Privacy Notice

This Privacy Notice explains how Sigma Software (“Sigma”, “we”, “us”) collects, uses, and protects personal data when you use our website or interact with us.

Sigma Software is committed to ensuring that your privacy is appropriately protected and that personal data is processed in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

This Privacy Notice applies to:

  • visitors of our websites,
  • business contacts,
  • individuals interacting with us in a professional context,
  • contacts provided to us by our partners, including business referral and lead generation partners.

Sigma Software may update this Privacy Notice from time to time. The latest version will always be available on this page.
This version is effective as of July 15, 2026

1. Sigma Software Entities and Roles (Multi-Entity Structure)

Sigma Software operates through a group of affiliated legal entities located in different jurisdictions.

Depending on your interaction with us, personal data may be processed by one or more Sigma Software entities acting as independent controllers or, where applicable, as joint controllers.

Typically:

  • the Sigma Software entity with which you have a contractual relationship or direct interaction acts as the primary data controller;
  • other Sigma Software group entities may process personal data for internal administrative, operational, and delivery purposes.

Such processing may include involvement of delivery teams, support functions, and shared services located in different countries.

Where multiple Sigma Software entities jointly determine the purposes and means of processing, they may act as joint controllers in accordance with applicable data protection laws.

In all cases, Sigma Software ensures that:

  • personal data is accessed only by authorized personnel on a need-to-know basis;
  • appropriate contractual, technical, and organizational safeguards are in place between group entities;
  • processing is carried out in accordance with this Privacy Notice and applicable laws.

For information about the specific Sigma Software entity acting as controller in your case, you may contact us at:
privacy@sigma.software

2. Information We Collect

We may collect the following categories of personal data:

  • Identification data (name, job title)
  • Contact data (email address, phone number)
  • Professional information (company name, role)
  • Technical data (IP address, browser type, device data)
  • Usage data (interaction with our website, pages visited)
  • Communication data (inquiries, correspondence)

Sources of data:

We collect personal data:

  • directly from you (e.g., via forms, emails, meetings),
  • from publicly available sources (e.g. business networks, websites),
  • automatically via cookies and tracking technologies,
  • from third parties, including our clients, partners and service providers, who may recommend our services to you or provide business contact details in the context of professional interactions or lead generation activities.

In such cases, we take reasonable steps to ensure that the personal data has been obtained lawfully and that appropriate transparency information has been provided to you, where required.

Where we obtain personal data from third parties, we may provide you with this Privacy Notice and relevant information at the time of first contact, in accordance with applicable data protection laws.

Where possible, data collected via cookies is aggregated or pseudonymized.

3. How We Use Your Information

We use personal data for the following purposes:

  • to respond to inquiries and provide requested information;
  • to manage business relationships and maintain records;
  • to provide and improve our services and website;
  • to send relevant business communications, including marketing (where permitted). This may include contacting individuals whose contact details were obtained through partners or business referrals, where such individuals may reasonably expect to be contacted in a professional context;
  • to conduct analytics and understand website usage;
  • to ensure security and prevent misuse.

Personal data may be stored in our CRM systems and internal tools.

4. Legal Basis for Processing

Depending on the context, we process personal data based on:

  • Legitimate interest (e.g. business communication, service improvement, security, including outreach to business contacts in a professional context and processing of data obtained from partners or publicly available sources);
  • Contract performance (e.g. when providing services);
  • Consent (e.g. marketing communications, cookies where required);
  • Legal obligation (e.g. compliance with applicable laws).

5. When Sigma Software Acts as a Data Processor

When Sigma Software provides services to clients, we typically process personal data on behalf of the client as a data processor.

In such cases:

  • the client acts as the data controller,
  • Sigma Software acts as a data processor,
  • processing is governed by a Data Processing Agreement and carried out according to the client’s instructions.

6. Data Sharing

We may share personal data with:

  • Sigma Software group companies;
  • service providers and vendors (e.g. IT, hosting, CRM, marketing tools);
  • partners involved in service delivery;
  • authorities where required by law.

We may also receive personal data from partners acting in their own capacity, including business introduction and lead generation partners.

Where personal data is received from third parties, Sigma Software relies on contractual assurances that such data has been collected and shared in accordance with applicable data protection laws.

All third parties are subject to appropriate confidentiality and data protection obligations.

7. International Data Transfers

Due to the global nature of our operations, personal data may be accessed or processed by Sigma Software personnel and partners located outside the EEA (including Ukraine and other delivery locations).

Where such transfers occur, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs), or
  • other legally recognized transfer mechanisms.

Access is limited to authorized personnel with a business need and subject to confidentiality and security obligations.

8. Data Retention

We retain personal data only as long as necessary for the purposes described above, including:

  • business relationship data — for the duration of cooperation and applicable limitation periods;
  • marketing data — until withdrawal of consent or objection;
  • technical/log data — for a limited period required for security and analytics purposes.

Longer retention may apply where required by law or to resolve disputes.

9. Security

Sigma Software applies appropriate technical and organizational measures to protect personal data, including:

  • access controls and authentication mechanisms,
  • data security policies and procedures,
  • monitoring and incident management,
  • organizational and contractual safeguards.

These measures are aligned with recognized standards, including ISO 27001.

10. Marketing, Advertising, Analytics, and Tracking Technologies

We may use marketing, advertising, analytics, and tracking technologies to analyze website usage, measure and optimize campaign performance, evaluate marketing effectiveness, and support remarketing and retargeting activities. Such technologies may include tools such as Google Analytics 4 (GA4), Google Tag Manager (GTM), LinkedIn Insight Tag, Microsoft Clarity, Microsoft Advertising (Universal Event Tracking), Hotjar, Meta (Facebook Pixel), and Leadfeeder.

These technologies may collect information such as cookie identifiers, device and browser information, website activity and interaction data, unique advertising identifiers, platform-specific click identifiers (such as GCLID and MSCLKID), and, where applicable, company-related information associated with website visits.

Where required by applicable law, such technologies are used only based on your consent. You can manage, update, or withdraw your preferences at any time through the Cookie Settings available on our website.

11. Third-Party Services

We use third-party tools and platforms, including (but not limited to):

  • analytics tools,
  • marketing platforms,
  • CRM systems.

These providers process data in accordance with their own privacy policies and applicable legal requirements.

12. Your Rights

Subject to applicable law, you may have the following rights:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure of data;
  • restriction of processing;
  • objection to processing;
  • data portability;
  • withdrawal of consent;
  • right to lodge a complaint with a supervisory authority.

To exercise your rights, please contact us using the details below.

13. Children’s Privacy

Our services are not directed to children, and we do not knowingly collect personal data from children.

If we become aware that such data has been collected, we will take steps to delete it.