SIOBuilder · Branding Lab
Privacy Policy
How personal data is processed in the SIOBuilder application and extension.
Last updated : 20 September 2026
1. Data Controller
The data controller is Branding Lab, a French SARL registered with the Paris Trade and Companies Register under number 894 714 401, with its registered office at 66 avenue des Champs-Élysées, 75008 Paris. For privacy questions or requests, contact hello@siobuilder.com.
2. Personal Data We Process
Depending on your use of SIOBuilder, we may process:
- account and authentication data, including name, email, identifier, sessions, IP address and browser or device information;
- profile, role, subscription and usage entitlement data;
- billing and payment information, including plan, payment status, transaction identifier and invoices;
- projects and content, including HTML, CSS, text, briefs, messages, imported Sections, settings and Results;
- usage data, including features used, generation activity, Section consumption, errors and timestamps;
- support requests and related correspondence;
- technical and security logs;
- cookies and local browser storage described in our Cookie Policy.
Please do not submit passwords, API keys, sensitive data or third-party personal data without a valid legal basis.
3. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Creating the account, authenticating Users and providing the service | Contract or pre-contractual steps |
| Saving projects, Results, Sections and history | Performance of a contract |
| Processing subscriptions, payments and refunds | Performance of a contract |
| Issuing and retaining invoices | Legal obligation |
| Providing support and transactional messages | Contract, pre-contractual steps or legitimate interests |
| Preventing fraud, securing, diagnosing and maintaining the service | Branding Lab’s legitimate interests |
| Complying with a legal duty or lawful request | Legal obligation |
| Introducing optional analytics or a non-essential tracker in the future | Prior consent |
4. Artificial Intelligence Processing
To perform the requested generation or conversion, relevant content, instructions and settings may be transmitted to one or more technical artificial intelligence model service providers. Data is limited to what is required for the feature but may include page content, code, text or briefs supplied by the User.
Where a Professional Customer uploads personal data for its own purposes, that Customer may act as controller and Branding Lab as processor. The applicable data processing agreement must then govern the parties’ respective obligations.
5. Recipients and Service Providers
Personal data may be accessed, only as necessary, by:
- authorised Branding Lab personnel;
- Vercel for infrastructure and hosting;
- Neon for database services;
- Better Auth for authentication and session-management functions, with account records stored in the SIOBuilder database;
- Resend for transactional email delivery;
- technical artificial intelligence model providers;
- Stripe or another payment provider once payments are enabled;
- professional advisers, auditors or authorities where legally required.
We do not sell personal data.
6. International Transfers
Some providers or subprocessors may be located outside the European Economic Area or allow access from a third country. Depending on the country, transfers may rely on an adequacy decision, the European Commission’s Standard Contractual Clauses with necessary supplementary safeguards, or another mechanism permitted under Articles 44 to 49 GDPR. SIOBuilder does not guarantee that all data is processed exclusively in the European Union. Information about safeguards may be requested at hello@siobuilder.com, subject to security and commercial confidentiality.
7. Retention Periods
| Data | Retention period |
|---|---|
| Account, profile, subscription and access data | For the life of the account or subscription, then up to 12 months after closure, unless legal archiving is required |
| Projects, code, briefs, conversations and generations | For the subscription and 12 months after it ends, unless deleted earlier |
| Authentication sessions | Until expiry or revocation |
| Technical and security logs | Up to 12 months, unless isolated for an investigation |
| Support correspondence | Until resolution, then up to 3 years after the last exchange where needed |
| Invoices and accounting records | 10 years from the end of the relevant financial year |
| Evidence of consent | For the processing period and the time needed to demonstrate valid consent |
Deleted data is removed from active systems and later from backups according to the applicable rotation cycle, unless legal retention is required.
8. Chrome Extension
The SIOBuilder extension stores the interface language preference locally in Chrome. It operates in the Systeme.io editor to detect the open page and create blocks requested by the User. It no longer uses a licence key, serial number or device identifier to authorise its operation. Uninstalling the extension or clearing its storage removes the local preference.
9. Security
Branding Lab implements appropriate technical and organisational measures, including access controls, secure sessions, encrypted communications, secrets management, security logging and appropriate backups. Users should use a unique password and never place secrets or API keys in a project.
10. Your Rights
Subject to the GDPR, you may request access, correction, deletion, restriction, objection to processing based on legitimate interests, portability, withdrawal of consent and post-mortem instructions allowed under French law. Contact hello@siobuilder.com. We normally respond within one month, extendable by two months for complex or numerous requests after notice in the first month. Proportionate identity verification may be requested.
You may also complain to the French data protection authority, the CNIL. SIOBuilder’s automated systems generate or convert content at your request but do not make decisions producing legal or similarly significant effects within Article 22 GDPR.
11. Changes to This Policy
This Policy may be updated to reflect changes to the service, providers or law. Users will be informed by an appropriate method where a change is material. The date at the top identifies the applicable version.