Signals Surveys is part of Compass, the AI-first customer intelligence platform. Explore Compass

Legal

Data Processing Addendum

The processing terms that apply when Signals handles personal data on a merchant's behalf.

Last updated July 2026.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Signals Surveys ("Signals", "Processor") and the merchant using the Service ("Merchant", "Controller"). It applies where Signals processes personal data on the Merchant's behalf. If the Terms and this DPA conflict on a data protection matter, this DPA governs.

1. Definitions

  • Data Protection Laws — the privacy and data protection laws applicable to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable US state privacy laws.
  • Personal Data — information relating to an identified or identifiable natural person that Signals processes on behalf of the Merchant under the Terms.
  • Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • Controller, Processor, Sub-processor, Data Subject, Personal Data Breach — as defined in the Data Protection Laws.
  • Service — Signals Surveys, as described in the Terms.
  • Standard Contractual Clauses — the clauses approved by the European Commission in Decision 2021/914, and, for the UK, the ICO's International Data Transfer Addendum.

2. Roles of the parties

The Merchant is the Controller of Personal Data relating to survey respondents and other individuals whose data the Merchant submits to or collects through the Service. Signals is the Processor of that Personal Data and processes it only on the Merchant's documented instructions.

The Terms, this DPA, and the Merchant's configuration of the Service constitute the Merchant's complete documented instructions. Signals will inform the Merchant if, in its opinion, an instruction infringes the Data Protection Laws.

Signals acts as an independent Controller for Merchant account data — the information used to create and administer the Merchant's account, bill the subscription, provide support, and secure the Service. That processing is described in our Privacy Policy and is not governed by this DPA.

3. Scope, nature, and purpose of processing

  • Subject matter — provision of the Service to the Merchant.
  • Nature and purpose — collecting survey and Spark responses; matching responses to Shopify customers; combining responses with commerce context; generating customer properties and analytics for the Merchant; transmitting events and profile properties to destinations the Merchant has connected; storing, exporting, and deleting the resulting data.
  • Duration — for the term of the Terms, plus the deletion period in section 11.
  • Frequency — continuous, for as long as surveys are published and responses are received.

4. Categories of Data Subjects and Personal Data

4.1 Categories of Data Subjects

  • The Merchant's customers and prospective customers who view or answer a survey or Spark.
  • The Merchant's personnel who administer the Service, to the extent their data appears in Merchant configuration.

4.2 Categories of Personal Data

  • Identifiers — Shopify customer identifier, and where the Merchant collects them, name and email address.
  • Survey responses — answers submitted, timestamps, completion state, and consent state.
  • Commerce context — order history, purchased products, order value, and customer tags drawn from Shopify.
  • Derived attributes — customer properties generated from responses, such as a declared goal or preference.
  • Technical data — survey and response identifiers, device type, coarse locale, and IP address processed for delivery and abuse prevention.

4.3 Special category data

The Service is not designed for special category data as defined in Article 9 GDPR, nor for payment card numbers, government identifiers, or financial account credentials. The Merchant must not configure surveys to collect such data.

5. Merchant obligations

The Merchant warrants that it:

  • has a valid legal basis for the processing it instructs Signals to perform;
  • provides its customers with the required privacy notice and, where applicable, obtains and maintains consent;
  • configures consent gating, retention, and integrations appropriately for its business; and
  • responds to Data Subject requests as Controller.

6. Sub-processors

The Merchant grants Signals general authorization to appoint Sub-processors to deliver the Service. Signals imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable for their performance.

Current Sub-processors:

  • Cloudflare — hosting, edge delivery, TLS termination, and network protection.
  • Shopify — the commerce platform integrated with the Service, and, where applicable, subscription billing.
  • Klaviyo — where the Merchant connects Klaviyo and instructs Signals to send events and profile properties.
  • Compass — where the Merchant uses Signals with a Compass workspace.
  • Email delivery, support, and error monitoring providers used to operate and support the Service.

Signals will give the Merchant notice before a new Sub-processor begins processing Personal Data. The Merchant may object on reasonable data protection grounds within 30 days of notice; if the parties cannot resolve the objection, the Merchant may terminate the affected part of the Service. To receive Sub-processor notices, write to privacy@signals.compass.st.

7. Security measures

Signals implements appropriate technical and organizational measures under Article 32 GDPR, including:

  • Tenant isolation, so each store's data is scoped to a single store identifier on every read and write.
  • Encryption of Personal Data in transit using TLS, and encryption at rest.
  • Least-privilege Shopify API scopes, disclosed at install.
  • Role-based access control, with production access restricted to named staff and protected by multi-factor authentication.
  • Logging of application, integration, and deployment activity.
  • Backups, and a documented restoration process.
  • Confidentiality obligations for all personnel with access to Personal Data.
  • Secure development practices, including code review and dependency monitoring.

Further detail is published on our security page. Signals may update these measures provided the level of protection is not reduced.

8. Data subject requests

Signals provides the Merchant with functionality to access, export, correct, and delete Personal Data within the Service, so that the Merchant can respond to Data Subject requests itself.

If Signals receives a request directly from a Data Subject relating to Merchant data, Signals will not respond substantively and will forward the request to the Merchant without undue delay. Signals will provide reasonable assistance, taking into account the nature of the processing, to help the Merchant meet its obligations under Articles 12 to 23 GDPR and its obligations regarding data protection impact assessments and prior consultation under Articles 35 and 36.

Requests received through Shopify's mandatory customer data request and redaction webhooks are actioned as required by the Shopify platform.

9. Personal Data Breach notification

Signals will notify the Merchant without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Merchant Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Signals will provide further information as the investigation progresses and will cooperate with the Merchant's own notification obligations.

10. Audits and information rights

Signals will make available to the Merchant the information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire and any third-party reports or certifications Signals holds.

Where the Data Protection Laws require an audit, the Merchant may conduct one no more than once per year, on at least 30 days' written notice, during business hours, at the Merchant's expense, subject to confidentiality, and conducted so as not to disrupt the Service or compromise the security of other customers' data. Additional audits may be conducted following a Personal Data Breach or where required by a supervisory authority.

11. International transfers

Personal Data may be processed in countries other than the country of collection. Where Signals transfers Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this DPA by reference. Module Two (controller to processor) applies between the Merchant as data exporter and Signals as data importer; Module Three (processor to processor) applies where the Merchant is itself a processor. The UK Addendum applies to UK transfers, and the Clauses apply with references to Swiss law and the Swiss Federal Data Protection and Information Commissioner for Swiss transfers.

The details in sections 3, 4, 6, and 7 of this DPA populate the corresponding annexes of the Standard Contractual Clauses. The governing law and forum are those specified in the Terms where permitted, and otherwise as required by the Clauses.

12. Deletion and return of data

During the term, the Merchant may export Personal Data at any time and may delete individual responses, whole surveys, or all data for the store.

On termination or expiry of the Terms, Signals will delete Merchant Personal Data within 90 days, unless the Merchant requests return of the data before deletion or Signals is required by law to retain it. Data removed from live systems is removed from backups as those backups expire on their normal schedule. Signals will confirm deletion in writing on request.

13. Term

This DPA takes effect when the Merchant accepts the Terms and continues for as long as Signals processes Personal Data on the Merchant's behalf, plus the deletion period in section 12. Obligations that by their nature should survive — including confidentiality, security, international transfer safeguards, and deletion — survive termination.

14. Contact

DPA questions, signed copies, Sub-processor notices, and audit requests: privacy@signals.compass.st.

Related documents: Privacy Policy, Terms of Service, Security & Privacy overview.