Privacy Policy
Last updated: [DATE]
Draft — not yet reviewed by a lawyer. This document was generated as a starting point. Every bracketed placeholder must be filled in, and the whole thing should be reviewed by a qualified solicitor or attorney before you take on a paying customer or process anyone's data under it. Delete this box once that's done.
1. Who we are
CX Signals is operated by [LEGAL ENTITY NAME], a company registered in [JURISDICTION] under company number [NUMBER], with its registered office at [REGISTERED ADDRESS] (“we”, “us”, “our”). We are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a customer, as set out in section 4.
For any privacy question, contact us at privacy@cx-signals.com.
2. What this policy covers
This policy covers the CX Signals website at cx-signals.com and the CX Signals application. It explains what personal data we collect, why, who we share it with, and what rights you have.
3. Data we collect about you directly
When you request access
If you submit the access request form, we collect and store:
- Your name
- Your work email address
- Your company name
- Your team size, if you provide it
- Any message you choose to write
- The date and time of your submission
We use this solely to respond to your enquiry and to assess whether the pilot is a fit for your team. The lawful basis is our legitimate interest in responding to business enquiries we have been asked to respond to. We do not add you to a marketing list or sell your details.
When you use the application
Accounts are created by invitation. Authentication is handled by Auth0, which stores your email address, name, and a hashed credential. We store your user identifier, email address, name, workspace membership, and a record of your activity in the product (accounts you track, analyses you run, ratings you give). The lawful basis is performance of our contract with you or your employer.
4. Data you put into the product
The core function of CX Signals is to monitor companies you tell it to monitor. The names and web domains of the companies in your book of business are stored in the product, along with any product context you supply.
Where that material contains personal data — for example the name of a contact at a customer company — we process it as a processor on your behalf, under your instructions. You remain the controller of that data and are responsible for having a lawful basis to put it into the product. [IF APPLICABLE: A data processing agreement is available on request and forms part of our contract with you.]
Separately, the product retrieves publicly published news and web content about the companies you track. That content may name individuals — for example an article reporting an executive appointment. We process such information because it is already in the public domain and because our customers have a legitimate interest in commercial developments affecting their business relationships.
5. Data we collect automatically
Our servers record standard technical logs, including IP address, browser user-agent, the pages or endpoints requested, and timestamps. We use these for security, abuse prevention, rate limiting, and diagnosing faults. We also use Sentry to capture application errors, which may incidentally include technical context about the request that failed.
Cookies. The marketing website sets no cookies and runs no analytics or advertising trackers. The application sets only the cookies strictly necessary to keep you signed in. [CONFIRM this remains true before launch — adding an analytics tool changes it and will require a consent banner in the UK/EU.]
6. Who we share data with
We do not sell personal data. We share it with the following service providers, who process it on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Auth0 (Okta) | Authentication and identity | [REGION] |
| Supabase | Database hosting | [REGION] |
| Railway | Application and pipeline hosting | [REGION] |
| Cloudflare | Website hosting and network security | Global edge |
| Anthropic | Language model used to interpret signals | United States |
| Exa | Web and news search | United States |
| Resend | Email delivery for digests and notifications | [REGION] |
| Sentry | Error monitoring | [REGION] |
We may also disclose data where required by law, or to a successor entity in the event of a merger or acquisition.
Model providers. Content sent to Anthropic for interpretation is not used to train their models. [VERIFY this against the commercial terms in force for your account before publishing, and update if it changes.]
7. International transfers
Some of our providers are located outside [JURISDICTION]. Where personal data is transferred internationally, we rely on [Standard Contractual Clauses / UK International Data Transfer Agreement / adequacy decisions — SELECT AND CONFIRM] to protect it.
8. How long we keep it
- Access requests: [24 months] from submission, then deleted.
- Account data: for as long as your account is active, and [90 days] after it closes.
- Signals and analysis output: for as long as the associated account is tracked in your workspace.
- Billing records: [7 years], as required for tax and accounting purposes.
- Technical logs: [30 days].
9. Security
Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production systems is restricted to those who need it. Authentication uses industry-standard tokens with short lifetimes. No system is perfectly secure, but we take the protection of your data seriously and will notify you and the relevant regulator of any breach affecting personal data within the timeframes the law requires.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. To exercise any of these, email privacy@cx-signals.com. We will respond within one month.
If you are in the UK or EU and are unhappy with our response, you may complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
11. Children
CX Signals is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. If a change materially affects your rights, we will notify account holders by email.
13. Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
privacy@cx-signals.com