Signalment · legal

Signalment data processing addendum

How personal information in a workspace is processed on your behalf.

Updated September 29, 2026. This data processing addendum (“DPA”) is part of the Signalment service terms and applies whenever personal information is processed in a workspace. It is written to meet the contract requirements for a service provider under the California Consumer Privacy Act (Cal. Code Regs. tit. 11, § 7051), the other US state privacy laws that use the same processor model, and Article 28 of the EU and UK GDPR where those apply.

1. Roles and scope

The Customer is the business or controller. Signalment is the service provider or processor, acting only on the Customer’s documented instructions, which are these terms, the workspace’s settings and the actions taken in it by its members. Personal information processed in the Service includes: workspace members’ names, email addresses, roles, titles and the hashed IP address and browser string recorded with each audited action; participating owners’ names, email addresses, phone numbers and consent signatures, held in the owner key of a subject; and billing contacts’ names and email addresses. Records about animals are not personal information, but the owner key links an animal to a person, which is why it is stored apart from study data and excluded from pseudonymous exports.

2. Signalment’s obligations as service provider or processor

3. Customer’s obligations

The Customer has the lawful basis, notices and consents needed to collect the personal information it enters or invites into the Service, gives owners the notices its law requires, and configures roles and settings appropriately. The Customer does not enter special-category data about people or human health information.

4. Security measures

5. Sub-processors

Signalment uses the following sub-processors, all in the United States unless noted: Cloudflare, Inc. (hosting, database, file storage, email routing; data stored in US data centers); Resend, Inc. (transactional email such as invitations, notices and alerts); Stripe, Inc. (billing; receives only billing contact and payment details); and Anthropic, PBC (the document reader: only when a user chooses to have an uploaded document read, that document is sent for processing under Anthropic’s commercial terms, which do not permit use of the content to train models). Signalment gives workspace owners at least 30 days’ notice by email before adding a sub-processor that will process personal information; a Customer who objects on reasonable data-protection grounds may end the Service and export its data under the terms. Signalment remains responsible for its sub-processors’ performance.

6. Security incidents

Signalment notifies the Customer without undue delay, and in any case within 72 hours of confirming a personal-information breach affecting the Customer’s workspace, with what is known about its nature, the categories and approximate number of individuals and records concerned, likely consequences, measures taken, and a contact. Signalment cooperates with the Customer’s own notification obligations, including the 30-day deadline that applies under California law.

7. Return and deletion

The Customer can export all workspace data at any time. Ninety days after a workspace is closed or the Service ends, Signalment deletes its data, including the audit trail, except for copies in routine backups (deleted within 35 days) and anything retained under a legal obligation. On request, Signalment confirms deletion in writing, and deletes a study’s owner keys separately from its pseudonymous data.

8. Audit

On request, Signalment provides documentation of its security measures and the results of relevant tests or assessments. Where that is not sufficient, the Customer or an independent auditor bound by confidentiality may audit Signalment’s compliance with this DPA once in any twelve months, on 30 days’ notice, during working hours, at the Customer’s cost, in a way that does not compromise other customers’ data.

9. International transfers

The Service is hosted in the United States. Where personal information subject to the EU or UK GDPR is processed, the parties incorporate the EU standard contractual clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum by reference, with the Customer as data exporter and Signalment as data importer, and Signalment signs them on request.

10. Term and liability

This DPA lasts as long as Signalment processes personal information for the Customer. Liability under it is subject to the limits in the service terms. Questions: hello@signalment.app.