Legal
Data Processing Addendum
Effective August 1, 2026
This Addendum governs SiteSignal's processing of personal data on behalf of customers. It is published so procurement teams can review it before a call, rather than waiting on a PDF request.
1.Roles of the parties
For personal data contained in customer project data, the Customer is the controller (or, where the Customer is itself acting as a processor for another entity, the processor) and SiteSignal is the processor (or subprocessor). SiteSignal processes personal data only on the Customer's documented instructions.
The Customer's instructions are: (a) these Terms and this Addendum, (b) any signed order form or MSA, and (c) the configuration choices the Customer makes in the application, such as which users hold which roles, which addresses receive alerts and reports, and whether AI features are enabled.
SiteSignal acts as an independent controller only for a narrow set of data: account administration records, billing contacts, and marketing site inquiries. That processing is described in the Privacy Policy.
SiteSignal will inform the Customer if, in its opinion, an instruction infringes applicable data protection law, and will not sell personal data or process it for its own purposes outside these instructions.
2.Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the SiteSignal construction portfolio risk platform. |
| Duration | The term of the subscription, plus up to 30 days for deletion or return. |
| Nature and purpose | Hosting, storage, retrieval, display, transmission, analysis, audit logging, backup, email delivery, and AI-assisted narrative generation. |
| Types of personal data | Names, work email addresses, job titles, roles, organization affiliation, authentication metadata, IP addresses, audit log entries, and any personal data the Customer chooses to enter in free-text project fields (for example, subcontractor contact details). |
| Categories of data subjects | Customer's employees and authorized users; subcontractor, vendor, and project stakeholder contacts entered by the Customer. |
| Special categories | None. The service is not designed for special category data and Customers should not enter it. |
| Frequency | Continuous for the duration of the subscription. |
3.Security measures
SiteSignal maintains technical and organizational measures appropriate to the risk, including at minimum:
- Encryption: TLS 1.3 in transit; AES-256 at rest for the database and backups.
- Tenant isolation: row-level security policies enforced in Postgres so a query cannot return another organization's rows, in addition to server-side organization scoping in application code.
- Access control: role-based permissions (Admin, Project Manager, Executive, Viewer) enforced server-side on every request; organization-enforced multi-factor authentication available; SSO available for Enterprise where configured.
- Least privilege: internal administrative access is limited to personnel with a documented need and is logged.
- Audit logging: immutable, timestamped records of create and update operations with before and after values, exposed to Customer admins in the application.
- Resilience: managed database with point-in-time recovery and encrypted backups on a rolling 30-day window.
- Secure development: code review before merge, dependency monitoring, and automated checks (lint, type check, build, tenant isolation tests) in continuous integration.
- Personnel: confidentiality obligations for everyone with access to customer data.
Our current compliance posture, including the SOC 2 timeline, is stated plainly on the Security page. SiteSignal will not materially reduce these measures during a paid term.
4.Subprocessors
The Customer provides general written authorization for SiteSignal to engage the subprocessors listed below. Each subprocessor is bound by a written contract imposing data protection obligations no less protective than this Addendum, and SiteSignal remains liable for their performance.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Managed Postgres database, authentication, and storage | Account data and all customer project records | United States |
| Vercel | Application hosting, edge network, and request logging | Request metadata, IP addresses, and data in transit | United States |
| Resend | Transactional email delivery (alerts, reports, invitations) | Recipient email addresses and message contents | United States |
| Anthropic | AI risk narratives, recovery plan drafts, and status reports | Aggregated project metrics; no intentional PII | United States |
SiteSignal will give at least 30 days' notice before adding or replacing a subprocessor to Customers who subscribe to notifications at privacy@getsitesignal.io. The Customer may object on reasonable data protection grounds within that window; if the parties cannot resolve the objection, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid unused fees.
5.International transfers
Personal data is hosted in the United States. Where the transfer of personal data from the European Economic Area, United Kingdom, or Switzerland is subject to applicable data protection law, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor, or Module Three where the Customer is itself a processor) are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies.
Supplementary measures include encryption in transit and at rest, strict access controls, and a commitment to challenge and to notify the Customer of any government access request unless legally prohibited.
6.Personal data breach notification
SiteSignal will notify the Customer without undue delay and, as an operational goal, within 72 hours of becoming aware of a personal data breach affecting the Customer's personal data.
Notification will be sent to the Customer's admin contacts and will include, to the extent known:
- The nature of the breach, including categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- Measures taken or proposed to address the breach and mitigate adverse effects.
- A contact point for further information.
Where full details are not available within the initial window, SiteSignal will provide information in phases as the investigation progresses, and will reasonably assist the Customer with its own notification obligations to supervisory authorities and data subjects. Notification is not an acknowledgment of fault.
7.Assistance and data subject requests
Taking into account the nature of the processing, SiteSignal will assist the Customer with:
- Responding to data subject requests for access, correction, deletion, restriction, portability, and objection. Most requests can be satisfied directly by Customer admins through in-product export, edit, and deactivate controls.
- Data protection impact assessments and prior consultations with supervisory authorities, by supplying information about our processing and security measures.
- Forwarding to the Customer, without undue delay, any request received directly from a data subject relating to Customer data, rather than responding to it ourselves.
8.Audit rights
SiteSignal will make available to the Customer information reasonably necessary to demonstrate compliance with this Addendum, including completed security questionnaires (SIG Lite, CAIQ, or a customer template), our current security documentation, and, once issued, our SOC 2 report.
- Documentation first: audit obligations are satisfied in the first instance by the documentation above, provided within a reasonable period of a written request.
- On-site or third-party audit: where documentation is insufficient to demonstrate compliance, the Customer may audit once per twelve months, on at least 30 days' written notice, during business hours, under confidentiality, and without unreasonably disrupting operations.
- Regulatory audits: additional audits required by a supervisory authority are permitted as directed by that authority.
- Costs: each party bears its own costs; SiteSignal may charge reasonable fees for audit support exceeding one business day of effort.
- Scope: audits may not include access to other customers' data, systems, or personnel.
9.Deletion and return of data
Throughout the subscription, Customer admins can export all organization records as CSV from the application at any time, at no charge.
On termination or expiry, at the Customer's election, SiteSignal will delete or return customer personal data within 30 days of a written request, and will delete existing copies unless retention is required by law. Encrypted backups containing customer data are overwritten on a rolling 30-day cycle; data in backups remains protected by this Addendum until overwritten.
Absent a request, SiteSignal will delete customer data 90 days after termination.
10.Liability
Each party's liability under this Addendum is subject to the exclusions and limitations of liability set out in the Terms of Service or the applicable master services agreement. Liability under the Terms and under this Addendum is aggregated and applies once in total, not cumulatively across documents.
Nothing in this Addendum limits a data subject's rights under the Standard Contractual Clauses or any liability that cannot be limited by applicable law.
11.Execution and order of precedence
This Addendum forms part of and is incorporated into the Terms of Service. Where a signed MSA or negotiated DPA exists between the parties, that document controls over this page.
Need a countersigned copy for your procurement file, or your own DPA template reviewed? Email legal@getsitesignal.io and we will return an executed version.
Need this signed? Email legal@getsitesignal.io with your entity name and signing contact and we will return a countersigned DPA, typically within one business day.
Related documents