Privacy notice
This notice describes SIAIO account data. The customer remains controller of data published on its website; controller and processor roles require an agreement for the specific service.
One account may operate several isolated organizations. SIAIO stores the organization name, membership and role and — for new-customer onboarding — the address and status of a time-limited invitation. A global platform administrator may access organizations as necessary for support, security and service operation. To protect third-party websites, we store the domain host, confirmation method and time, authority-attestation version, and an encrypted single-use code with a separate integrity hash. The code expires after at most seven days and its secret is removed independently of the backup cycle after success, replacement or expiry. A signed time-limited webmaster link stores no recipient address and provides public instructions only. A Search Console connection below siteOwner is for data only and does not confirm authority. The active domain assignment remains for the website service term.
1. Controller and contact
WEDA NATURY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. WOLNOŚĆ nr. 10A lok. U1 miejsc. RADOM, Polska · NIP 7963005414 · KRS 0000917887 · REGON 389784626. Privacy contact: office@siaio.com.
2. Data and purposes
- account: email, language, organization, role and secure password hash — contract performance and security;
- optional MFA: an encrypted TOTP key and hashes of one-time recovery codes — access protection;
- sessions and security events: dates, outcome and keyed IP and User-Agent fingerprints instead of raw values — service protection and accountability;
- website, Search Console and AI question data only for features selected by the customer;
- organization export and deletion: request time, status, organization fingerprint, export SHA-256 proof and minimal summary — request fulfilment, security and accountability;
- internal compliance register: capability manifests, review decisions and the identifier of the administrator approving a change — security, accountability and compliance evidence;
- policy acceptance history — transparency duties, contract and legal claims.
We do not sell or share personal information for behavioral advertising and use no advertising trackers.
3. Minimization and retention
We keep only data needed for the account and selected features. Active data remains for service delivery; an MFA code lasts 30 seconds, the pending second-step session 5 minutes, an MFA recovery link 30 minutes, invitations normally 72 hours, and an encrypted website-confirmation code at most seven days. The website-code secret is removed immediately after success, replacement or expiry regardless of backup completion; code-free attempt history may remain for 365 days for security and accountability. Login-attempt limits are removed after 2 days, expired or used account links after 7 days, revoked sessions after 30 days, security and notification-delivery history after 180 days, and audit, maintenance and completed privacy-request records after 365 days. Organization exports are streamed without storing their content on the server. After permanent organization deletion, only pseudonymous request evidence and a minimal summary remain for up to 365 days. Encrypted database backups follow the configured limit of the latest 3–30 files; deleted data may remain in a protected backup until rotation and is not returned to the active system except where necessary for disaster recovery. Capability manifests, compliance decisions, document snapshots and consent records are retained as evidence of versions, decisions and legal duties. Except for unconditional expiry of website-confirmation secrets, other automated operational cleanup starts after a new verified backup. Data required for legal claims or statutory duties may be kept longer.
4. Recipients, providers and transfers
Hosting, email, Google Search Console and — when AI testing is enabled — AI providers may process data. Each provider should be covered by an appropriate agreement. Transfers outside the EEA require a valid mechanism such as an adequacy decision or Standard Contractual Clauses.
5. Your rights
You may access, correct and export data, request deletion or restriction, object to processing and complain to the competent authority. In the Privacy Center each user manages their account, while an Owner may export the entire current organization and schedule its deletion. Organization deletion has a seven-day cancellation period; it removes its websites, integrations, results and settings, and accounts of people who belong to no other organization. US state residents also receive rights required by applicable state law; SIAIO honors access, correction and deletion requests independently of CCPA thresholds.
6. Automation and AI
SIAIO does not make solely automated decisions about users that produce legal effects. Recommendations concern the website. Site Bridge publishing requires explicit permissions and an approval record. AI question content is sent to the selected provider; SIAIO does not persist raw answers and the OpenAI integration uses store:false.
7. Cookies and browser storage
SIAIO uses only two first-party technical cookies. We use no advertising, analytics, social-media or profiling cookies. Both cookies support functionality explicitly selected by the user and expire with the browser session, so we do not display an optional-cookie consent banner.
Cookies can be deleted or blocked in browser settings; blocking them may prevent sign-in and language memory from working. If optional analytics or marketing are added in the future, they will remain blocked until any required consent is obtained.
8. User age
This B2B service is not directed to children; self-service accounts require age 18.