Signal over Noise Privacy Notice

Last updated 2026-06-02
Signal over Noise is provided by Signal over Noise AI Ltd, a company registered in Scotland under company number SC890775.
Registered office:
This privacy notice explains how Signal over Noise processes personal data when it acts as an independent controller. It is not a data processing agreement and does not replace processor terms for Tenant Data processed on an organisation's instructions.

Who This Covers

This notice covers personal data about:
  • authorised operators using Signal over Noise;
  • business contacts at organisations evaluating or using Signal over Noise;
  • people who join a waitlist, request a demo, or contact Signal over Noise;
  • support, billing, security, and operational contacts.
Tenant Data processed inside a Tenant and its connected integrations is covered by the relevant service agreement and DPA. In that context, the organisation is normally the controller and Signal over Noise acts as processor.

Personal Data We Process

We may process:
  • account and identity data, such as name, email address, organisation, role, authentication identifiers, and Tenant Membership;
  • contact and relationship data, such as sales, waitlist, demo, support, and billing communications;
  • Usage Analytics, such as operator account ID, tenant ID, role, route, timestamp, device/browser metadata, IP address, request ID, event name, error category, latency, and coarse workflow state. The planned first-party product direction uses Vercel Analytics, Vercel Speed Insights, and Vercel Observability when those layers are wired;
  • Security Logs, such as authentication events, access records, request IDs, IP addresses, device/browser metadata, error traces, abuse indicators, and incident-response records;
  • tenant workspace records stored in our database layer, such as membership, settings, briefing, automation, memory, interaction, generated-output, asset, and agent-run records. The current subprocessor for that layer is documented in Processing Layers And Subprocessors;
  • payment or billing contact data where needed for account administration;
  • cookies or similar technology data where used.
We do not include raw Tenant Data, prompt bodies, connected-source records, generated outputs, or records about natural persons from Tenant Data in Usage Analytics. Any approved support, debugging, security, or agreed-service-purpose payload access is handled outside Usage Analytics under narrow access, redaction where practical, and deletion controls.Support staff may access a Tenant workspace through a dedicated support-access session for debugging or agreed support. Those sessions are visibly marked in the product, recorded in the workspace audit trail with both the support actor and the acted-as operator where the identity provider supplies that actor claim, and exposed to workspace admins in Support Access History. Support sessions are blocked from approval decisions, external write actions, billing changes, and member or role management.Special-category or criminal-offence data must not be intentionally submitted to Signal over Noise. If such data is inadvertently submitted, we should treat it as out of scope, restrict access, and delete or remediate it in accordance with contractual and legal obligations.

Purposes And Lawful Bases

We process personal data to:
  • provide, administer, and secure the SaaS product;
  • authenticate operators and manage Tenant Memberships;
  • operate support, billing, sales, waitlist, and demo processes;
  • diagnose errors, improve reliability, and understand product usage;
  • protect against abuse, unauthorised access, and security incidents;
  • comply with legal, accounting, and compliance obligations;
  • communicate product, operational, or contractual updates.
The lawful basis may be contract, legitimate interests, legal obligation, or consent depending on the context. Where we rely on legitimate interests, we balance the purpose against the rights and expectations of the individuals affected and apply safeguards such as minimisation, access controls, aggregation, and retention limits.

Usage Analytics

Usage Analytics is service analytics about how authorised operators use Signal over Noise. It is used to operate, secure, debug, and improve the SaaS product. It can include authorised-operator personal data and should not be treated as anonymous by default. Tenant and operator identifiers may be used where needed to understand authenticated product usage, reliability, onboarding, and tenant-scoped adoption.If a Usage Analytics provider is adopted, the event schema should be limited to product workflow metadata and should avoid raw Tenant Data, prompt bodies, generated outputs, connected-source records, records about natural persons from Tenant Data, secrets, and unnecessary full URLs. Usage Analytics may use only redacted prompt-derived metadata that cannot reconstruct the prompt or output.Signal over Noise may also create Derived Usage Data: de-identified or pseudonymised service signals derived from how the service is used, such as workflow and action categories, session and feature classifications, quality and reliability signals, and approval outcomes. Derived Usage Data is used to operate, improve, and personalise the service, including building Signal over Noise-owned service models that validate recommended actions and personalise workflows. It excludes raw Tenant Data, prompt bodies, and generated outputs, is never exposed to any user of the service, and is never used to share one organisation's data with another.Usage Analytics is not advertising tracking. Signal over Noise does not use authenticated Usage Analytics for ads, retargeting, or building marketing audiences. Any future website marketing pixels or non-essential client-side tracking would be handled separately and assessed under applicable cookie/e-privacy consent rules.

Security Logs

Security Logs are operational records used to protect Signal over Noise and investigate access, abuse, reliability, or incident issues. They may include some of the same identifiers as Usage Analytics, but they serve a different purpose.Observability and Security Logs should not capture request bodies, AI prompt bodies, generated outputs, connected-source payloads, or records about natural persons from Tenant Data by default. A short-lived debug mode that captures additional detail requires explicit approval, narrow scope, redaction wherever practical, and deletion after the incident or investigation closes. Debug payloads are outside Usage Analytics and must not write raw prompt or output bodies into AI run ledgers or analytics events.

Tenant Data Boundary

This privacy notice covers SoN's own controller processing. Tenant Data processed inside a Tenant and its connected integrations is covered by the service agreement and DPA. The GDPR position note records the shared AI Inference and Model Training boundary.Slack, TripleWhale, Google Analytics, Google Ads, Meta Ads, TikTok, Shopify, Klaviyo/Bloomreach, Zendesk, Snowflake, and similar systems are conditional Tenant Data integrations. They are not assumed to be in scope for every Tenant; they become in-scope only when a Tenant connects that Data Source. They are not default production data flows for every Tenant.

Recipients And Subprocessors

We may share controller personal data with service providers that help us run Signal over Noise. Current processing layers include hosting and runtime, database and file storage, authentication and operator identity, AI routing, text AI models, and image AI models. The current subprocessors for those layers are documented in the Processing Layers And Subprocessors. Candidate providers are documented separately and are not active subprocessors until adopted. Slack chat integration metadata is processed only when that integration is enabled for a Tenant. Service providers should receive only the data needed for their role. The live subprocessor list should identify production providers, processing locations, transfer mechanisms, and change-notification process.

International Transfers

Where personal data is transferred outside the UK or EEA, we should use an appropriate transfer mechanism, such as adequacy regulations, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid safeguard.

Retention

We keep personal data only for as long as needed for the relevant purpose. Retention periods should be documented in the applicable retention policy, service agreement, DPA, or tenant settings. Current categories include:
  • raw Usage Analytics;
  • Security Logs;
  • support, billing, incident, compliance, and audit records: as documented in the retention policy for their specific purpose;
  • Tenant Data: as set out in the service agreement, DPA, and retention settings for the Tenant.

Individual Rights

Individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data. They may also have the right to withdraw consent where processing is based on consent.Where Signal over Noise acts as processor for Tenant Data, requests about that Tenant Data should normally be handled by the organisation that controls the Tenant. Signal over Noise should support the controller in responding where the DPA requires it.

Cookies And Similar Technologies

Strictly necessary cookies or similar technologies may be used to provide the service, maintain sessions, secure access, and remember operator choices. Optional cookies, local storage, device access, SDKs, or similar technologies that are not strictly necessary should be assessed separately and presented for consent where applicable law requires it. The current implementation plan uses c15t as the technically validated preferred candidate for web cookie and optional script consent. Legal review and the final hosted/backend consent persistence mode are still pending before production use.

Automated Decision-Making

Signal over Noise does not use personal data for solely automated decisions that produce legal or similarly significant effects on individuals.The product may use Derived Usage Data, including operator workflow and approval patterns, to personalise the service and to predict which recommended actions an operator is likely to approve. These predictions support operator decisions; they do not replace them. Recommended actions run without per-action review only where an authorised operator or workspace admin has configured an approval rule that permits it, and those rules can be changed or revoked by the workspace at any time.If any use is introduced that produces legal or similarly significant effects on individuals, the privacy notice and related governance documents should be updated before launch.

Complaints

Individuals can contact Signal over Noise about privacy questions or requests. They may also complain to their local data protection supervisory authority.

Related Documents

  • GDPR SaaS Analytics And AI Data Use Position
  • Data Processing Addendum (Draft)
  • Processing Layers And Subprocessors
  • Privacy Data-Use Boundaries
Signal over Noise AI Ltd · Registered in Scotland · Company number SC890775
Registered office: