01Controller and contact
The controller is JUQ ELECTRONIC INFORMATION TECHNOLOGY LTD, company number 15896962, with registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. Privacy requests may be sent to juq1991@gmail.com.
02Data we collect
- Account profile: user ID, email, display name and avatar.
- Authentication: session identifiers and the account identifier returned by Google or GitHub. Sigoo does not need your provider password.
- Research input: private Topic, included and excluded scope, saved Opportunities, private notes and publication requests.
- Order evidence: product, buyer capacity, confirmed scope, accepted document and consent versions, timestamp, limited IP address and user agent evidence.
- Payment references: Stripe Customer, Checkout Session, PaymentIntent, Charge or Refund identifiers, amount, currency and payment status. Sigoo does not store full card details.
- Delivery and support: research versions, citations, access/export events, issue reports, refund decisions and relevant correspondence.
- Security and service data: request IDs, operational logs, abuse signals, device/browser metadata and feature interactions.
- Public submissions: Topic requests, an optional result-notification email, feedback and material you separately ask Sigoo to consider for publication.
03Why we use data
| Purpose | Typical UK GDPR basis |
|---|---|
| Accounts, private research, delivery and support | Contract or steps requested before a contract |
| Payment, refunds, tax and accounting records | Contract and legal obligation |
| Security, fraud prevention and service reliability | Legitimate interests and, where applicable, legal obligation |
| Product measurement and improvement | Legitimate interests using minimised or aggregated data |
| Optional publication or marketing | Consent or a separate publication request, as applicable |
| Legal claims, complaints and regulatory compliance | Legal obligation and legitimate interests |
Sigoo does not sell personal data. Research input is not made public unless you separately request publication and Sigoo approves it.
04Service providers and recipients
Sigoo uses providers only where needed to operate the service. Current categories may include Cloudflare for hosting, storage and security; Google and GitHub for sign-in; Stripe for payments and refunds; OpenAI for bounded research analysis; DataForSEO for selected market data; and Resend for service email.
Public evidence sources such as websites, GitHub and Hacker News may receive ordinary network requests during research. Authorities, advisers or a buyer of the business may receive limited data where legally necessary and subject to appropriate protections.
05International transfers
Some providers may process data outside the UK. Where UK data protection rules treat this as a restricted transfer, Sigoo will use an applicable adequacy arrangement, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, and carry out any required transfer risk assessment.
Final provider locations and safeguards must be verified and recorded before live launch; this draft does not invent them.
06Retention
- Account and private workspace data: while the account is active, then deleted or anonymised after a valid closure request unless a narrower record must be retained.
- Order, consent, payment-reference, delivery and refund evidence: normally six years after completion or case closure for contract, tax and legal-claim purposes.
- Detailed access and security logs: normally up to 24 months, longer only for an active security, fraud or dispute matter.
- Raw third-party fetched material: minimised and normally removed within 90 days where practical; necessary citation metadata and fingerprints may be retained with the delivery.
- Optional Topic-request result email: until the request is selected or rejected, and normally no longer than 12 months.
- Withdrawn publication snapshots: restricted for the documented legal, security and audit period, then deleted or anonymised.
These are maximum working periods, not a reason to retain every field. Sigoo reviews necessity and deletes or anonymises data sooner where the purpose no longer applies.
07Cookies and similar technology
Sigoo uses a strictly necessary session cookie to keep signed-in users authenticated and secure. It is not used for advertising. If non-essential analytics or marketing technology is introduced, Sigoo will provide the notice and consent controls required before enabling it.
08Automated research
Automated systems help organise public evidence and generate opportunity research. They do not make a decision that has a legal or similarly significant effect on you. You decide whether and how to use the research. Internal prompts and reasoning traces are not customer data deliverables.
09Your rights
Depending on the circumstances, you may ask for access, correction, erasure, restriction, objection or portability of your personal data, or withdraw consent for future processing that relies on consent. These rights are not absolute and exemptions may apply.
Contact juq1991@gmail.com. Sigoo will verify identity and normally respond within one month. You may also complain to the UK Information Commissioner’s Office or the relevant supervisory authority where you live.
10Security, children and changes
Sigoo uses access controls, tenant-scoped queries, encrypted transport, bounded logs and restricted Admin operations. No internet service can promise absolute security. Sigoo is intended for adults and does not knowingly offer paid research to children.
This notice will be reviewed when processing changes. Material new uses will be brought to users’ attention before they begin where required. The version accepted for an existing paid Order remains recorded in its immutable confirmation evidence.