Data Processing Addendum (DPA)
Effective date: April 20, 2026
Plain English, first
This document is for B2B customers — businesses that put Signroad in front of their employees or members (for example, a wellness benefit for a company's team). If you are a regular individual user, you do not need to sign this; the main Terms of Service and Privacy Policy cover you.
A DPA spells out what each side is responsible for when a business (the "Controller") hires Signroad (the "Processor") to handle its employees' or members' personal data. GDPR Article 28 requires it. This DPA:
- names what data is processed and why;
- lists our sub-processors;
- describes our security measures;
- gives you, the customer, the right to audit us on reasonable notice; and
- sets the terms for international transfers.
If you are reviewing this before signing a Signroad Business contract, and something looks wrong for your organization, email privacy@signroad.com and we can usually adjust.
1. Parties and structure
This Data Processing Addendum ("DPA") forms part of the Signroad Business Agreement between SignRoad ("Signroad") and the Customer identified in the Business Agreement ("Customer"). The Customer is the Controller, and Signroad is the Processor, of Customer Personal Data.
If there is a conflict between the Business Agreement and this DPA, this DPA controls for matters of data protection.
2. Definitions
Terms like "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.
"Customer Personal Data" means Personal Data that Customer submits to Signroad, or that Signroad collects on Customer's behalf, as part of providing the service — for example, Customer's employees' or members' email addresses and the content they put into Signroad.
3. Subject matter, duration, nature, and purpose
- Subject matter: processing of Customer Personal Data by Signroad to provide the Signroad service described in the Business Agreement.
- Duration: for as long as the Business Agreement is in force, plus the retention periods in this DPA and the Privacy Policy.
- Nature: storage, retrieval, display, backup, personalization, delivery of messages at scheduled times, and other operations needed to run the service.
- Purpose: providing Customer with the Signroad service; not for any other purpose.
4. Categories of data and data subjects
- Data subjects: Customer's employees, members, or end users who have a Signroad account under Customer's tenant.
- Categories of personal data:
- Account data (email, name, authentication secrets);
- Profile data (optional bio, location, avatar);
- Content (signs, goals, reflections, letters to future self, whispers);
- Usage data (app events, timestamps);
- Support correspondence;
- Payment data at the tenant level (not per data subject).
- Special categories: Signroad does not intentionally collect special-category personal data under GDPR Article 9 (health, religion, etc.). Users may voluntarily include such information in their content; if Customer instructs us to limit collection further, we will implement reasonable technical measures.
5. Documented instructions
Signroad processes Customer Personal Data only on Customer's documented instructions, which are:
- the Business Agreement, Order Form, and this DPA;
- actions Customer takes through the admin console of the service;
- written instructions to privacy@signroad.com.
If Signroad believes an instruction violates applicable data protection law, Signroad will tell Customer promptly.
6. Confidentiality
Personnel authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations.
7. Security
Signroad implements appropriate technical and organizational measures to protect Customer Personal Data. These are detailed in the Signroad security architecture document and include, at a minimum:
- TLS for data in transit;
- encryption at rest via the hosting provider;
- password hashing with bcrypt;
- two-factor authentication available to all accounts;
- row-level security on every user-facing database table;
- restricted production access limited to a small, audited set of personnel;
- logging of administrative actions to an append-only audit table;
- vulnerability monitoring and a responsible-disclosure program;
- background-checked personnel handling Customer data on request.
Security measures evolve; Signroad may update them as long as the level of protection does not materially decrease.
8. Sub-processors
Customer authorizes Signroad to engage sub-processors to provide the service. The current sub-processor list is in the Privacy Policy and maintained at the same effective date as this DPA.
- Signroad gives at least 30 days' notice before adding or replacing a sub-processor that processes Customer Personal Data.
- Customer may object on reasonable data-protection grounds within 14 days of notice. If we cannot resolve the objection, Customer may terminate the affected service without penalty for the remaining paid term.
- Signroad remains liable to Customer for acts and omissions of its sub-processors to the same extent Signroad would be liable itself.
9. International transfers
Where Customer Personal Data is transferred from the EU/EEA, UK, or Switzerland to a country that does not have an adequacy decision, the parties rely on:
- the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with Modules 2 (Controller-to-Processor) or 3 (Processor-to-Processor) as appropriate;
- the UK International Data Transfer Addendum for transfers out of the UK; and
- the Swiss amendments where transfers involve Swiss data.
The SCCs are deemed incorporated into this DPA and are signed by the parties' execution of the Business Agreement.
10. Data subject requests
If a data subject contacts Signroad directly with a rights request (access, deletion, correction, portability, objection), Signroad forwards it to Customer and does not respond substantively unless Customer instructs it to.
Signroad provides tooling — the in-app export and delete flows, plus admin tools for the tenant — that helps Customer fulfill data-subject requests without additional integration work.
11. Personal data breach notification
If Signroad becomes aware of a Personal Data Breach affecting Customer Personal Data, Signroad notifies Customer without undue delay, and in any event within 72 hours of awareness. The notification includes, to the extent known:
- nature of the breach;
- categories and approximate number of data subjects and records affected;
- likely consequences;
- measures taken or proposed to address the breach and mitigate effects.
Signroad cooperates with Customer on further investigation and reporting to supervisory authorities or data subjects, where Customer is the one legally required to do so.
12. Audit rights
- Signroad makes available to Customer the documentation reasonably necessary to demonstrate compliance with this DPA (architecture docs, security overview, sub-processor list, completed security questionnaires, available third-party attestations).
- Once per year, or more often in case of a Personal Data Breach that affected Customer, Customer may audit Signroad's processing of Customer Personal Data. Audits are conducted on 30 days' written notice, during business hours, in a manner that does not interfere with Signroad's operations, under confidentiality, and at Customer's expense unless the audit reveals material non-compliance.
13. Return and deletion
On termination of the Business Agreement, Customer may export Customer Personal Data using the admin tools of the service for up to 30 days after termination. After 30 days, Signroad deletes Customer Personal Data, except where retention is required by law, in which case the data is kept only as long as legally required and remains protected under this DPA.
14. Liability
Liability under this DPA is subject to the limits set in the Business Agreement. Where law does not permit limiting liability for a given claim (for example, claims under GDPR Article 82), that limitation does not apply to the extent law forbids it.
15. Changes
Signroad may update this DPA by giving Customer at least 30 days' notice when the changes are required by a change in law, a sub-processor, or to maintain the security posture. Customer may terminate the affected service on the same 30 days' notice if the change materially reduces the protection of Customer Personal Data and the parties cannot agree on a remedy.
16. Governing law, jurisdiction
This DPA is governed by the law of the State of Wyoming, United States, without prejudice to any data protection law that applies to the Customer or data subject and that cannot be overridden by contract.
17. Contact
- Privacy: privacy@signroad.com
- Data Protection Officer (EU): privacy@signroad.com
- Postal: SignRoad, Privacy Team, 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, USA
Attribution
Adapted from patterns in Automattic's Legalmattic templates, extended with GDPR Article 28 structure common in Processor DPAs. Original and this adaptation are both licensed under CC-BY-SA 4.0. This document is a template, not a negotiated contract; consult an attorney before relying on it for a specific customer.