Legal

Privacy Policy

Effective Date: March 31, 2026

1. Controller and Processor

Digital Now Solutions GmbH Gotlandstraße 10d, 10439 Berlin, Germany Commercial Register: HRB 260377 B (Amtsgericht Charlottenburg) Managing Directors: Robert Vossen, Andreas Wawer Email: contact@signalist.io Website: www.signalist.io

Signalist operates in two distinct roles under the GDPR:

As Data Controller (Art. 4(7) GDPR): We are the controller for all processing activities related to our own platform operations, including user registration and account management, authentication, billing and payment processing, error monitoring, application logging, and internal notifications.

As Data Processor (Art. 4(8) / Art. 28 GDPR): We act as a processor on behalf of our clients (the Data Controllers) for all processing of prospect, lead, and campaign data. In this capacity, we process personal data solely on instruction of our clients and in accordance with applicable data processing agreements (DPAs).

The obligations and rights described in this policy apply accordingly depending on our role for each processing activity.

For inquiries regarding data protection, please contact: privacy@signalist.io

2. Data Protection Officer (Art. 37 GDPR)

We have appointed an external Data Protection Officer:

heyData GmbH Schützenstr. 5, 10117 Berlin, Germany Email: datenschutz@heydata.eu Website: www.heydata.eu

3. Categories of Personal Data Processed

3.1 User Account Data

Data CategoryFields
IdentificationEmail, first name, last name
AuthenticationPassword (bcrypt-hashed), two-factor authentication secret (TOTP), 2FA status
Contact InformationEmail, LinkedIn URL
Location DataCountry, city, region, timezone (derived from a one-time geolocation lookup)
PreferencesLanguage, notification settings (email, Slack, in-app), auto-accept, profile visits, connection scraping
StatusBlocked status, onboarding status, LinkedIn Premium status, admin rights, LinkedIn access status
Usage LimitsDaily limits for profile visits, connection requests, and messages

Note: We do not store IP addresses or Internet Service Provider (ISP) information. IP addresses are used only transiently for a one-time geolocation lookup to determine country, city, region, and timezone.

3.2 Company Data

Data CategoryFields
Company InformationName, LinkedIn URL, website
API Keys (encrypted/sensitive)Lemlist API key
Payment DataStripe customer ID, subscription ID, session ID
Onboarding ConfigurationPersonas, industries, location, size, keywords, organization, member (all JSON)
CRM IntegrationZoho OAuth tokens, HubSpot OAuth tokens (encrypted in separate tables)

3.3 Prospect / Lead Data (B2B)

Data CategoryFields
Personal DataFirst name, last name, full name, gender
Professional DataTitle, seniority, headline
Contact DataEmail, LinkedIn URL, phone number (via BetterContact)
LocationCity, country, state
Company AssociationVia Organization (company name, domain, industry, employee count, location)

3.4 Email Account Data

Email address, sender first name, sender last name, signature, associated user ID.

3.5 LinkedIn Connections

LinkedIn URL, first name, last name, company name, title, email, member URN, connection date.

3.6 Third-Party Data Sources (Art. 14 GDPR)

As part of our B2B lead research services, we obtain personal business contact data from external data providers who are independent controllers responsible for the lawful collection of the data. We are required to inform data subjects about these sources in accordance with Art. 14(2)(f) GDPR.

Data SourceOperatorData ObtainedLocation
CompanyEnrich (companyenrich.com)STDIO Ltd.Name, job title, seniority, business email, LinkedIn URL, company associationTurkey

Important: These providers are not sub-processors under Art. 28 GDPR. We do not transfer personal data to them — we submit non-personal search criteria (e.g., company domains, industry filters, position filters) and receive personal business contact data from their independently maintained databases. Each provider is solely responsible for the lawfulness of data collection on their end.

Our processing of the data received is based on Art. 6(1)(f) GDPR (legitimate interest in B2B sales communication). The corresponding legitimate interest assessment is documented in LIA-09 (Lead Research & Enrichment).

PurposeDetailsLegal Basis
Registration & Account ManagementEmail, LinkedIn URL, password, nameArt. 6(1)(b) — Contract performance
AuthenticationJWT tokens, 2FA (TOTP), Google OAuth, password resetArt. 6(1)(b) — Contract performance
Payment ProcessingVia Stripe (checkout, subscriptions, billing portal, automatic tax)Art. 6(1)(b) — Contract performance
Lead Research & EnrichmentSearch and enrichment of B2B contact data via LinkedInArt. 6(1)(f) — Legitimate interest
Email ValidationVerification of email addresses via ZeroBounce, Clearout, EnrowArt. 6(1)(f) — Legitimate interest
Phone Number ValidationVia BetterContactArt. 6(1)(f) — Legitimate interest
Web ScrapingScraping of company websites via ZenRows / internal web scraperArt. 6(1)(f) — Legitimate interest
LinkedIn IntegrationVia Unipile (profile visits, connection requests, messaging, search, Sales Navigator scraping)Art. 6(1)(f) — Legitimate interest
AI-Based AnalysisLead analysis and scoring via DeepInfra (Qwen, GLM-5), Parallel AIArt. 6(1)(f) — Legitimate interest
CRM SynchronizationSynchronization with Zoho CRM and HubSpot (OAuth-based)Art. 6(1)(b)/(f) — Contract/Legitimate interest
Email & LinkedIn CampaignsOutreach sequencing via internal campaign engine using Unipile (LinkedIn and email); legacy integration via Lemlist (API key) for existing customersArt. 6(1)(f) — Legitimate interest
Transactional EmailsSending via Mailjet (confirmations, password resets, notifications)Art. 6(1)(b) — Contract performance
Audit LoggingLogging of all CRUD operations (user ID, table name, old/new data)Art. 6(1)(f) — Legitimate interest (security)
Event HistoryTracking of login events and user actionsArt. 6(1)(f) — Legitimate interest
Error MonitoringSentry (error tracking)Art. 6(1)(f) — Legitimate interest
Application LoggingLogtail / Pino (structured logs; authorization headers and passwords are redacted)Art. 6(1)(f) — Legitimate interest
Internal NotificationsSlack webhooksArt. 6(1)(f) — Legitimate interest
Gender DetectionDetermination of gender from first names via Genderize.io for lead enrichment and personalizationArt. 6(1)(f) — Legitimate interest
Rate LimitingThrottler (IP-based via request-ip middleware; IP addresses are processed transiently in memory only and are not persisted)Art. 6(1)(f) — Legitimate interest

For all processing activities based on Art. 6(1)(f) (legitimate interest), we have conducted legitimate interest assessments (LIAs / balancing tests) to ensure that our interests do not override the rights and freedoms of data subjects. These assessments are documented and available upon request.

5. Cookies and Tracking Technologies

The Signalist application does not use cookies, analytics trackers, or tracking pixels for its own purposes. We do not employ any first-party or third-party advertising or behavioral tracking technologies.

The only monitoring tool we use is Sentry for error tracking, which collects error stack traces and request metadata strictly for the purpose of identifying and resolving software defects. Sentry does not track user behavior, set cookies, or build user profiles.

6. Data Minimization (Art. 5(1)(c) GDPR)

We only collect and process data that is strictly necessary for providing our services:

7. Data Retention

AspectDetails
Account DataRetained for the duration of the contractual relationship
Prospect / Lead DataUpon termination of a client contract, all prospect and lead data processed on behalf of that client is deleted or returned within 30 days, in accordance with the applicable DPA
Soft DeletionAll records use soft deletion (marked with deletedAt timestamp)
Hard Deletion — CompaniesCompanies are permanently deleted 30 days after soft deletion (daily cron job at 03
UTC)
Audit LogsAutomatically deleted after 30 days (daily cron job at 03
UTC)
Request LogsCleaned up after 30 days (data cleaner process)
HTTP CacheRedis cache with a TTL of 30 days
Application CacheIn-memory cache with a TTL of 5 minutes (default)

8. Sub-Processors (Art. 28 GDPR)

We engage the following sub-processors to provide our services:

Sub-ProcessorPurposeData ProcessedLocationTransfer Mechanism
Stripe (stripe.com)Payment processing, subscriptions, invoicingStripe customer ID, payment data, tax IDUSAEU-US DPF, SCCs
Mailjet (mailjet.com)Transactional emailsRecipient email, nameFrance (EU)N/A (EU)
ZeroBounceEmail validation & guessingEmail addresses, names, domainsUSASCCs
Clearout.ioEmail finding & verificationNames, domains, email addressesIndiaSCCs
EnrowEmail findingNames, domainsFrance (EU)N/A (EU)
LeadMagicEmail findingNames, domains, company namesUSASCCs
BetterContactPhone number validationContact dataEUN/A (EU)
UnipileLinkedIn & email account connection, messaging, search, Sales Navigator scraping, campaign outreach (LinkedIn & email)LinkedIn account IDs, messages, emailsFrance (EU)N/A (EU)
Lemlist (lemlist.com)Legacy email & LinkedIn campaign sending for existing customersEmail addresses, names, campaign contentFrance (EU)N/A (EU)
DeepInfraAI model execution (LLM)Prompt data with lead/company informationUSASCCs
Parallel AIAI-based company analysisCompany data, domainsUSA (San Francisco)SCCs
Google (OAuth)Social loginOAuth token, email, name (from ID token)USAEU-US DPF, SCCs
SentryError monitoringError stack traces, request metadataUSAEU-US DPF, SCCs
Logtail / BetterStackLog managementLog entries (passwords/auth headers are redacted)Czech Republic (EU)N/A (EU)
SlackInternal notificationsUsernames, emails, action detailsUSAEU-US DPF, SCCs
Zoho CRMCRM synchronization (OAuth2, EU region)Contacts, deals, company dataEU (zoho.eu)N/A (EU)
HubSpotCRM synchronization (OAuth2)Contacts, deals, company dataUSA/EUEU-US DPF, SCCs
RapidAPI (various)LinkedIn data APIs (Sales Navigator, bulk data, jobs)LinkedIn profile dataUSASCCs
Serper.devGoogle search resultsSearch queriesUSASCCs
SignalbaseFunding/acquisition signalsCompany dataUSASCCs
Genderize.io (Demografix ApS)Gender determination from first namesFirst name, country codeDenmark (EU)N/A (EU)
IPRoyalProxy servicesHTTP requestsLithuania (EU)N/A (EU)
ZenRowsWeb scrapingURLs, website contentSpain (EU)N/A (EU)
1Password (Connect)Credential storage for eventsLogin credentialsCanadaSCCs

Note: Qdrant (vector database) is self-hosted on our own infrastructure at Hetzner in Germany (EU) and is not a sub-processor.

Appropriate safeguards are in place for all international data transfers outside the EU/EEA, including:

9. International Data Transfers

Personal data may be transferred to sub-processors located outside the EU/EEA. The following non-EU sub-processors receive personal data, with the corresponding transfer safeguard:

Sub-ProcessorCountryTransfer Mechanism
StripeUSAEU-US DPF, SCCs
ZeroBounceUSASCCs
Clearout.ioIndiaSCCs
LeadMagicUSASCCs
DeepInfraUSASCCs
Parallel AIUSASCCs
GoogleUSAEU-US DPF, SCCs
SentryUSAEU-US DPF, SCCs
SlackUSAEU-US DPF, SCCs
HubSpotUSA/EUEU-US DPF, SCCs
RapidAPIUSASCCs
Serper.devUSASCCs
SignalbaseUSASCCs
1PasswordCanadaSCCs

All other sub-processors listed in Section 8 are located within the EU/EEA and do not require additional transfer mechanisms.

10. Automated Decision-Making and Profiling (Art. 22 GDPR)

The following automated processing activities may be performed on behalf of Data Controllers:

FeatureDetails
Lead ScoringAI-based scoring via DeepInfra (Qwen, GLM-5) — leads are automatically prioritized (Priority 1/2/3/Disqualified)
Signal DetectionAutomatic detection of business signals (funding rounds, acquisitions, job changes)
Email GuessingAutomatic determination of email addresses from name + domain
Gender DetectionVia Genderize.io based on first names

These automated processes support decision-making but do not produce legal effects or similarly significant effects on data subjects without human review by the Data Controller.

11. Technical and Organizational Measures (Art. 32 GDPR)

MeasureImplementation
Password Hashingbcrypt with configurable salt rounds
AuthenticationJWT access tokens + refresh tokens, OTP tokens for 2FA
Two-Factor AuthenticationTOTP (Time-Based One-Time Password)
EncryptionDedicated encryption service for OAuth tokens (Zoho, HubSpot)
Rate LimitingConfigurable throttler (TTL and limit via environment variables)
CORSEnabled with configurable origins
HTTP Security HeadersHelmet middleware
Log RedactionAuthorization headers and passwords are automatically removed from logs
Role-Based Access ControlGranular permissions system with role assignments
Multi-TenancyData isolation via company ID — every query is company-scoped
API Key AuthenticationSeparate API key authentication for external access
Token BlacklistingJWT blacklisting via Redis cache
Response CompressionEnabled for all API responses
Soft DeletionPrevents accidental permanent data loss
Comprehensive Audit LoggingAll data modifications are tracked (user ID, table, old/new values)

12. Data Subject Rights (Art. 15–22 GDPR)

Where we act as Data Processor, we support our clients (Data Controllers) in fulfilling data subject rights. Data subjects may contact the relevant Data Controller to exercise the following rights. Where we act as Data Controller (e.g., for user account data), data subjects may contact us directly.

Technical support for these rights is implemented through:

For questions about data processing by Signalist or if you need a data processing agreement, contact: privacy@signalist.io

13. Breach Notification (Art. 33/34 GDPR)

In the event of a personal data breach, we are committed to:

Detailed breach response procedures, including roles, responsibilities, and escalation paths, are documented in our internal incident response plan and in our Data Processing Agreements.

14. Children's Data

The Signalist service is a B2B platform directed at businesses and professionals. It is not intended for use by individuals under the age of 16. We do not knowingly collect or process personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete such data without undue delay.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Each version is timestamped. The latest version is always available via our API and displayed in the application.