Privacy Policy
This policy explains how Individual Entrepreneur Polshchykov Roman (Registration No: 2939422257), trading as Sigmalion, collects, uses, and protects your personal data.
Effective date: 13 May 2026
1. Who We Are
Individual Entrepreneur Polshchykov Roman (Registration No: 2939422257), trading as Sigmalion ("Sigmalion", "we", "us", "our") is the data controller responsible for your personal data. We are a software engineering and AI consultancy serving clients in the EU, UK, and US.
Registered address: Peace St, 57, ap. 198, Kharkiv, Kharkivs'ka oblast, 61000, Ukraine
Tax ID: 2939422257
Sigmalion is established outside the European Economic Area. Because we offer our services to data subjects in the Union, the GDPR applies to our processing activities under Article 3(2)(a). We have therefore designated a representative in the Union — see Section 7.
If you have any questions about this policy or how we handle your data, contact us at team@sigmalion.io.
2. Data We Collect
We collect personal data only when you actively provide it or when it is generated by your use of our website:
- Contact information — name, email address, and any message you send via our contact form or email.
- Inquiry details — project description, budget range, timeline, and other information you voluntarily share when requesting a consultation.
- AI assistant messages — text you send to the chat widget on our site. These messages are sent to Google (Gemini API, USA) to generate a response. According to Google's Gemini API Additional Terms of Service, when billing is enabled (paid tier) prompts and responses are logged by Google for a limited period solely for abuse-detection and safety monitoring, and are not used to train Google's models. We additionally retain our own copy for up to 90 days (see Section 6).
- Technical / security logs — when an authorised user accesses the admin area (
/crm) we record the IP address, browser User-Agent and login outcome for up to 30 days for security monitoring. - Communication records — email correspondence and notes from calls or meetings conducted in the course of a project engagement.
We do not deploy web analytics, advertising pixels, retargeting cookies, or any third-party tracking on the public pages of this site.
We do not collect payment card data directly — all billing is handled by third-party processors that are independently PCI-DSS compliant.
3. How We Use Your Data
We use your personal data for the following purposes:
- Responding to your inquiries and providing the services you request.
- Managing client relationships and project delivery.
- Sending service-related communications (project updates, invoices, and similar).
- Improving our website and understanding how visitors interact with our content.
- Complying with legal obligations (e.g., tax, accounting, anti-money-laundering).
We do not sell your personal data, use it for automated profiling, or send unsolicited marketing emails.
We are committed to AI safety: we do not use client data to train any third-party or proprietary AI models. We advocate for and implement local-first or zero-retention AI architectures for our clients.
4. Legal Basis for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
Contract
Processing your data is necessary to perform the contract for services you have requested or are about to enter into.
Legitimate interests
We have a legitimate interest in responding to inquiries, improving our website, and running our business — provided this does not override your rights.
Legal obligation
We must retain certain financial and business records to comply with UK and EU law.
Consent
Where we ask for your consent (e.g., optional newsletter), you can withdraw it at any time with no effect on prior processing.
5. Who We Share Your Data With
We share your data only where necessary:
- Sub-processors — see the table below for the third-party services that process your data on our behalf under written data-processing agreements (Article 28 GDPR).
- Professional advisors — accountants, lawyers, or auditors where required for legal or compliance purposes.
- Authorities — where required by law, regulation, or court order.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Google LLC | AI chat responses (Gemini API) | USA | EU–US Data Privacy Framework + SCCs (Art. 46(2)(c)) |
| Supabase Inc. | PostgreSQL database, file storage | USA + EU regions | Signed DPA + SCCs |
| Vercel Inc. | Website hosting and global edge CDN | USA + global edge | Signed DPA + SCCs |
A full, up-to-date sub-processor list including indirect sub-processors of our providers is available on request at team@sigmalion.io.
All third-party processors are bound by contractual data-protection obligations. Transfers outside the EEA rely on the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where applicable, otherwise on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with supplementary measures where required.
6. Data Retention
We apply the GDPR storage-limitation principle (Article 5(1)(e)): personal data is retained only for as long as necessary for the purposes described in this policy or as required by law.
| Data category | Retention period |
|---|---|
| Lead / contact-form submissions | 7 years (UA / EU accounting and tax obligations) |
AI chat messages (chat_history) | 90 days, then automatically deleted |
Admin access logs (system_logs) | 30 days, then automatically deleted |
| Email correspondence and engagement records | 7 years |
Automatic deletion for chat history and admin logs is enforced by a scheduled database job that runs daily. You may request earlier deletion where no statutory retention obligation applies — see Section 7.
7. Your Rights
Under GDPR and UK data protection law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your data where there is no lawful reason to retain it.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email us at team@sigmalion.io. We will respond within 30 days. You may also contact our EU Representative (see below) or the UK Information Commissioner's Office (ICO) at ico.org.uk, or lodge a complaint with the supervisory authority in your EU member state — see our GDPR Notice for the full list.
EU Representative (Article 27 GDPR)
As a controller established outside the Union, we are required to designate a representative in the EU. [Name and EU address — to be appointed]. Until appointment is finalised, please contact us directly at team@sigmalion.io.
9. Security
We follow the principle of Least Privilege (PoLP) and use industry-standard encryption for all data at rest and in transit.
We take data security seriously. All data is transmitted over encrypted connections (TLS). Access to personal data is restricted to team members who need it to perform their role, and we conduct regular reviews of our data-handling practices. A scheduled database job purges expired chat history and admin logs daily (see Section 6). In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours in accordance with Article 33 GDPR, and inform affected individuals without undue delay where required under Article 34 GDPR.
10. Children
Our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. We encourage you to review this policy periodically. Continued use of our website after changes are posted constitutes your acceptance of the revised policy.
Questions about your privacy?
Email us at team@sigmalion.io and we will get back to you within one business day.