SignalSign in
Legal

Privacy Notice

This notice explains how Signal Local handles personal information when people register, join a workspace, connect services, run audits or contact us.

Effective 28 August 2026

1. Who is responsible for your information

Signal Local ("Signal", "we", "us" or "our") is responsible for personal information used to operate accounts, trials, security, support and the Signal service. An agency using Signal is normally responsible for the client and team information it chooses to enter or connect; Signal processes that information to provide the service on the agency's instructions.

2. Information we collect

  • Account information such as name, work email, workspace, role and authentication status.
  • Trial, plan, audit-credit and workspace administration records.
  • Client, website, location and business information entered by authorised users.
  • Public website and search evidence collected while running an audit.
  • Google Search Console, Google Analytics or Business Profile information when an authorised user connects and selects those services.
  • Audit requests, evidence, reports, recommendations and AI-assisted output.
  • Security, session, invitation, delivery, error and support records.
  • Essential browser storage used for sign-in, security and interface preferences.

Please do not submit special-category information, confidential credentials or personal information that is not needed for an SEO audit or workspace administration.

3. How and why we use information

PurposeTypical lawful basis
Create accounts, workspaces, trials and deliver requested featuresContract or steps requested before a contract
Run audits, prepare reports and provide supportContract
Protect accounts, prevent abuse, diagnose failures and maintain service integrityLegitimate interests in operating a secure and dependable service
Keep financial, entitlement and compliance recordsLegal obligations and legitimate interests
Improve reliability and product behaviour using limited operational informationLegitimate interests, balanced against user privacy
Send invitations, security messages and service communicationsContract and legitimate interests

Accepting the Terms is a contractual action. Reading this notice is an acknowledgement, not consent to every use of information. Where a future feature legally requires consent, Signal will request it separately and make withdrawal clear.

4. Where information comes from

We receive information directly from users, from workspace owners or administrators who invite them, from client-authorised Google connections, from public websites and search sources used for an audit, and from our service providers' operational responses.

5. Service providers and sharing

We share information only where needed to operate Signal, follow an authorised request, protect legal rights or comply with law. Current provider categories include:

  • Hostinger for website and VPS hosting;
  • Supabase for database, authentication and storage services;
  • Resend and Gmail for transactional email and support communications;
  • Cloudflare Turnstile for bot and abuse protection;
  • n8n for workflow automation;
  • DataForSEO and Google services for requested audit evidence; and
  • OpenAI for bounded AI-assisted analysis and report generation.

We do not sell personal information. Workspace information is not shared with another Signal agency except where an authorised user has explicitly joined both workspaces.

6. International processing

Some providers may process information outside the United Kingdom. Where required, we use providers and contractual arrangements that support lawful international transfers, such as adequacy regulations or approved contractual safeguards. Contact us if you need more information about safeguards relevant to a particular provider.

7. Retention

We retain account and workspace information while the service is active and for a reasonable period afterwards for recovery, security, dispute and legal purposes. Audit evidence and reports are kept while needed by the workspace or applicable service arrangement. Security, consent, entitlement and founder-action records may be retained longer where needed to demonstrate account integrity and compliance. Provider execution logs and email delivery records are retained for shorter operational periods where practical. We delete or anonymise information when it is no longer reasonably required.

8. Security

Signal uses tenant access controls, encrypted transport, managed authentication, multi-factor authentication for privileged access, restricted service credentials, audit logging and recovery controls. No online system can be guaranteed completely secure, so users should also protect their credentials and report suspected misuse promptly.

9. Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or object to processing, and to receive portable information. Where Signal processes client data only for an agency, we may need to refer the request to that agency. Contact us to make a request. We may verify identity before disclosing or changing information.

You have the right to object to processing based on legitimate interests. Tell us what you object to and why so we can assess the request.

You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

10. Automated analysis

Signal uses automated scoring and AI-assisted analysis to generate SEO findings and recommendations. These outputs support professional review; they do not make decisions producing legal or similarly significant effects about individuals.

11. Changes to this notice

We will update this notice when our processing changes. Material new uses will be brought to active users' attention, and Signal will request a fresh acknowledgement when the published legal version changes.

Questions about these documents can be sent to services@signal-local.com.

Terms of ServicePrivacy Notice