Security, GDPR & sovereignty

Your email never passes through us. Your data stays in the EU.

The page to forward to your IT department, your DPO and your security officer. It sets out precisely what Signally does, what it does not do, and where the data lives.

WHAT SIGNALLY DOES
  • Store your signature templates and campaign artwork
  • Read, with restricted access, the directory attributes the signature needs (name, job title, phone, department, reporting line)
  • Insert an HTML signature block as the employee writes their message
  • Count clicks on the banner links you created
WHAT SIGNALLY DOES NOT DO
  • Read, analyse or index the content of your emails
  • Store your messages, your attachments or your address books
  • Route your emails through its servers
  • Send email on your behalf or change your SMTP routing
  • Transfer data outside the European Union

Hosting in the European Union

Infrastructure located in France, operated under European law. No transfer to a third country as part of the service.

GDPR compliance

Signally acts as a processor within the meaning of Article 28. Data processing agreement, register, retention periods and deletion procedure are documented.

Data minimisation

Only the directory fields actually shown in the signature are synchronised. Nothing more.

Authentication & access

Sign-in through your Microsoft or Google identity provider, granular administrator roles, action logging.

Encryption

Traffic encrypted in transit and data encrypted at rest, across the whole platform.

Reversibility

Export of your templates and complete deletion of your workspace on request, with no hidden retention.

Section to complete with your actual contractual details: hosting provider name, exact datacentre locations, certifications held or in progress, downloadable DPA, DPO contact.

Frequently asked questions — security and compliance

Does Signally read the content of my emails?
No. The add-in inserts a signature block as the message is written. The content of the message is neither read, nor analysed, nor stored, and it does not pass through our servers.
Where is the data hosted?
In the European Union. Templates, campaign artwork and synchronised directory attributes are hosted on infrastructure located in France, subject to the GDPR.
What personal data is processed?
Only the directory fields displayed in the signature: first name, last name, job title, department, email address, work phone number and reporting line. That is the minimisation principle applied strictly.
Is Signally a processor under the GDPR?
Yes. Signally acts as a processor for your company, which is the controller. A data processing agreement sets out the purposes, the retention periods and the security measures.
What happens to access if we terminate?
You retrieve your templates and artwork, then your workspace is deleted. Nothing is retained beyond the periods set out in the contract.
Are your servers subject to extraterritorial legislation?
Hosting in France and the absence of any transfer outside the European Union place the service under European law alone, which is precisely what many IT and legal departments are looking for.

A compliance question? Let us talk.

We are happy to answer the security questionnaires from your IT and legal departments.