PRIVACY POLICY

At SIBYL, protecting your personal data is our priority. 

The purpose of this policy is to inform you about how we process your personal data in connection with the use of the website https://sibyladvisory.io/ (the “Website”) in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR") and French Data Protection Law n° 78-17 of 6 January 1978 (together the "Applicable Regulations").

It is expressly stated that no cookies or trackers are used on the Website. Consequently, no personal data is processed through such devices.

  1. Who is the data controller?

The data controller is SIBYL, a simplified single shareholder company, registered with the Registry of Trade and Companies of Paris under the number 981 591 977 and whose head office is located at 54 rue des Martyrs, 75009 Paris (FRANCE) (“Us” or “We”) when browsing on our Website. 

However, when we provide our strategy and technology consulting services to our clients, we process personal data on their behalf and for their own purposes. Our clients act therefore as data controllers in accordance with Article 4 of GDPR while we act as data processor. Consequently, these processing operations are excluded from the scope of this Privacy Policy.

  1. What personal data we collect?

Personal data is a data that identifies an individual directly or indirectly, in particular by reference to an identifier such as a name.

We may collect the following personal data:

  • Identification data (e.g., full name, email address);
  • Data relating to your professional life (e.g., company name);
  • Any information you wish to send us as part of your contact request.

Mandatory data are indicated when you provide us with your data. They are indicated by any means.

  1. Details of the processing of your personal data

Objectives

Legal basis

Data retention period

To create a database of prospects

Our legitimate interest in developing and promoting our business

Personal data are retained for a period of 3 years from the date your last contact with us. 

To perform operations related to management of our prospects and customers concerning quotations, and ensuring the follow-up of the contractual relationship with our customers

Execution of the contract that you or your company have entered into with Us

Personal data are retained for the duration of our business relationship. 

In addition, personal data may be archived for probationary purposes for a period of 5 years.

To answer to your information request and other inquiries

Taking steps at your request prior to entering a contract

If you become a client: personal data is retained for the duration of the contract. 

If you do not become a client: personal data is retained for 3 years from the date of your last contact.

To comply with our legal and regulatory obligations

To comply with our legal and regulatory obligations

Invoices are archived for a period of 10 years.

In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.

To process data subjects’ requests to exercise their rights

To comply with our legal and regulatory obligations

If we ask you a proof of identity: we only retain it for the necessary time to verify your identity. Once the verification has been carried out, the proof is deleted.

  1. Who are the recipients of your personal data?

The following categories of recipients will have access to your personal data:

  1. The staff of our company;
  2. Our processors: hosting provider, CRM tool, payment service provider, webflow, billing tool;
  3. to any authority legally empowered to deal with it, in particular the judicial, police or administrative authorities, if they so request.


  1. Are your personal data likely to be transferred outside the European Union?

Your personal data is hosted for the duration of the processing on the servers of the company Amazon Web Services (AWS), located in the United States.

As part of the tools, we use (see article on the recipients of your personal data, especially our processors), your personal data may be transferred outside the European Union. The transfer of your personal data in this context is secured with the use of following safeguards:

  • Either personal data are transferred to a country that has been recognized as ensuring an adequate level of protection by a decision of the European Commission, in accordance with article 45 of the GDPR: in this case, this country ensures a level of protection deemed sufficient and adequate to the provisions of the GDPR; or

  • The personal data are transferred to a country whose level of data protection has not been recognized as adequate to the GDPR: in this case these transfers are based on appropriate safeguards indicated in article 46 of the GDPR, adapted to each provider, including but not limited the execution of Standard Contractual Clauses approved by the European Commission, the application of Binding Corporate Rules or an approved certification mechanism; or 

  • The personal data are transferred under any appropriate safeguards described in Chapter V of the GDPR.

  1. What rights can you exercise on your personal data?

You have the following rights regarding your personal data:

  • Right to be informed: this is precisely why we have drafted this privacy policy as defined by articles 13 and 14 of the GDPR.

  • Right of access: you have the right to access all your personal data at any time as defined by article 15 of the GDPR.

  • Right to rectification: you have the right to rectify your inaccurate, incomplete or obsolete personal data at any time as defined by article 16 of the GDPR.

  • Right to restriction of processing: you have the right to restrict the processing of your personal data in certain cases defined in article 18 of the GDPR.

  • Right to erasure (“right to be forgotten”): you have the right to request that your personal data be deleted and to prohibit any future collection as defined by article 17 of the GDPR.

  • Right to file a complaint to a competent supervisory authority (in France, the CNIL), under article 77 of the GDPR, if you consider that the processing of your personal data constitutes a breach of applicable regulations.

  • Right to define instructions related to the retention, deletion and communication of your personal data after your death.

  • Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. Such withdrawal will not affect the lawfulness of the processing carried out before the withdrawal.

  • Right to data portability: under specific conditions defined in article 20 of the GDPR, you have the right to receive the personal data you have provided us in a standard machine-readable format and to require their transfer to the recipient of your choice.
  • Right to object: You have the right to object to the processing of your personal data as defined by article 21 of the GDPR. Please note that we may continue to process your personal data despite this opposition for legitimate reasons or for the defense of legal claims.

You can exercise these rights by writing to us at the following address: contact@sibyladvisory.com 

We may ask you to provide us with additional information if there is reasonable doubt, or any document likely to prove your identity if the doubt persists. 

For any unsuccessful questions or requests, you are entitled to lodge a complaint with the competent supervisory authority in France, the Commission Nationale de l'Informatique et des Libertés (“CNIL”), located at 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07.

  1. Modifications

We may modify this privacy policy at any time, in particular to comply with any regulatory, jurisprudential, editorial or technical change. These modifications will apply on the date of entry into force of the modified version. Please regularly consult the latest version of this privacy policy. You will be kept posted of any significant change of the privacy policy.

Entry into force: [to be completed]

Sibyl’s end-to-end service offerings

We help organizations move from ambition to execution. Sibyl designs, builds, and deploys data and AI solutions in production, combining deep technical expertise with a sharp focus on business impact and long-term ownership.

Foundry & AIP Deployment

We build production-grade applications on the Palantir platform to solve real operational problems. Our teams design scalable data pipelines, ontologies, models, and applications using proven technical patterns that hold up in production.

Data & AI Strategy

We identify where data and AI can genuinely create value and translate those opportunities into execution-ready roadmaps. Our strategies are grounded in technical feasibility, operational constraints, and clear paths to production.

Platform Enablement & Acceleration

We combine hands-on delivery with structured knowledge transfer to accelerate outcomes and build lasting internal capability.

Palantir Platform Governance

We establish the structures, tooling, and processes needed to scale the Palantir platform enterprise-wide. From access control and FinOps to project intake and value tracking, we help scale with confidence and control.

Industries & Expertise

Supply Chain & Logistics
Procurement
Chemicals & Nutrition
Insurance & Banking
Anti-Financial Crime
Healthcare
AI for Climate & ESG
Aerospace & Defense

€50M logistics optimization through supplier consolidation algorithms and freight planning tool.

LLM-powered contract intelligence enabling systematic pricing discrepancy detection across €2B+ procurement portfolio.

€20M savings through AI-powered portfolio rationalization and dynamic SKU recommendation.

AI-driven catastrophe modeling and underwriting tools processing 1M+ contracts in minutes.

Network analysis and transparent fraud detection workflows reducing alert investigation work by 70%.

Real-time revenue cycle management across 300+ facilities unlocking €30M in trapped cash.

End-to-end supply chain carbon tracking and biomass sequestration simulation for permanent removal.

Procurement intelligence linking BOM evolution to commodity pricing for proactive contract negotiations.

How We Work

Operating Principles

Impact First

Understand what success means for your business, then work backward to the right solution.

Build to Scale

Production-grade from day one - no prototypes that need rebuilding later.

Deep Expertise, Hands-On Delivery

Senior ex-Palantir engineers stay embedded throughout delivery. No hand-offs, no compromises.

Sophisticated Modelling, Explainable Results

Deploy powerful quantitative solutions that stakeholders understand and trust.

Approach

Scope & Align

Understand operational reality and identify where interventions create genuine leverage.

1

Prototype & Prove

Test value hypotheses with real data before full-scale commitment.

2

Deploy & Scale

Build production systems designed for resilience, adoption, and operational complexity.

3

Enable & Optimize

Transfer capability through continuous collaboration, not formal training.

4

Evolve & Grow

Understand operational reality and identify where interventions create genuine leverage.

5