Privacy Policy
Version 2.0 · effective 23 September 2026
This is an English translation provided for convenience. In the event of any discrepancy, the Polish version prevails.
This Policy explains how we process personal data in connection with the Signal to Insight platform — the signaltoinsight.com pages, the web applications (portal., auth., operator.), the API and MCP server (api.signaltoinsight.com), the stiOS and stiPOS applications — and the integrations you connect to the Platform. Capitalised terms have the meaning given in the Terms of Service.
1. Controller and Data Protection Officer
The controller is Signal to Insight Sp. z o.o., a limited liability company incorporated in Poland. Contact: support@signaltoinsight.com.
We have appointed a Data Protection Officer (DPO) whom you can contact on any matter relating to the processing of your data and the exercise of your rights: iod@signaltoinsight.com.
2. Two roles: controller and processor
- We are the controller of User account data, Customer billing data, technical and security data, correspondence with us and data of visitors to our pages.
- We are the processor of Customer Data — content the Customer and its Users enter into the Workspace (e.g. CRM contacts, documents, mail, shop orders). The Customer is the controller of that data; we process it on the Customer’s instructions under the data processing agreement in the Terms of Service. If your data reached the Platform through one of our Customers (e.g. you are their business partner), please contact that Customer first about your rights — we will help them fulfil your request.
3. What data we process
- Account data: name, e-mail address, phone number (if provided), Workspace role, language, time zone, profile picture, passkeys (we store the public key only), second-factor settings.
- Customer (organisation) data: name, registration and address data, tax ID, contact person, plan and billing history. Payment card data is processed only by Stripe — we never see the full card number.
- Technical and security data: IP address, device and session identifiers, browser and operating-system type, timestamps, sign-in events, request and error logs.
- Integration data: data you grant access to when connecting an external account (section 5).
- Correspondence: messages sent to support and to the DPO.
- Website visitors: signaltoinsight.com uses no third-party analytics or advertising tools. The registration and demo-booking forms collect what you type into them.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account, providing the Platform | Art. 6(1)(b) — performance of a contract |
| Authentication, abuse prevention, security, event logs | Art. 6(1)(f) — legitimate interest (service security) |
| Billing, invoices, tax and accounting obligations | Art. 6(1)(c) — legal obligation |
| Support, enquiries, complaints | Art. 6(1)(b) and (f) |
| Service and security notices | Art. 6(1)(b) and (f) |
| Marketing about our services | Art. 6(1)(a) — consent (you may withdraw it at any time) |
| Establishing and defending legal claims | Art. 6(1)(f) |
| Processing Customer Data | Art. 28 — on the instructions of the Customer (controller) |
We do not sell personal data, do not use it for behavioural advertising and do not make decisions about you based solely on automated processing that produce legal effects.
5. Data from connected external accounts
Integrations are optional and enabled by the User. You grant access through the provider’s authorisation flow (OAuth 2.0), where you see the list of permissions, and you can revoke it in the Platform’s settings or with the provider. We store access tokens encrypted (AES-256-GCM) and use them only for the feature you enabled.
| Provider | Purpose and data |
|---|---|
| Google (Gmail, Calendar, Contacts, Tasks, Drive) | sending mail on your behalf and syncing your mailbox; two-way sync of events, contacts, tasks and files with the Platform |
| Microsoft 365 (Outlook, Calendar, Contacts, To Do, OneNote, OneDrive) | syncing mail, calendar, contacts, tasks, notes and files |
| basic profile data (identifier, name, e-mail) and publishing posts you prepare or approve | |
| Meta (Instagram, WhatsApp, Facebook) | handling messages from your customers in the Communicators module; publishing approved content |
| TikTok | once you connect your account: basic profile data (open_id, display name, avatar), publishing video content you select or approve and — if you enable it — reading the list and statistics of your own videos for reporting. We do not collect data about other TikTok users, followers or private messages |
| Telegram | handling messages of your Workspace’s bot |
Integration data is not used for advertising, not sold, not shared with third parties other than the sub-processors needed to run the feature, and not used to train AI models. When you disconnect an integration we delete the stored tokens and stop retrieving data; data already synchronised into the Workspace remains Customer Data and is governed by the Data Deletion Policy.
6. Google API Limited Use disclosure
Signal to Insight’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google account data only to provide and improve user-facing features the user knowingly enabled;
- we do not transfer this data to third parties unless necessary to provide those features, required by law, or as part of a merger or acquisition;
- we do not use Google data for advertising, including personalised advertising or retargeting;
- we do not use Gmail, Calendar, Contacts, Tasks or Drive data to develop, train or improve generalised artificial-intelligence or machine-learning models;
- we do not allow humans to read this data unless you consent for a specific support request, it is necessary for security purposes (e.g. investigating abuse), required by law, or the data is aggregated and anonymised for internal operations.
7. Artificial intelligence
When you use the assistant, AI agents or content generation, we send the model provider only the data needed for that task, and route language-model calls through the model gateway, which records which model handled the request. Model providers act as our sub-processors under commercial API terms that exclude using the submitted data to train their models. We do not train models on Customer Data either.
9. Recipients and sub-processors
We entrust data to providers that help us run the Platform, under data processing agreements (Article 28 GDPR). Current list:
| Entity | Purpose | Location / transfer safeguard |
|---|---|---|
| Railway Corporation (USA) | application, database and file hosting — region europe-west4 (Netherlands, EEA) | EEA |
| Vercel Inc. (USA) | hosting of public pages and web applications (CDN) | global; SCCs / DPF |
| Cloudflare, Inc. (USA) | DNS, attack protection, traffic proxying | global; SCCs / DPF |
| Stripe Payments Europe Ltd. (Ireland) | payment and subscription processing | EEA; SCCs for Stripe, Inc. |
| Resend (Plus Five Five, Inc., USA) | system e-mail delivery (sign-in codes, notifications) | USA; SCCs / DPF |
| Anthropic PBC (USA) | AI models (Claude) — only at a User’s instruction | USA; SCCs / DPF |
| OpenAI, L.L.C. (USA) | AI models — only at a User’s instruction | USA; SCCs / DPF |
| Google LLC / Google Ireland Ltd. | AI models (Gemini) — only at a User’s instruction | EEA / USA; SCCs / DPF |
| ElevenLabs Inc. (USA) | speech synthesis and recognition in the Voice Agent module | USA; SCCs |
| Twilio Inc. (USA) | telephone calls in the Voice Agent module | USA; SCCs / DPF |
Data may also be disclosed to public authorities where the law requires it and, for integrations, to the providers a User connected, within the feature the User enabled. We give Customers 14 days’ notice of changes to the sub-processor list.
10. Transfers outside the EEA
Our primary databases and files are stored in the European Economic Area (Netherlands). Some sub-processors are based in the USA; transfers rely on the European Commission’s adequacy decision (EU-US Data Privacy Framework) for certified entities or on the Commission’s standard contractual clauses (SCCs). You can obtain a copy of the safeguards by writing to the DPO.
11. How long we keep data
| Data | Period |
|---|---|
| User account | until the account is deleted; after a deletion request, 30 days to cancel, then permanent deletion |
| Workspace and Customer Data | for the term of the agreement; after a request to delete the Workspace or organisation, 30 days to cancel, then permanent deletion across all services |
| Files and documents in the trash | 30 days from being moved to the trash |
| Technical request logs and performance samples | 30 days |
| Security and action events, e-mail delivery log | 90 days |
| Aggregated statistics (no personal data) | 13 months |
| Meeting recordings (notetaker module) | 30 days |
| Billing documents and invoices | 5 years from the end of the tax year (tax law) |
| Data needed to defend claims | until the limitation period expires |
Details, including how to request deletion, are in the Data Deletion Policy.
12. Your rights
You have the right to access your data and obtain a copy, to rectification, erasure, restriction of processing, data portability, to object to processing based on legitimate interest, and to withdraw consent at any time (without affecting the lawfulness of prior processing).
You can exercise most rights yourself in the Platform (editing your profile, Takeout export, account deletion). For anything else write to the DPO: iod@signaltoinsight.com. We reply within one month; for complex requests this may be extended by two months, in which case we will tell you. We may ask you to confirm your identity.
You have the right to lodge a complaint with a supervisory authority — the President of the Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl) — or the authority of your place of residence or work in the EU.
13. Security
We use encryption in transit (TLS), encryption of secrets and tokens (AES-256-GCM), database-level isolation of Workspace data, passwordless sign-in with passkeys and a second factor, least privilege and event logging. Details: Information Security Policy.
14. Children
The Platform is intended for businesses and is not directed at persons under 16. We do not knowingly collect their data; if we learn of such a case we will delete it.
15. Changes to this Policy
We announce material changes in the Platform or by e-mail before they take effect. The version number and date are shown at the top of this document.