Legal / Privacy
Privacy notice
How we use personal information when you visit Signal OS, contact us or use a workspace. This notice distinguishes our own business records from information we process for customers.
Last updated 16 September 2026 · Revision 2026-09-16.v1Who we are and when this notice applies
Signal OS is operated by SCIALO CONSULTING LTD, company number 16357294, registered at 1st Floor Spitalfields House, Stirling Way, Borehamwood, Herts, England, WD6 2FX. Our UK VAT number is 493809938. Contact privacy@signaloshq.com about this notice.
We are the controller for website enquiries, subscriber records, account administration, billing references, support and service security. For personal information a business places in its workspace or asks us to process, that business normally decides the purposes and we act as its processor. Its privacy notice and our data processing addendum apply to that processing.
Information we receive
We receive names, job roles, business contact details, company information and correspondence you submit; account and workspace membership details; consent choices; billing references and subscription status; and records needed to investigate support or security matters. Paddle collects payment details for purchases through its checkout; Signal OS does not receive full card details.
Customer-directed workflows may process records imported or connected by the customer, signals, notes, messages and professional information found through public/business search. This can include names, job roles, public professional profiles and business contact details. Public availability does not remove an individual’s data-protection rights.
Our hosting and security providers process connection and device information, such as IP addresses, request details and browser information, to deliver and protect the service. Optional website statistics are described separately below.
Purposes and lawful bases
Enquiries and business account administration: we use contact information to respond, provide access and manage our relationship. The basis is taking steps towards or performing a contract where you are the contracting individual, or our legitimate interests in communicating with and serving the organisation you represent.
Security, fraud prevention, troubleshooting and support: we use relevant account, connection and case records for our legitimate interests in protecting users and operating a reliable service. Where a specific law requires retention or disclosure, the basis is compliance with that legal obligation.
Marketing email: we ask for consent for newsletter subscriptions and record confirmation and withdrawal. Optional website analytics: we rely on your consent and keep it off until you choose to accept. Refusing either does not prevent access to the website or ordinary service functions.
Accounting and legal matters: we retain necessary transaction and tax records to meet legal duties, and proportionate dispute records for our legitimate interests in establishing or defending claims. Customer workspace processing follows the customer’s instructions; the customer is responsible for its lawful basis and notices.
Optional website analytics
Optional analytics is off by default. If you accept through Cookie settings, we collect limited public-page and interaction statistics, coarse referral categories and approved campaign labels from the current page. The analytics store contains aggregate daily counts rather than a visitor profile or a history of one person’s browsing. We do not use these statistics for advertising or cross-site tracking.
You can refuse or withdraw consent through Cookie settings in the footer. We store your versioned preference for 180 days (about six months), then ask again; a material change to the consent request can also require a new choice. Global Privacy Control and Do Not Track signals keep optional analytics off. Ordinary hosting and abuse-prevention processing continues independently.
Intelligence and connected services
When a customer runs an intelligence task, relevant business context and evidence may be sent to search, enrichment or AI providers for retrieval, analysis or draft generation. We limit information to the task and apply the configured routing restrictions. AI output can be incomplete or wrong and requires human review before use.
OpenRouter routes configured model requests to downstream providers. A separate public-information categorisation route is restricted to organisation or building information and excludes personal and customer-confidential content. Provider terms and handling differ by route; we do not make a blanket promise that every provider has identical retention or training settings.
Customer-selected CRM, mailbox and calendar connections operate within the permissions and workflows the customer enables. Their providers also have their own terms and privacy notices.
Recipients and independent payment processing
We use service providers for hosting, database operations, email, security, search and configured intelligence workflows. Authorised personnel receive access needed to operate or support the service. Professional advisers, regulators or law-enforcement bodies may receive information where necessary and lawful.
Paddle acts as Merchant of Record and an independent controller for its payment, tax, fraud and buyer-support activities. We receive the billing information needed to administer your subscription. We do not sell personal information or use advertising trackers on this website.
International processing
Our suppliers operate internationally, including in the United States. Do not assume that a UK-registered operator means all processing takes place in the UK. The provider schedule distinguishes known locations from services whose location depends on configuration.
Where a restricted transfer requires safeguards, the relevant arrangement must use an applicable adequacy decision or contractual transfer mechanism, with additional protections where needed. Contact privacy@signaloshq.com for the safeguard relevant to your workspace and a copy or description of the applicable terms. Discuss any location restriction with us before providing affected data.
Retention and deletion
Our retention schedule calls for unconfirmed newsletter requests to be removed after 30 days; inactive subscriber records to be reviewed after 24 months; and ordinary unsubscribed profiles to be erased within 30 days, while retaining minimum suppression and consent evidence needed to respect your choice.
General enquiry and support records are scheduled for 24 months after closure. Privacy, material security and legal cases, and financial records, may be retained for six years or longer where a legal obligation or active claim requires it. Expired trial and unsuccessful checkout records are scheduled for 90 days. Operational delivery records are scheduled for minimisation after 90 days; optional aggregate website counts are retained for up to 25 months.
After paid access ends, the documented workspace schedule provides a read-only export period through day 30, a recovery period through day 89 and eligibility for reviewed deletion from day 90. Deletion depends on identity checks, entitlement status, legal holds and operational review; eligibility is not a promise of automatic deletion on that date. Contact us for a return or erasure request. Backups and provider logs have separate operational lifecycles; we do not claim immediate removal from every backup.
Your rights and requests
Depending on the law and circumstances, you can request access, correction, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent. Withdrawal does not affect processing that was lawful before it. Unsubscribe from marketing using the link in the message and change analytics consent through Cookie settings.
Email privacy@signaloshq.com or use our privacy request page. We may ask for proportionate identity or authority evidence. An email link alone does not authorise disclosure or deletion of an organisation’s workspace. If we process information for a customer, we will help route the request to that customer.
We aim to handle requests within our 28-day internal target and will explain any lawful extension or reason we cannot fulfil a request. You can complain to the UK Information Commissioner’s Office or the supervisory authority available under your local law.
Make a privacy requestContact privacy supportUK Information Commissioner’s Office
Children, required information and changes
Signal OS is intended for business users and is not directed at children. Please do not provide children’s information or sensitive personal information unnecessary for the agreed service. Without information needed to create or secure an account, we may be unable to provide the requested function.
We update this notice as the service changes and show the publication date above. Material changes affecting an existing customer relationship will be communicated through an appropriate service channel. A revised notice does not replace consent where new consent is required.