Skip to content
Signal OS
How it worksFor PropTechIntegrationsInsightsPricingSecurityContact
Sign in

Cookie settings

Choose whether to allow optional analytics. Rejecting it will not affect browsing, forms or checkout. You can change your choice here at any time.

Essential

Always on

Storage and services needed for security, requested services and remembering your privacy choice. These are separate from optional analytics and cannot be switched off here.

First-party aggregate counts of page views and actions help improve Signal OS. We do not use advertising trackers, cross-site profiles or visitor identifiers for this measurement.

We remember your choice in this browser for up to 180 days. Cookie notice · Privacy notice

Legal / Data processing

Data processing addendum

The processing terms offered for personal data in a Signal OS customer workspace. This addendum applies when incorporated into your organisation’s service agreement or order.

Last updated 16 September 2026 · Revision 2026-09-16.v1

On this page

  1. Parties, roles and scope
  2. Processing particulars
  3. Instructions and customer responsibilities
  4. Confidentiality and security
  5. Subprocessors and changes
  6. Rights requests and assistance
  7. Transfers and information for review
  8. Return, deletion and the end of processing

Parties, roles and scope

The customer is controller and SCIALO CONSULTING LTD is processor of personal data handled on the customer’s behalf in Signal OS. If the customer is itself a processor, it must have its controller’s authority and the corresponding obligations apply to us as a subprocessor. Each party remains responsible for the duties applicable data-protection law places on it.

This addendum concerns customer workspace processing. Our independent account, billing, support and security records are addressed in the privacy notice. An expressly agreed customer-specific processing addendum takes precedence over this text. A published copy does not by itself establish that an agreement has been executed with a particular customer.

Processing particulars

The subject matter is delivery of the customer’s Signal OS workspace. Processing lasts for the service term and the period necessary to return or delete data under the agreement. Operations include receiving, storing, organising, searching, analysing, drafting, displaying, exporting and deleting information as instructed.

The purposes are signal research, workflow coordination, customer-authorised integrations, reporting and service support. Data can include names, business contact details, job roles, professional profiles, correspondence, notes, account identifiers and activity records. Data subjects include the customer’s users, colleagues, prospects, customers, suppliers and professional contacts. Special-category data and children’s data are not required for ordinary use.

Instructions and customer responsibilities

We process customer personal data only on documented instructions, including the agreement, authorised workspace actions and recorded support requests. The customer determines lawful purposes, provides required notices and permissions, and controls who may issue instructions.

We will tell the customer if we consider an instruction to infringe applicable data-protection law and may suspend the affected operation while it is resolved. If law requires processing outside the instructions, we will inform the customer before processing unless the law prohibits that notice.

Confidentiality and security

People authorised to process customer data must be subject to confidentiality duties. Access is limited to the work they need to perform. We apply measures appropriate to the risks, including the controls described in the security schedule, and maintain the protection of data through relevant service changes.

Technical and organisational measures

Subprocessors and changes

When this addendum is incorporated, the customer gives general authorisation for the applicable subprocessors identified in the provider schedule. We impose equivalent relevant data-protection obligations and remain responsible for the obligations we delegate.

We will give the customer’s nominated contact advance notice of a proposed new or replacement subprocessor and a reasonable opportunity to object on data-protection grounds. Send objections to privacy@signaloshq.com. We will discuss a reasonable alternative or cessation of the affected processing before the change where required; emergency security changes will be communicated as soon as practicable.

Provider schedule

Rights requests and assistance

Taking account of the processing and information available, we will assist with individuals’ rights requests, security obligations, impact assessments and prior consultation. We refer requests about customer-controlled information to the customer and do not disclose workspace content on the strength of an email token alone.

We will notify the customer without undue delay after becoming aware of a personal-data breach affecting its data. Available information will cover the nature and likely consequences, affected records or people where known, response measures and a contact for follow-up; information may be supplied in stages. The customer remains responsible for its own notification decisions.

Transfers and information for review

International transfers made on the customer’s behalf must follow its documented instructions and applicable transfer requirements. Where needed, the parties must put an applicable adequacy basis or recognised contractual mechanism and supplementary measures in place. Contact us for the terms and locations relevant to the proposed processing.

We will make information needed to demonstrate compliance available and allow and contribute to proportionate audits or inspections by the customer or its appointed auditor. Arrangements must protect other customers and confidential information without preventing required oversight.

Return, deletion and the end of processing

At the customer’s choice, we will return or delete customer personal data at the end of processing and delete remaining copies, unless law requires retention. Requests are verified and carried out through the available export and reviewed deletion process; the default recovery schedule does not remove the customer’s right to give a lawful instruction.

Where immediate deletion from a backup is not practical, retained copies must be protected from ordinary use and removed through the applicable backup lifecycle. Necessary legal records remain restricted to their retention purpose. Contact privacy@signaloshq.com to agree the return format, timing and any retained-data explanation.

Policies and trust

Privacy NoticeWebsite, Trial and Subscription TermsCookie NoticeTechnical and Organisational MeasuresSubprocessor ScheduleRefund PolicyExercise your privacy rights
Signal OS

The commercial real estate signal-to-action workspace for PropTech sales teams.

Signal OS is owned and operated by SCIALO CONSULTING LTD.

ProductFor PropTech sales teamsBuilding energy and controlsProperty operationsWorkplace and occupancyIntegrationsPricing
ResourcesCRE buying signals guideCRE signal insightsSignal OS and your CRMSecurityProof of SignalContact
CompanyCompany and ownershipPrivacy noticePrivacy rightsTermsRefund policyCookiesCookie settingsDPASecurity measuresSubprocessors

© 2026 SCIALO CONSULTING LTD. Registered in England and Wales under company number 16357294. Registered office: 1st Floor Spitalfields House, Stirling Way, Borehamwood, Herts, England, WD6 2FX. VAT registration number: 493809938.