M ManySignal

Legal · ManySignal

Data Processing Addendum

Download PDF
Effective: Jul 01, 2026 Last updated: Aug 09, 2026 Version: 2026-Q3

This Data Processing Addendum governs how ManySignal processes personal data contained in customer security telemetry. It is designed to satisfy the requirements of the GDPR (Article 28), UK GDPR, Swiss revFADP, and the CCPA. Enterprise customers requiring a countersigned copy should contact their account team.

01

Definitions and roles

In this Data Processing Addendum ("DPA"), the following terms have the meanings given below. "Controller" means the Customer entity named on the applicable order form, which determines the purposes and means of processing Customer Personal Data. "Processor" means ManySignal, Inc., which processes Customer Personal Data on behalf of the Controller. "Customer Personal Data" means any personal data (as defined by applicable Data Protection Laws) contained within or derived from Customer Data that is submitted to the Service.

"Data Protection Laws" means the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("revFADP"), the California Consumer Privacy Act (CCPA) as amended by the CPRA, and any other applicable data-protection statute that imposes obligations on either party with respect to Customer Personal Data.

This DPA is incorporated into and governed by the Terms of Service or the applicable Master Services Agreement between the parties. In the event of conflict, the DPA takes precedence with respect to data-processing matters.

02

Processing instructions and purpose limitation

ManySignal will process Customer Personal Data only on the documented instructions of the Controller, which are set out in the applicable order form and in the specifications within the Service configuration. Customer's use of the Service constitutes an instruction to process Customer Personal Data for the purpose of providing the agentic security operations capabilities described in the Service documentation.

ManySignal will not process Customer Personal Data for any purpose other than: (a) providing and maintaining the Service; (b) detecting and responding to security and operational incidents affecting the Service; and (c) complying with legal obligations. ManySignal will not use Customer Personal Data to train external machine-learning models or to build user profiles for advertising.

If ManySignal believes an instruction from Customer infringes Data Protection Laws, ManySignal will promptly inform Customer. In such a case, ManySignal may refuse to act on the instruction pending Customer's clarification or correction.

03

Sub-processors

ManySignal engages sub-processors to assist in delivering the Service. The current list of approved sub-processors is published at /legal/subprocessors and updated as sub-processors are added or removed. ManySignal will provide at least 30 days' advance written notice of changes to the sub-processor list via the notification mechanism specified in the customer portal.

Customer may object to a new sub-processor on reasonable grounds related to data protection within 14 days of receiving notice. ManySignal will work with Customer in good faith to address the objection, which may include allowing Customer to terminate the affected Service without penalty if the parties cannot reach agreement.

ManySignal will impose data-protection obligations on each sub-processor, by contract, that are at least as protective as those in this DPA. ManySignal remains fully liable for the acts and omissions of its sub-processors.

04

Technical and organisational measures (TOMs)

ManySignal implements and maintains technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to: AES-256 encryption at rest; TLS 1.2 or higher in transit; per-tenant logical isolation at the storage, cache, and queue layers; role-based access control with the principle of least privilege; MFA enforcement for all production infrastructure access; annual penetration testing by qualified third-party assessors; and continuous vulnerability management.

The TOMs are further described in the ManySignal Security Overview, available from your account team under NDA. ManySignal maintains SOC 2 Type II certification (AICPA Trust Services Criteria) and ISO 27001:2022 certification. Current audit reports are available in the ManySignal Trust Portal.

05

International data transfers

Customer Personal Data that originates in the European Economic Area, the United Kingdom, or Switzerland and is transferred to ManySignal in the United States is subject to Standard Contractual Clauses as approved by the European Commission in Decision 2021/914 (Module Two: Controller to Processor). Where required, the UK Addendum and Swiss-equivalent addendum are also incorporated.

By entering into this DPA, each party is deemed to have signed the SCCs, which are incorporated herein by reference. ManySignal conducts a Transfer Impact Assessment for all such transfers and maintains records of those assessments, which are available to Customer upon written request.

06

Data subject rights

Customer is the Controller for Customer Personal Data and is responsible for responding to data-subject requests (access, rectification, erasure, portability, restriction, and objection). ManySignal will, on request and within 30 days, provide Customer with the tools or assistance necessary to fulfil data-subject rights, to the extent that ManySignal holds the relevant data and it is technically feasible.

If ManySignal receives a data-subject request directly relating to Customer Personal Data, ManySignal will, without undue delay and in any event within five business days, redirect the data subject to the Customer and notify Customer that it has done so.

07

Confidentiality of processing

ManySignal will ensure that personnel authorised to process Customer Personal Data are subject to a legally binding obligation of confidentiality, whether by contract or applicable law, with respect to Customer Personal Data. ManySignal will limit access to Customer Personal Data to those personnel who require access in order to provide the Service.

08

Security incidents and breach notification

ManySignal will notify Customer without undue delay — and in any event within 72 hours of ManySignal becoming aware — of a personal-data breach affecting Customer Personal Data. The notification will include, to the extent then known: a description of the nature of the breach; the categories and approximate number of data records and data subjects concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its effects.

ManySignal will cooperate with Customer in relation to any breach notification obligations Customer may have under applicable Data Protection Laws. ManySignal will document all breaches, including those not requiring notification, in accordance with Article 33(5) GDPR.

09

Audit rights

ManySignal will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, provided that: (a) Customer gives ManySignal at least 30 days' prior written notice; (b) the audit is conducted during normal business hours and does not unreasonably interfere with ManySignal's operations; (c) Customer and any third-party auditor execute ManySignal's standard confidentiality agreement; and (d) audits are limited to once per calendar year unless a security incident requires more frequent review.

ManySignal may satisfy audit requests by making available current SOC 2 Type II and ISO 27001 reports. In that case, Customer's right to conduct a further on-site audit is contingent on identifying a specific concern not addressed by those reports.

10

Deletion and return of data

At the expiry or termination of the Service, ManySignal will, at Customer's election, return Customer Personal Data in a machine-readable format or securely delete it, within 30 days of the termination date. Following such deletion, ManySignal will certify in writing that Customer Personal Data has been deleted, except to the extent retention is required by law.

Backup and disaster-recovery copies are purged within 30 days of deletion of the primary data. ManySignal will not retain Customer Personal Data beyond the periods specified in this DPA except where legally obligated to do so.

11

Term and hierarchy

This DPA remains in effect for the duration of the agreement under which ManySignal processes Customer Personal Data and will automatically terminate upon expiry or termination of that agreement, subject to the deletion obligations above.

This DPA supersedes any prior data-processing addendum between the parties with respect to Customer Personal Data. In the event of any conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to data-protection matters.

Questions about this document?

Contact our legal team at privacy@manysignal.com. For security disclosure, use security@manysignal.com.