Effective Date: March 31, 2026
1. Controller and Processor
Digital Now Solutions GmbH Gotlandstraße 10d, 10439 Berlin, Germany Commercial Register: HRB 260377 B (Amtsgericht Charlottenburg) Managing Directors: Robert Vossen, Andreas Wawer Email: contact@signalist.io Website: www.signalist.io
Signalist operates in two distinct roles under the GDPR:
As Data Controller (Art. 4(7) GDPR): We are the controller for all processing activities related to our own platform operations, including user registration and account management, authentication, billing and payment processing, error monitoring, application logging, and internal notifications.
As Data Processor (Art. 4(8) / Art. 28 GDPR): We act as a processor on behalf of our clients (the Data Controllers) for all processing of prospect, lead, and campaign data. In this capacity, we process personal data solely on instruction of our clients and in accordance with applicable data processing agreements (DPAs).
The obligations and rights described in this policy apply accordingly depending on our role for each processing activity.
For inquiries regarding data protection, please contact: privacy@signalist.io
2. Data Protection Officer (Art. 37 GDPR)
We have appointed an external Data Protection Officer:
heyData GmbH Schützenstr. 5, 10117 Berlin, Germany Email: datenschutz@heydata.eu Website: www.heydata.eu
3. Categories of Personal Data Processed
3.1 User Account Data
| Data Category | Fields |
|---|---|
| Identification | Email, first name, last name |
| Authentication | Password (bcrypt-hashed), two-factor authentication secret (TOTP), 2FA status |
| Contact Information | Email, LinkedIn URL |
| Location Data | Country, city, region, timezone (derived from a one-time geolocation lookup) |
| Preferences | Language, notification settings (email, Slack, in-app), auto-accept, profile visits, connection scraping |
| Status | Blocked status, onboarding status, LinkedIn Premium status, admin rights, LinkedIn access status |
| Usage Limits | Daily limits for profile visits, connection requests, and messages |
Note: We do not store IP addresses or Internet Service Provider (ISP) information. IP addresses are used only transiently for a one-time geolocation lookup to determine country, city, region, and timezone.
3.2 Company Data
| Data Category | Fields |
|---|---|
| Company Information | Name, LinkedIn URL, website |
| API Keys (encrypted/sensitive) | Lemlist API key |
| Payment Data | Stripe customer ID, subscription ID, session ID |
| Onboarding Configuration | Personas, industries, location, size, keywords, organization, member (all JSON) |
| CRM Integration | Zoho OAuth tokens, HubSpot OAuth tokens (encrypted in separate tables) |
3.3 Prospect / Lead Data (B2B)
| Data Category | Fields |
|---|---|
| Personal Data | First name, last name, full name, gender |
| Professional Data | Title, seniority, headline |
| Contact Data | Email, LinkedIn URL, phone number (via BetterContact) |
| Location | City, country, state |
| Company Association | Via Organization (company name, domain, industry, employee count, location) |
3.4 Email Account Data
Email address, sender first name, sender last name, signature, associated user ID.
3.5 LinkedIn Connections
LinkedIn URL, first name, last name, company name, title, email, member URN, connection date.
3.6 Third-Party Data Sources (Art. 14 GDPR)
As part of our B2B lead research services, we obtain personal business contact data from external data providers who are independent controllers responsible for the lawful collection of the data. We are required to inform data subjects about these sources in accordance with Art. 14(2)(f) GDPR.
| Data Source | Operator | Data Obtained | Location |
|---|---|---|---|
| CompanyEnrich (companyenrich.com) | STDIO Ltd. | Name, job title, seniority, business email, LinkedIn URL, company association | Turkey |
Important: These providers are not sub-processors under Art. 28 GDPR. We do not transfer personal data to them — we submit non-personal search criteria (e.g., company domains, industry filters, position filters) and receive personal business contact data from their independently maintained databases. Each provider is solely responsible for the lawfulness of data collection on their end.
Our processing of the data received is based on Art. 6(1)(f) GDPR (legitimate interest in B2B sales communication). The corresponding legitimate interest assessment is documented in LIA-09 (Lead Research & Enrichment).
4. Purposes of Processing and Legal Basis (Art. 6 GDPR)
| Purpose | Details | Legal Basis |
|---|---|---|
| Registration & Account Management | Email, LinkedIn URL, password, name | Art. 6(1)(b) — Contract performance |
| Authentication | JWT tokens, 2FA (TOTP), Google OAuth, password reset | Art. 6(1)(b) — Contract performance |
| Payment Processing | Via Stripe (checkout, subscriptions, billing portal, automatic tax) | Art. 6(1)(b) — Contract performance |
| Lead Research & Enrichment | Search and enrichment of B2B contact data via LinkedIn | Art. 6(1)(f) — Legitimate interest |
| Email Validation | Verification of email addresses via ZeroBounce, Clearout, Enrow | Art. 6(1)(f) — Legitimate interest |
| Phone Number Validation | Via BetterContact | Art. 6(1)(f) — Legitimate interest |
| Web Scraping | Scraping of company websites via ZenRows / internal web scraper | Art. 6(1)(f) — Legitimate interest |
| LinkedIn Integration | Via Unipile (profile visits, connection requests, messaging, search, Sales Navigator scraping) | Art. 6(1)(f) — Legitimate interest |
| AI-Based Analysis | Lead analysis and scoring via DeepInfra (Qwen, GLM-5), Parallel AI | Art. 6(1)(f) — Legitimate interest |
| CRM Synchronization | Synchronization with Zoho CRM and HubSpot (OAuth-based) | Art. 6(1)(b)/(f) — Contract/Legitimate interest |
| Email & LinkedIn Campaigns | Outreach sequencing via internal campaign engine using Unipile (LinkedIn and email); legacy integration via Lemlist (API key) for existing customers | Art. 6(1)(f) — Legitimate interest |
| Transactional Emails | Sending via Mailjet (confirmations, password resets, notifications) | Art. 6(1)(b) — Contract performance |
| Audit Logging | Logging of all CRUD operations (user ID, table name, old/new data) | Art. 6(1)(f) — Legitimate interest (security) |
| Event History | Tracking of login events and user actions | Art. 6(1)(f) — Legitimate interest |
| Error Monitoring | Sentry (error tracking) | Art. 6(1)(f) — Legitimate interest |
| Application Logging | Logtail / Pino (structured logs; authorization headers and passwords are redacted) | Art. 6(1)(f) — Legitimate interest |
| Internal Notifications | Slack webhooks | Art. 6(1)(f) — Legitimate interest |
| Gender Detection | Determination of gender from first names via Genderize.io for lead enrichment and personalization | Art. 6(1)(f) — Legitimate interest |
| Rate Limiting | Throttler (IP-based via request-ip middleware; IP addresses are processed transiently in memory only and are not persisted) | Art. 6(1)(f) — Legitimate interest |
For all processing activities based on Art. 6(1)(f) (legitimate interest), we have conducted legitimate interest assessments (LIAs / balancing tests) to ensure that our interests do not override the rights and freedoms of data subjects. These assessments are documented and available upon request.
5. Cookies and Tracking Technologies
The Signalist application does not use cookies, analytics trackers, or tracking pixels for its own purposes. We do not employ any first-party or third-party advertising or behavioral tracking technologies.
The only monitoring tool we use is Sentry for error tracking, which collects error stack traces and request metadata strictly for the purpose of identifying and resolving software defects. Sentry does not track user behavior, set cookies, or build user profiles.
6. Data Minimization (Art. 5(1)(c) GDPR)
We only collect and process data that is strictly necessary for providing our services:
- IP addresses are not stored — used only transiently in memory for a one-time geolocation lookup and for rate limiting; they are not persisted to any database or log
- ISP information is not collected
- Geolocation data (country, city, region, timezone) is retrieved once and cached; no repeated lookups are performed
- Passwords are stored only in hashed form (bcrypt)
- OAuth tokens and API keys are encrypted at rest
7. Data Retention
| Aspect | Details |
|---|---|
| Account Data | Retained for the duration of the contractual relationship |
| Prospect / Lead Data | Upon termination of a client contract, all prospect and lead data processed on behalf of that client is deleted or returned within 30 days, in accordance with the applicable DPA |
| Soft Deletion | All records use soft deletion (marked with deletedAt timestamp) |
| Hard Deletion — Companies | Companies are permanently deleted 30 days after soft deletion (daily cron job at 03 UTC) |
| Audit Logs | Automatically deleted after 30 days (daily cron job at 03 UTC) |
| Request Logs | Cleaned up after 30 days (data cleaner process) |
| HTTP Cache | Redis cache with a TTL of 30 days |
| Application Cache | In-memory cache with a TTL of 5 minutes (default) |
8. Sub-Processors (Art. 28 GDPR)
We engage the following sub-processors to provide our services:
| Sub-Processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Stripe (stripe.com) | Payment processing, subscriptions, invoicing | Stripe customer ID, payment data, tax ID | USA | EU-US DPF, SCCs |
| Mailjet (mailjet.com) | Transactional emails | Recipient email, name | France (EU) | N/A (EU) |
| ZeroBounce | Email validation & guessing | Email addresses, names, domains | USA | SCCs |
| Clearout.io | Email finding & verification | Names, domains, email addresses | India | SCCs |
| Enrow | Email finding | Names, domains | France (EU) | N/A (EU) |
| LeadMagic | Email finding | Names, domains, company names | USA | SCCs |
| BetterContact | Phone number validation | Contact data | EU | N/A (EU) |
| Unipile | LinkedIn & email account connection, messaging, search, Sales Navigator scraping, campaign outreach (LinkedIn & email) | LinkedIn account IDs, messages, emails | France (EU) | N/A (EU) |
| Lemlist (lemlist.com) | Legacy email & LinkedIn campaign sending for existing customers | Email addresses, names, campaign content | France (EU) | N/A (EU) |
| DeepInfra | AI model execution (LLM) | Prompt data with lead/company information | USA | SCCs |
| Parallel AI | AI-based company analysis | Company data, domains | USA (San Francisco) | SCCs |
| Google (OAuth) | Social login | OAuth token, email, name (from ID token) | USA | EU-US DPF, SCCs |
| Sentry | Error monitoring | Error stack traces, request metadata | USA | EU-US DPF, SCCs |
| Logtail / BetterStack | Log management | Log entries (passwords/auth headers are redacted) | Czech Republic (EU) | N/A (EU) |
| Slack | Internal notifications | Usernames, emails, action details | USA | EU-US DPF, SCCs |
| Zoho CRM | CRM synchronization (OAuth2, EU region) | Contacts, deals, company data | EU (zoho.eu) | N/A (EU) |
| HubSpot | CRM synchronization (OAuth2) | Contacts, deals, company data | USA/EU | EU-US DPF, SCCs |
| RapidAPI (various) | LinkedIn data APIs (Sales Navigator, bulk data, jobs) | LinkedIn profile data | USA | SCCs |
| Serper.dev | Google search results | Search queries | USA | SCCs |
| Signalbase | Funding/acquisition signals | Company data | USA | SCCs |
| Genderize.io (Demografix ApS) | Gender determination from first names | First name, country code | Denmark (EU) | N/A (EU) |
| IPRoyal | Proxy services | HTTP requests | Lithuania (EU) | N/A (EU) |
| ZenRows | Web scraping | URLs, website content | Spain (EU) | N/A (EU) |
| 1Password (Connect) | Credential storage for events | Login credentials | Canada | SCCs |
Note: Qdrant (vector database) is self-hosted on our own infrastructure at Hetzner in Germany (EU) and is not a sub-processor.
Appropriate safeguards are in place for all international data transfers outside the EU/EEA, including:
- EU-US Data Privacy Framework (DPF) — for US-based sub-processors certified under the framework
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR — for all non-EU sub-processors
- Zoho CRM operates on EU infrastructure (zoho.eu)
9. International Data Transfers
Personal data may be transferred to sub-processors located outside the EU/EEA. The following non-EU sub-processors receive personal data, with the corresponding transfer safeguard:
| Sub-Processor | Country | Transfer Mechanism |
|---|---|---|
| Stripe | USA | EU-US DPF, SCCs |
| ZeroBounce | USA | SCCs |
| Clearout.io | India | SCCs |
| LeadMagic | USA | SCCs |
| DeepInfra | USA | SCCs |
| Parallel AI | USA | SCCs |
| USA | EU-US DPF, SCCs | |
| Sentry | USA | EU-US DPF, SCCs |
| Slack | USA | EU-US DPF, SCCs |
| HubSpot | USA/EU | EU-US DPF, SCCs |
| RapidAPI | USA | SCCs |
| Serper.dev | USA | SCCs |
| Signalbase | USA | SCCs |
| 1Password | Canada | SCCs |
All other sub-processors listed in Section 8 are located within the EU/EEA and do not require additional transfer mechanisms.
10. Automated Decision-Making and Profiling (Art. 22 GDPR)
The following automated processing activities may be performed on behalf of Data Controllers:
| Feature | Details |
|---|---|
| Lead Scoring | AI-based scoring via DeepInfra (Qwen, GLM-5) — leads are automatically prioritized (Priority 1/2/3/Disqualified) |
| Signal Detection | Automatic detection of business signals (funding rounds, acquisitions, job changes) |
| Email Guessing | Automatic determination of email addresses from name + domain |
| Gender Detection | Via Genderize.io based on first names |
These automated processes support decision-making but do not produce legal effects or similarly significant effects on data subjects without human review by the Data Controller.
11. Technical and Organizational Measures (Art. 32 GDPR)
| Measure | Implementation |
|---|---|
| Password Hashing | bcrypt with configurable salt rounds |
| Authentication | JWT access tokens + refresh tokens, OTP tokens for 2FA |
| Two-Factor Authentication | TOTP (Time-Based One-Time Password) |
| Encryption | Dedicated encryption service for OAuth tokens (Zoho, HubSpot) |
| Rate Limiting | Configurable throttler (TTL and limit via environment variables) |
| CORS | Enabled with configurable origins |
| HTTP Security Headers | Helmet middleware |
| Log Redaction | Authorization headers and passwords are automatically removed from logs |
| Role-Based Access Control | Granular permissions system with role assignments |
| Multi-Tenancy | Data isolation via company ID — every query is company-scoped |
| API Key Authentication | Separate API key authentication for external access |
| Token Blacklisting | JWT blacklisting via Redis cache |
| Response Compression | Enabled for all API responses |
| Soft Deletion | Prevents accidental permanent data loss |
| Comprehensive Audit Logging | All data modifications are tracked (user ID, table, old/new values) |
12. Data Subject Rights (Art. 15–22 GDPR)
Where we act as Data Processor, we support our clients (Data Controllers) in fulfilling data subject rights. Data subjects may contact the relevant Data Controller to exercise the following rights. Where we act as Data Controller (e.g., for user account data), data subjects may contact us directly.
- Right of Access (Art. 15) — obtain confirmation and a copy of personal data being processed
- Right to Rectification (Art. 16) — correct inaccurate personal data
- Right to Erasure (Art. 17) — request deletion of personal data ("right to be forgotten")
- Right to Restriction of Processing (Art. 18) — restrict how personal data is processed
- Right to Data Portability (Art. 20) — receive personal data in a structured, machine-readable format (JSON)
- Right to Object (Art. 21) — object to processing based on legitimate interest
- Right to Lodge a Complaint — with a competent supervisory authority. Our lead supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany (https://www.datenschutz-berlin.de)
Technical support for these rights is implemented through:
- Soft deletion with automatic hard deletion after 30 days
- Comprehensive audit logs tracking all data changes per record
- Structured data storage (JSON) for portability
- Per-user notification and processing preferences
For questions about data processing by Signalist or if you need a data processing agreement, contact: privacy@signalist.io
13. Breach Notification (Art. 33/34 GDPR)
In the event of a personal data breach, we are committed to:
- Notification to supervisory authorities — Without undue delay and, where feasible, within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority in accordance with Art. 33 GDPR.
- Notification to data subjects — Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, we will notify the affected data subjects without undue delay in accordance with Art. 34 GDPR.
- Notification to Data Controllers — Where we act as processor, we will notify the affected Data Controller without undue delay after becoming aware of a breach, as specified in the applicable DPA.
Detailed breach response procedures, including roles, responsibilities, and escalation paths, are documented in our internal incident response plan and in our Data Processing Agreements.
14. Children's Data
The Signalist service is a B2B platform directed at businesses and professionals. It is not intended for use by individuals under the age of 16. We do not knowingly collect or process personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete such data without undue delay.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Each version is timestamped. The latest version is always available via our API and displayed in the application.
