Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Use between ACTION SIGNAL LLC, d/b/a Action Signal (“Action Signal,” “we,” “us”) and the customer agreeing to those Terms (“Customer”), and applies where Action Signal processes Personal Data on Customer’s behalf in providing the Services.
Capitalized terms not defined here have the meaning given in the Terms of Use. “Personal Data,” “processing,” “controller,” “processor,” and “data subject” have the meanings given in the EU General Data Protection Regulation (“GDPR”).
1. Roles of the Parties
The parties’ roles depend on the data in question, and they are not the same for everything Action Signal holds.
- Where Customer connects a third-party system, uploads a document, or otherwise submits Customer Content that contains Personal Data, Customer is the controller and Action Signal is a processor acting on Customer's instructions.
- For publicly available data that Action Signal collects on its own initiative, such as public product reviews, Action Signal acts as a controller.
- For account registration data, billing records, and usage telemetry about Customer's own personnel, Action Signal acts as a controller.
This DPA governs the first category. Action Signal’s processing as a controller is described in our Privacy Policy.
2. Processing on Documented Instructions
Action Signal will process Personal Data only on Customer’s documented instructions, including as to international transfers, unless required otherwise by law that applies to Action Signal. Where such a legal requirement applies, Action Signal will inform Customer before processing unless the law prohibits that notice.
Customer’s documented instructions are: the Terms of Use, this DPA, Customer’s configuration of the Services, and any further written instruction Customer gives. Action Signal will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
Instructions regarding Aggregated Data. Customer may instruct Action Signal in writing to stop including Customer Content from Customer’s account, or from identified brand workspaces within it, in the creation of Aggregated Data. Action Signal will give effect to that instruction within thirty (30) days of receipt. The instruction applies prospectively only, and does not require deletion of Aggregated Data already created or of anything already derived from it. Giving such an instruction does not reduce Customer’s access to any feature of the Services.
3. Confidentiality
Action Signal ensures that personnel authorized to process Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide the Services.
4. Security
Action Signal implements appropriate technical and organizational measures to protect Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects. Those measures currently include:
- Encryption of data in transit and at rest
- Tenant isolation enforced in the application layer, verified by an automated gate on every build and by a runtime guard that rejects any unscoped query
- Role-based access control within each workspace
- Two-factor authentication available to every user, which a workspace may require of its members
- Audit logging of administrative actions and of any access by Action Signal personnel that crosses workspace boundaries
- Encryption at rest of third-party credentials that Customer authorizes
Action Signal maintains a current description of these measures and will provide it on request.
5. Subprocessors
Customer gives Action Signal general written authorization to engage subprocessors to process Personal Data in providing the Services. The current subprocessors are listed in Annex B below.
Action Signal will give Customer at least thirty (30) days notice before adding or replacing a subprocessor, by updating Annex B and by notice to the account owner. Customer may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith; if the objection cannot be resolved, Customer may terminate the affected Services without penalty for the remainder of the then-current term.
Action Signal imposes on each subprocessor data protection obligations no less protective than those in this DPA, and remains liable for its subprocessors’ performance.
Model providers. Customer Content transmitted to the model providers identified in Annex B is processed solely to generate the output requested through the Services. Those providers are contractually prohibited from using Customer Content to train or improve their own models, and Action Signal will not adopt a model provider whose terms permit it. This does not limit Action Signal’s rights in Aggregated Data under Section 6 of the Terms of Use.
6. Data Subject Requests
Taking into account the nature of the processing, Action Signal will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to data subject requests for access, rectification, erasure, restriction, portability, or objection.
Where Customer connects a commerce platform that transmits data subject requests to Action Signal programmatically, Action Signal will act on those requests through that mechanism. If Action Signal receives a data subject request directly and the request relates to Personal Data processed on Customer’s behalf, Action Signal will refer the request to Customer rather than responding to it, unless legally required to respond.
7. Personal Data Breach
Action Signal will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer’s behalf. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed. Action Signal will provide reasonable assistance to Customer in meeting Customer’s own notification obligations.
8. Data Protection Impact Assessments
Action Signal will provide reasonable assistance to Customer with any data protection impact assessment and any prior consultation with a supervisory authority, in each case solely in relation to processing carried out by Action Signal on Customer’s behalf and taking into account the information available to Action Signal.
9. Deletion and Return
On termination or expiration of the Terms of Use, and at Customer’s election, Action Signal will delete or return Personal Data processed on Customer’s behalf, and delete existing copies, unless applicable law requires continued storage. Customer may make that election within thirty (30) days of termination; absent an election, Action Signal will delete.
Aggregated Data is excluded from this Section. Aggregated Data, as defined in Section 6 of the Terms of Use, has been de-identified and does not identify and cannot reasonably be used to identify or re-identify Customer, Customer’s brands, Customer’s products, Customer’s end users, or any individual. It is therefore not Personal Data, and the deletion and return obligations in this Section do not apply to it, nor to any model, analysis, benchmark, or Service improvement already derived from it. Action Signal’s rights in Aggregated Data survive termination, as stated in Section 6 of the Terms of Use.
10. Audits
Action Signal will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates.
Audits are limited to once in any twelve (12) month period unless a Personal Data Breach has occurred or a supervisory authority requires otherwise, must be conducted on at least thirty (30) days written notice, during normal business hours, in a manner that does not unreasonably disrupt the Services, and subject to confidentiality obligations. Where Action Signal holds a current third-party audit report or certification covering the relevant controls, providing it satisfies this Section.
11. International Transfers
Where Action Signal processes Personal Data subject to the GDPR and transfers it outside the European Economic Area to a country without an adequacy decision, the transfer is governed by the Standard Contractual Clauses approved by the European Commission in Decision 2021/914, which are incorporated into this DPA by reference. Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is itself a processor.
For Personal Data subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies to those clauses. For Personal Data subject to the Swiss Federal Act on Data Protection, references to the GDPR and to supervisory authorities are read as references to Swiss law and the Swiss Federal Data Protection and Information Commissioner.
12. California
Where Action Signal processes personal information subject to the California Consumer Privacy Act on Customer’s behalf, Action Signal acts as a service provider. Action Signal will not sell or share that personal information, will not retain, use, or disclose it for any purpose other than performing the Services specified in the Terms of Use, and will not retain, use, or disclose it outside the direct business relationship between the parties, except as permitted by the Act. Action Signal will not combine that personal information with personal information received from another source, except as the Act permits a service provider to do.
Aggregated Data is deidentified information as defined by the Act and is not personal information. Action Signal maintains it in deidentified form, does not attempt to reidentify it, and contractually obligates any recipient not to reidentify it.
13. Order of Precedence
In the event of a conflict between this DPA and the Terms of Use, this DPA controls as to the processing of Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control. Section 19 of the Terms of Use governs precedence in all other respects.
Annex A: Details of Processing
Subject matter and duration. Provision of the Services described in the Terms of Use, for the duration of the Terms of Use plus any period required to complete deletion or return under Section 9.
Nature and purpose. Hosting, storage, collection, structuring, analysis, and generation of insights and recommendations from Customer Content, including processing by large language models.
Categories of data subjects. Customer’s personnel and authorized users; authors of publicly available reviews and comments relating to Customer’s products; and, where Customer connects a commerce, advertising, or customer relationship system, the individuals whose records that system contains.
Categories of Personal Data. Names, business email addresses, job titles, account identifiers, authentication data, usage and device data, publicly available review text and reviewer display names, and any Personal Data contained in documents, spreadsheets, catalog records, order records, or communications that Customer submits or connects.
Special categories. Action Signal does not request special categories of Personal Data and the Services are not designed to process them. Customer should not submit them.
Annex B: Subprocessors
The following subprocessors process Personal Data on Action Signal’s behalf. Changes are subject to the notice and objection process in Section 5.
“Entity location” below is the jurisdiction in which each provider is established. It is not a statement about where processing physically occurs, which can vary by provider and by configuration. Any transfer of Personal Data out of the European Economic Area is governed by Section 11 above.
- Vercel Inc. — Application hosting, serverless compute, and content delivery. Data: All data transiting the Services, including account data and Customer Content. Entity location: United States.
- Neon Inc. — Managed PostgreSQL database hosting. Data: All stored account data and Customer Content. Entity location: United States.
- Sentry (Functional Software, Inc.) — Application error monitoring and performance tracing. Data: Technical diagnostics, user and tenant identifiers, request metadata. Entity location: United States.
- Anthropic PBC — Large language model inference for analysis and generation. Data: Customer Content submitted to the Services within prompts. Entity location: United States.
- OpenAI, L.L.C. — Large language model and embedding inference. Data: Customer Content submitted to the Services within prompts. Entity location: United States.
- Google LLC (Gemini API) — Large language model inference. Data: Customer Content submitted to the Services within prompts. Entity location: United States.
- Apify Technologies s.r.o. — Collection of publicly available product listing and review data from retail sites. Data: Publicly available review text and reviewer display names. Entity location: Czech Republic.
- Jungle Scout, LLC — Marketplace keyword and search volume data. Data: Product and keyword identifiers. No personal data expected. Entity location: United States.
- Stripe, Inc. — Payment processing and subscription billing. Data: Billing contact details and transaction records. Entity location: United States.
- Resend, Inc. — Transactional and notification email delivery. Data: Recipient name and email address, message content. Entity location: United States.
- PostHog, Inc. — Product usage analytics and session replay. Data: Usage events, user and tenant identifiers, IP address. Form inputs are masked. Not loaded at all for visitors in the EEA, the UK, or Switzerland. Entity location: United States.
- Attio Ltd. — Customer relationship management for our own sales operations. Data: Business contact details of prospects and customers. Entity location: United Kingdom.
Customer-directed connections. The following platforms are not Action Signal subprocessors. Customer authorizes each connection and instructs Action Signal to read from or write to it, and Customer’s own agreement with that platform governs the platform’s processing. They are listed here for transparency.
- Amazon Advertising — Reading advertising performance data from an account the customer connects. Data: Campaign, keyword, and performance metrics.
- Shopify Inc. — Reading and, where enabled, writing catalog data for a store the customer connects. Data: Product catalog data, store metadata, order data.
- Slack Technologies, LLC — Delivering notifications to a workspace the customer connects. Data: Notification content and recipient channel identifiers.
Contact
ACTION SIGNAL LLC
2108 N ST STE N
Sacramento, CA 95816
United States