1. Who is the controller?
The controller of personal data collected in connection with the Siftbox service is: WEBDIGIT, Place de Moulbaix 10, 7812 Moulbaix (Ath), Belgique — contact: hello@siftbox.ai.
2. What data do we process?
- Account data: identifier, login email, profile elements needed to operate the service.
- Mail data (if you connect Gmail, Outlook / Microsoft 365 or IMAP): message metadata (subject, sender, labels, snippets per configuration), and possibly content or excerpts sent to the classification engine depending on the level chosen in account settings (standard, excerpt for AI refinement, transient body if enabled).
- Technical data: security and operations logs, correlation identifiers, IP address, audit logs for sensitive actions (login, OAuth, settings), under a minimisation policy (no plaintext passwords in logs).
- Waitlist or pre-launch contact data: as shown on site forms.
3. Why and on which legal basis (GDPR)?
We process your data for the following purposes and legal bases:
- Providing the SaaS service (account creation, authentication, dashboard) — performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR).
- Gmail OAuth, Microsoft OAuth (Outlook / Microsoft 365) or IMAP linking and synchronisation — performance of a contract (Art. 6(1)(b)), with access authorised by you via OAuth or IMAP configuration.
- Classification and prioritisation aids — performance of a contract (Art. 6(1)(b)); optional levels involving extra excerpts or body text for AI refinement rely on your explicit choice in account settings (consent, Art. 6(1)(a)).
- Security, abuse prevention, evidence in disputes — legitimate interest (Art. 6(1)(f)), and legal obligation where applicable (Art. 6(1)(c)).
- Audience measurement (Google Analytics 4) on certain public pages — only after your consent (Art. 6(1)(a)).
- Legal and accounting obligations — Art. 6(1)(c) where applicable.
4. Recipients and subprocessors
Data is processed by the publisher and, as needed, by technical subprocessors: application hosting and transactional email (Infomaniak), database (OVHcloud France), Google for the Gmail API when you enable connection, Microsoft for Outlook / Microsoft 365 OAuth (IMAP XOAUTH2 sync) when you enable connection, Google LLC / Google Ireland Limited for Google Analytics 4 on public pages (home, sign-in, registration and related marketing pages) only after your consent, and queue/cache infrastructure (Redis).
Art. 28 GDPR safeguards are set out contractually with these providers. Business customers may obtain a full data processing agreement (DPA) on request.
5. Transfers outside the European Economic Area
Infomaniak application hosting may involve Switzerland (European Commission adequacy decision). OVHcloud (database) is located in France (EEA). Google and Microsoft may process data outside the EEA; such transfers rely on EU Commission standard contractual clauses and/or the Data Privacy Framework, according to mechanisms published by those providers.
6. Retention periods
Account data: kept for the life of the account, then deleted or anonymised within a reasonable technical period (at most 90 days) after closure, unless a longer legal obligation applies. Mail metadata and account-linked classifications: while the account (and sync) remain active, then under the same purge period. Technical and audit logs: limited period needed for security and diagnostics (in practice up to 12 months). Analytics consent: until consent is withdrawn or the local key “siftbox_ga_consent” is cleared.
7. Your rights
Under the GDPR, you have, subject to conditions, rights of access, rectification, erasure, restriction, objection, portability (where applicable), and the right to withdraw consent at any time where processing is based on consent.
To exercise them: hello@siftbox.ai. You may also lodge a complaint with your country’s data protection authority (in Belgium: APD-GBA; in France: CNIL).
8. Security
The publisher implements appropriate technical and organisational measures: encryption of sensitive secrets at rest where provided by the product, access control, controlled logging, multi-tenant isolation at database level as designed.
9. Cookies and trackers
The site uses cookies or local storage strictly necessary for operation (session, language preferences, remembering your analytics consent choice). On public home, sign-in and registration pages, and in production only, a banner lets you accept or refuse Google Analytics 4 (audience measurement: page views, scrolls, outbound clicks per GA configuration). No Google Analytics script is loaded before acceptance. You may change your choice by clearing the local key “siftbox_ga_consent” in your browser, or by contacting us.
10. Minors
The service is not directed at persons under 16 (or the applicable digital consent age in your jurisdiction). We do not knowingly collect their data.
11. Policy changes
This policy may be updated. Material changes will be communicated to users by a reasonable channel (email or in-product notice).