacy Policy
How we handle personal data across the Asemic website and product.
Last updated: July 25, 2026
This policy explains what personal data Asemic collects, why, and what rights you have. It covers our website at asemicanalytics.com, our application at app.asemicanalytics.com, and the AI assistant integration we provide over the Model Context Protocol (MCP).
A principle runs through all of it: Asemic is warehouse-native. Your raw event data stays in your own data warehouse. We send queries to it and receive results; we do not copy your event tables out, and we do not train any AI model on your data.
1. Who we are
Asemic doo ("Asemic", "we", "us") is the data controller for the processing described here.
- Registered address: Gandijeva 33A, 11070 Beograd (Novi Beograd), Serbia
- Company registration (MB): 21994375. Tax number (PIB): 114246979
- Privacy contact: privacy@asemicanalytics.com
2. Information we collect
When you visit the website
We collect privacy-respecting, aggregate usage statistics (pages viewed, approximate region, referrer, device type) through a self-hosted, cookieless analytics tool. This data does not identify you and is not combined with anything else to do so. Our hosting provider also processes standard server request logs, including IP addresses, to deliver and secure the site.
When you contact us or subscribe
If you submit a form to subscribe to updates, join a launch list, or request a demo, we collect the details you provide, which is typically your email address and any message. We use these to reply and to send the updates you asked for. Every subscription email includes an unsubscribe link.
When you use the Asemic application
To provide the product we process:
- Account data: your name and email address, your authentication method (email and password, or Google sign-in), your role, and the workspace and projects you belong to.
- Warehouse connection details: the credentials you provide so Asemic can query your warehouse. These are encrypted at rest. Where your warehouse supports it, you can connect with a user-scoped OAuth grant that you can revoke at any time.
- Product usage: records of key actions (for example a sign-up or a first warehouse-connection attempt) used to operate the service, provide support, and improve onboarding.
Your analytics data
The event and user data you analyze in Asemic stays in your warehouse. Asemic compiles your definitions into SQL that runs inside your BigQuery or Snowflake, and returns the results to display in the product. We do not store copies of your raw event tables, and we do not use your data to train AI models.
AI assistant (MCP) connections
If you connect an AI assistant (such as Claude, ChatGPT, or Gemini) to Asemic, that assistant signs in as you through OAuth and can query only what your role allows. The assistant receives the results of the queries it runs, under your own account with the AI provider you chose. Asemic does not send your data to any AI model on its own initiative; the AI in this flow is the one you connected, acting on your request. You can revoke a connected assistant at any time.
3. How we use information
- To provide, secure, and maintain the website and product.
- To authenticate you and enforce your permissions.
- To respond to your enquiries and send updates you requested.
- To understand aggregate usage and improve the product and onboarding.
- To comply with our legal obligations.
4. Legal bases
Where the GDPR or Serbia's Law on Personal Data Protection applies, we rely on: performance of a contract (to provide the product to you and your organization), consent (for marketing emails, which you can withdraw at any time), and legitimate interests (to secure our services and understand aggregate usage, balanced against your rights).
5. Cookies
The website uses no tracking cookies; our analytics are cookieless. The application uses strictly necessary cookies to keep you signed in and to operate the service. The demo booking page embeds a Google Calendar scheduler, which may set its own cookies when you interact with it.
6. Service providers
We share personal data only with providers that process it on our behalf to run our services, under appropriate agreements. These currently include:
- Cloudflare: website hosting and delivery.
- Google Cloud: application hosting, Google sign-in, and the calendar scheduler on our demo page. If your warehouse is BigQuery, queries run in your own Google Cloud project under your credentials.
- Web3Forms: processing of website form submissions.
- Microsoft 365: our business email.
- Our self-hosted analytics provider for aggregate, cookieless statistics.
We do not sell personal data.
7. International transfers
We are based in Serbia and use providers that may process data in the European Union, the United States, and elsewhere. Where data is transferred across borders, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.
8. Retention
We keep personal data only as long as necessary for the purposes above: account data for the life of your account and a limited period afterward, form and subscription data until you unsubscribe or ask us to delete it, and aggregate usage statistics on a rolling basis. We delete or anonymize data when it is no longer needed.
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest for warehouse credentials, role-based access controls, and scoped, revocable authentication. No system is perfectly secure, but keeping your raw data in your own warehouse means the most sensitive data never sits with us.
10. Your rights
Subject to applicable law, you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact privacy@asemicanalytics.com. If you are in a workspace created by your employer, some requests may be directed to that organization as the controller of its own account data.
You also have the right to lodge a complaint with your data protection authority. In Serbia this is the Commissioner for Information of Public Importance and Personal Data Protection; in the EU it is your national supervisory authority.
11. Children
Asemic is a business product not directed to children, and we do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this policy as our product and obligations evolve. We will change the "last updated" date above and, for material changes, provide a more prominent notice.
13. Contact
Questions about this policy or your data: privacy@asemicanalytics.com.