Our Privacy Policy
Our Privacy Policy outlines how we collect, use, and protect your personal information. Your privacy and security are our priorities.
Last Updated on September, 1, 2026
Who we are
This policy describes how SYDEMAP ("Sydemap", "we", "us"), sole proprietorship under the French micro-enterprise tax regime registered with its registered office at France, Paris, processes your personal data when you use the Sydemap application available at app.sydemap.io (the "Service").
Data controller: SYDEMAP, reachable at contact@sydemap.io.
We act as a data controller for account data, and as a data processor for the data you enter into your workspace (your IT map), which we process on your behalf.
Data we collect
Account data : when you create an account via Google or email: your name, email address, organization name, and role (administrator / editor).
Content you enter : the information in your IT map: applications, infrastructure, processes, initiatives, costs, contracts, dependencies, notes, and any other content you add. This data belongs to you; we host it to provide the Service.
AI feature interactions : content you submit to AI-assisted features (generation, analysis, chat) is sent to our AI sub-processor to produce the response (see §5).
Technical and usage data : connection logs, IP address, browser type, pages viewed, and technical error reports (for security, diagnostics, and Service improvement).
Billing data : for paid subscriptions, the data required for payment is processed by our payment provider, we do not store your card numbers.
We do not collect special categories of data (sensitive data within the meaning of Article 9 GDPR) and ask that you do not enter any into your IT map.
Data Security
We take data security seriously and employ industry-standard measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Purposes and legal bases (GDPR)
Purpose Legal basis
Providing and operating the Service (account, mapping, AI) : Performance of the contract (Art. 6.1.b)
Security, abuse prevention, logging : Legitimate interest (Art. 6.1.f)
Technical diagnostics and Service improvement : Legitimate interest (Art. 6.1.f)
Billing and subscription management : Performance of the contract / legal obligation
Service-related communications (support, transactional emails) : Performance of the contract
Optional marketing communications : Consent (Art. 6.1.a), revocable at any time
Sub-processors and recipients
To operate the Service, we rely on sub-processors, governed by data processing agreements (DPAs), falling within the following categories:
hosting of the application and database (within the European Union);
authentication and identity management;
processing of artificial-intelligence features;
transactional email delivery;
payment processing;
technical error monitoring.
Some of these sub-processors are located outside the European Union, notably in the United States; these transfers are governed by Standard Contractual Clauses (see §6). The up-to-date, named list of our sub-processors is available on request at contact@sydemap.io.
About AI: content submitted to AI features is processed by Anthropic solely to generate the requested response. In accordance with Anthropic's commercial terms, this data is not used to train its models.
Location and international transfers
Your IT-map data is hosted in the European Union. Some sub-processors (§5) are located outside the EU, notably in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses and/or other GDPR-compliant mechanisms.
Retention
Account data and content: kept for as long as your account is active, then deleted within [X days/months] after account closure, unless a legal retention obligation applies.
Technical and security logs: [X months].
Billing data: for the period required by law (generally 10 years in France for accounting records).
We do not sell your data
We do not sell your personal data and do not share it for advertising purposes. We only share it with the sub-processors listed below, strictly to operate the Service.
Cookies
Our website may use cookies to enhance your browsing experience and collect information about how you interact with our site. You can adjust your browser settings to refuse cookies or alert you when cookies are being sent, but some features of the site may not function properly without cookies.
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection, and data portability, as well as the right to withdraw your consent at any time. You can exercise these rights by writing to contact@sydemap.io
Changes to this Privacy Policy
We reserve the right to update or change this Privacy Policy at any time. Any changes will be posted on this page, and the effective date will be updated accordingly. We encourage you to review this Privacy Policy periodically for any updates.
Contact Us
If you have any questions or concerns about our Privacy Policy or the handling of your personal information, please contact us at contact@sydemap.io