Privacy Policy
Signal Loom Inc., website, platform, and Early Access Program
Version 1.3 · Effective 8 September 2026
Signal Loom Inc. collects the minimum information needed to operate the Signal Loom platform and to bill for it. We do not sell your personal data, your configuration data, or the outputs the platform generates for you. This policy explains what we collect, why, how long we keep it, and what rights you have.
1. Who We Are
Signal Loom Inc. is the identity control plane for the enterprise agent era, governing Non-Human Identities (NHIs) at the credential layer across cloud, agent, and directory infrastructure.
Signal Loom Inc. is the controller of the personal data described in this Policy.
Business and mailing address: Signal Loom Inc., 2810 N Church St NUM 526509, Wilmington, DE 19802, United States.
Registered office: 131 Continental Drive, Suite 305, Newark, DE 19713, United States.
Data protection contact
For all data protection and privacy matters, including requests under the GDPR, the UK GDPR, or the California Consumer Privacy Act as amended by the CPRA, contact us at gdpr@signal-loom.ai.
Signal Loom Inc. carries out part of its activities from France. Data subjects in the European Economic Area, the United Kingdom, and Switzerland may use the address above for all data protection matters, and we will respond within the periods set out in Section 8.
You also have the right to lodge a complaint with your local data protection supervisory authority. You are not required to contact us first.
2. Scope of This Policy
This Policy applies to personal data collected through:
- the Signal Loom website at signal-loom.ai, including the sign-up and checkout flow;
- the Signal Loom platform and any tenant provisioned for your organization, including the Early Access Program (EAP);
- any downloadable agents, connectors, or integrations we provide; and
- communications with us about any of the above.
Where Signal Loom processes personal data on behalf of a customer organization, that processing is additionally governed by the Data Processing Addendum (DPA), which forms part of the agreement between us. Where this Policy and the DPA differ on a data protection matter, the DPA controls.
This Policy does not apply to third-party websites or services linked from our properties.
3. Information We Collect
3.1 Account and Registration Information
When you sign up, we collect:
- Name and business email address
- Company or organization name
- Job title or role, where provided
- Account credentials (passwords are stored only as a salted cryptographic hash, never in plaintext)
3.2 Payment Information
Payments are processed by Stripe, Inc. Card details are entered on a payment page hosted by Stripe. Signal Loom Inc. does not receive, process, or store full payment card numbers, card security codes, or authentication data.
Stripe acts as our processor when it completes the transactions we instruct, and as a controller in its own right for fraud detection and prevention, compliance with legal and anti-money-laundering obligations, and improving its own services. Stripe's handling of your data is described in its privacy policy at stripe.com/privacy.
Through our Stripe account we hold:
- Billing name, billing email address, and any billing address collected at checkout
- Stripe customer and subscription identifiers
- The card brand and the last four digits, for support and reconciliation
- Invoice, charge, refund, and subscription status records
Within the Signal Loom platform itself we store only your billing email address and the Stripe customer identifier. The remaining records above are held in our Stripe account.
We use this information to take the payment you authorize, to bill the recurring subscription described in the EAP Order Terms, to issue invoices and receipts, and to meet our tax and accounting obligations.
Because the Early Access Program converts to a paid subscription, the payment method you provide is stored by Stripe in tokenized form and used for the recurring charges described in the EAP Order Terms. It is retained for as long as your subscription is active, and afterwards for the period required to handle refunds, chargebacks, and tax and accounting obligations. The commercial terms of that conversion, including the price, the timing, and how to cancel, are set out in the EAP Order Terms rather than in this Policy.
Payment data may be transferred to, processed, and stored in the United States and other countries outside your country of residence, where it may be subject to disclosure as required by law.
3.3 Connected Environments and Submitted Data
To operate the platform, you may submit or connect:
- API tokens, OAuth credentials, or read-only access keys scoped to the environment you authorize us to govern
- Cloud account identifiers (for example AWS Account ID, Azure Tenant ID, GCP Project ID)
- Directory or identity provider configuration details
- Agent framework configuration metadata (for example MCP server endpoints, A2A relay addresses)
We process this data solely to deliver the Service to you. We do not use access credentials for any purpose other than performing the operations you authorize.
The data in this category is predominantly organizational and technical rather than personal. Where it incidentally contains personal data, for example a person's name or email embedded in credential metadata, we process it only to perform the authorized operation.
3.4 Platform Outputs
The Service generates an inventory of discovered Non-Human Identities in your environment, together with metadata such as credential types, expiration dates, permission scopes, and risk indicators, and a record of any governance actions taken on them.
Outputs specific to your environment are your data.
3.5 Usage and Technical Data
We automatically collect:
- IP address and approximate geolocation (country or region)
- Browser type, operating system, and device characteristics
- Pages visited, features used, and interaction timestamps
- Configuration parameters, never credential values
- Error logs and performance telemetry
- Records of your acceptance of our legal terms, including which document versions you accepted, when, and a cryptographic hash of each document as it stood at that moment
3.6 Communications
If you contact us by email or through our website, we retain the content of those communications and your contact information to respond to your inquiry and improve our support.
4. How We Use Your Information
We use the information we collect to:
- Provide the Service: Provision and operate your tenant, execute the governance operations you authorize, and deliver outputs to you.
- Manage your account: Create and maintain your account, authenticate you, and send transactional messages.
- Bill for the Service: Take the payment you authorize, manage your subscription, issue invoices, and handle cancellations and refunds.
- Maintain security and prevent fraud: Detect, investigate, and prevent unauthorized access, abuse, or violations of our Terms of Service.
- Improve the Service: Analyze usage patterns, diagnose technical issues, and develop new features, using aggregated and anonymized data only.
- Meet legal obligations: Comply with applicable law, including tax and accounting obligations and responses to lawful requests from authorities.
- Communicate with you: Send transactional messages and, with your consent, product updates. You may opt out of non-transactional communications at any time.
We do not use your Submitted Data or platform outputs to train machine learning models without your explicit consent.
5. Legal Basis for Processing (EEA, UK, and Swiss Users)
We process your personal data on the following legal bases under Article 6(1) GDPR. Performance of a contract (Article 6(1)(b)): creating and managing your account, authenticating you, provisioning and operating your tenant, executing the operations you request, taking the payments you have authorized, and delivering outputs and transactional messages. Consent (Article 6(1)(a)): sending product or marketing updates, setting non-essential cookies, and any use of Submitted Data or platform outputs to train machine-learning models; you may withdraw consent at any time without affecting the lawfulness of prior processing. Compliance with a legal obligation (Article 6(1)(c)): meeting tax, accounting, and lawful-request obligations. Legitimate interests (Article 6(1)(f)): the specific interests described below. Where a purpose could rest on more than one basis, we rely on the basis stated here for that purpose.
Where we rely on Article 6(1)(f) GDPR legitimate interests as our lawful basis for processing your personal data, the specific interests we rely on are:
- Providing and improving the Service, operating the platform, generating outputs, and evolving the product based on aggregate usage patterns and customer feedback.
- Platform security and fraud prevention, rate-limiting, abuse detection, and maintaining audit logs for SOC 2 compliance and incident response.
- Responding to user-initiated inquiries, answering questions submitted by email or through in-product support.
- Business operations, billing, accounting, and compliance reporting.
- Maintaining a record of contract formation, retaining evidence of which version of our terms you accepted and when, so that both parties can establish what was agreed.
You may object to processing based on legitimate interests at any time as described in Section 8 (Your Rights).
6. Data Sharing and Disclosure
We do not sell, rent, or broker your personal data or your platform outputs.
6.1 Sub-processors
We engage third-party providers who process data on our behalf under data processing agreements that restrict their use of the data to providing services to Signal Loom Inc. These providers fall into the following categories:
- Cloud infrastructure and hosting
- Payment processing and subscription billing
- Customer relationship management and marketing communications
- Authentication and identity services
- Transactional email delivery
- Product analytics and error monitoring
A current list of our sub-processors, identified by name, is available on request to gdpr@signal-loom.ai. Customers may also subscribe at that address to receive notice of changes to the list.
We remain liable to you for the acts and omissions of our sub-processors to the same extent as if we performed the services ourselves. We will give reasonable notice before adding or replacing a sub-processor.
6.2 Legal Requirements
We may disclose data where required to do so by law or in response to a valid court order, subpoena, or government request. Where permitted, we will notify you before disclosing.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of Signal Loom Inc.'s assets, your data may be transferred to the successor entity. We will provide notice of such a transfer and of any material change in data handling practices.
6.4 Protection of Rights
We may disclose data where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Signal Loom Inc., our users, or the public.
7. Data Retention
We retain data for the following periods:
| Category | Retention period |
|---|---|
| Submitted Data and platform outputs | For the duration of your subscription. Deleted from production systems within 30 days of termination or of your deletion request. Backup copies may persist up to 90 days. |
| Account information | For the duration of the customer relationship, plus 12 months, to support dispute resolution and legal compliance. |
| Billing and payment records | 7 years from the date of the transaction, to meet tax and accounting obligations. This period is fixed by law and a deletion request cannot shorten it. |
| Consent and acceptance records | For the duration of the customer relationship, plus 6 years, to evidence contract formation. |
| Usage and technical logs | 90 days in production; up to 12 months in archived logs. |
| Communications | Up to 3 years, for customer support records. |
You may request earlier deletion of your data by contacting gdpr@signal-loom.ai. We will fulfill deletion requests within 30 days except where retention is required by law, in which case we will tell you which category is affected and why.
Where this table and the retention provisions of the DPA differ in respect of personal data processed under the DPA, the DPA controls.
8. Your Rights
Subject to applicable law, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your data (‘right to be forgotten’), subject to applicable legal retention requirements.
- Portability: Request your data in a structured, commonly used, machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on our legitimate interests.
- Withdrawal of consent: Withdraw any consent you have given, at any time, without affecting the lawfulness of processing before withdrawal.
- Opt-out of marketing: Unsubscribe from marketing communications at any time using the link in our emails or by contacting us.
To exercise any of these rights, email gdpr@signal-loom.ai with the subject line ‘Privacy Request.’ We will respond to your request without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay. (Article 12(3) GDPR.) We may verify your identity before processing requests.
If you are located in the EEA, the United Kingdom, or Switzerland and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
9. Data Security
Signal Loom Inc. implements commercially reasonable technical and organizational security measures, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Strict access controls and role-based permissions for Signal Loom Inc. personnel
- Credential inputs processed in isolated, ephemeral compute environments
- Regular security assessments and vulnerability management
- Audit logging of platform activity
Despite these measures, no system is completely secure. You should limit the permissions of any credentials you provide to the minimum necessary, and read-only access is strongly recommended where the operation allows it. We encourage you to report any suspected security vulnerabilities to security@signal-loom.ai.
10. International Data Transfers
Signal Loom Inc. is incorporated in the United States and carries out part of its activities from France. Personal data may therefore be processed in both the European Economic Area and the United States.
EU data residency. We use commercially reasonable efforts to store and process the personal data of data subjects in the EEA, the United Kingdom, and Switzerland on infrastructure located in those territories. Our current EU infrastructure is Microsoft Azure, West Europe region (Netherlands, EU).
Transfer mechanism. Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to the United States or to any other country outside those territories, we rely on the European Commission's Standard Contractual Clauses (SCCs) as updated in Commission Implementing Decision (EU) 2021/914. For transfers of UK personal data we rely on the UK International Data Transfer Addendum to the SCCs issued under Section 119A of the UK Data Protection Act 2018. For transfers of Swiss personal data we apply the SCCs as amended in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Transfer Impact Assessment (TIA). For each material transfer destination, we conduct a Transfer Impact Assessment evaluating: (a) the laws and practices of the recipient country, (b) the contractual, technical, and organizational supplementary measures applied, and (c) the practical risks to the transferred data. The TIA is reviewed at least annually and following any material change in destination-country law.
Access to documentation. A copy of the SCCs we use, and a summary of our most recent TIA, is available on request to gdpr@signal-loom.ai.
11. Cookies and Tracking Technologies
Our website and platform use cookies and similar tracking technologies to:
- Maintain session state and authentication
- Remember your preferences
- Analyze usage patterns
We do not use third-party advertising cookies. Strictly necessary cookies (for session state and authentication) are used without consent because they are essential to deliver the Service. For all non-essential cookies and similar technologies, including analytics, we obtain your prior, freely given, specific, and informed consent through a consent banner before any such cookie is placed. Non-essential cookies are not set unless and until you consent, and you may withdraw or change your choices at any time through the cookie-settings control. We also honor browser-level Do Not Track signals for non-essential analytics. Refusing non-essential cookies will not prevent your use of the core Service.
12. Children's Data
Signal Loom's services are offered exclusively to businesses and organizations, and our Terms of Service require every user to be at least 18 years of age and to be acting on behalf of a legal entity. The services are not directed to children, and we do not knowingly collect personal data from anyone under 18.
If you become aware that personal data of a person under 18 has been provided to us, please contact gdpr@signal-loom.ai. We will delete the data promptly upon discovery.
13. Third-Party Links and Integrations
The Service may contain links to third-party websites or integrate with third-party platforms. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you use in connection with Signal Loom.
14. California Privacy Rights (CCPA as amended by the CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, ‘CCPA/CPRA’), provides you with specific rights regarding your personal information. This section describes those rights and how to exercise them.
Your CCPA/CPRA rights include:
- Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. Signal Loom Inc. does not sell or share personal information as those terms are defined under CCPA/CPRA, so this right requires no affirmative opt-out action, but you may contact us to confirm.
- Right to limit the use and disclosure of sensitive personal information.
- Right to non-discrimination for exercising your CCPA/CPRA rights.
To submit a request, or to designate an authorized agent to make a request on your behalf, California residents can submit requests via gdpr@signal-loom.ai.
We will respond to a verifiable consumer request within 45 days of receipt. We may extend the response period by an additional 45 days where necessary, with notice.
15. Personal Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after we become aware of the breach, in accordance with Article 33 GDPR.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected data subjects directly, without undue delay, in accordance with Article 34 GDPR. Notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the contact point for further information, the likely consequences, and the measures taken or proposed to address the breach.
Internal breach response procedures, including the 72-hour notification path, are documented in our internal Incident Response Policy.
16. Data Protection Officer
Signal Loom Inc.'s processing activities, evaluated at our current scale, do not require the designation of a Data Protection Officer under Article 37 GDPR (the activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor do they include processing of special categories of personal data or data relating to criminal convictions on a large scale).
For all data protection inquiries, please contact us at gdpr@signal-loom.ai. We will respond as described in Section 8 (Your Rights).
Signal Loom Inc. commits to reviewing this position at least annually and upon any material change in its processing activities. If a DPO designation becomes required, this Policy will be updated and the DPO's contact details published in this section.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised Policy on signal-loom.ai and, where feasible, by email. Every published version carries a version number and an effective date, and superseded versions remain available on request.
Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the changes.
18. Contact Us
For privacy questions, data access requests, or to report a privacy concern:
- Data protection and privacy: gdpr@signal-loom.ai
- Security: security@signal-loom.ai
- General legal: legal@signal-loom.ai
- Website: signal-loom.ai
We are committed to resolving privacy concerns promptly and in accordance with applicable law.