Security
How we protect the data you bring to ProductSignal, and who else handles it to run the service.
1. Overview
This page summarizes the technical and organizational measures we use to protect the Service and the data in it. The binding version is Annex B of our Data processing agreement, which we may update as long as the overall level of protection does not go down.
2. Where data is processed
The Service runs on a small set of subprocessors: Railway for application hosting, database storage and content delivery, OpenAI for AI processing, and Resend for email delivery. All three process data in the United States. Our marketing website uses Bunny and Plausible Analytics, both in Europe, and Loops, in the United States, to send newsletter and release note emails. The full list, with purposes and locations, is on the Subprocessors page.
When personal data leaves the European Economic Area, we use appropriate safeguards where the law requires them: adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent lawful mechanism.
3. Encryption
Data is encrypted in transit using TLS where supported.
4. Access control
- Access controls protect our systems and every customer workspace.
- Customer workspaces are logically separated, and access is scoped to the organization.
- Authorized users sign in through authentication and session controls.
- Personnel and service accounts get least-privilege access.
- Only people in authorized roles with a business need can access customer data, and they are bound by confidentiality obligations.
5. Monitoring, backups and incidents
We log and monitor operational and security events, keep backups with recovery practices appropriate for the Service, and follow incident response procedures to investigate and respond to security events.
If we become aware of a personal data breach involving your data, we notify you without undue delay and share the information we have to help you meet your own notification obligations.
6. AI and your data
We send customer content to AI providers only as needed to provide the features you use. We do not use customer content or personal data to train AI models, and our AI subprocessors are contractually required to process personal data only to provide their services to us.
7. Subprocessors
We review every subprocessor’s security practices, data processing terms and compliance with data protection law before we engage them. Each one is contractually bound to process data only on our documented instructions and to protect it with appropriate security measures. We notify customers at least 14 days before adding or replacing a subprocessor, and you can object on reasonable data protection grounds.
8. Retention and deletion
Customer data is kept according to your instructions, your agreement with us and the DPA. When the agreement ends, we delete or return it, unless the law requires us to keep it. You can ask to export your data within 30 days after termination. Backup copies may remain for a limited period and stay protected under the DPA until they are deleted.
9. Data we ask you not to send
Unless we have agreed in writing, do not submit sensitive personal data, special category data, payment card data, health data, government identifiers, children’s data, or data subject to heightened regulatory requirements.
10. Your part
You are responsible for making sure only authorized users access your workspace, for keeping account credentials and access tokens confidential, and for the secure configuration of your accounts, integrations, exports, user permissions and devices. Tell us promptly if you suspect unauthorized access.
11. Contact
Security questions, requests for compliance information and reports of suspected unauthorized access go to legal@productsignal.com.