Signal over Noise Privacy Notice
Last updated 2026-06-02Signal over Noise is provided by Signal over Noise AI Ltd, a company registered in Scotland under company number SC890775.
Registered office:
This privacy notice explains how Signal over Noise processes personal data when it acts as an independent controller. It is not a data processing agreement and does not replace processor terms for Tenant Data processed on an organisation's instructions.This notice covers personal data about:We may process:We process personal data to:Usage Analytics is service analytics about how authorised operators use Signal over Noise. It is used to operate, secure, debug, and improve the SaaS product. It can include authorised-operator personal data and should not be treated as anonymous by default. Tenant and operator identifiers may be used where needed to understand authenticated product usage, reliability, onboarding, and tenant-scoped adoption.If a Usage Analytics provider is adopted, the event schema should be limited to product workflow metadata and should avoid raw Tenant Data, prompt bodies, generated outputs, connected-source records, records about natural persons from Tenant Data, secrets, and unnecessary full URLs. Usage Analytics may use only redacted prompt-derived metadata that cannot reconstruct the prompt or output.Signal over Noise may also create Derived Usage Data: de-identified or pseudonymised service signals derived from how the service is used, such as workflow and action categories, session and feature classifications, quality and reliability signals, and approval outcomes. Derived Usage Data is used to operate, improve, and personalise the service, including building Signal over Noise-owned service models that validate recommended actions and personalise workflows. It excludes raw Tenant Data, prompt bodies, and generated outputs, is never exposed to any user of the service, and is never used to share one organisation's data with another.Usage Analytics is not advertising tracking. Signal over Noise does not use authenticated Usage Analytics for ads, retargeting, or building marketing audiences. Any future website marketing pixels or non-essential client-side tracking would be handled separately and assessed under applicable cookie/e-privacy consent rules.Security Logs are operational records used to protect Signal over Noise and investigate access, abuse, reliability, or incident issues. They may include some of the same identifiers as Usage Analytics, but they serve a different purpose.Observability and Security Logs should not capture request bodies, AI prompt bodies, generated outputs, connected-source payloads, or records about natural persons from Tenant Data by default. A short-lived debug mode that captures additional detail requires explicit approval, narrow scope, redaction wherever practical, and deletion after the incident or investigation closes. Debug payloads are outside Usage Analytics and must not write raw prompt or output bodies into AI run ledgers or analytics events.This privacy notice covers SoN's own controller processing. Tenant Data processed inside a Tenant and its connected integrations is covered by the service agreement and DPA. The GDPR position note records the shared AI Inference and Model Training boundary.Slack, TripleWhale, Google Analytics, Google Ads, Meta Ads, TikTok, Shopify, Klaviyo/Bloomreach, Zendesk, Snowflake, and similar systems are conditional Tenant Data integrations. They are not assumed to be in scope for every Tenant; they become in-scope only when a Tenant connects that Data Source. They are not default production data flows for every Tenant.We may share controller personal data with service providers that help us run Signal over Noise. Current processing layers include hosting and runtime, database and file storage, authentication and operator identity, AI routing, text AI models, and image AI models. The current subprocessors for those layers are documented in the Processing Layers And Subprocessors. Candidate providers are documented separately and are not active subprocessors until adopted. Slack chat integration metadata is processed only when that integration is enabled for a Tenant. Service providers should receive only the data needed for their role. The live subprocessor list should identify production providers, processing locations, transfer mechanisms, and change-notification process.Where personal data is transferred outside the UK or EEA, we should use an appropriate transfer mechanism, such as adequacy regulations, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid safeguard.We keep personal data only for as long as needed for the relevant purpose. Retention periods should be documented in the applicable retention policy, service agreement, DPA, or tenant settings. Current categories include:Individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data. They may also have the right to withdraw consent where processing is based on consent.Where Signal over Noise acts as processor for Tenant Data, requests about that Tenant Data should normally be handled by the organisation that controls the Tenant. Signal over Noise should support the controller in responding where the DPA requires it.Strictly necessary cookies or similar technologies may be used to provide the service, maintain sessions, secure access, and remember operator choices. Optional cookies, local storage, device access, SDKs, or similar technologies that are not strictly necessary should be assessed separately and presented for consent where applicable law requires it. The current implementation plan uses c15t as the technically validated preferred candidate for web cookie and optional script consent. Legal review and the final hosted/backend consent persistence mode are still pending before production use.Signal over Noise does not use personal data for solely automated decisions that produce legal or similarly significant effects on individuals.The product may use Derived Usage Data, including operator workflow and approval patterns, to personalise the service and to predict which recommended actions an operator is likely to approve. These predictions support operator decisions; they do not replace them. Recommended actions run without per-action review only where an authorised operator or workspace admin has configured an approval rule that permits it, and those rules can be changed or revoked by the workspace at any time.If any use is introduced that produces legal or similarly significant effects on individuals, the privacy notice and related governance documents should be updated before launch.Individuals can contact Signal over Noise about privacy questions or requests. They may also complain to their local data protection supervisory authority.
Who This Covers
- authorised operators using Signal over Noise;
- business contacts at organisations evaluating or using Signal over Noise;
- people who join a waitlist, request a demo, or contact Signal over Noise;
- support, billing, security, and operational contacts.
Personal Data We Process
- account and identity data, such as name, email address, organisation, role, authentication identifiers, and Tenant Membership;
- contact and relationship data, such as sales, waitlist, demo, support, and billing communications;
- Usage Analytics, such as operator account ID, tenant ID, role, route, timestamp, device/browser metadata, IP address, request ID, event name, error category, latency, and coarse workflow state. The planned first-party product direction uses Vercel Analytics, Vercel Speed Insights, and Vercel Observability when those layers are wired;
- Security Logs, such as authentication events, access records, request IDs, IP addresses, device/browser metadata, error traces, abuse indicators, and incident-response records;
- tenant workspace records stored in our database layer, such as membership, settings, briefing, automation, memory, interaction, generated-output, asset, and agent-run records. The current subprocessor for that layer is documented in Processing Layers And Subprocessors;
- payment or billing contact data where needed for account administration;
- cookies or similar technology data where used.
Purposes And Lawful Bases
- provide, administer, and secure the SaaS product;
- authenticate operators and manage Tenant Memberships;
- operate support, billing, sales, waitlist, and demo processes;
- diagnose errors, improve reliability, and understand product usage;
- protect against abuse, unauthorised access, and security incidents;
- comply with legal, accounting, and compliance obligations;
- communicate product, operational, or contractual updates.
Usage Analytics
Security Logs
Tenant Data Boundary
Recipients And Subprocessors
International Transfers
Retention
- raw Usage Analytics;
- Security Logs;
- support, billing, incident, compliance, and audit records: as documented in the retention policy for their specific purpose;
- Tenant Data: as set out in the service agreement, DPA, and retention settings for the Tenant.
Individual Rights
Cookies And Similar Technologies
Automated Decision-Making
Complaints
Related Documents
- GDPR SaaS Analytics And AI Data Use Position
- Data Processing Addendum (Draft)
- Processing Layers And Subprocessors
- Privacy Data-Use Boundaries