SIGILLUM Privacy Policy
Version 2026-09-25
1. Data controller
The controller is MAORI DI MARCELLO ORIZIO. Identification and contact details are shown at the end of this page.
2. Scope of the service
SIGILLUM creates, signs, registers and verifies technical evidence for photos, videos and text through HCV-IDs, cryptographic fingerprints, signed certificates, HCVPACK and an online Registry. Free verification may be used without an account; Creator functions require an account and the eligibility conditions shown by the service.
3. Data processed
Depending on the feature, SIGILLUM may process account/profile data, email, acceptance status, device technical data and public-key fingerprints, Apple subscription information, Stripe Identity status and minimum outputs, HCV-IDs, certificates, hashes, signatures, technical metadata, capture signals, security logs and content required for the requested operation. Certified photos, videos and HCVPACK files are stored locally in encrypted form in the app’s private area. When a Creator chooses to share an original, the content is temporarily transmitted to SIGILLUM infrastructure for verification and creation of the reference copy; the reference derivative is then uploaded to the official SIGILLUM YouTube channel. SIGILLUM does not sell personal data and does not use user content for behavioural advertising.
4. Purposes and legal bases
Data is processed for account and security, email verification, access recovery, subscription entitlement, Creator identity verification, HCV creation and verification, Registry operation, fraud prevention, support and applicable obligations. Legal bases may include performance of a contract, pre-contractual steps, legal obligations and legitimate interests in security and service integrity. Separate consent is requested where legally required.
5. Stripe Identity
The process may require an identity document, live capture and selfie and may involve biometric processing by Stripe under Stripe notices and consent flow. SIGILLUM stores verification status, the technical session reference and minimum data needed to link the result to the account and certificates.
6. Apple and subscriptions
SIGILLUM receives only technical information needed to determine Creator entitlement and does not directly receive App Store payment details. Deleting a SIGILLUM account does not automatically cancel an Apple subscription.
7. Providers and recipients
Technical providers may include:
- Apple for app distribution and in-app purchases
- Stripe for identity verification
- Render and the associated database for infrastructure and Registry
- Google/YouTube to host the official reference copy when a Creator chooses to share an original
- Resend and email providers for codes and transactional messages
8. International transfers
Some providers may process data outside the EEA. Transfers are handled through mechanisms and safeguards available under applicable law and the providers’ terms.
9. Retention
Account data is retained as needed to provide the service and meet applicable obligations. Encrypted originals and HCVPACK files on the device remain in the app’s private area until removed under the app’s operation or together with local app data. Clear temporary files created for viewing, verification or sharing are deleted when the operation ends. Reference copies published through YouTube and related technical records may remain available while the publication is active or until the service’s withdrawal function is used, subject to audit, security, integrity and applicable retention requirements. After account deletion, separable personal data is deleted or minimized where possible; technical records strictly necessary to preserve the integrity and verifiability of previously issued certificates may be retained where legally permitted.
10. Rights
Where applicable, users may request access, rectification, erasure, restriction, portability and objection and may withdraw consent where processing relies on consent. Users may also lodge a complaint with the competent supervisory authority.
11. Account deletion
Account deletion can be initiated directly in the app. The account, sessions, devices and personal associations are removed according to the service design, subject to technical records required for verifiability and applicable retention duties. Apple subscriptions must be managed separately.
12. Security
SIGILLUM uses technical and organisational measures intended to protect accounts, sessions, technical keys, certificates and data against unauthorised access, loss, alteration and abuse. No system can guarantee absolute security.
13. Updates and contact
This Policy may be updated to reflect changes in the service, providers or applicable obligations. Requests and communications: marcelloorizio@legalmail.it.
14. Google/YouTube data and OAuth
To publish and verify the official reference copy, SIGILLUM uses OAuth 2.0 and the YouTube Data API on the YouTube channel controlled by SIGILLUM. The backend securely retains the authorization token required to maintain channel access and uses the granted permissions only to upload, read status and manage SIGILLUM reference copies. SIGILLUM does not use Google data for advertising, profiling or sale and does not share OAuth tokens with users. Access can be revoked by the Google Account owner from Google security settings.
MAORI DI MARCELLO ORIZIO · Via della Battaglia 28, 25030 Maclodio (BS), Italy · VAT 04773680980 · REA BS-640525 · PEC marcelloorizio@legalmail.it