SignalDart logoSignalDart
Legal

Data Processing Agreement

Article 28 terms for customers who need a DPA in place before using SignalDart.

Last updated: August 3, 2026

This DPA forms part of the Terms of Service between SignalDart, operated from Maharashtra, India (“Processor”), and the customer (“Controller”), and applies where SignalDart processes personal data on the Controller’s behalf under the UK GDPR / EU GDPR.

1. Roles

The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller’s documented instructions, which the Terms and this DPA constitute.

2. Subject matter and duration

  • Subject matter: providing the SignalDart market-intelligence platform.
  • Duration: for as long as the Controller has an active account, plus the retention window in section 8.
  • Nature and purpose: hosting, storage, AI-assisted analysis, report generation and monitoring.

3. Categories of data and data subjects

  • Data subjects: the Controller’s users, team members, and any individuals named in content the Controller submits.
  • Personal data: names, email addresses, account identifiers, IP addresses, usage data, and any personal data contained in submitted research inputs.
  • Special category data: not required, and the Controller must not submit it.

4. Processor obligations

  • Process only on documented instructions, including for international transfers.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Controller with data-subject requests, DPIAs and regulator consultations.
  • Notify the Controller without undue delay, and at the latest within 72 hours, of becoming aware of a personal data breach.
  • Delete or return personal data at the end of the engagement (section 8).
  • Make available the information needed to demonstrate compliance and allow audits (section 9).

5. Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors, each bound by terms no less protective than this DPA. Current sub-processors:

  • Cloud hosting and managed database
  • Authentication: Clerk
  • AI model providers: Anthropic, OpenAI, Google
  • Search and web-data providers: Serper, Firecrawl, DataForSEO
  • Payment processing: Stripe, Razorpay
  • Transactional email delivery

A current, named list with regions is available on request from support@signaldart.com. We will give 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service.

6. Security measures

Encryption in transit and at rest, role-based access control, tenant isolation, signed webhooks, SSRF protection, rate limiting, audit logging, least-privilege internal access, encrypted backups with tested restores, and monitoring with alerting. Full detail on the Security page.

7. International transfers

The Processor is established in India, which is not covered by a UK or EU adequacy decision. Transfers of personal data outside the UK/EEA therefore rely on the Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference. Enterprise customers may select a data-residency region.

8. Deletion and return

On termination, the Controller may export its data via the product. The Processor will delete or anonymise personal data within 30 days, except where retention is required by law. Backups age out on the standard backup cycle.

9. Audit

The Processor will respond to reasonable written security questionnaires no more than once per year, and will share any third-party audit reports once available. On-site audits may be requested with 30 days’ notice, subject to confidentiality and reasonable cost recovery.

10. Liability

Liability under this DPA is subject to the limitations in the Terms of Service.

11. Requesting a signed copy

Email support@signaldart.com with the subject “DPA request” and your legal entity name and address. We will return a countersigned copy.