Last updated · June 28, 2026

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Axiom Tech Lab(“Signum”, “Processor”) and the Signum customer (“Customer”, “Controller”) named in the relevant Signum subscription or order form. It governs Signum’s processing of Personal Data on Customer’s behalf in connection with Customer’s use of the Signum platform.

Where Customer is subject to the GDPR, the UK GDPR, the Indian DPDP Act 2023, or the California Consumer Privacy Act (CCPA/CPRA), this DPA reflects the corresponding processor / data-fiduciary / service-provider obligations. Where Customer is not subject to those laws, this DPA still applies and Customer benefits from the equivalent contractual protections.

This DPA is incorporated by reference into our Terms of Service. If anything in this DPA conflicts with the Terms of Service, this DPA controls for the subject matter of data protection.

1. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person, as defined in the applicable Data Protection Law.
  • Data Protection Law: the GDPR (EU 2016/679), UK GDPR, the Indian DPDP Act 2023, the CCPA/CPRA, and any other equivalent laws applicable to the Customer’s processing.
  • Customer Personal Data: Personal Data that Customer (or Customer’s end users) submits to or causes to be processed by Signum.
  • Processing: any operation or set of operations performed on Personal Data.
  • Subprocessor: a third party engaged by Signum to process Customer Personal Data on Customer’s behalf.
  • Data Subject: the identified or identifiable natural person to whom Personal Data relates.
  • Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

2. Scope and roles

Under this DPA, Customer is the Controller (or equivalent) and Signum is the Processor (or equivalent) with respect to Customer Personal Data.

Signum processes Customer Personal Data only on Customer’s documented instructions and only for the purpose of providing the Signum platform as described in our Terms of Service. Customer’s configuration of the platform (rules, agents, sends, recipients) constitutes those documented instructions.

3. Categories of data subjects and personal data

Data subjects whose Personal Data is processed:

  • Customer’s employees and authorised users of the Signum platform.
  • Customer’s contacts — recipients of emails Customer sends through Signum.

Categories of Personal Data processed:

  • Identifiers (name, email address) for both Customer users and Customer’s contacts.
  • Engagement metadata (open events, click events, document view events, reply detection).
  • Email subject lines (encrypted with a per-workspace key).
  • Email bodies (only if and when Customer explicitly opts in to body-level processing; off by default).
  • Technical data (IP address, user-agent, timestamps) for the purposes of bot detection, security, and audit logging.

Signum does not ask for or process Special Categories of Personal Data (Article 9 GDPR / sensitive personal data under DPDP) as part of normal operation. Customers must not submit such data via Signum unless a separate processing agreement is in place.

4. Duration

Signum will process Customer Personal Data for the duration of Customer’s subscription and for the periods set out in our Privacy Policy for post-termination retention (operational data 30 days, audit logs 365 days, recipient suppression lists indefinitely).

5. Signum’s obligations

  • Process Customer Personal Data only on Customer’s documented instructions.
  • Ensure persons authorised to process Customer Personal Data are bound by confidentiality.
  • Implement and maintain appropriate technical and organisational measures (see Annex II).
  • Assist Customer, where reasonably possible, in meeting its obligations to respond to data-subject requests.
  • Assist Customer, where reasonably possible, with security, breach notification, data protection impact assessments, and prior consultations with supervisory authorities.
  • Delete or return Customer Personal Data at the end of the subscription, per Customer’s choice and subject to legal retention obligations.
  • Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA.

6. Customer’s obligations

  • Establish and maintain a lawful basis for processing Customer Personal Data through Signum (consent, legitimate interest, contract, etc.).
  • Provide all required privacy notices to data subjects, including notice of Signum’s role as a processor.
  • Comply with all applicable laws when configuring agents, sending lists, and using the platform — particularly anti-spam laws (CAN-SPAM, CASL, GDPR Article 6, India DPDP consent rules).
  • Honour data-subject requests received directly from Customer’s contacts. Signum will assist with the technical execution but is not the controller of that relationship.
  • Not submit Special Categories of Personal Data through Signum without first executing a separate agreement.

7. Subprocessors

Customer authorises Signum to engage subprocessors to perform specific processing activities on Customer’s behalf, subject to the following conditions:

  • The current list of subprocessors is published in our Privacy Policy, section 7, and is kept up to date.
  • Signum will give Customer 30 days’ prior notice of any intended addition or replacement, by email to the workspace owner. Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, Customer may terminate the affected subscription with pro-rata refund.
  • Signum remains fully liable for the acts and omissions of its subprocessors as if they were its own.
  • Each subprocessor is bound by written terms that impose equivalent data-protection obligations to those in this DPA.

8. International data transfers

Signum primarily processes Customer Personal Data within India (Bengaluru region for primary storage) and the United States (Cloud Run + Cloudflare edge). Where transfers leave a jurisdiction with a binding adequacy decision, Signum relies on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or, for UK transfers, the UK International Data Transfer Addendum. Signum will execute the relevant SCC or IDTA module on request at no charge.

9. Security

Signum implements the technical and organisational measures described in Annex IIbelow. These include encryption at rest and in transit, per-workspace encryption keys for sensitive fields, principle-of-least-privilege access controls, multi-factor authentication for engineering access, audit logging, dependency scanning, and incident response procedures.

10. Security incident notification

Signum will notify Customer without undue delay, and in any event within 72 hoursof becoming aware of a Security Incident affecting Customer Personal Data. The notification will describe (to the extent then known) the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

Notification will be sent to the workspace owner’s registered email address. Customer is responsible for keeping that contact current.

11. Data-subject requests

Signum provides Customer with the technical means to respond to data-subject requests:

  • Access: workspace data export from Settings → Your data.
  • Deletion: per-recipient deletion from the Contacts page; workspace-wide deletion via account closure.
  • Portability: workspace data export is delivered as a structured JSON archive.
  • Rectification: contact fields are editable directly in the dashboard.
  • Objection / opt-out: every tracked email includes a one-click opt-out link. Suppression lists are honoured indefinitely.

Where Customer cannot fulfil a request without Signum’s assistance, Customer will contact [email protected] and Signum will provide reasonable assistance within the timeframes required by the applicable Data Protection Law.

12. Audits

On reasonable prior written notice (at least 30 days), Customer may once per twelve-month period audit Signum’s compliance with this DPA. The audit may be conducted by Customer’s own personnel or by an independent third-party auditor bound by confidentiality obligations, provided the audit:

  • is conducted during normal business hours and at Customer’s cost;
  • does not unreasonably interfere with Signum’s business operations;
  • does not require Signum to disclose information that would compromise other customers’ data or violate Signum’s confidentiality obligations.

In the interim, Signum will provide a current copy of relevant audit reports (SOC 2 Type II when available, ISO 27001 certifications when available) to satisfy reasonable due-diligence requests.

13. Return and deletion

At Customer’s choice, on termination Signum will either return or delete all Customer Personal Data within 90 days, unless retention is required by applicable law (for example, a tax or audit retention obligation), in which case Signum will protect that data with equivalent technical and organisational measures and confirm deletion as soon as the legal basis for retention expires.

14. Liability

The liability of each party under or in connection with this DPA is subject to the limitations of liability set out in the Terms of Service.

15. Order of precedence

In the event of any conflict between this DPA, the Terms of Service, and an applicable order form, the order of precedence is: (1) this DPA, (2) the order form, (3) the Terms of Service.

16. How to execute this DPA

This DPA is automatically incorporated into Customer’s subscription when Customer accepts the Terms of Service. No separate signature is required for the DPA to take effect.

Customers who require a signed counterpart for their own compliance records may request one by emailing [email protected] with the workspace name and signatory details. Signum will return a signed PDF within 5 business days.

Annex I — Description of processing

  • Subject matter: provision of the Signum email engagement intelligence platform.
  • Duration: term of Customer’s subscription plus the post-termination retention periods in the Privacy Policy.
  • Nature and purpose: hosting, transmitting, analysing, and storing email-engagement signals and related metadata; sending email on Customer’s behalf via Gmail.
  • Categories of data subjects: Customer users; Customer’s contacts (email recipients).
  • Categories of Personal Data: as described in Section 3.

Annex II — Technical and organisational measures

  • Encryption: TLS 1.2+ in transit; AES-256 at rest. Per-workspace keys for sensitive fields (refresh tokens, contact email hashes, subject lines).
  • Access control: role-based access (OWNER / ADMIN / MEMBER / VIEWER) within workspaces; engineering access via per-engineer SSO with MFA; audit-logged.
  • Network security: HSTS site-wide, Content Security Policy on the dashboard, rate limiting on all public endpoints, web application firewall at the edge.
  • Application security: dependency scanning in CI (pnpm audit), regular third-party security audits, responsible disclosure program at security.txt.
  • Personnel: confidentiality obligations in employment contracts; security training.
  • Subprocessor management: written agreements with equivalent obligations; the current list is at privacy § 7.
  • Incident response: defined runbook, 72-hour notification commitment, post-mortem published for material incidents.
  • Business continuity: daily database backups, point-in-time restore, regular disaster-recovery drills.
  • Data minimisation: only the fields needed to run the platform are collected; email bodies are not stored by default.

Contact

Questions about this DPA, or to request a signed counterpart, contact [email protected].

India DPDP grievance officer: Krishna · [email protected].