01
Who is responsible for your data
Sigma Trade Hub is the controller for personal data collected through this website and through our own business activities.
For privacy questions, requests or complaints, contact info@sigmatradehub.com or +1 313-495-7949.
When we process personal data inside a workflow we operate for a client, that client is the controller and we act as their processor. This policy describes our own processing; the client’s own notice governs theirs.
02
What we collect
CATEGORY
WHAT IT INCLUDES
WHERE IT COMES FROM
Contact details
Name, work email, company, job role, phone number where you give it
You, directly
Session details
The date and time you pick, the process description you write, your time zone
You, directly
Correspondence
Emails, call notes, documents you share for scoping
You, directly
Engagement records
Statements of work, invoices, approval decisions attributed to named users
You and our systems
Technical data
IP address, device and browser type, pages viewed, referring page, approximate location from IP
Automatically, on visit
Preferences
Cookie choices, light or dark theme
Your browser, locally
We do not ask for special category data, government identifiers or payment card numbers through this website. Please do not send them to us by email.
03
Why we use it, and on what basis
PURPOSE
DATA USED
LAWFUL BASIS
Arrange and run a working session
Contact and session details
Contract, or your consent
Answer an inquiry and prepare a proposal
Contact details, correspondence
Legitimate interests
Deliver and govern an engagement
Engagement records, correspondence
Contract
Keep the site secure and available
Technical data
Legitimate interests
Understand how the site is used
Technical data, analytics cookies
Consent
Send occasional updates about our work
Contact details
Consent, withdrawable at any time
Meet tax, accounting and legal duties
Engagement records
Legal obligation
Where we rely on legitimate interests, we have weighed our interest in running and improving a professional services business against your rights, and we use the least data needed for the purpose. You can object at any time.
04
Booking and inquiry data specifically
When you complete the booking form we collect your name, work email, company and your one-line description of the process you want to map, together with the slot you selected. We use it to hold the appointment, prepare for the session and follow up afterwards.
·A calendar invitation is created for the chosen time and sent to the address you gave and to our own inbox.
·The process description is read only by the people preparing your session.
·We keep inquiry records for 24 months from our last contact, then delete or anonymise them, unless the inquiry became an engagement — in which case engagement retention applies.
·Consent to marketing updates is recorded separately and can be withdrawn by replying to any message or writing to us.
05
Client system data
During an audit or a live workflow we may access data in your systems: purchase orders, invoices, tickets, emails, supplier records and similar operating data that can contain personal data about your staff, customers or suppliers.
·We access it only under the scope in your statement of work and data processing agreement.
·Access uses credentials you issue, with least-privilege permissions, and is revoked on completion.
·Every read and write a workflow performs is logged with a timestamp, the tool called and the responsible approver.
·We do not use your operating data to train general-purpose models, and we do not reuse it for other clients.
06
AI models and processors
Workflows call third-party AI model providers and cloud infrastructure. We name every provider a workflow depends on before it goes live, contract with them as sub-processors, and select configurations that exclude your content from provider model training where the provider offers that option.
Our own business tools — email, calendar, storage, invoicing, analytics — also process limited personal data as our processors under written terms. A current list is available on request.
07
When we share data
We do not sell personal data and we do not share it for cross-context behavioural advertising.
·Service providers and sub-processors, acting only on our instructions.
·Professional advisers — accountants, auditors, lawyers — where they need it and are bound by confidentiality.
·Authorities or courts where we are legally required to disclose, and where permitted we will tell you first.
·A buyer or successor if our business is sold, under equivalent protections.
08
International transfers
We are based in the United States and some of our providers operate in other countries. Where personal data moves outside its country of origin we rely on an approved transfer mechanism — standard contractual clauses, the UK addendum, or an adequacy decision — and we assess the destination before the transfer starts.
09
How long we keep it
RECORD
RETENTION
Inquiries and bookings that did not become engagements
24 months from last contact
Engagement records, statements of work, approval logs
7 years after the engagement ends
Invoices and accounting records
As required by tax law, currently 7 years
Marketing consent records
Until withdrawn, plus 2 years as proof of consent
Website analytics
14 months, aggregated thereafter
Security and access logs
12 months
Client operating data accessed during an engagement is retained only for the period set in the relevant data processing agreement, then returned or deleted on your instruction.
10
How we protect it
·Encryption in transit and at rest for data we hold.
·Least-privilege access, individual accounts and mandatory multi-factor authentication for our team.
·Credential rotation and revocation at the end of every engagement phase.
·Change control and an audit trail for every workflow modification.
·Incident response with notification to affected controllers without undue delay, and within 72 hours where the law requires it.
No system is perfectly secure. If you believe your data has been exposed, contact us immediately and we will investigate and tell you what we find.
11
Your rights
Depending on where you live, you may have the right to:
·ask what personal data we hold about you and receive a copy;
·have inaccurate data corrected;
·have data deleted where we no longer need it;
·restrict or object to processing, including profiling and direct marketing;
·receive your data in a portable format;
·withdraw consent at any time, without affecting processing already carried out;
·not be discriminated against for exercising any of these rights.
To exercise a right, write to info@sigmatradehub.com. We will verify your identity and respond within 30 days, or tell you if we need longer. You may use an authorised agent. If you are unhappy with our response you can complain to your data protection authority — in the UK the Information Commissioner’s Office, in the EU your national authority, and in the US your state Attorney General.
12
Children
Our services are sold to businesses and this site is not directed at children. We do not knowingly collect personal data from anyone under 16. If we learn we have, we delete it.
13
Cookies
We use a small number of cookies and similar technologies. What they are, what each one does and how to change your choices are set out in the Cookie Policy.
14
Changes to this policy
We update this policy when our processing changes or the law requires it. The effective date at the top shows the current version. Material changes are flagged on this page, and where we rely on your consent we will ask again rather than assume it.
CONTACT
Questions about this policy?
Write to us and we will respond within five working days. For anything urgent during a live pilot, call.
Sigma Trade Hub