Signal Sparrow

Legal

Data Processing Agreement

Last updated: 29 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Signal Sparrow LTD ("Signal Sparrow," "Processor," "we"), and the customer agreeing to those Terms ("Customer," "Controller," "you"), and governs our processing of personal data on your behalf. Where it conflicts with the Terms on data-protection matters, this DPA prevails.

1. Definitions

"Data Protection Law" means the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, and any other applicable privacy law. "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Sub-processor" have the meanings given in the GDPR. "Customer Personal Data" means personal data we process on your behalf under the Terms.

2. Roles of the parties

You are the Controller of Customer Personal Data (the data your website visitors / end-users generate, which you collect using the Service). We are the Processor, acting only on your instructions. You are responsible for the lawfulness of the data you collect, including having a valid legal basis and any required consent.

For your own account and billing data, we act as an independent Controller under our Privacy Policy; that processing is outside the scope of this DPA.

3. Scope and instructions (Art. 28(3)(a))

We process Customer Personal Data only on your documented instructions, including as set out in Annex 1, the Terms, and your configuration of the Service (such as consent mode and retention settings). We will not process Customer Personal Data for any other purpose. If we believe an instruction violates Data Protection Law, we will inform you. We will tell you if we are legally required to process data beyond your instructions, unless prohibited from doing so by law.

Your use of the Service, including configurations and settings selected within the Service, constitutes documented instructions for processing purposes.

4. Customer instructions and responsibility

You determine the purposes and means of processing Customer Personal Data and are responsible for ensuring that instructions provided to Signal Sparrow comply with applicable Data Protection Law. You are responsible for configuring the Service, including consent settings, tracking behavior, and integrations, appropriately for your legal obligations.

5. Processing by advertising platforms

Where you instruct Signal Sparrow to transmit conversion events or identifiers to third-party advertising or analytics platforms, those platforms may process such information under their own privacy policies and terms. You are responsible for ensuring that such transfers and uses are lawful. Those platforms generally act as independent controllers of the data they receive and are not Sub-processors under this DPA.

6. Confidentiality (Art. 28(3)(b))

We ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Service.

7. Security measures (Art. 28(3)(c) / Art. 32)

We implement appropriate technical and organizational measures to protect Customer Personal Data. A summary of measures is in Annex 2.

8. Sub-processors (Art. 28(3)(d) / Art. 28(2))

You provide general authorization for us to engage Sub-processors to provide the Service. Our current Sub-processors that process Customer Personal Data on our behalf are:

  • Hostinger — application and database hosting.
  • Postmark, Resend, Titan, or Amazon SES — transactional and account email delivery, depending on the active production configuration.

The current Sub-processor list is maintained on our Sub-processors page.

We require each Sub-processor to enter into written obligations that provide an appropriate level of data protection consistent with applicable Data Protection Law. We remain responsible for the performance of our Sub-processors to the extent required under applicable Data Protection Law.

We will give you at least 30 days' advance notice before adding or replacing a Sub-processor by updating the Sub-processors page and emailing the account owner. If you reasonably object on data-protection grounds, you must identify the specific Sub-processor and the reasonable data-protection grounds for the objection. The parties will work in good faith to resolve the objection. If no reasonable solution is available, either party may exercise applicable termination rights.

9. Data subject rights (Art. 28(3)(e))

Taking into account the nature of the processing, we will provide reasonable assistance to enable you to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection) within the timeframes required by applicable Data Protection Law. The Service provides functionality enabling you to export or delete the data of an individual. If a data subject contacts us directly regarding data we process on your behalf, we will refer them to you and not respond substantively except on your instruction.

10. Assistance with compliance (Art. 28(3)(f) / Arts. 32–36)

Taking into account the information available to us, we will assist you in ensuring compliance with your obligations regarding security (Art. 32), personal data breach notification (Arts. 33–34), data protection impact assessments (Art. 35), and prior consultation (Art. 36).

We will also reasonably cooperate with inquiries from supervisory authorities relating to our processing of Customer Personal Data.

11. Personal data breach (Art. 33)

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Such notification will include information reasonably available to us to assist you with your obligations under applicable Data Protection Law.

12. Deletion or return of data (Art. 28(3)(g))

On termination of the Service, or on your request, we will delete or return Customer Personal Data, at your choice, and delete existing copies unless law requires retention. Raw events and sessions are deleted per the retention window you configure (default 24 months). You may export Customer Personal Data within 30 days of termination before deletion.

Certain data may be retained where required by applicable law, security requirements, dispute resolution, or legitimate business recordkeeping obligations.

13. Audits and information (Art. 28(3)(h))

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable advance notice, generally at least 30 days, confidentiality, frequency limits (no more than once per 12 months absent a breach or regulator requirement), and not compromising other customers' data or our security. We may satisfy audit requests by providing relevant third-party certifications or reports where available.

14. International transfers

Customer Personal Data may be processed and stored in countries where Signal Sparrow or its Sub-processors operate infrastructure necessary to provide the Service. Where processing involves transfers of Customer Personal Data outside the European Economic Area (EEA) or the UK, such transfers are governed by appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference (Annex 3).

15. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where Data Protection Law does not permit such limitation. Nothing in this DPA limits either party's obligations under applicable Data Protection Law.

16. Term

This DPA takes effect when you accept the Terms and remains in force while we process Customer Personal Data on your behalf.

17. Contact

For questions about this DPA, contact [email protected].

Annex 1 — Details of processing

  • Subject matter: provision of conversion-tracking and revenue-attribution services.
  • Duration: the term of the Service plus the configured retention period.
  • Nature and purpose: capturing website events; resolving visitor identity; computing attribution; forwarding conversion events to advertising/analytics platforms on your instruction.
  • Categories of data subjects: your website visitors and end-users; individuals identified to the Service via your identity function.
  • Categories of personal data: pseudonymous visitor identifiers; advertising click identifiers (e.g. fbclid, gclid, ttclid, msclkid) and UTM parameters; landing page, referrer, device data; hashed IP addresses; email addresses or user IDs you pass (stored encrypted, matched by keyed hash).
  • Conversion and transaction data: revenue events, transaction amounts, currencies, timestamps, and related identifiers provided by you or your connected Stripe account.
  • Special category data: The Service is not designed or intended to process special category personal data. Customers must not configure the Service to collect or process such data unless legally permitted and supported by appropriate safeguards.

Annex 2 — Technical and organizational measures

  • Encryption of data in transit using TLS.
  • Encryption of data at rest for database storage and backups.
  • Hashing of personal identifiers, including email addresses, before forwarding to advertising platforms.
  • No storage of raw IP addresses; IP addresses are processed transiently and stored only as one-way hashes.
  • Multi-tenant isolation so one customer's data is not accessible to another.
  • Role-based access controls and least-privilege administrative access.
  • Two-factor authentication for administrative access.
  • Audit logging of access and changes to production systems.
  • Regular backups and documented incident-response procedures.
  • Vulnerability management and periodic review of security measures.

Annex 3 — Standard Contractual Clauses / UK Addendum

Where required for lawful international transfers, the European Commission Standard Contractual Clauses (Module Two: Controller to Processor), adopted on 4 June 2021, together with the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference. If you require an executed or completed copy of the SCCs and/or UK IDTA for your records, please contact us at [email protected].