Data processing agreement

Last updated: · First published:

This English version is an informative translation. Only the French version is legally binding.

This agreement (hereinafter the "DPA") is concluded within the meaning of article 28 of Regulation (EU) 2016/679 (the "GDPR") between the Customer, acting as controller, and Siggmund - Structure en cours de formation, acting as processor (hereinafter "Siggmund"). It forms an integral part of the terms of sale and is accepted by the Customer upon subscription. In the event of a contradiction, this DPA prevails over the other contractual documents as regards the processing of personal data.

1. Purpose and roles

Siggmund processes personal data on behalf of the Customer for the sole purpose of performing the service described in the general terms: measuring how likely assistants are to recommend the Customer's brand, producing a score and recommendations. The Customer determines the purposes and means of this processing; Siggmund acts only on its documented instructions, which consist of the general terms, this DPA and the settings made by the Customer in its account.

Siggmund remains a controller for its own needs (account management, invoicing, security), governed by the privacy policy.

2. Description of the processing

  • Nature and purpose: collection, storage, automated analysis and reporting of data relating to the Customer's online presence.
  • Categories of data subjects: users designated by the Customer; where applicable, identifiable natural persons mentioned in the public content analysed or in the answers of language models.
  • Categories of data: identifiers and e-mail addresses of users; public content of the Customer's site; Search Console and Analytics 4 metrics (impressions, clicks, positions, sessions, traffic sources); technical identifiers of the connected Google properties.
  • Special categories of data: none. The service is not designed to process data referred to in article 9 of the GDPR, and the Customer undertakes not to submit any.
  • Duration: the duration of the subscription, plus the retention periods set out in article 8.

3. Siggmund's obligations

Siggmund undertakes to:

  • process the data only on documented instructions from the Customer, and inform it without delay if an instruction appears to infringe the GDPR;
  • not use the Customer's data for other purposes, in particular neither for advertising nor to train general-purpose artificial intelligence models;
  • guarantee the confidentiality of the data and bind any person authorised to access it to an obligation of confidentiality;
  • implement the technical and organisational measures described in article 5;
  • assist the Customer, to a reasonable extent, in carrying out impact assessments, responding to requests from data subjects and dealing with a supervisory authority;
  • make available the information necessary to demonstrate compliance with this DPA.

4. Customer's obligations

The Customer warrants that it has a legal basis for the processing entrusted, that it has informed the data subjects, and that it holds the necessary rights over the sites and Google accounts it connects. It is responsible for transmitting only the data necessary for the service.

5. Security

In accordance with article 32 of the GDPR, Siggmund implements: encryption of communications (TLS) and of data at rest; dedicated encryption of Google access tokens; role-based access control, checked server-side on every request; segregation of data between customers; logging of administrator access; backups; restriction of production access to the people who need it; review of dependencies and secrets.

6. Sub-processors

The Customer authorises Siggmund to use the sub-processors listed below. Siggmund imposes on them by contract data protection obligations equivalent to those of this DPA and remains liable for their performance.

  • Google Ireland Limited (Firebase, Cloud Run, Firestore, Cloud SQL) — hosting, database, application runtime. Location: European Union (europe-west1)
  • Google Ireland Limited (Google Analytics 4) — audience measurement of the public website, subject to your consent. Location: Ireland (European Union), with transfers to the United States Transfer safeguards: EU–US adequacy decision (Data Privacy Framework), Google LLC being certified under it; standard contractual clauses otherwise
  • Mailjet (Sinch France SAS) — sending transactional e-mails (login link, notifications). Location: France
  • Stripe Payments Europe, Ltd. — collection of subscription payments. Location: Ireland
  • DataForSEO OÜ (n° 14502291) — public ranking and search data. Location: Estonia (European Union)
  • Mistral AI — language model analysis. Location: France
  • Anthropic PBC — language model analysis. Location: United States Transfer safeguards: European Commission standard contractual clauses, incorporated into Anthropic's commercial terms
  • OpenAI Ireland Limited — language model analysis. Location: Ireland (European Union) Transfer safeguards: transfers to affiliates outside the EEA governed by the European Commission standard contractual clauses
  • OpenRouter, Inc. — routing of calls to language model providers. Location: United States Transfer safeguards: European Commission standard contractual clauses (art. 46), or an adequacy decision where applicable

Siggmund informs the Customer of any addition or replacement of a sub-processor at least 30 days before it takes effect, by e-mail to the account's contact address. The Customer may object on legitimate and reasonable grounds within this period; failing agreement, it may terminate its subscription without penalty, the unused portion of the subscription being refunded.

7. Transfers outside the European Union

The data is hosted in the European Union, in europe-west1 (Belgium). Some language model providers are established in the United States; the corresponding transfers are governed by an adequacy decision (EU-US Data Privacy Framework) or by the European Commission standard contractual clauses, depending on the provider, accompanied where necessary by supplementary measures. A copy of the applicable safeguards is provided on request. The Customer's Search Console and Analytics data is not transmitted to these providers.

[Mechanism chosen for each provider to be confirmed and documented in the register].

8. Retention, return and deletion

The applicable retention periods are as follows:

  • Account and e-mail address: duration of the subscription, then 3 years after the last contact.
  • Phone number (where applicable): duration of the subscription, then 3 years after the last contact.
  • Analyses, scores and recommendations produced: duration of the subscription, then 12 months.
  • Imported Search Console and Analytics data (snapshots): 13 rolling months, and deletion within 30 days after revocation of Google access or termination.
  • Google access tokens (encrypted): until you revoke them, or 30 days after termination.
  • Unclaimed anonymous lead (before sign-up): 7 days after submission, automatic daily purge (SIG-88) — a claimed lead (converted into a customer) is never subject to this duration.
  • Messages sent through the contact form: 3 years after the last exchange.
  • Technical and security logs: 12 months.
  • Administrator access logs (GDPR traceability): 3 years.
  • Invoices and accounting records: 10 years (legal obligation, art. L123-22 of the French Commercial Code).

At the end of the service, Siggmund deletes the data processed on behalf of the Customer according to these periods, unless a legal obligation requires it to be kept. Before termination, the Customer may request the return of its data in a structured and commonly used format.

9. Personal data breach

Siggmund notifies the Customer without undue delay, and no later than 48 hours after becoming aware of it, of any personal data breach affecting its data, providing the information the Customer needs for its own notification under articles 33 and 34 of the GDPR, as well as the measures taken to remedy it.

10. Audit

Siggmund answers the Customer's security questionnaires and provides it with the relevant documentation. The Customer may, no more than once a year and subject to 30 days' notice, have a proportionate audit carried out, at its own expense, under conditions that preserve the confidentiality of other customers and the security of the service.

11. Contact

Any request relating to this agreement: privacy@siggmund.com.