Effective 22 July 2026
Privacy notice
1. Controller and contact
SIGVORA is operated by Dirk Zimmermann, operating under the project name SIGVORA, Carrer Llubí 97, 07300 Inca, Spain. The operator decides why and how personal data submitted to SIGVORA is used and is the data controller for that information. Privacy requests can be sent to media.dirk@gmail.com.
2. Data we process
We receive your name and email address when you sign in with ChatGPT. We also process account and organisation details, professional or registration references submitted for trust-profile review, authenticity records, ownership-transfer details, reviewer assignments and decisions, files you choose to upload, external-pilot invitations and feedback, concerns reported about a record, support messages, and technical security information required to operate the service.
Public verification pages may display product or document details, issuer claims, record history, reviewer name and organisation, review scope, a review statement, and whether the relevant professional identity profile was approved. Private evidence files—including bottle photos submitted during a mobile pilot—registration references, reporter contact details, and administrator notes are not displayed publicly.
3. Purposes and legal bases
- To provide accounts, records, professional profiles, reviews, transfers, reports, and verification pages as necessary to perform our agreement with you.
- To assess submitted identity and qualification information, investigate reported concerns, protect the service, prevent fraud, preserve audit integrity, and resolve disputes based on our legitimate interests and those of users relying on provenance records.
- To meet legal obligations and respond to lawful requests.
- For optional uses only when consent is specifically requested. SIGVORA currently does not add optional advertising or analytics cookies.
4. Authentication, hosting, and recipients
ChatGPT sign-in is provided by OpenAI. OpenAI processes the sign-in service under its own privacy terms and provides SIGVORA with the authenticated name and email needed for access control. The published site is hosted for the operator by OpenAI and its authorised hosting providers under applicable data-processing terms.
Information is also shared with people you deliberately involve, such as a new owner or an invited reviewer. Public record fields are available to anyone with the SIGVORA ID or verification link. We do not sell personal data.
5. International transfers
Service providers may process data outside your country. Where EU/EEA data is transferred internationally, the operator will rely on an applicable adequacy decision or approved safeguards such as standard contractual clauses, as required.
6. Retention
Review, ownership-transfer, and external-pilot invitations expire after 14 days. Account information, trust-profile submissions, pilot feedback, reported concerns, and private evidence are otherwise kept while needed to provide, evaluate, and protect the service and are reviewed when an account or deletion request is received. A privacy request and its operator response are retained as evidence that the request was handled. Audit events and decisions may be retained longer where necessary to preserve the integrity of an authenticity or ownership history, prevent fraud, resolve disputes, or comply with law. Retention periods will be limited and reviewed against those purposes.
7. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. Signed-in users can download a machine-readable JSON export and submit a deletion request from the account privacy page. Evidence file contents can be requested separately from the operator. You may withdraw consent where processing relies on consent. These rights can be subject to lawful exceptions, including the rights of other people and the integrity of fraud-prevention records. Contact media.dirk@gmail.com to make a request. You may also complain to Agencia Española de Protección de Datos (AEPD), www.aepd.es.
8. Your responsibilities
Upload only information you are authorised to use. Do not upload payment-card information, health information, government identity documents unless expressly approved for a compliant workflow, or evidence containing unnecessary personal data. Record owners are responsible for ensuring invited recipients and reviewers can lawfully receive the information shared with them.
9. Security and changes
We use access controls, authenticated review and transfer links, private file storage, request limits, and event histories to reduce risk. Limited technical identifiers are transformed into short-lived rate-limit keys used to prevent spam and excessive automated activity. No online service can guarantee absolute security. We may update this notice as the product, providers, or law change and will show the effective date above.