Data Processing Addendum
Signal Loom Inc., EAP customers, EU/UK/US
Version 1.3 · Effective 8 September 2026
Parties
This Data Processing Addendum (“DPA”) is entered into between Signal Loom Inc., a Delaware corporation with its principal place of business in the United States (“Signal Loom” or “Processor”), and the customer entity that has accepted the applicable Signal Loom Terms of Service (“Customer” or “Controller”).
This DPA forms part of, and is subject to, the Terms of Service and (where applicable) the EAP Order Terms between Signal Loom and Customer. In the event of conflict between this DPA and those agreements on a data-protection matter, this DPA controls.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Law.
“Data Protection Law” means, as applicable to the processing in question: (a) the EU General Data Protection Regulation (EU 2016/679) (“GDPR”); (b) the UK GDPR and Data Protection Act 2018; (c) the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”); and (d) any other applicable privacy or data protection legislation in force from time to time.
“Submitted Data” has the meaning given in the applicable Terms of Service: data, credentials, configurations, or environment details submitted by Customer to the Service.
“Controller,” “Processor,” “Data Subject,” “Processing,” and “Supervisory Authority” each have the meaning given under applicable Data Protection Law.
“Sub-processor” means any third-party processor engaged by Signal Loom to process Personal Data under this DPA.
“EU Data” means Personal Data of Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland.
“Service” has the meaning given in the applicable Terms of Service.
2. Scope, Role, and Nature of Processing
Signal Loom's service is designed for business-to-business use. The primary subject matter of processing is organizational and technical data (cloud account identifiers, API credentials, agent configuration metadata, NHI inventory data). To the extent that Submitted Data or account registration data includes Personal Data, for example, the name and email address of the individual who registers and administers the Customer tenant, Signal Loom processes that Personal Data as a Processor acting on behalf of Customer as Controller.
Signal Loom does not process Personal Data beyond what is necessary to deliver the Service and perform its obligations under the applicable Terms of Service.
The subject matter, duration, nature, and purpose of processing, the type of Personal Data, and the categories of Data Subjects are set out in Schedule 1 (Processing Details) to this DPA.
3. Controller Obligations
Customer, as Controller, represents and warrants that: (a) it has a lawful basis for instructing Signal Loom to process Personal Data; (b) it has provided all required notices and obtained all required consents from Data Subjects in connection with the use of the Service; and (c) its instructions to Signal Loom comply with applicable Data Protection Law.
4. Signal Loom's Processor Obligations
Signal Loom shall:
- Process Personal Data only on documented instructions from Customer, including as set out in the applicable Terms of Service, except where required to do so by applicable law;
- Ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations;
- Implement the technical and organizational security measures described in Section 5 of this DPA;
- Assist Customer in responding to Data Subject rights requests under applicable Data Protection Law, to the extent technically feasible and within Signal Loom's control;
- Assist Customer in meeting its obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation) to the extent the information required is available to Signal Loom;
- Delete or return all Personal Data to Customer within 30 days of termination of the Service, in accordance with Section 11 of this DPA and the data-retention schedule in the applicable Privacy Policy;
- Make available to Customer all information necessary to demonstrate compliance with this DPA, and permit and contribute to audits in accordance with, and subject to the limitations of, Section 12 of this DPA.
5. Technical and Organizational Security Measures
Signal Loom implements commercially reasonable technical and organizational security measures, including:
- Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256);
- Strict access controls and role-based permissions for Signal Loom personnel;
- Submitted Data processed in isolated, ephemeral compute environments;
- Regular security assessments and vulnerability management.
Signal Loom may update these measures from time to time, provided that updates do not materially reduce the level of protection. Customer may request the current list of measures by contacting security@signal-loom.ai.
6. Sub-processors
Customer provides general authorization for Signal Loom to engage sub-processors to assist in delivering the Service, subject to the conditions of this Section. Signal Loom shall: (a) ensure sub-processors are bound by data protection obligations no less protective than those in this DPA; (b) remain liable to Customer for the acts and omissions of its sub-processors to the same extent Signal Loom would be liable if performing the services itself.
Signal Loom will maintain a list of current sub-processors and make it available to Customer on request to gdpr@signal-loom.ai. Signal Loom will provide reasonable notice of any intended changes to the sub-processor list. If Customer reasonably objects to a new sub-processor on data-protection grounds, the parties will work in good faith to resolve the objection; if unresolved within 30 days, Customer may terminate the Service on written notice.
7. EU Data Residency
Signal Loom shall use commercially reasonable efforts to store and process EU Data on infrastructure located within the EEA or the United Kingdom. Where any transfer of EU Data outside those territories occurs, the safeguards in Section 8 apply.
Signal Loom's current EU infrastructure for EU Data is Microsoft Azure, West Europe region (Netherlands, EU). Signal Loom will notify Customer of any material change to the EU infrastructure location.
8. International Data Transfers
Where Signal Loom transfers EU Data to the United States or any other country outside the EEA, United Kingdom, or Switzerland, Signal Loom shall ensure that an appropriate transfer mechanism applies. Signal Loom relies on the European Commission's Standard Contractual Clauses (SCCs) as updated in Commission Implementing Decision (EU) 2021/914, Module 2 (Controller-to-Processor), as the primary safeguard for transfers to Signal Loom's service providers in the United States. For transfers of UK Personal Data, Signal Loom relies on the UK International Data Transfer Addendum to the SCCs issued under Section 119A of the UK Data Protection Act 2018; for transfers of Swiss Personal Data, Signal Loom applies the SCCs as amended in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC). For each material transfer destination, Signal Loom conducts a Transfer Impact Assessment (TIA) evaluating the laws and practices of the recipient country, the contractual, technical, and organizational supplementary measures applied, and the practical risks to the transferred data. The TIA is reviewed at least annually. A copy of the SCCs and a summary of the most recent TIA is available on request to gdpr@signal-loom.ai.
9. Data Subject Rights
If Signal Loom receives a request from a Data Subject exercising rights under applicable Data Protection Law (access, correction, deletion, portability, restriction, or objection), Signal Loom shall promptly forward the request to Customer. Customer is responsible for responding to Data Subject requests in respect of Personal Data that Customer controls. Signal Loom shall provide reasonable assistance to Customer in fulfilling such requests to the extent the relevant Personal Data is under Signal Loom's control.
10. Personal Data Breach Notification
Signal Loom shall notify Customer without undue delay of becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this DPA (a “Personal Data Breach”). Notification shall include, to the extent then known: (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects and records concerned; (c) the name and contact details of Signal Loom's data protection contact point; (d) the likely consequences of the breach; and (e) the measures taken or proposed to address the breach. Signal Loom shall cooperate with Customer and take such reasonable steps as directed by Customer to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
11. Retention and Deletion
Signal Loom retains Personal Data for the periods set out in the applicable Privacy Policy. Submitted Data and Service outputs are retained for the duration of the Customer's subscription and are deleted from production systems within 30 days of termination of the subscription or of a Customer deletion request; backup copies may persist up to 90 days. Account information is retained for the duration of the Customer relationship plus 12 months. Upon termination of the Service, Signal Loom shall, at Customer's election, delete or return all Personal Data within 30 days, except to the extent retention is required by applicable law. In the event of any conflict between this Section 11 and the data-retention schedule in the applicable Privacy Policy, this Section 11 controls with respect to Personal Data processed under this DPA.
12. Audit Rights
Customer may, on reasonable written notice (not less than 30 days) and no more than once per calendar year (unless a Personal Data Breach has occurred), audit Signal Loom's compliance with this DPA, either directly or through a mandated third-party auditor subject to appropriate confidentiality obligations, at Customer's reasonable cost. Signal Loom may satisfy the audit obligation by providing a current third-party audit report (SOC 2 Type II or equivalent), at Customer's reasonable request, in lieu of an on-site audit, where such report covers the relevant controls.
13. Governing Law
This DPA is governed by the laws of the State of Delaware, United States, subject to the mandatory provisions of applicable Data Protection Law. Nothing in this DPA overrides any right of a Data Subject or supervisory authority under applicable Data Protection Law.
14. Limitation of Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to, and counts toward, the limitations and exclusions of liability set out in the Terms of Service. This applies to the maximum extent permitted by applicable law and does not limit any liability that cannot be limited under applicable Data Protection Law.
Schedule 1 — Processing Details
The following details describe the processing carried out by Signal Loom as Processor under this DPA:
Subject matter of processing
Identity governance and Non-Human Identity (NHI) management for the Customer's cloud, agent, and directory infrastructure. Processing is incidental to the primary B2B service: the principal data processed is organizational and technical, not personal.
Duration of processing
For the term of the applicable Service agreement and the retention periods set out in Section 11 of this DPA.
Nature and purpose of processing
Execution of NHI discovery and governance operations; generation of identity inventory reports; account provisioning and authentication; security monitoring and incident response; service improvement using aggregated and anonymized data.
Types of Personal Data
Account registration data: name, business email address, job title (where provided). Usage and technical data: IP address, browser/device characteristics, interaction logs. Communications: content of support or legal inquiries. Submitted Data: to the extent it contains Personal Data of natural persons (e.g., names or emails embedded in credential metadata), it is processed solely to perform the operations the Customer authorizes.
Categories of Data Subjects
Employees, contractors, and administrators of the Customer entity who register for or use the Service. Potentially, natural persons whose identifiers appear incidentally in Submitted Data (e.g., named service accounts).
Processing locations
United States (primary infrastructure). For EU Data, currently: Microsoft Azure, West Europe region (Netherlands, EU). Signal Loom uses commercially reasonable efforts to maintain EU Data on EEA/UK infrastructure and will notify Customer of any material change to this location.