SIGBOT
Legal

Privacy Policy

Last updated: 19 July 2026

1. Regulatory Compliance

Sigbot complies with applicable privacy laws, including: UK GDPR & Data Protection Act 2018, EU GDPR, and Canada PIPEDA.

2. Data Protection Roles

Where Sigbot processes personal data as a Processor, the terms of our Data Processing Addendum apply.

3. Personal Data We Process

Account Data: Name, email address, login credentials, subscription status.

Contact Data (Customer-provided): Names, email addresses, phone numbers, job titles, company names, and other details extracted from email signature blocks in connected inboxes.

Sigbot does not read, store, or index the substantive body content of emails — only signature-block information is extracted.

How extraction works

Signature-block text is processed using third-party artificial-intelligence models to identify and structure contact details. Specifically, signature-block text is sent server-side to Anthropic PBC's Claude API for parsing, and images captured with the business-card scanner are sent to Google Cloud Vision for optical character recognition. These providers process the data solely to provide the extraction service to us, under data protection agreements, and are listed as subprocessors in our Data Processing Addendum. Sigbot's agreements with these providers do not permit them to use your data to train their models.

4. Cloud Storage & Sync

Sigbot uses secure cloud infrastructure (including Google Cloud Platform and Firebase) to provide device synchronisation, backups, team collaboration, and real-time database features. Data may be cached locally and stored in the cloud.

5. Cookies & Local Storage

Sigbot uses only strictly necessary cookies and browser storage — we do not use advertising or cross-site tracking cookies.

Because these are strictly necessary for the Services to function, they cannot be disabled while using Sigbot. You can clear them at any time through your browser settings, which will sign you out.

6. Lawful Basis for Processing

We rely on contractual necessity (to provide the Services), legitimate interests (security and service improvement), legal obligations, and consent where required by law.

7. Data Sharing

We do not sell personal data. We may share data with subprocessors providing cloud hosting, authentication, and payment processing. All processors operate under data protection agreements. A current list of subprocessors is set out in our Data Processing Addendum.

8. International Transfers

Data may be transferred outside the UK/EU/Canada. We rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions, as detailed in our Data Processing Addendum.

9. Security Measures

We implement encryption in transit (TLS), encryption at rest, access controls, OAuth-based authentication where supported, and monitoring systems. Full details are available on our Security Overview page.

10. Data Retention

11. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. To exercise these rights, contact legal@sigbot.co.

12. Children's Data

Sigbot is not intended for individuals under 18. We do not knowingly collect personal data from children.

13. Complaints

You may lodge a complaint with a supervisory authority: UK ICO, an EU Data Protection Authority, or the Office of the Privacy Commissioner of Canada, depending on your location.

14. Policy Updates

We may update this Privacy Policy periodically. We will post the updated version with a new "Last updated" date and provide notice of material changes.

15. Contact

Privacy questions: legal@sigbot.co. General enquiries: support@sigbot.co.