Privacy policy
Last updated: · First published:
This English version is an informative translation. Only the French version is legally binding.
1. Controller and contact
The "Siggmund" service is published by Siggmund - Structure en cours de formation, whose full contact details appear in the legal notice. For any question or request relating to your personal data: privacy@siggmund.com.
We act as controller for your account data and the operation of the service. We act as processor, on your behalf, for the data you entrust to us in connection with your site and your Google accounts; this role is governed by our data processing agreement.
2. Data we process
- Account data: your e-mail address, used for magic-link authentication and communications related to the service, and — if you provide it at the end of onboarding — your phone number, to contact you again about your audit.
- Subscription data: plan subscribed to, trial and billing dates, payment status. Bank card data never passes through our servers: it is processed directly by our payment provider.
- Site data: the URL of the site you submit, its public content and the public information associated with your brand.
- Google data (Search Console and Analytics 4): if you connect your Google accounts, we access read only your Search Console statistics (impressions, clicks, positions) and your Google Analytics 4 audience metrics. We make no write or change to your Google accounts, and this connection is not an identification mechanism: we do not use it to log you in to Siggmund.
- Technical data: access and error logs needed for security and diagnosis.
3. Purposes and legal bases
Each processing operation relies on an identified legal basis (art. 6 GDPR):
- Providing the service — producing your recommendability analysis, your score and your recommendations: performance of the contract.
- Managing your account, your subscription and invoicing: performance of the contract and legal obligation for accounting records.
- Connecting your Google accounts: your consent, given at authorisation and revocable at any time.
- Securing the service — preventing abuse, fraud and intrusions: legitimate interest.
- Informing you about the service — operational messages, changes, end of trial: legitimate interest, with the option to object for non-essential messages.
- Answering your contact requests — messages sent through the form on the Contact page: legitimate interest.
We never use your data for advertising purposes, and we do not sell it.
4. Use of Google data — Limited Use
Siggmund's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In practice:
- we use this data only to provide and improve user-facing features in Siggmund;
- we do not transfer or sell this data to third parties, except where necessary to provide the service, for security reasons, or to comply with the law;
- we do not use this data for advertising purposes nor to train general-purpose artificial intelligence models;
- no human reads this data, except with your agreement, for security reasons, or where the law requires it.
On this last point, two human accesses exist and are disclosed to you here in full transparency. First, the consultant you have designated for your account accesses the same data as you: that is the very purpose of their mandate, and they only access the accounts attached to them. Second, our support team may consult your connection indicators to diagnose an incident you report to us. These accesses are limited to the people who need them and logged: you can request the record at any time. No other human access takes place.
Permissions requested and why
- Search Console — read only (
https://www.googleapis.com/auth/webmasters.readonly) — read your impressions, clicks and positions to compute your traffic potential and detect pages waiting just below the top positions. No narrower scope exists for these metrics. - Analytics 4 — read only (
https://www.googleapis.com/auth/analytics.readonly) — read your sessions and your share of organic traffic to relate your recommendations to your real audience. The read-only scope is the most restrictive one the API offers.
We request no other Google permission. You can revoke this access at any time from your Google account permissions or from your Siggmund account.
What happens when you revoke access
On revocation, or on termination of your subscription, your access tokens are immediately invalidated: they can no longer be used and no new import takes place. The tokens and the Search Console and Analytics data already imported are then deleted from our databases within 30 days. The analyses already produced remain available in your account as long as it is active; they only contain aggregated results, not the raw Google data.
5. Retention periods
- Account and e-mail address: duration of the subscription, then 3 years after the last contact.
- Phone number (where applicable): duration of the subscription, then 3 years after the last contact.
- Analyses, scores and recommendations produced: duration of the subscription, then 12 months.
- Imported Search Console and Analytics data (snapshots): 13 rolling months, and deletion within 30 days after revocation of Google access or termination.
- Google access tokens (encrypted): until you revoke them, or 30 days after termination.
- Unclaimed anonymous lead (before sign-up): 7 days after submission, automatic daily purge (SIG-88) — a claimed lead (converted into a customer) is never subject to this duration.
- Messages sent through the contact form: 3 years after the last exchange.
- Technical and security logs: 12 months.
- Administrator access logs (GDPR traceability): 3 years.
- Invoices and accounting records: 10 years (legal obligation, art. L123-22 of the French Commercial Code).
Beyond these periods, the data is deleted. Our purge is automated and extends to the internal copies used to display the dashboard.
6. Recipients and sub-processors
We use the following providers to operate the service. They only access the data to the extent necessary for their service, on instruction and under contract.
- Google Ireland Limited (Firebase, Cloud Run, Firestore, Cloud SQL) — hosting, database, application runtime. Location: European Union (europe-west1)
- Google Ireland Limited (Google Analytics 4) — audience measurement of the public website, subject to your consent. Location: Ireland (European Union), with transfers to the United States Transfer safeguards: EU–US adequacy decision (Data Privacy Framework), Google LLC being certified under it; standard contractual clauses otherwise
- Mailjet (Sinch France SAS) — sending transactional e-mails (login link, notifications). Location: France
- Stripe Payments Europe, Ltd. — collection of subscription payments. Location: Ireland
- DataForSEO OÜ (n° 14502291) — public ranking and search data. Location: Estonia (European Union)
- Mistral AI — language model analysis. Location: France
- Anthropic PBC — language model analysis. Location: United States Transfer safeguards: European Commission standard contractual clauses, incorporated into Anthropic's commercial terms
- OpenAI Ireland Limited — language model analysis. Location: Ireland (European Union) Transfer safeguards: transfers to affiliates outside the EEA governed by the European Commission standard contractual clauses
- OpenRouter, Inc. — routing of calls to language model providers. Location: United States Transfer safeguards: European Commission standard contractual clauses (art. 46), or an adequacy decision where applicable
7. Location and transfers outside the European Union
Your data is hosted in the European Union, in europe-west1 (Belgium).
Some analyses rely on language model providers established in the United States (see the list above). In this context, the public content of your site and the elements necessary for the analysis may be transmitted outside the European Union. These transfers are governed by the mechanisms provided for in chapter V of the GDPR — adequacy decision (EU-US Data Privacy Framework) or European Commission standard contractual clauses, depending on the provider.
Your Search Console and Analytics data is part of the elements transmitted to these providers when it is used to produce your analyses and recommendations — for example to interpret your best-ranked queries or your traffic sources. It is transmitted for this sole purpose, and only for inference: it is never used to train or fine-tune a model. When a provider offers an option to retain content or share data in exchange for a reduced price, we do not enable it. You can obtain a copy of the applicable safeguards on request at privacy@siggmund.com.
8. Data about third parties
By nature, the service observes what artificial intelligence assistants say about a brand and its market. The analyses may therefore mention competing brands and, occasionally, identifiable natural persons (executives, authors of cited content). This data comes from public sources or from the answers of language models, not from the data subject (art. 14 GDPR).
The outputs of language models may be inaccurate. We present them as measured observations, never as established facts. Anyone mentioned can request the rectification or deletion of the elements concerning them by writing to privacy@siggmund.com; we handle these requests within one month.
9. No automated decision-making
The Recommendability Score and the associated opportunities are decision-support indicators. They produce no legal effect and do not constitute automated decision-making within the meaning of article 22 of the GDPR: no contractual, pricing or access consequence follows from them. The ranking of recommendations relies on deterministic and auditable rules, not on a language model.
10. Security
We implement the measures provided for in article 32 of the GDPR: encryption of exchanges (TLS) and of data at rest, specific encryption of Google access tokens, role-based access segregation with server-side checks on every request, logging of administrator access for traceability, and segregation of data between customers. Access to production data is restricted to the people who need it to operate the service.
In the event of a data breach likely to result in a risk to your rights, we notify the CNIL (the French data protection authority) within 72 hours and inform you without undue delay.
11. Cookies and local storage
The following items are strictly necessary for the service to work and are, as such, exempt from consent (art. 82 of the French Data Protection Act, loi Informatique et Libertés):
- __session — keep you logged in to your account. Duration: 14 days.
- OAuth state cookie — protect the connection of your Google account against CSRF attacks. Duration: the duration of the connection (a few minutes).
- Display preference (local storage) — remember whether the side menu is expanded or collapsed. Duration: until deleted by your browser.
- Consent choice (local storage) — remember your answer to the audience measurement banner — without it, you would be asked again on every visit. Duration: 6 months.
Two other purposes exist, and neither is exempt from consent. Audience measurement (Google Analytics 4) counts visits to our public pages. Advertising (StackAdapt and OpenAI Ads) measures our campaigns and builds audiences.
These two purposes can be refused separately: the banner shown on your arrival offers "Reject all" at the same level as "Accept all", and a "Customise" button to accept only one of them. Nothing is set until you have answered, a refusal is kept as long as an agreement, and you can change your choice at any time through the "Cookies" link in the footer.
- sa-user-id, sa-user-id-v2, sa-user-id-v3 — identify your browser to measure the effectiveness of our advertising campaigns and avoid showing you our ads at random — set only after you agree to the “Advertising” purpose. Duration: 13 months at most.
- _ga, _ga_C7415YM28Y — measure the website's audience with Google Analytics 4 (page views, referrers) — set only after your agreement. Duration: 13 months.
- __obref — identify your browser for the OpenAI Ads advertising pixel and match your visit with an advertising account — set only after you agree to the “Advertising” purpose. Duration: not documented by OpenAI — to be reassessed if published.
Your choice is remembered for six months, after which you are asked again. Audience measurement is configured without Google signals or personalised advertising — accepting advertising does not enable Google's advertising categories, which remain refused; Analytics data is kept for fourteen months.
In addition to cookies, the advertising pixel transmits a fingerprint of your browser (rendering of a test image and style sheet), as well as the address and title of the page viewed. This fingerprint serves the same purpose as the cookies and falls under the same consent: it is only transmitted after you agree to the “Advertising” purpose.
In addition to a cookie, the OpenAI Ads pixel automatically looks, on the page where it is present, for information such as your e-mail address, phone number or name if you have entered them in a form; this information is hashed before transmission (it is not sent in clear text) and is used to match your visit with an advertising account. This matching is only enabled after you agree to the “Advertising” purpose.
StackAdapt acts as a separate controller and not as our processor: it therefore does not appear in the list in section 6, but below.
- StackAdapt Inc. (200 Bay Street, Toronto, Ontario, Canada) — measurement of advertising campaigns and building of audiences, subject to your consent. Established in: Canada, with operations in the United States. Transfers: European Commission adequacy decision regarding Canada; for processing carried out in the United States, StackAdapt's certification under the EU–US Data Privacy Framework.
- OpenAI OpCo, LLC (1455 3rd Street, San Francisco, California, United States) — advertising pixel, distinct from the subprocessor “OpenAI Ireland Limited” listed above for language model analysis — measurement of advertising campaigns and matching of visitors with an advertising account, subject to your consent — TO BE CONFIRMED: exact role (separate controller or processor) according to the text of their Ad Tools DPA. Established in: United States. Transfers: TO BE CONFIRMED — not read in the source document, do not publish as is.
12. Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction, objection and portability, and the right to withdraw your consent at any time. Send your request to privacy@siggmund.com; we answer within one month, which may be extended by two months for complex requests, in which case we inform you.
You may also lodge a complaint with the competent supervisory authority. In France, this is the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
13. Changes
We may change this policy. Any substantial change is notified to you by e-mail or in the application before it takes effect, and the date of the last update appears at the top of this page.