Privacy Policy
1. Data Controller
The data controller for your personal data is:
Alexis Larcher, operating the Sigwen service as a sole proprietor. Contact: contact@sigwen.com
Sigwen is in beta. Sigwen operates as a sole proprietorship; no company has yet been incorporated. This page will be updated once operations transfer to a dedicated legal entity.
2. Data We Collect
2.1 If You Request Access (Waitlist)
When you fill out the "Request Access" form, we collect:
- your first and last name;
- your email address;
- your company name.
This information is provided directly by you, voluntarily.
2.2 If You Have an Account (Beta Access)
- email address (login identifier);
- profile data you provide to personalize your monitoring: country of origin, description of your activity, type of presence in the region, decision horizon, sector and areas of interest;
- technical usage logs (timestamps, processing volumes), for service operation and cost management purposes.
2.3 Technical Connection Data
While you browse, our hosting providers process technical data (IP address, server logs, security data) necessary to provide and protect the service.
We do not collect any special category data within the meaning of Article 9 of the GDPR.
3. Purposes and Legal Bases
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Name, email, company (waitlist) | Process your beta access request and follow up with you | Pre-contractual measures taken at your request (Art. 6(1)(b)) |
| Email and profile (account) | Provide the personalized monitoring service | Performance of a contract (Art. 6(1)(b)) |
| Usage logs | Operate the service, manage costs, prevent abuse | Legitimate interest (Art. 6(1)(f)) |
| Technical connection data | Security, availability and integrity of the service | Legitimate interest (Art. 6(1)(f)) |
4. Recipients and Processors
Your data is never sold or transferred for commercial purposes. It is processed by the following technical processors, each bound by a Data Processing Agreement (DPA):
| Processor | Role | Data Location |
|---|---|---|
| Supabase | Database, authentication, storage of access requests | European Union (Ireland) |
| Railway | Application infrastructure hosting (backend) | European Union (Amsterdam) |
| Sentry | Technical monitoring and error detection | European Union |
| Vercel | Website and application hosting (frontend) | Transfers to the United States (see section 5) |
| Anthropic | AI processing of profile elements to produce personalized summaries | United States (see section 5) |
| Resend | Transactional email delivery (not active during beta) | United States (see section 5) |
Anthropic only processes the profile elements necessary for personalization; monitoring content (geopolitical sources) comes from open public databases that never receive any of your personal data.
5. Transfers Outside the European Union
Some of our processors handle data in the United States (Anthropic, Vercel, Resend). These transfers are governed by:
- the European Commission's Standard Contractual Clauses (SCCs), incorporated into each processor's data processing agreement; and/or
- these processors' certification under the EU–US Data Privacy Framework.
In addition, some processors whose data resides within the European Union (Supabase, Railway, Sentry) belong to parent companies established in the United States and may therefore remain subject to non-EU access legislation. The Standard Contractual Clauses and the Data Privacy Framework also apply to these relationships.
6. Retention Periods
- Access requests (waitlist): retained for 12 months after your request, or deleted as soon as your access is granted if that happens sooner.
- Account and profile: retained for the entire lifetime of your account, then deleted when it is closed.
- Usage logs: 12 months.
- Connection logs: 6 months.
7. Security
We implement appropriate technical and organizational measures: encryption of data in transit (HTTPS), per-user data isolation at the database level (Row Level Security), strict management of secrets and access rights. As no system is infallible, we cannot guarantee absolute security.
8. Your Rights
In accordance with the GDPR, you have the following rights: right of access, right to rectification, right to erasure, right to restriction of processing, right to object, right to data portability, and the right to withdraw your consent where processing is based on it.
To exercise these rights, write to contact@sigwen.com. We respond within one month. Proof of identity may be requested.
You may also lodge a complaint with the CNIL (French Data Protection Authority — Commission nationale de l'informatique et des libertés), 3 place de Fontenoy, 75007 Paris, France, www.cnil.fr.
9. Cookies
The service only uses cookies that are strictly necessary for its operation (maintaining your login session). These cookies are exempt from prior consent requirements. We do not use any audience measurement, advertising, or tracking cookies.
10. Contact
For any question regarding this policy or the processing of your data: contact@sigwen.com.