GDPR Privacy Notice (EU / EEA / UK appendix)

Effective date: April 20, 2026

Plain English, first

This page is an appendix to the Privacy Policy for people in the European Economic Area, the United Kingdom, or Switzerland. The main Privacy Policy still applies to you; this page adds the details your local law requires, written in plain language.


1. Scope

This notice applies if you are a resident of the European Economic Area, the United Kingdom, or Switzerland ("EEA/UK user") using Signroad. It supplements the main Privacy Policy; to the extent of a conflict, the notice that gives you more protection applies.

2. Controller and DPO

3. Legal bases (recap)

Purpose Legal basis
Create and authenticate your account Contract (Art. 6(1)(b))
Run core features (sign assignment, goals, boards, letters) Contract
Generate personalized Whispers from your in-app content Contract
Send operational email (receipts, security alerts) Contract
Send product-update email Consent (Art. 6(1)(a))
Analytics cookies Consent
Detect and prevent abuse, fraud, automated attacks Legitimate interests (Art. 6(1)(f))
Maintain backups and short-lived logs Legitimate interests
Comply with legal obligations (tax, subpoena, regulator request) Legal obligation (Art. 6(1)(c))

4. Your rights

As an EEA/UK user, you have the rights listed below. You can exercise all of them at privacy@signroad.com, or through the self-serve tools in Profile → Privacy.

We do not retaliate for exercising any of these rights.

5. How to make a request

6. International transfers

Where we transfer your personal data outside the EEA/UK, we rely on:

You can request a copy of the transfer safeguards used for a specific provider by emailing privacy@signroad.com.

7. Children in the EEA/UK

Signroad is not directed at children under 16. In jurisdictions that set a higher digital-consent age under GDPR Article 8 (e.g., 13, 14, or 15 in some Member States), the minimum use age matches that local threshold without parental consent, and is 16 by default where the threshold is not lower.

8. Retention (EEA/UK detail)

Data Retention period
Account and in-app content while active While your account is active
Deleted account 30-day soft-delete window, then permanent deletion
Backups Roll off within 35 days of deletion
Operational logs 30 days; truncated/hashed IPs in longer aggregates
Audit log (security events) 12 months, then aggregate-only
Financial records As required by applicable tax and accounting law
DMCA and legal hold records Duration of the matter and applicable statute of limitations

9. Automated decision-making

We do not use automated decision-making that has legal or similarly significant effects on you. Personalized Whispers and sign assignment are content features, not decisions about access, pricing, or rights.

10. Contact and complaints


Attribution

Adapted from Automattic's Legalmattic template and extended to cover GDPR/UK GDPR specifics common in privacy notices. Original and this adaptation are both licensed under CC-BY-SA 4.0.