Signalment · legal
Signalment data processing addendum
How personal information in a workspace is processed on your behalf.
Updated September 29, 2026. This data processing addendum (“DPA”) is part of the Signalment service terms and applies whenever personal information is processed in a workspace. It is written to meet the contract requirements for a service provider under the California Consumer Privacy Act (Cal. Code Regs. tit. 11, § 7051), the other US state privacy laws that use the same processor model, and Article 28 of the EU and UK GDPR where those apply.
1. Roles and scope
The Customer is the business or controller. Signalment is the service provider or processor, acting only on the Customer’s documented instructions, which are these terms, the workspace’s settings and the actions taken in it by its members. Personal information processed in the Service includes: workspace members’ names, email addresses, roles, titles and the hashed IP address and browser string recorded with each audited action; participating owners’ names, email addresses, phone numbers and consent signatures, held in the owner key of a subject; and billing contacts’ names and email addresses. Records about animals are not personal information, but the owner key links an animal to a person, which is why it is stored apart from study data and excluded from pseudonymous exports.
2. Signalment’s obligations as service provider or processor
- Process personal information only for the business purpose of providing, securing and supporting the Service, and never for any other commercial purpose.
- Not sell or share personal information, and not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than the business purposes in this DPA.
- Not combine personal information received from the Customer with personal information from other sources, except as permitted by law for the business purpose.
- Comply with the CCPA and the other applicable privacy laws, and provide the same level of privacy protection they require of the Customer.
- Notify the Customer without undue delay if Signalment determines it can no longer meet its obligations under those laws.
- Allow the Customer to take reasonable and appropriate steps to ensure that Signalment uses personal information consistently with the Customer’s obligations, and to stop and remediate unauthorized use.
- Ensure that people authorized to process personal information are bound by confidentiality.
- Take the security measures in section 4.
- Engage sub-processors only under section 5.
- Assist the Customer, taking into account the nature of the processing, in responding to requests from individuals to exercise their rights, and in security, data protection impact assessments and consultations with supervisory authorities.
- Delete or return personal information at the end of the Service under section 7.
- Make available the information needed to demonstrate compliance and allow audits under section 8.
- Inform the Customer if, in Signalment’s opinion, an instruction infringes applicable data protection law.
3. Customer’s obligations
The Customer has the lawful basis, notices and consents needed to collect the personal information it enters or invites into the Service, gives owners the notices its law requires, and configures roles and settings appropriately. The Customer does not enter special-category data about people or human health information.
4. Security measures
- Encryption in transit (TLS) and at rest for the database and file storage.
- Accounts with salted, peppered password hashing; optional sign-in with Google or Apple; sessions bound to a secure cookie; a workspace-configurable idle sign-out and password-age policy; re-authentication at every electronic signature.
- Role-based access to each workspace and study; monitors and viewers never see owner identities; participating owners see only their own animal.
- An append-only, hash-chained audit trail per workspace recording who did what, when and why, with a hashed IP address and browser string; hash-chained records with full change history.
- Rate limiting, same-origin checks on writes and a content security policy for the application.
- Automated backups of the database; point-in-time recovery for up to 35 days.
- Secrets held in the hosting platform’s encrypted secret store; access to production limited to named administrators.
- Automated tests of the access model and audit trail run before each deployment.
5. Sub-processors
Signalment uses the following sub-processors, all in the United States unless noted: Cloudflare, Inc. (hosting, database, file storage, email routing; data stored in US data centers); Resend, Inc. (transactional email such as invitations, notices and alerts); Stripe, Inc. (billing; receives only billing contact and payment details); and Anthropic, PBC (the document reader: only when a user chooses to have an uploaded document read, that document is sent for processing under Anthropic’s commercial terms, which do not permit use of the content to train models). Signalment gives workspace owners at least 30 days’ notice by email before adding a sub-processor that will process personal information; a Customer who objects on reasonable data-protection grounds may end the Service and export its data under the terms. Signalment remains responsible for its sub-processors’ performance.
6. Security incidents
Signalment notifies the Customer without undue delay, and in any case within 72 hours of confirming a personal-information breach affecting the Customer’s workspace, with what is known about its nature, the categories and approximate number of individuals and records concerned, likely consequences, measures taken, and a contact. Signalment cooperates with the Customer’s own notification obligations, including the 30-day deadline that applies under California law.
7. Return and deletion
The Customer can export all workspace data at any time. Ninety days after a workspace is closed or the Service ends, Signalment deletes its data, including the audit trail, except for copies in routine backups (deleted within 35 days) and anything retained under a legal obligation. On request, Signalment confirms deletion in writing, and deletes a study’s owner keys separately from its pseudonymous data.
8. Audit
On request, Signalment provides documentation of its security measures and the results of relevant tests or assessments. Where that is not sufficient, the Customer or an independent auditor bound by confidentiality may audit Signalment’s compliance with this DPA once in any twelve months, on 30 days’ notice, during working hours, at the Customer’s cost, in a way that does not compromise other customers’ data.
9. International transfers
The Service is hosted in the United States. Where personal information subject to the EU or UK GDPR is processed, the parties incorporate the EU standard contractual clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum by reference, with the Customer as data exporter and Signalment as data importer, and Signalment signs them on request.
10. Term and liability
This DPA lasts as long as Signalment processes personal information for the Customer. Liability under it is subject to the limits in the service terms. Questions: hello@signalment.app.