Data Protection
Last updated: 18 September 2026
1. Scope
This page explains how SignalKit handles personal data under the EU and UK GDPR and equivalent laws. It supplements our Privacy Policy, which describes what we collect and with whom it is shared, including the data we obtain through Google APIs.
2. Controller and processor roles
For accounts on signalkit.ai, SignalKit is the data controller for account data (email, name, billing references, settings) and for the usage analytics on our own site. SignalKit is a data processor for the brands, prompts and domains you submit for tracking, and for the data read from integrations you connect — Google Analytics, Google Search Console, Cloudflare, and the public Slack channel names the Slack app lists so you can choose one (it reads no messages) — which you control and can disconnect at any time.
3. Lawful basis
We process personal data on the basis of: (a) contract performance — to deliver the service you signed up for, including reading the integrations you connect; (b) legitimate interest — for product analytics, fraud prevention and security; (c) consent — where required for marketing communications, and for the Google API access you grant on Google's consent screen; (d) legal obligation — for tax and accounting records.
4. Subprocessors
SignalKit uses the following subprocessors. We review each annually and require equivalent data protection commitments. Logs and traces are kept on our own servers and are not on this list.
- Neon — managed PostgreSQL database
- Hetzner — application hosting (Germany)
- Clerk — authentication and account identity
- Stripe — payment processing; card details never reach SignalKit
- OpenAI, Anthropic, Google (Gemini), xAI, Perplexity, and Z.AI — AI providers used for measurement or content generation. A customer-key content call goes directly to the provider selected by your account. Content calls can include brand material and page evidence you provide.
- SerpAPI — Google AI Overviews retrieval; receives prompt text only
- Cloudflare — AI request routing (AI Gateway) and DeepSeek model hosting, edge proxy and TLS termination for public sites, Turnstile abuse prevention for free audits, and crawl data only if you connect the integration using credentials you supply.
- Inngest — background jobs
- Resend — transactional email (alerts, digests)
- Sentry — error monitoring
- PostHog — product analytics (EU hosting)
- Google Analytics 4 — usage analytics for signalkit.ai
- DataForSEO — search-volume data, and a weekly Google search for each tracked prompt's search keyword to see whether an AI Overview shows and whom it cites. It receives the keyword, country and language; no customer account data is sent.
- Google (Analytics and Search Console APIs) — only if you connect an integration, and only to read your own property's data using the access you grant. Google is the source of that data, not a recipient of it.
5. Data retention
Account data is retained for as long as your account exists. Measurements are retained for as long as the project they belong to exists. Google Search Console data is kept for 90 days on a rolling basis; raw AI traffic pixel visits for 30 days; Google Analytics summaries and Cloudflare crawl history for the life of the project. Database backups are kept daily for 14 days and weekly for a further 8 weeks. Disconnecting an integration deletes its stored credential immediately. Deleting a project deletes its data. When you ask us to close your account, processing stops at once and your data is deleted within 30 days, except invoices and records we must keep by law.
6. International transfers
The application and its database backups run on Hetzner in Germany; product analytics go to PostHog's EU region. Neon (database), Clerk, Stripe, Inngest, Resend, Sentry, Google, SerpAPI, Cloudflare and the AI platforms we query may process data in the United States or other countries outside the EU/UK. Where they do, the transfer is covered by the EU Standard Contractual Clauses, the UK addendum, or the EU-US Data Privacy Framework where the provider is certified. We send measurement prompts — never your account email or identifiers — to the AI platforms. Content-generation prompts include the brief and selected supporting evidence, and go to Anthropic and OpenAI through Cloudflare AI Gateway on the managed plan, or to OpenAI, Anthropic or Z.AI directly under a key you supply. The Google Analytics site-audit summary and any Google measurements you separately permit for content AI are described in the Privacy Policy.
7. Your rights (EU/UK)
You have the right to access, rectify, erase, restrict processing, object to processing, and request portability of your personal data, and to withdraw consent where processing rests on it. To exercise these rights, email hello@signalkit.ai and we will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority.
8. Data processing agreement
We sign DPAs on request for paid plans. Email hello@signalkit.aiwith your company name and we'll send our standard DPA for counter-signature.
9. Security
All data is encrypted in transit (TLS 1.2+) and at rest. Integration tokens are encrypted with AES-256-GCM before storage, using a key held outside the database; API keys are stored as one-way hashes. Every query is scoped to the account making it. Access to production systems is limited to named engineers over an identity-bound private network; there is no public SSH. Backups are integrity-checked when they are taken. We notify affected customers of a personal-data breach without undue delay, as Articles 33 and 34 GDPR require.
10. Contact
For data protection inquiries: hello@signalkit.ai.