Privacy Policy
Version 1.0 · Effective 26 September 2026
This Policy explains which personal data Blossom Solutions L.P. processes when you use Sightelle or the website www.sightelle.com, why, for how long, and what your rights are. The General Data Protection Regulation (EU) 2016/679 ("GDPR") and Greek Law 4624/2019 apply.
1. Who we are
Blossom Solutions L.P., 111 Vasileos Pavlou, Spata 19004, Attica, Greece · VAT EL802462265, Tax office: KEFODE Attikis · GEMI no. 176808501000 · Tel. +30 210 6635959.
Personal data enquiries: dpo@blossom-solutions.gr
2. Two roles: when we are the controller and when we are not
- We are the controller for the data of application users, billing details, website visitors, and anything you send us through the contact form. This Policy covers those.
- We are the processor for the data our customers import into their workspace. This includes tickets, comments, survey responses, and lists of customers, recipients or employees. Our customer is the controller for that data, and the Data Processing Agreement applies.
If you answered a survey, or your details appear in the tickets of a company that uses Sightelle, contact that company about your rights. If you write to us, we will forward your request to them (see section 9).
3. What we process, why, on what basis and for how long
| Processing | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Registration and account | First and last name, email, password (hash only), language, MFA settings | Creating and running the account | Performance of a contract (Art. 6(1)(b)) | While the account exists; deleted within 30 days of a deletion request |
| Company and billing details | Legal name, VAT number, tax office, address, phone, website, business activity, name of the responsible person | Contract, issuing billing documents | Performance of a contract; legal obligation (Art. 6(1)(c)) | For the duration of the contract; tax records for as long as tax law requires |
| Payments | Amount, plan, order number, legal name | Collecting the subscription | Performance of a contract; legal obligation | As long as tax law requires. We do not receive card details; the payment provider processes them. |
| Security history | IP address, browser, time, email used at sign-in, password and MFA changes | Protecting accounts, detecting abuse | Legitimate interest (Art. 6(1)(f)): security of the Service | 365 days |
| Workspace activity log | Which user did what, and when | Accountability within the workspace | Legitimate interest; performance of a contract | 730 days (configurable by the customer) |
| Platform emails | Email, name, language | Account confirmation, password reset, invitations, alerts, weekly report | Performance of a contract; legitimate interest for alerts | We keep no copies of emails. Alerts are configured on the "Alerts" page; the weekly report can be stopped in "Settings", and every report links there. |
| Contact form | Name, email, company, message | Answering your request | Pre-contractual steps; legitimate interest | Up to 24 months after the last contact. We do not store your IP address. |
| AI cost and usage | Purpose of the call, model, number of tokens, cost, duration (not the text) | Billing, cost control | Legitimate interest | While the workspace exists |
| Server logs | IP address, path, time, browser | Operation and security | Legitimate interest | Limited size, usually a few days |
| Backups | All of the above | Recovery after failure | Legitimate interest; Art. 32 GDPR | 14 days |
We do not send marketing messages. If we ever do, we will ask for your consent first.
We do not take decisions based solely on automated processing that produce legal or similarly significant effects for you.
4. Artificial intelligence
To analyse our customers' text, we use models from OpenAI. This processing is done on our customers' behalf, as their processor (see the Data Processing Agreement).
- What is removed before text is sent to the provider. Email addresses, phone numbers, tax ids and IBANs are replaced with placeholders. Names written inside the text are not removed. The author name of a ticket is not sent.
- Where and for how long. Under the provider's terms, the data:
- is not used for training models;
- may be kept by the provider for up to 30 days for abuse monitoring;
- is processed in the United States (see section 6).
- We do not train any model on customer data.
5. Who receives the data
We share data only with those needed to run the Service, under contracts that bind them:
| Recipient | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Server and backup hosting | Finland (EU) |
| OpenAI | Text analysis with AI models | USA |
| [Email delivery provider — to be completed] | Sending platform emails | [location] |
| Scan & Pay | Payment processing | Greece |
| Accountant / accounting firm | Bookkeeping and tax obligations | Greece |
Data is also disclosed to public authorities where the law requires it. We do not sell personal data.
6. Transfers outside the EU
Hosting, the database and backups are in the European Union. Text analysis by OpenAI takes place in the USA.
The transfer relies on:
- the EU-US Data Privacy Framework, where the recipient is certified under it;
- otherwise, the European Commission's Standard Contractual Clauses (Art. 46 GDPR).
You can request a copy of the relevant safeguards at dpo@blossom-solutions.gr.
7. Cookies and local storage
Website (www.sightelle.com). We use no cookies, analytics or advertising tools. Fonts are served from our own server.
Application (app.sightelle.com) — only what is strictly necessary:
- one sign-in cookie (
echora_rt), which keeps your session secure (HttpOnly, limited to the authentication path, up to 14 days); - display preferences in the browser's
localStorage: language, theme, palette, and the state of the side menu and sections; - on a public survey page, a draft of your answers in
sessionStorage, deleted when the tab closes or as soon as you submit.
These do not require consent (Greek Law 3471/2006, Art. 4(5)), because they are necessary for the service you requested.
Surveys embedded in a customer's website. When a survey appears as a pop-up, our script stores in that website's localStorage when you saw or answered it, so that it does not bother you again. It stores no answers or identity. The owner of that website is responsible for consent there.
8. Security
The main security measures are:
- encrypted connections (TLS);
- encrypted storage of secrets (tokens, webhooks);
- passwords stored only as hashes;
- a second authentication factor (MFA);
- full isolation between workspaces;
- rate limits on public endpoints;
- activity logs;
- nightly backups with integrity checks.
Details are on the Security page.
9. Your rights
You have the right:
- to access your data;
- to rectification;
- to erasure;
- to restriction of processing;
- to data portability;
- to object to processing based on legitimate interest.
To exercise your rights, write to dpo@blossom-solutions.gr. We reply within one month. We may ask you to confirm your identity.
Some rights can also be exercised in the application:
- change your password and delete your account on the "Security" page (to correct your name, write to us);
- stop the weekly report in "Settings";
- export and delete the whole workspace on the "Your data" page (for the Owner).
If your data is in a customer's workspace (for example, you answered their survey), we forward your request to that customer, who is the controller, and assist them.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifisias Ave, 115 23 Athens, www.dpa.gr).
10. Changes
When this Policy changes, we update the version and date at the top of the page. For material changes, we notify users by email.