Data Processing Addendum

Last updated: August 3, 2026

1. Introduction

This Data Processing Addendum (“DPA”) describes how SignalThread processes Personal Data for a business customer in connection with the Services. It applies whenever SignalThread processes Personal Data on the Customer's behalf.

This DPA forms part of the applicable SignalThread Terms of Service and should be read with the Privacy Policy. If those documents conflict with this DPA regarding the processing of Personal Data, this DPA controls.

2. Definitions

Customer
The business customer that uses the Services.
Customer Data
Data submitted to, collected through, or otherwise made available in the Services by or for Customer, including Personal Data.
Personal Data
Information relating to an identified or identifiable person, where protected by Applicable Privacy Laws.
Controller and Processor
Have the meanings given to them under Applicable Privacy Laws, including equivalent terms such as “business” and “service provider.”
Services
SignalThread's event-intelligence software, related support, and associated services provided to Customer.
Security Incident
A confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
Subprocessor
A third party engaged by SignalThread to process Customer Data in support of the Services.

3. Roles

Customer is the Controller of Customer Data, and SignalThread is the Processor. SignalThread will process Customer Data only as necessary to provide the Services, on Customer's documented instructions, or as required by applicable law. Where law requires processing, SignalThread will notify Customer before doing so unless the law prohibits notice.

4. Scope of Processing

SignalThread may process Customer Data to provide event management, lead retrieval, surveys, meeting scheduling, customer communications, AI-generated summaries, AI insights, analytics, voice recordings where enabled by Customer, customer support, platform administration, and security. SignalThread does not sell Customer Data or process Customer Data for unrelated advertising purposes.

5. Confidentiality

SignalThread limits access to Customer Data to personnel who need it to provide, support, secure, or administer the Services and who are subject to appropriate confidentiality obligations.

6. Security Measures

SignalThread maintains reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Services and the Customer Data processed. These measures are summarized in Appendix B and may be updated as the Services and risks evolve.

7. Subprocessors

SignalThread may use carefully selected Subprocessors to deliver the Services, such as infrastructure, communications, analytics, and support providers. Current Subprocessors are available upon request at support@signalthread.ai. SignalThread will impose written data-protection obligations on Subprocessors appropriate to their services and remains responsible for their processing as required by Applicable Privacy Laws.

8. Applicable Privacy Laws

The Services are designed to support Customers in meeting obligations under Applicable Privacy Laws, including, where applicable, the GDPR, UK GDPR, and the CCPA/CPRA. Customer remains responsible for determining which laws apply to its processing and for its own compliance obligations. Nothing in this DPA represents a certification or a guarantee of compliance.

9. Data Subject Rights

Taking account of the nature of processing and the information available, SignalThread will reasonably assist Customer with requests for access, correction, deletion, portability, or restriction of processing involving Customer Data. If SignalThread receives a request directly relating to Customer Data, it may refer the request to Customer unless otherwise required by law. Account holders may also use the Account Deletion page to request deletion of their SignalThread account and associated data.

10. Security Incidents

SignalThread will notify an affected Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Data. SignalThread will provide reasonable information available to assist Customer in meeting its applicable notification obligations.

11. Data Retention & Deletion

SignalThread retains Customer Data only as long as necessary to provide the Services, meet documented obligations, resolve disputes, or comply with law. Where supported by the Services, Customer may export available Customer Data. On termination or deletion, SignalThread will delete or anonymize Customer Data in accordance with its retention practices unless retention is legally required.

12. International Transfers

Where Customer Data is transferred internationally, SignalThread will use appropriate legal transfer mechanisms when required by Applicable Privacy Laws.

13. Customer Responsibilities

Customer is responsible for:

  • Providing appropriate notices and obtaining required consents.
  • Determining and documenting lawful bases for its processing.
  • Ensuring information submitted to the Services is accurate and lawful.
  • Configuring and using the Services appropriately for its needs and applicable laws.

14. Changes

SignalThread may update this DPA from time to time to reflect changes in the Services, law, or processing practices. SignalThread will update the Last Updated date when material changes are made.

15. Contact

Questions about this DPA may be sent to support@signalthread.ai.

Appendix A — Details of Processing

Subject Matter
Processing of Customer Data through SignalThread's event-intelligence platform.
Nature and Purpose of Processing
To provide, support, secure, and improve the Services for event planning, lead retrieval, surveys, scheduling, communications, analytics, and related workflows.
Duration of Processing
For the term of the Services and thereafter as described in this DPA and applicable retention practices.
Categories of Data Subjects
Customer employees, event organizers, event staff, attendees, exhibitors, sponsors, speakers, prospects, and other individuals whose information Customer submits to or collects through the Services.
Categories of Personal Data
Contact information, business information, event registrations, lead information, survey responses, meeting information, voice recordings where enabled, AI-generated outputs derived from Customer content, and technical information such as device, log, and usage data.
Special Categories of Data
SignalThread does not intentionally require or request Special Categories of Personal Data. Customer should not submit such data unless it has a lawful basis and the Services are appropriate for that use.
Processing Activities
Collection, storage, organization, retrieval, analysis, AI-assisted processing, transmission, export, deletion, and destruction of Customer Data as needed to provide the Services.
Back to top

Appendix B — Security Measures

SignalThread's current safeguards include:

  • Encryption in transit and encryption of sensitive data at rest where applicable.
  • Role-based access controls and authentication protections.
  • Logging and monitoring designed to support security operations and investigation.
  • Secure backup practices appropriate to the Services.
  • Security updates, vulnerability management, and reasonable review of identified risks.
  • Limited employee access to Customer Data based on job responsibilities.
  • Administrative policies and confidentiality obligations for personnel with access to Customer Data.
Back to top