SIGILLUM Privacy Policy

Version 2026-09-25

1. Data controller

The controller is MAORI DI MARCELLO ORIZIO. Identification and contact details are shown at the end of this page.

2. Scope of the service

SIGILLUM creates, signs, registers and verifies technical evidence for photos, videos and text through HCV-IDs, cryptographic fingerprints, signed certificates, HCVPACK and an online Registry. Free verification may be used without an account; Creator functions require an account and the eligibility conditions shown by the service.

3. Data processed

Depending on the feature, SIGILLUM may process account/profile data, email, acceptance status, device technical data and public-key fingerprints, Apple subscription information, Stripe Identity status and minimum outputs, HCV-IDs, certificates, hashes, signatures, technical metadata, capture signals, security logs and content required for the requested operation. Certified photos, videos and HCVPACK files are stored locally in encrypted form in the app’s private area. When a Creator chooses to share an original, the content is temporarily transmitted to SIGILLUM infrastructure for verification and creation of the reference copy; the reference derivative is then uploaded to the official SIGILLUM YouTube channel. SIGILLUM does not sell personal data and does not use user content for behavioural advertising.

4. Purposes and legal bases

Data is processed for account and security, email verification, access recovery, subscription entitlement, Creator identity verification, HCV creation and verification, Registry operation, fraud prevention, support and applicable obligations. Legal bases may include performance of a contract, pre-contractual steps, legal obligations and legitimate interests in security and service integrity. Separate consent is requested where legally required.

5. Stripe Identity

The process may require an identity document, live capture and selfie and may involve biometric processing by Stripe under Stripe notices and consent flow. SIGILLUM stores verification status, the technical session reference and minimum data needed to link the result to the account and certificates.

6. Apple and subscriptions

SIGILLUM receives only technical information needed to determine Creator entitlement and does not directly receive App Store payment details. Deleting a SIGILLUM account does not automatically cancel an Apple subscription.

7. Providers and recipients

Technical providers may include:

8. International transfers

Some providers may process data outside the EEA. Transfers are handled through mechanisms and safeguards available under applicable law and the providers’ terms.

9. Retention

Account data is retained as needed to provide the service and meet applicable obligations. Encrypted originals and HCVPACK files on the device remain in the app’s private area until removed under the app’s operation or together with local app data. Clear temporary files created for viewing, verification or sharing are deleted when the operation ends. Reference copies published through YouTube and related technical records may remain available while the publication is active or until the service’s withdrawal function is used, subject to audit, security, integrity and applicable retention requirements. After account deletion, separable personal data is deleted or minimized where possible; technical records strictly necessary to preserve the integrity and verifiability of previously issued certificates may be retained where legally permitted.

10. Rights

Where applicable, users may request access, rectification, erasure, restriction, portability and objection and may withdraw consent where processing relies on consent. Users may also lodge a complaint with the competent supervisory authority.

11. Account deletion

Account deletion can be initiated directly in the app. The account, sessions, devices and personal associations are removed according to the service design, subject to technical records required for verifiability and applicable retention duties. Apple subscriptions must be managed separately.

12. Security

SIGILLUM uses technical and organisational measures intended to protect accounts, sessions, technical keys, certificates and data against unauthorised access, loss, alteration and abuse. No system can guarantee absolute security.

13. Updates and contact

This Policy may be updated to reflect changes in the service, providers or applicable obligations. Requests and communications: marcelloorizio@legalmail.it.

14. Google/YouTube data and OAuth

To publish and verify the official reference copy, SIGILLUM uses OAuth 2.0 and the YouTube Data API on the YouTube channel controlled by SIGILLUM. The backend securely retains the authorization token required to maintain channel access and uses the granted permissions only to upload, read status and manage SIGILLUM reference copies. SIGILLUM does not use Google data for advertising, profiling or sale and does not share OAuth tokens with users. Access can be revoked by the Google Account owner from Google security settings.

MAORI DI MARCELLO ORIZIO · Via della Battaglia 28, 25030 Maclodio (BS), Italy · VAT 04773680980 · REA BS-640525 · PEC marcelloorizio@legalmail.it