Legal
Privacy policy
A plain-English notice of what Sigila stores, how long we keep it, who we share it with, and how to ask for erasure. Written for an EU SME audience — GDPR-aligned, no legalese, no micro-print, no waiver of your statutory rights.
Last updated: . Material changes get a 30-day notice — see §10.
§1
Data controller and contact
Controller. The data controller for this Service is the sole trader operating under the trading name Sigila, with an EU seat in Finland. References to “we”, “us”, “our” below mean that operator.
Contact for data requests. Every privacy, access, rectification and erasure request goes to sigila@polsia.app. The same address is the contact for the data protection officer — Sigila is a sole-trader operation so there is no separate DPO; the operator reads and answers each request personally.
§2
What we store
We collect only what we need to run the Service, prove weekly evidence, and bill for a paid plan. We do not enrich it with advertising data, and we do not resell it. The records below are the whole list — no other personal data is collected by Sigila.
2.1 Scan results and sealed vault rows.
Each weekly pass writes a row to an append-only vault: the public URL you pointed the scanner at, the timestamp, the sanitised axe-core findings, the hash of that entry, and the hash of the previous entry. The append-only ledger is the evidence chain — it is the core of the Service and the data that proves a regulator what your site looked like on a given week.
2.2 Lead email records (free-scan unlock).
When a visitor runs the free 60-second scan and asks to see >5 findings, we capture the email they give us together with the scan and the URL the scan hit. We use that email only to send the unlock link and — with one follow-up — to let them know the weekly digest is available. We do not send marketing email.
2.3 Stripe customer records.
Paid plans run on Stripe Connect. A Stripe customer record is created for the email you give at checkout, and Stripe stores the billing name, address, country, VAT number and payment-method tokens (we see only the brand — Visa / Mastercard / SEPA — and the last four digits, never the PAN).
§3
Why we store it (lawful basis)
Each category of data above has a different lawful basis under the GDPR. We pick the narrowest basis that fits and we do not use the data for any other purpose without your fresh opt-in.
- Sealed vault rows — contract. Storing the hash chain is the contract you accepted when you started a paid plan: it is the evidence we owe you, and the evidence your regulator can audit.
- Lead email records — consent. You give us your email at the unlock step, and you can withdraw that consent at any time by emailing sigila@polsia.app — we will erase the lead rows and stop sending.
- Stripe customer records — contract + legal-obligation. We rely on Stripe to bill you; the underlying record is also needed for tax and accounting law (typically 7 years in EU member states) which is a legal-obligation basis.
- Fraud and AML signals — legitimate interest. Stripe processes payment-fraud and AML signals under its own legitimate-interest basis; we do not see those raw signals, only the outcome (chargeback / refund).
§4
Retention windows
We hold data only as long as it serves a stated purpose. Where the law requires a minimum retention (tax, accounting, AML) we keep to that minimum; everywhere else we delete on the schedule below.
| Record | Kept for | Why |
|---|---|---|
| Anonymous scan | Not stored (no email captured) | Free 60-second scans need no account. |
| Lead email | ≤ 12 months | Trigger a follow-up, then archive. |
| Sealed vault row | ≤ 90 days after the chain seal + 30 days termination grace | See the Terms of service §6. |
| Stripe customer & invoice | Stripe retention + EU tax law (~7 years) | Legal obligation. Erasure does not apply while the law requires retention. |
§5
Third-party processors
We rely on a small set of processors to run the Service. We do not engage any advertising, retargeting, social-tracking or audience-profiling sub-processor — none are compatible with an EU SME audience and none are needed for the Service to work. The full sub-processor list is requestable by emailing sigila@polsia.app.
- Payments — Stripe (Stripe Connect). Checkout, billing and fraud/AML signals. Stripe is a separate data controller in its own right; its privacy notice is at stripe.com/privacy.
- Hosting — the Polsia platform. The app and its database (Postgres) run on the Polsia platform, an EU-resident hosting provider; the platform supplies the runtime, the database and the TLS termination.
- Timestamping authority (Pro tier only). The RFC 3161 trusted-timestamping authority we use to seal each weekly vault entry. The authority sees the hash we ask it to stamp, never the underlying URL or findings.
§6
International transfers
Sigila is operated from Finland in the EU/EEA; our primary hosting and database storage are likewise in the EU/EEA. Where a sub-processor is outside the EEA (Stripe’s payment processing routes through the United States for non-EU cards), the transfer is governed by the European Commission’s Standard Contractual Clauses adopted under EU data-protection law and by Stripe’s published Data Processing Addendum.
§7
Your rights — and how to use them
EU data-protection law gives you the rights below. We answer each request inside 30 days (extendable by 60 days for complex requests, with notice) and we do not charge for handling the request.
- Right to access. Ask what we hold, in a portable format. Email sigila@polsia.app.
- Right to rectification. Tell us a record is wrong and we will correct it.
- Right to erasure. Ask for the vault email, the lead rows, and the account rows deleted. Where the law makes us keep a record (invoices for tax) we will tell you which fields survive and why, then erase the rest.
- Right to restriction & right to objection. Ask us to pause processing while a dispute is open, or to stop a specific processing based on legitimate interest.
- Right to portability. Ask for a machine- readable copy of the data you gave us. The vault row’s
payloadJSON is already portable — we will hand it back on a verifiable request. - Right to lodge a complaint. With your national data-protection authority (in Finland, the Ombudsman / Tietosuojavaltuutettu) if you believe we have mishandled your data. We would, of course, prefer to hear from you first at sigila@polsia.app.
§8
Cookies and local storage
We do not set marketing, advertising or analytics cookies on this site. The only server-set identifiers on our domain are the session cookie that keeps you signed in and the theme preference stored in localStorage by the theme switcher. The full row-by-row inventory — including the Polsia platform beacon, the consent choice and the stubbed analytics row — lives on the cookie policy.
The Stripe-hosted checkout page may set its own cookies and localStorage entries to power fraud and AML signals; that domain is controlled by Stripe, not by us, and is governed by Stripe’s privacy notice.
§9
Security
We apply the controls below to the data we hold. They are not a certification and they do not replace your own duty to keep your sign-in safe.
- TLS everywhere. All traffic is over HTTPS; HSTS is set on the app domain.
- Hashed credentials. Sign-in passwords are stored using argon2id with per-user salt. We cannot read a password — only verify one.
- Hash-chained vault. Each weekly pass is appended to a SHA-256 chain sealed with a trusted RFC 3161 timestamp on Pro tier; the chain cannot be silently edited.
- Scoped queries. Every authenticated read is scoped by
userIdat the application layer; cross-tenant data is not exposed. - Incident response. A confirmed breach is reported to affected users and to the supervisory authority within the 72-hour GDPR window.
§10
Changes to this policy
- Material changes get a 30-day notice via the email on your Stripe customer record, and we’ll bump the “Last updated” line above.
- Non-material changes (typos, language clarifications, link fixes) get a refreshed “Last updated” line and no email.
- Continued use of the Service after a change takes effect counts as acceptance of the updated notice.
Contact
Contact
Data requests, access requests and erasure requests go to sigila@polsia.app. Pauliina reads every message and a reply usually goes out inside a working day. The operator’s EU seat is in Finland — there is no in-app live-chat support, by design.