SIGBOT
Legal

Data Processing Addendum

Last updated: 19 July 2026  ·  Covers the UK/EEA, Canada, and United States

This DPA forms part of, and is incorporated by reference into, Sigbot's Terms of Service. It takes effect automatically when you create an account and agree to the Terms of Service. It sets out how Sigbot processes personal data on behalf of customers as a data processor / service provider.

1. Definitions

This DPA is intended to address Sigbot's processing of personal data of individuals connected to the United Kingdom, European Economic Area, Canada, and United States. Region-specific terms are set out in the Annexes below.

  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing under this DPA, including the UK GDPR and Data Protection Act 2018; the EU GDPR; Canada's PIPEDA and applicable provincial legislation; and applicable US state privacy laws including the CCPA/CPRA.
  • "Controller" (= "Business" under the CCPA, "Organization" under PIPEDA) determines the purposes and means of processing. "Processor" (= "Service Provider" under the CCPA) processes on the Controller's behalf.
  • "Customer Data" means the personal data Sigbot processes on Customer's behalf, principally contact and signature information extracted from Customer's connected email accounts.
  • "Standard Contractual Clauses" / "SCCs" means the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914); "UK Addendum" means the ICO's International Data Transfer Addendum to the SCCs.
  • "Subprocessor" means any third party engaged by Sigbot to process Customer Data.

2. Roles of the Parties

Customer is the Controller of Customer Data; Sigbot is the Processor acting on Customer's documented instructions, as set out in the Terms of Service, this DPA, and Customer's ordinary configuration of the Services. If Sigbot believes an instruction infringes Applicable Data Protection Law, it will inform Customer and may suspend that instruction pending clarification.

3. Subject Matter and Details of Processing

Subject matter
Provision of the Services — automated extraction of contact details from email signatures into a searchable database.
Duration
For the term of the Terms of Service, plus any post-termination retention period described in Section 10.
Nature & purpose
Automated parsing of email signature blocks — including AI-assisted extraction using third-party large language models — to identify, extract, structure, and store contact information for Customer's business use.
Data subjects
Individuals whose contact details appear in signature blocks processed through Customer's connected inboxes — typically employees, clients, and suppliers.
Data categories
Name, job title, company, email, phone, business address, and any other details voluntarily included in a signature block. No special category data is intentionally processed.

4. Sigbot's Obligations

  • Process Customer Data only on documented instructions, including regarding international transfers;
  • Ensure personnel are bound by confidentiality obligations;
  • Implement the security measures described in Section 8;
  • Assist Customer in responding to data subject rights requests (Section 7);
  • Assist Customer with its own obligations around security, breach notification, and impact assessments;
  • Delete or return Customer Data at the end of the relationship (Section 10); and
  • Make information available to demonstrate compliance and support audits (Section 9).

5. Subprocessing

Customer provides a general authorisation for Sigbot to engage the Subprocessors below. Sigbot will give at least 14 days' notice before adding or replacing a Subprocessor, during which Customer may object on reasonable data-protection grounds.

SubprocessorPurposeLocation / Transfer Mechanism
Google Cloud Platform (Google LLC)Cloud hosting & infrastructureUS-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data
Firebase (Google LLC)Application backend, auth, data storageUS-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data
Google Cloud Vision (Google LLC)Optical character recognition for business-card scanningUS-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data
Anthropic PBCAI-assisted parsing of email signature blocks into structured contact fieldsUS — SCCs & UK Addendum for UK/EEA-originating data
Vercel Inc.Web application hosting & content delivery (processes request metadata such as IP addresses and logs)US-based, global edge network — SCCs & UK IDTA addendum for UK/EEA-originating data
Paddle.com Market LtdPayment processing & billing (merchant of record)UK/EU/US — Paddle's SCCs for UK/EEA-originating data

6. International Data Transfers

Customer Data may be processed in the UK, EEA, Canada, and United States, reflecting Sigbot's operations and its Subprocessors. Transfers out of the UK/EEA rely on: an adequacy decision (Canada's federal regime under PIPEDA currently benefits from UK/EU adequacy findings for PIPEDA-covered organisations); the SCCs and UK Addendum for transfers to the United States or other non-adequate jurisdictions; or another valid transfer mechanism. For data collected in Canada, Sigbot ensures Subprocessors outside Canada provide comparable protection as required under PIPEDA.

7. Data Subject Rights

Sigbot will assist Customer, insofar as reasonably possible, in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If Sigbot receives a request directly from a data subject, it will not respond substantively without Customer's authorisation and will promptly forward the request to Customer.

8. Security Measures

Sigbot implements technical and organisational measures appropriate to the risk, described in full on our Security Overview page, including encryption in transit and at rest, role-based access controls, OAuth-based authentication where supported, logging and monitoring, and a defined incident response process. Sigbot will notify Customer without undue delay, and in any event within 72 hours of confirming a personal data breach affecting Customer Data.

9. Audit Rights

Sigbot will make information available to demonstrate compliance and allow audits by Customer or its mandated auditor, no more than once per year absent a regulatory requirement or breach, on 30 days' notice, during business hours, with Customer bearing its own audit costs.

10. Deletion and Return of Data

On termination or Customer's written request, Sigbot will delete or return all Customer Data within 30 days, except where retention is required by law, in which case that data is isolated and protected from further processing.


Annex A

United Kingdom / European Economic Area

Applies where Customer Data is subject to the UK GDPR, UK Data Protection Act 2018, and/or EU GDPR.

  • Sigbot processes Customer Data as a Processor under Article 28 UK/EU GDPR, per Sections 1–10 above.
  • Transfers to non-adequate jurisdictions (including the United States) rely on the SCCs and, where applicable, the UK Addendum.
  • Customer may request a standalone SCCs/UK Addendum document by contacting legal@sigbot.co.
  • Breach-notification obligations to the ICO / relevant EU supervisory authority remain with Customer as Controller; Sigbot provides the assistance described in Section 8.
Annex B

Canada

Applies where Customer Data is subject to PIPEDA or substantially similar provincial law (e.g. Quebec's Law 25, BC's PIPA, Alberta's PIPA).

  • Sigbot acts as a service provider processing Personal Information on behalf of Customer (the accountable organization under PIPEDA).
  • Security safeguards appropriate to the sensitivity of the Personal Information are maintained, per Section 8.
  • In the event of a breach of security safeguards creating a real risk of significant harm, Sigbot will notify Customer without unreasonable delay, with sufficient information for Customer to meet its own notification obligations to the Privacy Commissioner of Canada and affected individuals.
  • Sigbot assists with access and correction requests, and — for Customers subject to Quebec's Law 25 — with information needed for a privacy impact assessment before any disclosure outside Quebec.
Annex C

United States

Applies where Customer Data is "Personal Information" of a "Consumer" under the CCPA, or subject to a comparable state law (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and similar).

  • Sigbot is a "Service Provider" (not a "Third Party") receiving Personal Information from Customer, a "Business," for the business purpose of providing the Services.
  • Sigbot will not sell or share Customer Data; will not retain, use, or disclose it outside the business purpose of performing the Services or the direct business relationship; and will not combine it with data from other sources except as permitted under the CCPA.
  • Sigbot certifies it understands and will comply with these restrictions.
  • Sigbot provides reasonable cooperation for verifiable consumer requests to know, delete, correct, or opt out.