Data Processing Addendum
Version 0.1.0-draft · Applies to: signaliq.brandconnectai.com and all related services
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and SignalIQ and governs our processing of Personal Data on your behalf. It is designed to support compliance with the GDPR, the UK GDPR, and the CCPA/CPRA.
Draft — LEGAL-REVIEW-REQUIRED. This document is a scaffold. Before this DPA is countersigned with a customer it must be reviewed by counsel, the sub-processor list must be confirmed, and the Standard Contractual Clauses (2021/914) and UK IDTA annexes must be attached.
Parties & Scope
This DPA supplements the SignalIQ Terms of Service ("Agreement"). In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data.
Roles of the Parties
For the purposes of the GDPR, the UK GDPR, and comparable frameworks, the Customer is the Controller of Personal Data submitted to the Service, and SignalIQ is the Processor. Where Customer acts as a Processor on behalf of a third-party Controller, SignalIQ acts as a Sub-processor.
Subject Matter & Nature of Processing
- Subject matter: processing of Personal Data required to deliver the SignalIQ Service to Customer.
- Duration: the term of the Agreement plus any post-termination period required to return or delete data.
- Nature & purpose: filtering, classification, enrichment, storage, and transmission of the communications and metadata Customer submits.
- Categories of data subjects: Customer's end-users, Customer's employees, and the senders/recipients of communications Customer processes.
- Categories of Personal Data: contact data, communication content and metadata, authentication data, device/log data.
Sub-processors
Customer provides a general authorization for SignalIQ to engage sub-processors to deliver the Service. A current list of sub-processors is available at /legal/dpa#subprocessors (to be published post-review). We will give at least 30 days' notice before adding a new sub-processor, and Customer may object on reasonable data-protection grounds.
Security Measures
SignalIQ maintains the technical and organisational measures ("TOMs") described in Annex II of this DPA, including TLS-in-transit, AES-256-at-rest, role-based access controls, secrets management, least-privilege production access, and an internal security-review program.
International Transfers
Where processing involves the transfer of Personal Data out of the EEA, UK, or Switzerland to a jurisdiction without an adequacy decision, the parties agree to rely on the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two), the UK International Data Transfer Addendum, and, for Swiss data, the additional FDPIC clauses, each as attached in Annex III.
Data Subject Rights
Taking into account the nature of the processing, SignalIQ will provide reasonable assistance to Customer so that Customer can respond to requests from data subjects exercising their rights under applicable law. When we receive a data-subject request directly, we will route it to the relevant Customer without undue delay.
Incident Notification
SignalIQ will notify Customer without undue delay — and in any event within 72 hours — of becoming aware of a Personal Data Breach affecting Customer's data, together with the information reasonably required for Customer to meet its own notification obligations under Articles 33 and 34 of the GDPR.
Audits
SignalIQ makes available to Customer the information necessary to demonstrate compliance with this DPA. At Customer's request and no more than once per year, SignalIQ will share its most recent SOC 2 Type II report or equivalent third-party assessment. Direct on-site audits may be conducted for cause under terms to be agreed in good faith.
Return or Deletion of Data
On termination of the Agreement, and at Customer's choice, SignalIQ will return Customer's Personal Data or delete it (including from all backups as they naturally rotate), within 30 days unless retention is required by law. Certification of deletion will be provided on written request.