1. Scope & roles
This Data Processing Addendum ("DPA") forms part of the agreement between SignalGate("Processor") and the customer ("Customer," "Controller") for use of the SignalGate Service. It applies whenever SignalGate processes Personal Data on Customer's behalf and is intended to satisfy Article 28 of the General Data Protection Regulation (EU GDPR), the UK GDPR, and analogous requirements under the California Consumer Privacy Act (CCPA), Brazilian LGPD and similar laws.
For data SignalGate processes for its own purposes — for example, billing the Customer or improving the Service — SignalGate acts as Controller; that processing is described in the Privacy Policy.
2. Subject matter & duration
The subject matter of the processing is the operation of the SignalGate Service for the Customer. The duration is the term of the Customer's subscription, plus any post-termination retention window expressly required by law or set out in this DPA.
3. Nature & purpose
SignalGate processes Personal Data to:
- Receive RSA-encrypted browser-fingerprint payloads from the Customer's site, decrypt them server-side, and return a verdict (
allow/dry_run_block/block). - Apply Customer-defined rules and Customer-configured flows to those payloads.
- Maintain logs and metrics that allow the Customer to audit, debug, and refine its anti-fraud configuration.
4. Categories of data & subjects
Categories of data:
- Device and browser signals (GPU renderer, user-agent, screen resolution, timezone, etc.) supplied by the SDK.
- Network identifiers — IP address, autonomous-system number.
- Behavioural metadata — timing of the request, the Customer-defined "method" identifier and the associated outcome event.
- Any additional data the Customer chooses to include in requests to the API.
Categories of data subjects:visitors and end-users of Customer's websites and applications. SignalGate does not knowingly process data about children and the Service is not designed for that purpose.
5. Processor instructions
SignalGate will process Personal Data only on the documented instructions of Customer, including with regard to transfers to a third country or an international organisation, unless required to do otherwise by EU or Member State law. The Agreement, this DPA, and Customer's use of the Service (including configurations made through the dashboard and API) constitute such instructions.
SignalGate will inform Customer if, in its opinion, an instruction infringes applicable data-protection law.
6. Confidentiality
SignalGate ensures that persons authorised to process Personal Data are bound by appropriate confidentiality obligations and have received data-protection training relevant to their role.
7. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, SignalGate implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- End-to-end encrypted fingerprint payloads — the public key is bundled into the Customer's SDK, the private key is generated and held server-side and never leaves SignalGate's infrastructure.
- Least-privilege access controls, separation of production and non-production environments, and centralised audit-logging.
- Periodic vulnerability scanning and penetration testing.
- A documented incident-response plan and breach-notification procedure (see §10).
A more detailed description is available in our Security Overview.
8. Subprocessors
Customer authorises SignalGate to engage subprocessors as listed at /legal/subprocessors. SignalGate will:
- Impose, by written contract, data-protection obligations on each subprocessor at least as protective as this DPA.
- Remain fully liable to Customer for the performance of each subprocessor's obligations.
- Give Customer at least 30 days' advance notice of any intended additions or replacements of subprocessors. Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected Service without penalty.
9. Data-subject rights
Taking into account the nature of the processing, SignalGate will assist Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of Customer's obligation to respond to requests for exercising data-subject rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection).
If a data subject contacts SignalGate directly with such a request, SignalGate will redirect them to Customer (where identification permits) and notify Customer without undue delay.
10. Breach notification
SignalGate will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data, and will provide reasonable information to enable Customer to meet its own notification obligations to supervisory authorities and data subjects.
11. Audits & inspections
SignalGate will make available to Customer all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. To minimise disruption, audits will be conducted on reasonable prior notice, no more than once per year, during business hours, and subject to confidentiality obligations.
Where available, SignalGate may satisfy audit obligations by providing relevant third-party attestations (e.g. SOC 2 Type II reports) under appropriate confidentiality terms.
12. International transfers
Customer Data is hosted in AWS's Frankfurt region (eu-central-1). Where personal data is transferred outside the EEA, the United Kingdom, or Switzerland, SignalGate relies on the European Commission's Standard Contractual Clauses (Module Two: controller-to-processor) and, where relevant, the UK International Data Transfer Addendum, the Swiss FDPIC mechanism, and any supplementary measures required by Schrems II.
A copy of the SCCs incorporated by reference into this DPA is available on request.
13. Return or deletion at end of services
On termination of the Service, SignalGate will delete or return all Customer Data within 30 days, at Customer's choice, subject to legal-retention obligations. Backup copies will be deleted in accordance with the regular backup-rotation schedule, in no case more than 90 days after termination.
14. Liability
The liability of each party under this DPA is subject to the limitations of liability set out in the main agreement (see Terms of Service §9), except where prohibited by mandatory law.
15. General
In the event of a conflict between this DPA and the main agreement, this DPA controls with respect to processing of Personal Data. All other provisions of the main agreement remain in effect.
Requests, notifications, or objections under this DPA should be sent to [email protected].