sirenic

Privacy policy

Last updated: 2 September 2026. We do not sell any personal data, and we share it with third parties only in the cases named below.

Source and nature of the data

Sirenic redistributes public French company data from the Sirene database (INSEE) and the national company register (INPI), obtained through the public API recherche-entreprises.api.gouv.fr under the Etalab 2.0 open licence. Some of this data concerns natural persons (company officers): surname, first name, role and, where applicable, year of birth. This service never publishes a personal address or a full date of birth.

Managers' transactions (MAR art. 19) — Belgium and Germany

The service redistributes managers' transaction notifications published by the FSMA (Belgium, CC BY 4.0 licence) and by BaFin (Germany — © Federal Financial Supervisory Authority / www.bafin.de). These publications name the declaring manager at the source. No name is stored or published by this service: only a non-reversible cryptographic fingerprint is derived from it, used solely to count distinct declarants so that no breakdown can single out a person. What we serve is an aggregate per listed company, never a profile of a person.

Retention: BaFin removes these notifications from its database twelve months after first publication, and our German stock is entirely replaced at each daily collection, so it never exceeds that window. On the Belgian side, a removal by the FSMA is reflected at the next collection.

Legal basis

Processing relies on legitimate interest (GDPR art. 6(1)(f)): redistribution of data that is legally public in company registers, within the limits set by law (notably art. A123-96 of the French Commercial Code) and by the redistribution terms of INPI and INSEE. For managers' transaction notifications, publication is required by article 19 of Regulation (EU) No 596/2014 and carried out by the market authority itself.

“Partial disclosure” status

Where an officer or a sole trader has objected to the public disclosure of their data (“partial disclosure” status in Sirene), this service honours that status and returns only the minimal legal company record, without any officer data.

Right to object and data subject rights

If you are a natural person whose data (officer, shareholder or sole trader) is redistributed by this service, you may exercise your rights (objection, access, rectification, erasure, restriction):

You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

Data collected by the service itself

Without an account — the x402 rail requires none: the agent pays per call and no cookie is set. Technical logs (IP address, user agent, timestamp) are kept for security and billing. Settlements in crypto-assets (USDC or EURC) are recorded in an accounting journal kept in line with French legal obligations (10 years, art. L123-22 of the Commercial Code); it contains the payer's blockchain address, which is pseudonymous data.

With a client account (API key and prepaid credits, open to companies and individuals alike) — we keep: the email address used as the identifier, the sign-up IP address (90 days, against abuse), the billing details you enter (name or company name, country, and for a company the SIREN or VAT number), the log of charged calls and the credits purchased. A session cookie is set after you click your sign-in link: it is strictly necessary for the client area to work and is used for no analytics whatsoever. Card payments are handled by Stripe, which receives the billing and payment data; no card data passes through our servers. A closed account is anonymised after 30 days, except for the accounting entries the law requires us to keep for 10 years.

Early-access request — while public sign-up is not open, the client area offers to take an email address. It is used solely to invite you when the service opens, is shared with no one, and is deleted 30 days after the invitation is sent — or at the latest 180 days after the request if the service has not opened in the meantime.

The MCP connector and OAuth authorisation

When you connect an assistant (Claude, ChatGPT, Le Chat, Perplexity, n8n…) to your account, what we keep is limited to the following:

What the assistant gets: the right to call the data routes on your behalf, against your quota and then your balance. What it does not get: your email address, your invoices, or the right to top up or close the account. You can cut this access off at any time from your API keys; revocation is immediate. Unfinished authorisation requests and single-use codes are deleted automatically once their short lifetime has passed.

Document-analysis processor and transfer outside the European Union

Two features call a language model provided by Anthropic, whose processing servers are located in the United States:

This processing is governed by Anthropic's data processing addendum (DPA), which incorporates the European Commission's standard contractual clauses for the transfer; documents sent through the API are not used to train the models. Details of the flows and safeguards: rgpd@sirenic.eu.

Security

The service is reachable over HTTPS only (TLS, HSTS). No secret is stored in clear: API keys, connector tokens, authorisation codes and session tokens are kept only as SHA-256 fingerprints — so we can neither read them back nor resend them to you. There is no wallet private key on our servers: only the public receiving address is held. The client area uses neither passwords nor JavaScript; its session relies on an httpOnly, Secure, SameSite cookie that can be revoked at any time. The front-end access logs keep no request headers at all — precisely so that no key can appear in them — and are purged after 7 days. In the event of a data breach presenting a risk, we notify the CNIL within 72 hours and, where the risk is high, the individuals concerned.

Data controller

For any question about your personal data or the exercise of your rights: rgpd@sirenic.eu. The identity and address of the data controller are given in the legal notice.