Back to home

Privacy Policy

Last updated: 14 July 2026

Your privacy is central to how WESEP is designed. This page explains precisely what data we collect, why, for how long, and how to exercise your rights.

1. Who we are and who is responsible for processing?

SINIAMIN OVERSEAS (SIRET 833 549 785, 10 Route de Balata, 97234 Fort-de-France, Martinique, France), trading as WESEP, is the data controller for the personal data collected through the WESEP Orbe service at wesep.com.

For any questions relating to the protection of your data, you can contact us at: contact@wesep.com.

2. What data do we collect?

We collect the following data:

Identity and account data - First and last name - Email address - Password (stored as a bcrypt hash, never in plain text) - Country of residence

Service usage data - Orb metadata (title, scheduled delivery date, status, content type) - Cryptographic records (SHA-256 hash, Arweave identifier, Scroll transaction) - Designated beneficiary's phone number (encrypted at rest with AES-256-GCM) - Credits history and transactions

Technical data - IP address (pseudonymised in server logs) - Session data (session cookie, 7-day lifetime) - Connection data for security purposes (login attempts, timestamps)

Payment data We do not store any banking data. Payments are processed by Stripe, Inc. under their own terms. We retain only the transaction reference and payment status.

What we do not collect Orb content is encrypted server-side with AES-256-GCM at the point of sealing. Once sealed, WESEP cannot technically access the contents of your Orb.

3. What is our legal basis for processing your data?

We process your data on the following legal grounds, in accordance with Article 6 of the GDPR:

- Contract performance (Art. 6.1.b): processing necessary to provide the WESEP Orbe service (account creation, Orb management, delivery to beneficiaries).

- Legitimate interests (Art. 6.1.f): service security, abuse prevention, anonymised technical logs, service improvement.

- Legal obligation (Art. 6.1.c): retention of certain data for accounting and tax purposes under French law.

- Consent (Art. 6.1.a): analytical cookies, if you have expressly consented.

4. How do we use your data?

Your data is used exclusively for the following purposes:

- Creating and managing your user account - Creating, encrypting, sealing, and archiving your Orbs - Delivering Orbs and access codes to designated beneficiaries (by email or SMS) - Transactional communications: registration confirmation, password reset, PDF certificates - Service security: abuse detection, fraud prevention, rate limiting - Billing and credits management - Service improvement based on aggregated, anonymised metrics

We do not sell your data. We do not profile you for advertising purposes. We do not send marketing communications without your explicit consent.

5. How long do we retain your data?

We apply the following retention periods:

- Active account data: retained for as long as the account is active. - Data after account deletion: erased within 30 days of the request, except where a longer retention is required by law. - Billing and transaction data: 10 years from the date of the transaction (French accounting and tax obligation, Article L.123-22 of the Commercial Code). - Anonymised server logs: maximum 12 months. - Session cookies: 7 days, renewed on each active login. - Arweave cryptographic data: records archived on the Arweave network are permanent by nature (immutable decentralised storage). This permanence is inherent to the technology and constitutes the very guarantee of the service.

At the end of the applicable retention period, your data is deleted or anonymised.

6. Who has access to your data? (Sub-processors)

We may engage the following sub-processors to deliver the service:

- Replit, Inc. (United States) : application infrastructure and database hosting - Stripe, Inc. (United States) : payment processing - Resend : transactional email delivery - Twilio, Inc. (United States) : SMS delivery for beneficiary access codes - Irys : archiving on the Arweave network - Scroll network : recording existence proofs on the blockchain

These sub-processors act solely on our instructions, under contracts that meet GDPR requirements. For transfers to countries outside the European Union (in particular the United States), we ensure that appropriate safeguards are in place (European Commission standard contractual clauses).

7. Your GDPR rights

Under the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and the French Data Protection Act, you have the following rights:

- Right of access (Art. 15): obtain a copy of your personal data. - Right to rectification (Art. 16): have inaccurate data corrected. - Right to erasure (Art. 17): request the deletion of your data ("right to be forgotten"), subject to legal retention obligations. - Right to restriction (Art. 18): temporarily restrict the processing of your data. - Right to data portability (Art. 20): receive your data in a structured, machine-readable format. - Right to object (Art. 21): object to processing based on legitimate interests. - Right not to be subject to automated decision-making (Art. 22): we do not carry out profiling or automated decisions with legal effects.

How to exercise your rights Send your request to contact@wesep.com, stating your account email address and the nature of your request. We will respond within 30 days. If we have doubts about your identity, we may ask for proof of identity.

Right to lodge a complaint If you believe your rights have not been respected, you have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) : https://www.cnil.fr, 3, place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.

8. Cookies and trackers

Strictly necessary cookies (no consent required) - Session cookie (wesep_sid): maintaining your login session. Duration: 7 days.

Analytical cookies (with consent) - Google Tag Manager (GTM-W2SKNSDH) and Google Analytics (G-BWK5PNGQ68): aggregated and anonymised audience measurement. Enabled only if you consent.

You can refuse or withdraw your consent at any time through your browser settings. Refusing analytical cookies does not affect your access to the service.

9. Data security

We apply the following technical and organisational measures to protect your data:

- Communications encryption: HTTPS/TLS across the entire service - Orb content encryption: AES-256-GCM (authenticated encryption) - Encryption of sensitive PII data at rest: AES-256-GCM (beneficiary phone numbers) - Password hashing: bcrypt (adaptive cost factor) - Secure sessions: httpOnly, secure, SameSite=Lax, stored in PostgreSQL - HTTP security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options - Rate limiting: protection against brute-force attacks - Data access restricted to authorised personnel

In the event of a data breach likely to result in a risk to your rights and freedoms, we undertake to notify the CNIL within 72 hours and to inform you without undue delay.

10. Changes to this policy

We reserve the right to amend this privacy policy at any time to reflect changes to our service or applicable regulations. In the event of a material change, we will notify you by email with 30 days' notice before the new provisions take effect. The date of the last update is shown at the top of this page.

Questions? contact@wesep.com · Terms of Service · Legal Notice