Privacy Policy
Sirion Technologies S.r.l. — Last updated: August 13, 2026
Sirion ("we", "us") provides data analytics and marketing management services for e-commerce brands. This policy describes how our platform — including our applications that connect to third-party services such as Meta (Facebook/Instagram) Marketing API, Google Ads API, Criteo API, Google Analytics, Klaviyo and Shopify — collects, uses and protects data.
1. What data we process
Our applications access, on behalf of our business clients and with their explicit authorization, advertising and commerce performance data: campaign and ad statistics (spend, impressions, clicks, conversions), ad creative assets, web analytics, email marketing metrics and order data. Our applications operate strictly within the scope of the permissions each client has granted on the respective platform, and any action on a client's accounts is performed only on behalf of, and as authorized by, that client.
We do not collect, request or process personal data of end users of Meta products (such as profile information of people who see or interact with ads). Performance data we access is aggregated at campaign, ad or day level.
Information collected automatically. Like most online services, our systems automatically record limited technical information when our applications or websites are used: server logs (timestamps, IP addresses, request metadata), browser and device information, and usage information. We use this information solely for security, troubleshooting and service operation, and retain it only as long as needed for those purposes.
2. How we obtain access
Access is always granted by our clients: through Business Manager partnership grants, manager-account links, or explicit API consent flows on each platform. Clients can revoke this access at any time from the respective platform, which immediately terminates our ability to read their data.
3. How we use the data
Data is used exclusively to provide our services to the client that owns it: analytics, performance reporting, business intelligence and marketing recommendations. We do not sell data, we do not share one client's data with another client or any third party, and we do not use client data for advertising of our own.
4. Where the data is stored and how it is protected
Data is stored in the European Union on managed cloud infrastructure (PostgreSQL databases and cloud storage) with encryption in transit and at rest. Access is limited to authorized Sirion personnel through role-based, least-privilege credentials; API secrets are stored in a dedicated secret manager and are never embedded in code or documents. Each client's data is logically segregated.
5. Retention and deletion
We retain data for as long as needed to provide the service to the client. Upon termination of a client relationship, or upon written request from the client, we delete the client's data from our systems within 30 days. To request deletion, contact us at the address below.
6. Your rights
Where the data we process includes personal data subject to the GDPR, data subjects have the right to access, rectify, erase, restrict or object to processing, and to data portability. Requests can be sent to the contact below and will be answered within 30 days.
7. Contact
Sirion Technologies S.r.l.
Email: privacy@sirion.work
8. Changes
We may update this policy from time to time; the current version is always available at this URL with the date of the last revision.