Privacy Policy
INEYA Studio is committed to protecting your personal data. This policy explains what data we process on Sygnara (https://sygnara.fr), why, on what legal basis, with whom it is shared, how long it is kept, and what your rights are.
1. Data controller
The data controller is INEYA Studio, a SASU with share capital of €500, registered office at 36 rue de Wattignies, 75012 Paris, France, registered with the Paris Trade and Companies Register under number 107 137 994. For any data-related request: contact@ineya.studio (or by post to the registered office).
2. Data we process
Depending on your use of the site, we may process: account and identification data (name, e-mail, password stored in hashed form, organisation); contact data submitted through forms; service usage data (ideal-customer profiles, preferences, saved lists and tracked signals, activity logs); payment data (handled by our payment provider; we do not store your card numbers); technical data (IP address, browser type, pages viewed, timestamps, security logs); and cookies and trackers (see section 7). We do not collect special-category data (Article 9 GDPR) unless you voluntarily include it in your content.
Sygnara also aggregates public company data from official open-licence sources (SIRENE, BODACC, DECP, France Travail). Information about company officers who are natural persons is processed on the basis of legitimate interest (B2B prospecting); the "non-disclosable" status of the SIRENE register is respected and a right to object is available at contact@ineya.studio.
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Create/manage your account and provide the service | Performance of a contract |
| Process payments and invoicing | Contract / legal obligation |
| Respond to your enquiries | Pre-contractual measures / legitimate interest |
| Ensure security, prevent fraud and abuse | Legitimate interest |
| Measure audience and improve the service | Consent (or legitimate interest if anonymous/aggregated) |
| Send communications (where applicable) | Consent / legitimate interest |
| Comply with accounting and legal obligations | Legal obligation |
4. Recipients and processors
Your data is accessible to authorised INEYA Studio staff and to our processors, bound by contract under Article 28 GDPR:
- OVH SAS (France, EU): infrastructure hosting;
- Stripe Payments Europe, Ltd. (Ireland): payment and invoicing processing;
- Proprietary, cookieless, self-hosted audience measurement (France): usage statistics;
- Sentry (Functional Software, Inc., USA): technical monitoring and error tracking.
Intent scoring and outreach-angle generation rely on AI run locally on our own servers (open-source models): none of your data is transmitted to a third party for this purpose. We never sell or rent your personal data. It may be disclosed to an authority where required by law.
5. Transfers outside the EU
Our servers and hosting are located in the European Union. Where a processor involves a transfer outside the EU (for example Sentry), it is governed by appropriate safeguards (European Commission Standard Contractual Clauses and/or the EU-US Data Privacy Framework), a copy of which is available on request.
6. Retention periods
Account and service data: for the duration of the contractual relationship, then intermediate archiving as required by law (notably 10 years for accounting records); prospects/contact messages: up to 3 years from the last contact; technical data and logs: up to 12 months; cookies: as indicated in the consent banner (max. 13 months for audience-measurement trackers). Data is then deleted or anonymised.
7. Cookies and trackers
The site uses strictly necessary cookies (session, security, preferences) that do not require consent, and, where applicable, audience-measurement trackers set only after your consent. Our audience measurement is cookieless and self-hosted. You may accept, refuse or withdraw consent at any time via the dedicated banner or your browser settings. Refusing non-essential trackers does not prevent access to the site.
8. Security
INEYA Studio implements appropriate technical and organisational measures to protect your data against loss, unauthorised access, disclosure or alteration: password hashing, encrypted communications (HTTPS/TLS), access control, per-organisation data isolation, logging and backups.
9. Your rights
Under the GDPR and the French Data Protection Act, you have the rights of access, rectification, erasure, objection, restriction, portability, withdrawal of consent at any time, and to set directives regarding your data after your death. To exercise them, e-mail contact@ineya.studio; we may request proof of identity in case of reasonable doubt. You may also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
10. Minors
The site is not intended for children under 15. We do not knowingly collect their data without parental consent.
11. Changes
This policy may be updated to reflect changes to the service or regulations. The version in force is the one published on this page. Last updated: 2026.