Privacy Policy

Last updated: [DATE]

Draft — not yet reviewed by a lawyer. This document was generated as a starting point. Every bracketed placeholder must be filled in, and the whole thing should be reviewed by a qualified solicitor or attorney before you take on a paying customer or process anyone's data under it. Delete this box once that's done.

1. Who we are

CX Signals is operated by [LEGAL ENTITY NAME], a company registered in [JURISDICTION] under company number [NUMBER], with its registered office at [REGISTERED ADDRESS] (“we”, “us”, “our”). We are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a customer, as set out in section 4.

For any privacy question, contact us at privacy@cx-signals.com.

2. What this policy covers

This policy covers the CX Signals website at cx-signals.com and the CX Signals application. It explains what personal data we collect, why, who we share it with, and what rights you have.

3. Data we collect about you directly

When you request access

If you submit the access request form, we collect and store:

We use this solely to respond to your enquiry and to assess whether the pilot is a fit for your team. The lawful basis is our legitimate interest in responding to business enquiries we have been asked to respond to. We do not add you to a marketing list or sell your details.

When you use the application

Accounts are created by invitation. Authentication is handled by Auth0, which stores your email address, name, and a hashed credential. We store your user identifier, email address, name, workspace membership, and a record of your activity in the product (accounts you track, analyses you run, ratings you give). The lawful basis is performance of our contract with you or your employer.

4. Data you put into the product

The core function of CX Signals is to monitor companies you tell it to monitor. The names and web domains of the companies in your book of business are stored in the product, along with any product context you supply.

Where that material contains personal data — for example the name of a contact at a customer company — we process it as a processor on your behalf, under your instructions. You remain the controller of that data and are responsible for having a lawful basis to put it into the product. [IF APPLICABLE: A data processing agreement is available on request and forms part of our contract with you.]

Separately, the product retrieves publicly published news and web content about the companies you track. That content may name individuals — for example an article reporting an executive appointment. We process such information because it is already in the public domain and because our customers have a legitimate interest in commercial developments affecting their business relationships.

5. Data we collect automatically

Our servers record standard technical logs, including IP address, browser user-agent, the pages or endpoints requested, and timestamps. We use these for security, abuse prevention, rate limiting, and diagnosing faults. We also use Sentry to capture application errors, which may incidentally include technical context about the request that failed.

Cookies. The marketing website sets no cookies and runs no analytics or advertising trackers. The application sets only the cookies strictly necessary to keep you signed in. [CONFIRM this remains true before launch — adding an analytics tool changes it and will require a consent banner in the UK/EU.]

6. Who we share data with

We do not sell personal data. We share it with the following service providers, who process it on our behalf:

ProviderPurposeLocation
Auth0 (Okta)Authentication and identity[REGION]
SupabaseDatabase hosting[REGION]
RailwayApplication and pipeline hosting[REGION]
CloudflareWebsite hosting and network securityGlobal edge
AnthropicLanguage model used to interpret signalsUnited States
ExaWeb and news searchUnited States
ResendEmail delivery for digests and notifications[REGION]
SentryError monitoring[REGION]

We may also disclose data where required by law, or to a successor entity in the event of a merger or acquisition.

Model providers. Content sent to Anthropic for interpretation is not used to train their models. [VERIFY this against the commercial terms in force for your account before publishing, and update if it changes.]

7. International transfers

Some of our providers are located outside [JURISDICTION]. Where personal data is transferred internationally, we rely on [Standard Contractual Clauses / UK International Data Transfer Agreement / adequacy decisions — SELECT AND CONFIRM] to protect it.

8. How long we keep it

9. Security

Data is encrypted in transit using TLS and at rest by our infrastructure providers. Access to production systems is restricted to those who need it. Authentication uses industry-standard tokens with short lifetimes. No system is perfectly secure, but we take the protection of your data seriously and will notify you and the relevant regulator of any breach affecting personal data within the timeframes the law requires.

10. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. To exercise any of these, email privacy@cx-signals.com. We will respond within one month.

If you are in the UK or EU and are unhappy with our response, you may complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

11. Children

CX Signals is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed. If a change materially affects your rights, we will notify account holders by email.

13. Contact

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
privacy@cx-signals.com