Privacy policy
Last updated: 2 September 2026. We do not sell any personal data, and we share it with third parties only in the cases named below.
Source and nature of the data
Sirenic redistributes public French company data from the Sirene database (INSEE) and the national company register (INPI), obtained through the public API recherche-entreprises.api.gouv.fr under the Etalab 2.0 open licence. Some of this data concerns natural persons (company officers): surname, first name, role and, where applicable, year of birth. This service never publishes a personal address or a full date of birth.
Managers' transactions (MAR art. 19) — Belgium and Germany
The service redistributes managers' transaction notifications published by the FSMA (Belgium, CC BY 4.0 licence) and by BaFin (Germany — © Federal Financial Supervisory Authority / www.bafin.de). These publications name the declaring manager at the source. No name is stored or published by this service: only a non-reversible cryptographic fingerprint is derived from it, used solely to count distinct declarants so that no breakdown can single out a person. What we serve is an aggregate per listed company, never a profile of a person.
Retention: BaFin removes these notifications from its database twelve months after first publication, and our German stock is entirely replaced at each daily collection, so it never exceeds that window. On the Belgian side, a removal by the FSMA is reflected at the next collection.
Legal basis
Processing relies on legitimate interest (GDPR art. 6(1)(f)): redistribution of data that is legally public in company registers, within the limits set by law (notably art. A123-96 of the French Commercial Code) and by the redistribution terms of INPI and INSEE. For managers' transaction notifications, publication is required by article 19 of Regulation (EU) No 596/2014 and carried out by the market authority itself.
“Partial disclosure” status
Where an officer or a sole trader has objected to the public disclosure of their data (“partial disclosure” status in Sirene), this service honours that status and returns only the minimal legal company record, without any officer data.
Right to object and data subject rights
If you are a natural person whose data (officer, shareholder or sole trader) is redistributed by this service, you may exercise your rights (objection, access, rectification, erasure, restriction):
- at the source, with INSEE (Sirene disclosure status) or INPI — the most effective route, since it binds every redistributor;
- directly with us, at the dedicated address rgpd@sirenic.eu (suggested subject: “Right to object”). Please state your surname and first name and, if possible, the SIREN of the company concerned. Your request is handled as quickly as possible, and within 30 days at the latest; once the objection is applied, your personal data is excluded from the service's responses. This removal covers our redistribution and does not affect the original public registers.
You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
Data collected by the service itself
Without an account — the x402 rail requires none: the agent pays per call and no cookie is set. Technical logs (IP address, user agent, timestamp) are kept for security and billing. Settlements in crypto-assets (USDC or EURC) are recorded in an accounting journal kept in line with French legal obligations (10 years, art. L123-22 of the Commercial Code); it contains the payer's blockchain address, which is pseudonymous data.
With a client account (API key and prepaid credits, open to companies and individuals alike) — we keep: the email address used as the identifier, the sign-up IP address (90 days, against abuse), the billing details you enter (name or company name, country, and for a company the SIREN or VAT number), the log of charged calls and the credits purchased. A session cookie is set after you click your sign-in link: it is strictly necessary for the client area to work and is used for no analytics whatsoever. Card payments are handled by Stripe, which receives the billing and payment data; no card data passes through our servers. A closed account is anonymised after 30 days, except for the accounting entries the law requires us to keep for 10 years.
Early-access request — while public sign-up is not open, the client area offers to take an email address. It is used solely to invite you when the service opens, is shared with no one, and is deleted 30 days after the invitation is sent — or at the latest 180 days after the request if the service has not opened in the meantime.
The MCP connector and OAuth authorisation
When you connect an assistant (Claude, ChatGPT, Le Chat, Perplexity, n8n…) to your account, what we keep is limited to the following:
- the identity of the software requesting access: its name, its redirect URI and, where applicable, the address of the metadata document it publishes. This information comes from the software, not from you;
- the link between your account and that software, created when you click “Authorise”, together with the date of that consent;
- token fingerprints, never the tokens: the access token is a key of your account, of which we keep only a SHA-256 fingerprint, as for an API key. It expires after one hour; the refresh token expires after 90 days without use;
- the log of calls made through the connector, identical to that of a direct API call: route, timestamp, amount charged. This is what lets you check your usage.
What the assistant gets: the right to call the data routes on your behalf, against your quota and then your balance. What it does not get: your email address, your invoices, or the right to top up or close the account. You can cut this access off at any time from your API keys; revocation is immediate. Unfinished authorisation requests and single-use codes are deleted automatically once their short lifetime has passed.
Document-analysis processor and transfer outside the European Union
Two features call a language model provided by Anthropic, whose processing servers are located in the United States:
/v1/entreprise/{siren}/capitalsends Anthropic the PDF of the PUBLIC deed filed with the national company register (articles of association published by INPI), for the duration of the extraction. That public deed may name natural persons (shareholders, officers) as it publishes them. The response served by Sirenic is minimised: year of birth at most, never a personal address or a full date./v1/entreprise/{siren}/santesends NO name of a natural person: the file given to the model is limited to the company's REGISTERED name (only where it is proven to be a legal entity — never that of a sole trader), together with amounts, ratios and qualifications. No officer name, no year of birth, no address.
This processing is governed by Anthropic's data processing addendum (DPA), which incorporates the European Commission's standard contractual clauses for the transfer; documents sent through the API are not used to train the models. Details of the flows and safeguards: rgpd@sirenic.eu.
Security
The service is reachable over HTTPS only (TLS, HSTS). No secret is stored in clear: API keys, connector tokens, authorisation codes and session tokens are kept only as SHA-256 fingerprints — so we can neither read them back nor resend them to you. There is no wallet private key on our servers: only the public receiving address is held. The client area uses neither passwords nor JavaScript; its session relies on an httpOnly, Secure, SameSite cookie that can be revoked at any time. The front-end access logs keep no request headers at all — precisely so that no key can appear in them — and are purged after 7 days. In the event of a data breach presenting a risk, we notify the CNIL within 72 hours and, where the risk is high, the individuals concerned.
Data controller
For any question about your personal data or the exercise of your rights: rgpd@sirenic.eu. The identity and address of the data controller are given in the legal notice.