Who is responsible
The controller for the personal data described here is Fyrvest AB (org. no. 559032-5220), Sweden, trading as Sigill. Questions, requests and complaints go to privacy@sigill.tech.
Two different roles
Sigill appears in your life in two ways, and data protection law treats them differently.
On this website and in our sales and support correspondence, we decide what is collected and why. We are the controller, and this statement is the full description.
In the reporting portal, the data you upload is your institution's data. You decide what goes in it and what it is for; we process it on your instructions to produce and validate your submissions. There we are a processor, and the binding terms are the data processing agreement in your contract, not this page. Supervisory reporting data is mostly figures rather than personal data, but it can contain the names and contact details of the people who prepare, approve and sign a submission — those are covered by the same agreement.
What we collect
When you request a pilot or a demo
The form asks for your name, work email address, institution and, optionally, a phone number and a short description of what you report today. We use it to answer you and to prepare that conversation. The legal basis is our legitimate interest in responding to a business enquiry you initiated, and, once a pilot is being arranged, the steps taken at your request before entering a contract. We keep enquiries for 24 months from our last contact, then delete them.
When you simply visit
Our server records the request: IP address, the page requested, the time and the browser's user agent. We need it to keep the site available and to stop automated abuse of the pilot form — the form is rate-limited per IP address for exactly that reason. The legal basis is our legitimate interest in the security and integrity of the service. Logs are kept short-term and are not used to build any profile of you.
When you have a portal account
An account holds your name, work email address, the institution you belong to and your role in it, so that we can authenticate you and apply the right permissions. We also log which user performed which action on a submission — that audit trail is part of what makes the reporting defensible, and it is a feature of the product rather than an afterthought. The legal basis is the performance of the contract with your institution, and our legal obligation to keep records adequate for a regulated process.
No cookies, no analytics, no tracking
This website sets no cookies, embeds no analytics, loads no fonts or scripts from third-party networks, and does not track you across sites. There is no consent banner because there is nothing to consent to. The portal sets a strictly necessary session cookie to keep you logged in, which needs no consent and is used for nothing else.
Who else sees the data
We keep the list of third parties deliberately short, and we do not sell or rent personal data to anyone, ever.
- Resend — Email delivery. United States.
- Attio — CRM for customer and prospect contact details. United Kingdom.
- Our own infrastructure — the site and the portal run on servers we operate ourselves, inside the EU/EEA.
Where a recipient is outside the EU/EEA, the transfer is covered by the European Commission's standard contractual clauses together with the supplementary measures agreed with that provider. Ask us and we will tell you exactly which mechanism applies to which provider.
We may also disclose data where the law requires it — a court order, or a lawful request from a supervisory or law enforcement authority. If that ever happens and we are permitted to tell you, we will.
How long we keep it
- Pilot and demo enquiries: 24 months from our last contact.
- Support and sales correspondence: for the duration of the relationship, then 24 months.
- Portal accounts: for as long as the institution is a customer, then deleted or anonymised.
- Submission audit trails: as agreed in the contract, because they may be needed to evidence a filing.
- Server logs: short-term, for security purposes only.
- Accounting records: as required by Swedish bookkeeping law.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it if it is wrong, to delete it, to restrict how we use it, or to receive it in a portable format. Where we rely on legitimate interest, you can object — and for direct marketing, an objection is absolute: we stop, no questions asked.
Write to privacy@sigill.tech. We answer within one month. If we ever get it wrong, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se), or to the supervisory authority where you live or work.
How we protect it
Everything is encrypted in transit. Access is limited to the people who need it, and the portal separates institutions from one another at the database level — a customer's data is unreachable from another customer's session by construction, not by a filter someone remembered to apply. Secrets are held outside the source code, and the reporting engine reads reference data read-only.
Changes to this statement
If we change how we handle personal data, we update this page and the date at the top. If the change is significant and affects you as a customer, we tell you directly rather than relying on you to notice.