1. Who we are
Sigmira ("Sigmira", "we", "us", "our") is the controller responsible for the personal data described in this notice, except where we act as a processor on behalf of our merchant customers (see Section 2).
| Controller | Quincy van der Ree, trading as Sigmira — a sole proprietorship (eenmanszaak) established in the Netherlands |
| Chamber of Commerce (KvK) | 82195757 |
| VAT (BTW) | NL003652487B20 |
| Registered address | Verdiweg 671, 3816 KW Amersfoort, The Netherlands |
| Privacy / contact email | hello@sigmira.com |
Data Protection Officer (DPO). We have assessed our processing against Article 37 GDPR and concluded that we are not required to appoint a statutory Data Protection Officer (our core activities do not consist of large-scale systematic monitoring or large-scale processing of special-category data). We have therefore not appointed a DPO. For all privacy matters, please use the contact point above: hello@sigmira.com.
2. Scope of this notice
This notice explains how we handle personal data of:
- Website visitors — people who visit our website and marketing pages;
- Prospective customers — people and businesses who contact us, request information, or sign up for a trial;
- Active customers / merchants — the online merchants (businesses and individuals) who subscribe to and use the Sigmira platform.
Our dual role: controller and processor
Sigmira operates a SaaS "product customizer" platform that online merchants embed in their stores (currently WooCommerce; Shopify planned) so that their shoppers can personalise products (adding text, monograms, and uploaded images or photos) and the merchant receives a print-ready file for each order.
- We are the controller for: (a) merchant and customer account data (registration, login, billing administration, support), and (b) website-visitor data. This notice governs that processing.
- We are a processor for the design content that a merchant’s own shoppers submit through the embedded customizer: for example uploaded images and photos, entered text and monograms, and the generated design/print files. For that content, the merchant is the controller and Sigmira processes it only on the merchant’s instructions.
Our processor relationship with each merchant is governed by a separate Data Processing Agreement (DPA), which sets out the subject-matter, duration, security measures, sub-processors, and the rights and obligations of the parties. If you are a shopper who used a customizer on a merchant’s store and you wish to exercise data rights over your design content, please contact that merchant; they are the controller of that content. This notice does not reproduce the DPA; the DPA governs in case of any conflict for processor-role processing.
3. Categories of personal data we collect
As a controller, we collect and process the following categories of personal data:
- Account data — your name, business / company name, and email address.
- Authentication data — credentials and session information used to secure your login (passwords are stored in hashed form; we do not store them in plain text).
- Billing and subscription data — your subscription plan, status, and invoicing details. Payment card and full billing data are collected and processed by Paddle, not by Sigmira (see Sections 5 and 4). We do not store full payment card numbers.
- Communications and support data — the content of emails, support requests, and other correspondence you send us, and our replies.
- Technical and usage data — IP address, device and browser information, and server log data (such as access times, pages requested, and error logs), generated when you use our website or platform.
- Cookie data — see Section 13. We currently use only strictly necessary cookies.
We do not intentionally collect special-category data (Article 9 GDPR) from merchants or website visitors as part of providing the service.
4. Purposes of processing and lawful bases
We process personal data only where we have a lawful basis under Article 6 GDPR.
| Purpose | Personal data used | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Provide, operate and administer the Sigmira platform and your account; authenticate logins | Account, authentication, billing/subscription data | Performance of a contract — Art. 6(1)(b) |
| Respond to your enquiries and provide customer support | Communications/support data, account data | Contract — Art. 6(1)(b); or legitimate interests — Art. 6(1)(f) for prospects not yet customers |
| Secure our systems, prevent and detect fraud and abuse, maintain service integrity | Technical/usage data, authentication data, IP address | Legitimate interests — Art. 6(1)(f) |
| Improve and develop the product (diagnose errors, understand aggregate usage) | Technical/usage data, log data | Legitimate interests — Art. 6(1)(f) |
| Send marketing emails about our products and features | Name, email | Consent — Art. 6(1)(a) (where required), or legitimate interests for existing-customer service messaging where permitted |
| Set non-essential cookies (e.g. analytics/marketing, if introduced) | Cookie/usage data | Consent — Art. 6(1)(a) (and Telecommunicatiewet art. 11.7a) |
| Keep invoices and financial/tax records | Billing administration data | Legal obligation — Art. 6(1)(c) (Dutch tax law) |
Legitimate-interests balancing. Where we rely on legitimate interests (security, fraud prevention, product improvement, contacting prospects), we have weighed our interests against your rights and freedoms and concluded the processing is necessary, proportionate, limited to what is needed, and not overridden by your interests. It involves no sensitive data and produces no legal or similarly significant effects on you. You may object at any time; see Section 8.
5. Recipients, third parties and sub-processors
We share personal data only with the providers and parties below. Where they act as processors, they do so under a data processing agreement; where they act as independent controllers, they are responsible for their own processing.
| Recipient | Purpose | Role | Location / transfer |
|---|---|---|---|
| Paddle (Paddle.com Market Ltd, UK; Paddle Payments Ltd, Ireland) | Payments, subscription billing and invoicing — Merchant of Record | Independent controller for payment/billing data | UK and Ireland |
| Amazon Web Services (AWS) | Cloud hosting, database (RDS PostgreSQL), file/asset storage (S3), CDN (CloudFront), transactional email (Amazon SES) | Processor | EU — eu-central-1 (Frankfurt, Germany) |
| Resend | Transactional email delivery | Processor | |
| Google (Google Workspace) | Company email mailbox / correspondence | Processor | EU / global |
About Paddle (Merchant of Record). When you purchase a subscription, you contract with Paddle as the reseller (Merchant of Record). Paddle collects and processes your payment and billing data as an independent controller and issues your invoice. Sigmira receives only limited subscription and billing-administration data and does not store your full payment card details. Paddle’s own privacy policy governs its processing: https://www.paddle.com/legal/privacy.
We do not sell personal data. We may disclose data where required by law, court order, or to protect our legal rights.
6. International transfers
Your data is hosted and stored in the European Union (AWS, Frankfurt / eu-central-1). However, some of the service providers we use (see Section 5) operate, or have group companies, outside the EEA: for example Paddle (United Kingdom) and certain email providers. Where personal data is transferred outside the EEA, we rely on a valid transfer mechanism under Chapter V GDPR: an adequacy decision of the European Commission (such as the UK adequacy decision, or the EU–US Data Privacy Framework for certified US providers), or the European Commission’s Standard Contractual Clauses (SCCs) with any required supplementary measures. You can request more information and a copy of the relevant safeguards by emailing hello@sigmira.com.
7. How long we keep your data (retention)
- Account data — kept for up to 6 months after your subscription ends (so you can reactivate without losing your setup), then deleted or anonymised, subject to the legal-retention items below.
- Invoices and financial / accounting records — retained for 7 years, the statutory Dutch tax retention period (fiscale bewaarplicht).
- Server and security logs — retained for no longer than 90 days (and only longer where needed to investigate a specific security incident or suspected fraud), then deleted or anonymised.
- User-submitted content (held as processor on a merchant’s behalf) — deleted on the merchant’s documented instruction in line with the DPA, and in any event within 6 months of account termination.
- Marketing / consent records — kept until you withdraw consent or object, plus a short period to evidence the withdrawal.
8. Your data-subject rights
Under the GDPR you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), object to processing based on legitimate interests and to direct marketing at any time (Art. 21), and withdraw consent at any time where processing is based on consent (Art. 7(3)).
How to exercise your rights. Email hello@sigmira.com. We may need to verify your identity. We will respond within one month; for complex or numerous requests we may extend by up to two further months and will tell you (Art. 12). Exercising these rights is free unless a request is manifestly unfounded or excessive.
If your request concerns design content you submitted through a merchant’s store, please contact that merchant (the controller of that content); we will support the merchant in responding (see Section 2).
9. Right to lodge a complaint
If you believe we have not handled your personal data lawfully, you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP):
- Website (English): https://www.autoriteitpersoonsgegevens.nl/en
- Submit a complaint: https://www.autoriteitpersoonsgegevens.nl/en/submitting-a-tip-off-or-a-complaint-to-the-ap
We would appreciate the chance to address your concerns first; please contact us at hello@sigmira.com.
10. Automated decision-making and profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Security and fraud-prevention measures may flag activity for review, but any consequential decision involves human assessment.
11. Security measures
We take appropriate technical and organisational measures, including: encryption in transit (TLS/HTTPS) and at rest; access controls (least-privilege, authentication, restricted admin access); EU hosting (AWS, Frankfurt); and logging, monitoring and regular review. No system is completely secure, but we work to protect your data and to respond promptly to incidents, including notifying the AP and affected individuals where legally required.
12. Children
The Sigmira platform is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16. Each merchant is responsible for the lawful basis and any required parental consent for its own shoppers, including minors, under the DPA and applicable law.
13. Cookies
We use cookies and similar technologies on our website. Today we use only strictly necessary cookies, e.g. cookies that keep you logged in (session/authentication) and protect the security of the service. Under the Dutch Telecommunicatiewet (art. 11.7a) and the ePrivacy rules, strictly necessary cookies do not require prior consent.
| Cookie type | Purpose | Consent required? |
|---|---|---|
| Strictly necessary (session / login, security) | Keep you signed in; protect against abuse | No — exempt |
| Analytics / statistics (not currently used) | — | Yes — prior consent |
| Marketing / tracking (not currently used) | — | Yes — prior consent |
If in future we introduce analytics or marketing cookies (or any non-essential cookies), we will request your prior consent through a cookie banner before they are set, as required by the Telecommunicatiewet/ePrivacy, and update this notice. You can withdraw consent at any time.
14. Changes to this notice
We may update this notice to reflect changes in our processing, technology, or legal requirements. The "Last updated" date shows the latest version. For material changes, we will take reasonable steps to notify you (e.g. by email or a website notice).
15. Contact
Sigmira (Quincy van der Ree, eenmanszaak) — Verdiweg 671, 3816 KW Amersfoort, The Netherlands
Email: hello@sigmira.com · KvK 82195757 · VAT NL003652487B20