1. Scope
This Privacy Policy describes how Sigigo ("Sigigo", "we", "us") handles personal data when you visit https://sigigo.com, subscribe to communications, request a demo, create an account, or use Sigigo evidence infrastructure services.
This policy applies to our marketing website and general customer relationships. Enterprise customers may also receive a Data Processing Agreement (DPA) that governs processing of data submitted to the Sigigo platform.
2. Who is responsible
For this website and our direct marketing activities, Sigigo acts as the data controller. For data your organization submits to the Sigigo platform for evidence logging, Sigigo typically acts as a data processor on your instructions — see our Data Processing Agreement.
Privacy inquiries: privacy@sigigo.com. Data protection requests may also be sent to this address.
3. Data we collect
We may collect the following categories of personal data:
- Contact and identity data — name, work email, company, job title, and messages you send via forms or email.
- Account data — if you sign in (for example via our authentication provider), account identifiers and session metadata.
- Usage and technical data — IP address, browser type, device information, pages viewed, referral URLs, and approximate location derived from IP.
- Cookie and analytics data — as described in our Cookie Policy.
- Customer platform data — when you use Sigigo services, event metadata and evidence records as configured by your organization. Sensitive payloads may remain in your environment when Private Commitment Mode is enabled.
4. How we use data and lawful bases (GDPR)
Where the GDPR applies, we rely on the following lawful bases:
- Contract — to respond to inquiries, provide services, manage accounts, and perform our agreement with you.
- Legitimate interests — to operate and secure our website, understand aggregate usage, improve our services, and communicate about products relevant to your role (balanced against your rights).
- Consent — for non-essential cookies/analytics where required, and for certain marketing where consent is the appropriate basis.
- Legal obligation — to comply with applicable law, respond to lawful requests, and maintain records required by regulation.
5. Product privacy posture
Sigigo is designed for data minimization and sovereignty. By default, EU-oriented deployments use region-pinned infrastructure, public blockchain anchoring off unless your legal team approves it, and evidence capture at decision boundaries rather than bulk export of sensitive payloads.
Private Commitment Mode allows customers to keep sensitive content in their vault while Sigigo witnesses signed commitments — narrowing our role as processor and reducing exposure of personal data on our systems.
Sigigo does not sell personal data. We do not use customer evidence payloads for advertising or model training.
7. International transfers
Sigigo may process data in the United States and other countries where we or our sub-processors operate. Where personal data is transferred from the EEA, UK, or Switzerland to countries without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) and supplementary measures where required.
Enterprise customers may select EU-sovereign deployment profiles on AWS or Microsoft Azure that keep primary processing and storage in approved regions.
8. Retention
We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law or legitimate business need (for example, dispute resolution).
Customer evidence records are retained according to your subscription configuration and applicable regulatory minimums (for example, EU AI Act deployer log retention). Erasure and tombstoning options are available subject to integrity and legal hold requirements documented in your DPA.
9. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, audit logging, and region-scoped key management for production services.
Report security issues to security@sigigo.com.
10. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object to processing, data portability, and withdraw consent where processing is consent-based.
EU/EEA and UK residents may lodge a complaint with their local supervisory authority. We encourage you to contact us first so we can address your concern.
To exercise rights, email privacy@sigigo.com. We may need to verify your identity.
11. Children
Sigigo services and this website are directed at business users. We do not knowingly collect personal data from children under 16.
12. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may be communicated by email or prominent notice where appropriate.