Part 1 · Privacy Policy
Who we are and how we use your data
SIGNALANALYTICS.AI LTD is committed to protecting the privacy and security of personal and business data. This part explains what we collect, why and the choices you have.
1.1Who we are
SIGNALANALYTICS.AI LTD ("we", "us", "the Company") is a company registered in the United Kingdom. We are the data controller for the personal data described on this page, which means we decide why and how it is processed. We are registered with the Information Commissioner's Office (ICO) under number ZC137914.
We have a Data Protection Lead who is accountable for how we handle personal data. You can reach them at data@signalanalytics.ai.
1.2Who and what this covers
This is the single privacy policy for Signal Analytics and everything we operate. It applies whoever you are and however you reach us: visitors to signalanalytics.ai and our other sites, people who submit information through a form or a diagnostic, people who email or otherwise contact us, members of the public whose data reaches us through a public source, plus clients who engage us for demonstrations, analytics, consulting or software services.
It also covers the products and applications we build, whatever they are called. That includes our decision tools, our diagnostics and any field or survey application we run. Where a particular product handles data in its own way, that handling is set out by activity below, so this one page stays the complete picture rather than the story being split across many.
1.3Information we collect
We collect only what we need. Depending on how you interact with us, that can include:
- Contact information such as your name, email address, company name and the content of any message you send through a form or by email.
- Technical and usage data such as IP address, browser type, device information, pages visited and time spent on the site. This is limited and used to keep the site working and to understand how it is used.
- Business data supplied by clients where it is required to deliver an agreed piece of work. This is handled under the Data Policy below and, where relevant, a separate Data Processing Agreement.
- Field and survey data, where one of our products captures information on the ground. This can include a photograph of a site with any faces blurred, the location of the site itself rather than of the person recording it, and structured notes on what is there. It is held in an isolated environment for that project alone.
- Public and community data, where a service draws on information people have already made public, for example public reports or public reviews about a place. We use it as an aggregate signal about a location, coded to the task, not to build a profile of any individual.
We do not seek special category data (for example health, biometric or political data) through our website. Where a field product captures photographs, we blur faces at the point of capture, so we are not collecting identifying imagery, and we record the location of the site, not of the person. Where any special category data is involved in a client engagement, we handle it under an additional condition in Article 9 UK GDPR, recorded alongside the lawful basis.
1.4How and why we use it
We use personal data to:
- Respond to your correspondence and enquiries.
- Provide demonstrations, analytics, consulting or software services.
- Operate and improve the products we run, such as our decision tools, diagnostics and field applications.
- Improve the performance, reliability and security of our site.
- Support the delivery of agreed client projects.
- Send updates or marketing only where you have asked us to, and you can opt out at any time.
We do not sell personal data, and we do not use client business data outside the scope of the agreed work.
1.5Our lawful basis
We process personal data only where a lawful basis under Article 6 UK GDPR applies. The basis for each activity is recorded in our internal Records of Processing Activities. In practice the bases we rely on are:
| Lawful basis | When we rely on it |
|---|---|
| ContractArticle 6(1)(b) | Delivering a service to a client and managing that engagement. |
| Legitimate interestsArticle 6(1)(f) | Responding to enquiries, keeping the site secure and reliable and improving our services, where this is not overridden by your rights. |
| ConsentArticle 6(1)(a) | Analytics cookies and any marketing communications. You can withdraw consent at any time. |
| Legal obligationArticle 6(1)(c) | Where we are required to process data to meet a legal or regulatory duty. |
1.6Who we share it with
We share personal data only where necessary to run our website and services, and always under appropriate security and confidentiality controls. That can include trusted providers such as cloud hosting, analytics, software platforms and email systems. These act as our sub-processors under written contracts. The detail of where your data is stored, who processes it and how it is protected is set out in the Data Policy below.
1.7How long we keep it
We keep personal data only for as long as necessary for the purpose it was collected, whether that is correspondence, service delivery, business administration or a legal requirement. Retention periods are covered in more detail in the Data Policy.
Part 2 · Data Policy
Where your data lives and how we protect it
This part sets out our technical and organisational measures: where data is hosted, how it is secured, how long we keep it and how we handle transfers and breaches.
2.1Where data is stored and hosted
Where data storage is required, information is securely hosted on our cloud infrastructure on Google Cloud Platform, primarily in the europe-west2 (London) region. No client data is processed on personal cloud accounts, personal devices or infrastructure outside the Company's legal control.
Solutions can also be configured so that a client's business data remains entirely within the client's own cloud, private environment or internal systems where that is required.
Each product and client project runs in its own isolated cloud environment, kept separate from every other. Data collected by one product is not pooled with another. Where a product accepts submissions from the field or the public, those writes are held to a fixed, validated shape, so the store only ever holds the specific information the task needs.
2.2How we keep it secure
We apply technical and organisational measures appropriate to the risk of the processing:
- Encryption in transit using TLS 1.2 or higher for all network traffic.
- Encryption at rest using AES-256 for stored data.
- Role-based access managed through Google Cloud IAM, limited to directors and individuals under signed agreements.
- Access logging through Cloud Audit Logs, with permissions reviewed at least annually.
2.3How long we keep it
We retain personal data only for as long as necessary for correspondence, service delivery, business administration or legal purposes. Specific retention periods are recorded in our Records of Processing Activities and, where applicable, in client Data Processing Agreements. When data is no longer needed it is deleted. Where data is deleted at the request of a client or a data subject, we confirm the deletion in writing.
2.4Sub-processors and third parties
We use third-party sub-processors only where necessary and under appropriate contracts. Before engaging any provider that will process personal data on our behalf, we confirm they can demonstrate appropriate security measures and put a written Data Processing Agreement in place under Article 28 UK GDPR. Each sub-processor is recorded in our Records of Processing Activities, and the current list is available on request.
2.5International transfers
Personal data is stored primarily on UK and EU infrastructure. Where data is transferred to or processed in a country outside the UK or EEA, for example where a sub-processor is based in the United States, we put appropriate safeguards in place under Chapter V of the UK GDPR. These usually take the form of Standard Contractual Clauses and the UK International Data Transfer Addendum. Current transfers are recorded alongside our sub-processor list.
2.6Data breaches
A personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. We have a breach response procedure. Where a breach meets the threshold, we notify the ICO within 72 hours as required by Article 33 UK GDPR, and we tell affected individuals where the law requires it.
Part 3 · Cookie Notice
Cookies and analytics
We use cookies to keep the site running and to understand how it is used so we can improve it. You are in control of the optional ones.
3.1The cookies we use
A cookie is a small text file stored on your device by your browser. We group ours into two kinds:
| Type | What it does | Basis |
|---|---|---|
| EssentialAlways on | Keeps the site working and secure, and remembers your cookie choice. The site cannot function properly without these, so they are not optional. | Strictly necessary |
| AnalyticsOptional | Helps us understand how the site is used so we can improve it. This may include Google Analytics and basic server logs. These are only set if you accept them. | Consent |
3.2Managing your choice
When you first visit the site you can accept analytics cookies or choose essential only. You can change your mind at any time using the "Manage preferences" option in the cookie notice on the site. Analytics cookies are not loaded until you have given consent, and turning them off stops them being set going forward.
3.3Analytics and tracking
Our website may use analytics tools, cookies and basic tracking technologies to understand website usage, monitor performance and improve the experience. These may include Google Analytics and server logs. Analytics data is used to understand trends and usage, not to identify you personally, and it is only collected where you have accepted analytics cookies.
Your rights
The rights you have over your data
Under UK data protection law you have a set of rights over your personal data. We are here to help you use them.
- Be informed about how your data is processed. That is what this page is for.
- Access your personal data through a subject access request.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data in certain circumstances.
- Restriction of processing in certain circumstances.
- Portability, to receive your data in a portable format.
- Object to processing based on our legitimate interests.
- Rights around automated decisions, so you are not subject to a solely automated decision with a legal or similarly significant effect.
To use any of these rights, email data@signalanalytics.ai. We will respond within one calendar month. If a request is complex we may extend this, and we will tell you if we do. There is normally no charge.
•Complaints
If you have a concern about how we handle your data, please contact us first and we will do our best to put it right. You also have the right to complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk or on 0303 123 1113.
•Changes to this policy
We review this policy at least once a year, and whenever our processing activities or the law change. When we update it we change the date at the top of the page and record what changed in the version history below.
•Version history
We keep a short record of material changes, so you can see how this policy has evolved and when.
| Date | What changed |
|---|---|
| 30 July 2026 | Restructured as the single company-wide policy for every Signal Analytics product and service. Added how we handle field and survey capture and public or community data, and set out per-project isolation. |
| 21 October 2025 | Published our first consolidated privacy policy, data policy and cookie notice covering the website and client work. |