Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) is entered into by and between Signal Depth (“Processor”) and the entity appearing on the signature line or the entity using the Signal Depth services (“Controller”).

1. Definitions

  • “Controller” means the client who determines the purposes and means of the processing of Personal Data.
  • “Processor” means Signal Depth, which processes Personal Data on behalf of the Controller.
  • “Data” refers to the aggregated revenue and spend data uploaded by the Controller via CSV to the Processor’s server.
  • “Processing” means any operation performed on the Data, such as collection, recording, organization, structuring, storage, or analysis.

2. Scope and Purpose

The Processor shall process Data solely for the purpose of providing marketing analytics consulting and SaaS services as defined in the primary Service Agreement. The Processor shall not process the Data for any other purpose unless required by law.

3. Processor’s Obligations

  • Instructions: The Processor shall process Data only on documented instructions from the Controller.
  • Confidentiality: The Processor ensures that persons authorized to process the Data have committed themselves to confidentiality.
  • Sub-processors: The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors. (Current sub-processors include: Google Analytics and StatSig for functional monitoring).

4. Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:

  • Encryption: Use of SSL (Secure Sockets Layer) for all data in transit.
  • Access Control: Use of Two-Factor Authentication (2FA) for all internal systems accessing Controller data.
  • Integrity: Regular monitoring to ensure data has not been altered or accessed by unauthorized parties.

5. Data Subject Rights

The Processor shall, insofar as is possible, assist the Controller by appropriate technical and organizational measures for the fulfillment of the Controller’s obligation to respond to requests for exercising Data Subject rights (e.g., access, rectification, or deletion).

6. Personal Data Breach

In the event of a confirmed Data Breach, the Processor shall notify the Controller without undue delay (typically within 48–72 hours) after becoming aware of the breach, providing sufficient information to allow the Controller to meet any personal data breach notification obligations.

7. Deletion or Return of Data

Upon termination of services or at the Controller’s request, the Processor shall delete or return all Data to the Controller, unless local law requires continued storage.

  • Standard Protocol: Data is immediately deleted from the Processor’s active servers upon the Controller’s deletion action or account cancellation.

8. Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of Illinois, United States.