Legal
Privacy Policy
How we handle personal data, yours, your contacts', and the B2B leads Sigora sources on your behalf.
Last updated: June 2026
1. Introduction
Sigora is operated by EI - ENZO ROMA(Agen, France; SIRET 98972292100024), the data controller ("Sigora", "we", "us"). Sigora is an AI lead-sourcing platform for B2B prospecting, it sources high-intent leads, verifies them, scores them by fit and buying intent, and reveals verified business contact details you can export to your own tools. This policy explains how we collect, use, store, and protect personal data, and your rights under the EU General Data Protection Regulation (GDPR) and, where applicable, the California Consumer Privacy Act (CCPA). It covers both data about our users and data about the B2B leads we process (see Section 3).
2. Data Controller
- EI - ENZO ROMA, Agen, France
- SIRET: 98972292100024
- Privacy contact: privacy@sigora.eu
- General contact: contact@sigora.eu
3. The Data We Process
We process personal data in three distinct roles:
3.1 About you (our user), we are the controller
- Account & identity: name, email, and authentication data managed by our auth provider (Clerk).
- Profile: company, role, and the ICP / sourcing configuration you set up.
- Billing: subscription and payment details processed by Stripe. We never store card numbers.
- Product content: prompts, saved searches, lists, notes, and files you create in your workspace.
- Usage & device data: features used, actions, session data, IP address, browser/OS (see our Cookie Policy).
3.2 Contacts you import, you are the controller, we are the processor
If you upload or import your own contact lists, you remain the controller of that data and you are responsible for having a lawful basis to share it with us. We act as your processor and only process it to provide the Service, under our agreement with you (a DPA is available, see /dpa).
3.3 Leads Sigora sources (third parties), we are the controller
To deliver the core Service, Sigora sources business contact data about potential leads. This is personal data about people who are not our users, so we explain it transparently here.
- Data processed: first and last name, professional title, company, public LinkedIn URL, business email address, business phone (depending on plan and your request), and public professional signals (e.g. funding events, hiring activity, public posts).
- Sources: public web pages, professional networks (e.g. LinkedIn), and reputable B2B data providers. We do not source special-category (sensitive) data.
- Legal basis (GDPR Art. 6(1)(f)): our and our users' legitimate interest in business-to-business prospecting, limited to professional contact data relevant to a genuine business proposition, and balanced against the data subject's rights.
- Information notice (GDPR Art. 14): because we collect this data indirectly, individuals have the right to be informed. This section, together with our opt-out page, serves that purpose.
- Data-subject rights: any sourced individual may object (Art. 21), request erasure (Art. 17), or access their data (Art. 15) at any time via sigora.eu/opt-out or privacy@sigora.eu. We honor these within 30 days and add the contact to a suppression list to prevent re-sourcing.
4. How We Use Data
- For users: to provide, operate, secure, and bill the Service, to provide support, and to improve the product using aggregated/anonymized data.
- For sourced leads: solely to enable a user to conduct legitimate B2B outreach (find, score, and contact relevant business prospects). Outreach itself is sent by the user, who is the sender of record (see our Acceptable Use Policy).
- We do not sell personal data, and we do not use your content or lead data to train general-purpose AI models.
Legal bases (EEA/UK GDPR). Where the GDPR or UK GDPR applies to our processing as a controller, we rely on: performance of a contract (to provide the Service you request); legitimate interests (to secure, analyze, and improve the Service, and for B2B prospecting data, balanced against the rights of the individuals concerned); consent (for non-essential cookies and marketing, where required); and legal obligation (for tax, accounting, and compliance). For sourced-lead and other Customer Data, you are the controller and are responsible for establishing your own legal basis.
5. AI Processing
AI features (sourcing logic, scoring, drafting, reply suggestions) are powered in real time by third-party AI processing providers under contract. Data sent to these providers is governed by their Data Processing Agreements and is not retained by them to train their general models. You remain responsible for reviewing AI-generated messages before they are sent.
6. Sub-processors
We rely on a vetted set of service providers (sub-processors) to run Sigora, covering hosting, payments, authentication, AI processing, data enrichment, and messaging infrastructure. Each is bound by a Data Processing Agreement, with the European Commission's Standard Contractual Clauses where data is transferred outside the EEA. We provide the current sub-processor list to customers on request under our DPA. We do not sell personal data; we only share it with these processors under contract, or where required by law.
7. International Transfers
Sigora is based in France. Some sub-processors are located outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs).
8. Your Rights
Under GDPR (EEA/UK)
- Access, rectify, erase ("right to be forgotten"), restrict, or object to processing.
- Data portability, and the right to withdraw consent where processing is based on consent.
- Lodge a complaint with your supervisory authority, in France, the CNIL (cnil.fr).
Under CCPA (California)
- Know what we collect and how it is used; request deletion; opt out of "sale" (we do not sell data); non-discrimination for exercising your rights.
To exercise any right, contact privacy@sigora.eu or use sigora.eu/opt-out. We respond within 30 days.
9. Security
We apply industry-standard safeguards: encryption in transit (TLS 1.2+) and at rest, role-based access controls, secure password hashing (via our auth provider), and regular review. In the event of a personal-data breach posing a risk to your rights, we notify the CNIL within 72 hours and affected individuals without undue delay, as required by GDPR.
10. Data Retention
We keep your personal data while your account is active. After account deletion, we remove personal data within 30 days, except where law requires longer retention (e.g. financial records for 10 years under French law). Suppression-list entries (opt-outs) are kept as long as necessary to honor the opt-out. Anonymized, aggregated data may be retained indefinitely.
11. Cookies
We use essential cookies (for authentication and session security) and, where applicable, functional cookies. Full details and how to manage them are in our Cookie Policy.
12. Children
Sigora is a business tool not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact privacy@sigora.eu and we will delete it.
13. Changes
We may update this policy. We will notify users of material changes by email or in-product at least 30 days before they take effect. The revision date is shown at the top of this page.
14. Contact
Questions or requests: privacy@sigora.eu. EEA users may also complain to their local supervisory authority; in France, the CNIL (cnil.fr).