Legal
Privacy policy
This privacy policy explains which personal data we process when you use sigmacode.io, for what purposes and on which legal basis, in accordance with the EU General Data Protection Regulation (GDPR).
1. Controller
SANICURA d.o.o., Ulica Andrije Hebranga 8, 10000 Zagreb, Croatia · Email: eckerstorfer@sanicura.com · OIB: 87611335623
Data protection contact: eckerstorfer@sanicura.com
2. Hosting and server logs
This website is hosted on a server of netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, in a data centre in Vienna, Austria (EU). When you visit the site, technically necessary data is processed, such as your IP address, date and time of the request, the requested page, browser and operating system. This is required to deliver the website securely and is based on our legitimate interest (Art. 6(1)(f) GDPR). Log data is deleted after the hosting provider's short-term log retention period.
Where one of the service providers named in this policy (such as Resend or Anthropic) processes data outside the EU/EEA, this is based on the EU Commission's adequacy decision (EU-U.S. Data Privacy Framework) and/or Standard Contractual Clauses.
If error monitoring is enabled, technical error data (error message, stack trace, the affected page without query parameters, browser and operating system, time) is sent to Sentry (Functional Software, Inc., USA), using its EU data region in Germany, so that we can detect and fix malfunctions. We do not send form contents or AI demo inputs, and IP addresses are not stored with error reports. Legal basis: our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR). Error data is deleted after at most 90 days.
3. Contact form and email
If you contact us via the form or by email, we process the data you provide (name, email, company, project details) to answer your request and, where applicable, to prepare a contract (Art. 6(1)(b) GDPR) or on the basis of our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
With an enquiry sent through the website we also receive the page you sent it from, the first page of your visit, the host name of the website that referred you and any campaign parameters (UTM) in the link you followed, so that we can see how enquiries reach us (Art. 6(1)(f) GDPR). These details are held in your browser's working memory only — no cookies, no browser storage — and are transmitted solely together with an enquiry you send yourself.
Form submissions are delivered to us by email via Resend Inc., USA. We delete enquiry data when it is no longer needed, unless statutory retention obligations apply.
After you send an enquiry, we send a one-off confirmation with a summary of your message to the email address you entered (also via Resend). We do not send newsletters or marketing emails.
4. AI demos
If you use our AI demos, the content you enter or upload (messages, documents, images, code) is sent to Anthropic PBC (USA) to generate a response. We do not store this content on our servers. Anthropic processes API data according to its commercial terms and does not use it to train models by default; data may be retained by Anthropic for a limited period for trust & safety purposes. The chat assistant can prepare a draft project brief for you. That brief and the contact details you enter in the brief card are only transmitted to us (via our contact form processing and Resend) after you tick the consent box and click Send yourself; the contact details you enter there are not sent to Anthropic.
To prevent abuse, we process your IP address to enforce rate limits. Counters are kept in memory or in Upstash Redis (EU region), if enabled and expire automatically after at most 24 hours. Legal basis: our legitimate interest in the secure operation of the demos (Art. 6(1)(f) GDPR).
Please do not enter confidential information or personal data of third parties into the demos.
5. Cookies and local storage
We do not use tracking or marketing cookies. The website stores your language preference in a technically necessary cookie. The chat assistant keeps the current conversation only in your browser's memory.
6. Embedded content and external links
Links to client websites and block explorers open third-party sites; their privacy policies apply. The live smart-contract panel reads public blockchain data directly from your browser via a public RPC endpoint (the respective network's public default RPC provider), which receives your IP address.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests (Art. 15–21 GDPR). To exercise your rights, contact eckerstorfer@sanicura.com.
You also have the right to lodge a complaint with a supervisory authority, in Croatia the Personal Data Protection Agency (AZOP, azop.hr), or the authority in your country of residence.
8. Changes
We may update this policy when our services or legal requirements change. Last updated: 18 September 2026.