1. Definitions
This DPA is intended to address Sigbot's processing of personal data of individuals connected to the United Kingdom, European Economic Area, Canada, and United States. Region-specific terms are set out in the Annexes below.
- "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing under this DPA, including the UK GDPR and Data Protection Act 2018; the EU GDPR; Canada's PIPEDA and applicable provincial legislation; and applicable US state privacy laws including the CCPA/CPRA.
- "Controller" (= "Business" under the CCPA, "Organization" under PIPEDA) determines the purposes and means of processing. "Processor" (= "Service Provider" under the CCPA) processes on the Controller's behalf.
- "Customer Data" means the personal data Sigbot processes on Customer's behalf, principally contact and signature information extracted from Customer's connected email accounts.
- "Standard Contractual Clauses" / "SCCs" means the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914); "UK Addendum" means the ICO's International Data Transfer Addendum to the SCCs.
- "Subprocessor" means any third party engaged by Sigbot to process Customer Data.
2. Roles of the Parties
Customer is the Controller of Customer Data; Sigbot is the Processor acting on Customer's documented instructions, as set out in the Terms of Service, this DPA, and Customer's ordinary configuration of the Services. If Sigbot believes an instruction infringes Applicable Data Protection Law, it will inform Customer and may suspend that instruction pending clarification.
3. Subject Matter and Details of Processing
4. Sigbot's Obligations
- Process Customer Data only on documented instructions, including regarding international transfers;
- Ensure personnel are bound by confidentiality obligations;
- Implement the security measures described in Section 8;
- Assist Customer in responding to data subject rights requests (Section 7);
- Assist Customer with its own obligations around security, breach notification, and impact assessments;
- Delete or return Customer Data at the end of the relationship (Section 10); and
- Make information available to demonstrate compliance and support audits (Section 9).
5. Subprocessing
Customer provides a general authorisation for Sigbot to engage the Subprocessors below. Sigbot will give at least 14 days' notice before adding or replacing a Subprocessor, during which Customer may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Location / Transfer Mechanism |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting & infrastructure | US-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data |
| Firebase (Google LLC) | Application backend, auth, data storage | US-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data |
| Google Cloud Vision (Google LLC) | Optical character recognition for business-card scanning | US-based, global infrastructure — SCCs & UK IDTA addendum for UK/EEA-originating data |
| Anthropic PBC | AI-assisted parsing of email signature blocks into structured contact fields | US — SCCs & UK Addendum for UK/EEA-originating data |
| Vercel Inc. | Web application hosting & content delivery (processes request metadata such as IP addresses and logs) | US-based, global edge network — SCCs & UK IDTA addendum for UK/EEA-originating data |
| Paddle.com Market Ltd | Payment processing & billing (merchant of record) | UK/EU/US — Paddle's SCCs for UK/EEA-originating data |
6. International Data Transfers
Customer Data may be processed in the UK, EEA, Canada, and United States, reflecting Sigbot's operations and its Subprocessors. Transfers out of the UK/EEA rely on: an adequacy decision (Canada's federal regime under PIPEDA currently benefits from UK/EU adequacy findings for PIPEDA-covered organisations); the SCCs and UK Addendum for transfers to the United States or other non-adequate jurisdictions; or another valid transfer mechanism. For data collected in Canada, Sigbot ensures Subprocessors outside Canada provide comparable protection as required under PIPEDA.
7. Data Subject Rights
Sigbot will assist Customer, insofar as reasonably possible, in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If Sigbot receives a request directly from a data subject, it will not respond substantively without Customer's authorisation and will promptly forward the request to Customer.
8. Security Measures
Sigbot implements technical and organisational measures appropriate to the risk, described in full on our Security Overview page, including encryption in transit and at rest, role-based access controls, OAuth-based authentication where supported, logging and monitoring, and a defined incident response process. Sigbot will notify Customer without undue delay, and in any event within 72 hours of confirming a personal data breach affecting Customer Data.
9. Audit Rights
Sigbot will make information available to demonstrate compliance and allow audits by Customer or its mandated auditor, no more than once per year absent a regulatory requirement or breach, on 30 days' notice, during business hours, with Customer bearing its own audit costs.
10. Deletion and Return of Data
On termination or Customer's written request, Sigbot will delete or return all Customer Data within 30 days, except where retention is required by law, in which case that data is isolated and protected from further processing.
United Kingdom / European Economic Area
Applies where Customer Data is subject to the UK GDPR, UK Data Protection Act 2018, and/or EU GDPR.
- Sigbot processes Customer Data as a Processor under Article 28 UK/EU GDPR, per Sections 1–10 above.
- Transfers to non-adequate jurisdictions (including the United States) rely on the SCCs and, where applicable, the UK Addendum.
- Customer may request a standalone SCCs/UK Addendum document by contacting legal@sigbot.co.
- Breach-notification obligations to the ICO / relevant EU supervisory authority remain with Customer as Controller; Sigbot provides the assistance described in Section 8.
Canada
Applies where Customer Data is subject to PIPEDA or substantially similar provincial law (e.g. Quebec's Law 25, BC's PIPA, Alberta's PIPA).
- Sigbot acts as a service provider processing Personal Information on behalf of Customer (the accountable organization under PIPEDA).
- Security safeguards appropriate to the sensitivity of the Personal Information are maintained, per Section 8.
- In the event of a breach of security safeguards creating a real risk of significant harm, Sigbot will notify Customer without unreasonable delay, with sufficient information for Customer to meet its own notification obligations to the Privacy Commissioner of Canada and affected individuals.
- Sigbot assists with access and correction requests, and — for Customers subject to Quebec's Law 25 — with information needed for a privacy impact assessment before any disclosure outside Quebec.
United States
Applies where Customer Data is "Personal Information" of a "Consumer" under the CCPA, or subject to a comparable state law (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and similar).
- Sigbot is a "Service Provider" (not a "Third Party") receiving Personal Information from Customer, a "Business," for the business purpose of providing the Services.
- Sigbot will not sell or share Customer Data; will not retain, use, or disclose it outside the business purpose of performing the Services or the direct business relationship; and will not combine it with data from other sources except as permitted under the CCPA.
- Sigbot certifies it understands and will comply with these restrictions.
- Sigbot provides reasonable cooperation for verifiable consumer requests to know, delete, correct, or opt out.