Privacy Policy
Effective as of: 2/4/2026
1. Introduction
Signuply.io Sp. z o.o. with registered office in Łódź at ul. Semaforowa 9, 92-632 Łódź, Poland, Tax ID (NIP): 7282889300, REGON: 529657839, KRS: 0001127475 (hereinafter referred to as "we," "our," or "Signuply") provides email automation services through our product Smart Inquiry Router.
This Privacy Policy explains how we collect, use, and protect your personal data when you use our email automation service that connects to your email account (Gmail, Outlook, Microsoft 365).
We operate in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR").
2. Data Controller
The controller of your personal data is:
Signuply.io Sp. z o.o.
Address: ul. Semaforowa 9, 92-632 Łódź, Poland
Tax ID (NIP): 7282889300
REGON: 529657839
KRS: 0001127475
Email: contact@signuply.io
If you have any questions regarding the processing of personal data, you can contact us at:contact@signuply.io
3. What Data We Collect
3.1 OAuth Authorization
When connecting your email account using OAuth 2.0 protocol, we receive:
Google (Gmail)
- Your Google account email address
- Access tokens (access & refresh tokens)
- Permissions to Gmail API
- Basic profile (name, photo - optional)
Microsoft (Outlook/365)
- Your Microsoft account email address
- Access tokens (access & refresh tokens)
- Permissions to Microsoft Graph API
- Basic profile (name, photo - optional)
3.2 Email Message Data
As part of providing the service, we process the following data from your email messages:
- Message content (subject, body, sender, recipients)
- Message metadata (date, time, size, message ID)
- Message attachments (file names, content)
- Message headers (From, To, Subject, Date, Message-ID, Reply-To)
- Message status (read/unread, flagged)
3.3 Technical Data
We automatically collect the following technical data:
- IP address
- Browser type and operating system
- Authorization timestamps and system activity
- Error logs and system activity logs
- User Agent (browser identifier)
3.4 Analytics Data (Cookies)
Using Google Analytics 4 (GA4), we collect analytics data about website usage:
- Traffic source (where you came from)
- Time spent on site
- User actions (clicks, scrolling)
- Anonymous session ID
- Approximate geographic location (country, city)
GA4 data is processed by Google LLC based in the USA. More information:Google Privacy Policy
4. Purpose and Legal Basis for Data Processing
We process your personal data for the following purposes:
4.1 Service Provision (Art. 6(1)(b) GDPR)
Purpose: Automatic categorization of incoming emails, sending automatic responses, saving attachments, generating reports.
Legal basis: Performance of a contract for the provision of services.
Retention period: For the duration of the contract and until the expiry of the statute of limitations for claims (in accordance with the Civil Code).
4.2 Compliance with Legal Obligations (Art. 6(1)(c) GDPR)
Purpose: Issuing invoices, maintaining accounting records, archiving documents.
Legal basis: Compliance with legal obligations (Accounting Act, tax regulations).
Retention period: 5 years from the end of the year in which the tax obligation arose.
4.3 Legitimate Interests (Art. 6(1)(f) GDPR)
Purposes:
- Establishing, pursuing, and defending claims
- Ensuring IT security (monitoring, security logs)
- Analyzing service usage for improvement purposes (GA4)
- Direct marketing of our services (for existing customers)
Retention period: Until the expiry of the statute of limitations for claims or until a valid objection is raised.
4.4 Consent (Art. 6(1)(a) GDPR)
Purpose: Newsletter, marketing of partner products, analytics cookies (GA4), profiling.
Retention period: Until consent is withdrawn.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
5. How We Use Your Data
We use your data only to the extent necessary to provide the service:
- Automatic categorization: Analyzing message content using artificial intelligence (AI) to assign the appropriate category
- Automatic responses: Sending initial responses based on the identified category
- Attachment management: Automatically saving attachments in designated locations (e.g., Google Drive, OneDrive)
- Reporting: Generating summaries and statistics about processed messages
- Service improvement: Analyzing anonymized data to optimize categorization algorithms
- Website analytics: Tracking traffic on connect.signuply.io using Google Analytics 4
IMPORTANT:
We do not permanently store the content of your email messages. We process them in real-time and do not create backups of message content.
6. Sharing Data with Third Parties
To provide our services, we use the following data processors:
n8n GmbH
Workflow automation platform. Servers: EU (Germany)
Purpose: Email automation process orchestration, data flow management
Data processed: Email addresses, message content, metadata
Security: EU hosting, end-to-end encryption, ISO 27001
Privacy policy: https://n8n.io/legal/privacy
Google LLC (Vertex AI / Gemini)
Artificial intelligence services. Servers: USA with EU processing (Belgium, europe-west1)
Purpose: Email categorization, response generation, document OCR (invoices, attachments)
Data processed: Email content, attachments
Security: Zero data retention (data deleted after processing), not used for model training, ISO 27001, SOC 2 Type II, Standard Contractual Clauses (SCC)
Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice
Google LLC (Gmail, Google Sheets, Google Drive)
Google Workspace infrastructure. Servers: EU / USA
Purpose: OAuth authorization for Gmail, Gmail API access, processing results storage
Data processed: Full email inbox contents (with OAuth consent), categorization results
Security: Google Workspace DPA, ISO 27001, ISO 27017, ISO 27018, SOC 2/SOC 3, Standard Contractual Clauses
Privacy policy: https://policies.google.com/privacy
Make.com (Celonis SE) (optional)
Alternative workflow automation platform. Servers: EU (Frankfurt, Germany) / USA
Purpose: Data flow management (for selected clients as alternative to n8n)
Security: ISO 27001, SOC 2 Type II
Note: Used only for selected clients as per agreement
Privacy policy: https://www.make.com/en/privacy-notice
OpenAI LLC (optional)
Alternative artificial intelligence services (GPT-5). Servers: USA
Purpose: AI categorization and processing (only when explicitly agreed with client)
Data processed: Email content (only for clients requiring this provider)
Security: API Enterprise Tier with DPA, zero data retention, SOC 2 Type II, ISO 27001, Standard Contractual Clauses
Note: Used only when client explicitly requires OpenAI models
Privacy policy: https://openai.com/policies/privacy-policy
Anthropic PBC (Claude) (optional)
Alternative artificial intelligence services. Servers: USA
Purpose: AI processing for selected use cases
Data processed: Email content (only when agreed)
Security: Zero data retention, SOC 2 Type II, Standard Contractual Clauses
Note: Used only for selected applications as per agreement
Privacy policy: https://www.anthropic.com/privacy
Microsoft Corporation (Azure, Microsoft 365)
Microsoft cloud infrastructure. Servers: EU / USA
Purpose: OAuth authorization for Outlook/Microsoft 365, Microsoft Graph API access
Security: ISO 27001, ISO 27018, SOC 2, EU Model Clauses
Privacy policy: https://privacy.microsoft.com
Vercel Inc.
Web application hosting. Servers: EU / USA
Purpose: Hosting OAuth authorization interface (connect.signuply.io)
Security: SOC 2 Type II, ISO 27001
Privacy policy: https://vercel.com/legal/privacy-policy
Stripe, Inc.
Online payment platform. Servers: USA / EU
Purpose: Credit/debit card payment processing, recurring subscription management
Data processed: Payment card data, billing address, email, transaction history
Security: PCI DSS Level 1, ISO 27001, SOC 2 Type II
IMPORTANT: Service provider does NOT store card data - it is processed directly by Stripe
Privacy policy: https://stripe.com/privacy
Google Analytics 4 (Google LLC)
Web analytics tool. Servers: USA
Purpose: Website traffic analysis, user experience optimization
Legal basis: User consent (Art. 6(1)(a) GDPR)
Security: Standard Contractual Clauses, Data Processing Amendment
Privacy policy: https://policies.google.com/privacy
Important Information About Subprocessors:
- Subprocessor selection: Not all listed subprocessors are used for all clients. Specific vendors are selected based on project technical requirements, client preferences, and specific use cases.
- Current list: The current list of subprocessors used for your specific implementation is available in the Data Processing Agreement (DPA) or upon request at: contact@signuply.io
- Changes to subprocessors: We will notify you 30 days in advance of planned changes. You have the right to raise justified objections. In case of objection, vendor change or contract termination is possible.
- Full list: Detailed list of all subprocessors with change history available at:signuply.io/en/legal/subprocessors
All data processors operate under data processing agreements in accordance with Art. 28 GDPR and ensure an appropriate level of security. For data transfers outside the European Economic Area, we use Standard Contractual Clauses (SCC) approved by the European Commission and additional technical measures (encryption, pseudonymization).
7. Data Transfers to Third Countries
Some of the data processors (OpenAI, parts of Google, Microsoft, and Vercel infrastructure) have headquarters or servers in the United States, which is a third country under GDPR.
To ensure an adequate level of protection:
- We use entities that apply Standard Contractual Clauses (SCC) adopted by the European Commission (Art. 46(2)(c) GDPR)
- OpenAI additionally applies a Data Processing Addendum compliant with Schrems II requirements
- Google Cloud has certifications: ISO 27001, ISO 27017, ISO 27018, SOC 2/SOC 3
- Microsoft Azure applies EU Model Clauses and has ISO/SOC certifications
- Stripe, Inc. applies Standard Contractual Clauses and additional safeguards compliant with PCI DSS
- Google Analytics 4 processes data in accordance with Google Ads Data Processing Terms
More information about the safeguards applied by individual entities can be found on their websites in privacy sections:
8. Cookies and Tracking Technologies
8.1 What Are Cookies?
Cookies are small text files stored on your device (computer, phone, tablet) when visiting a website. They allow the site to "remember" your actions and preferences.
8.2 What Cookies Do We Use?
Strictly Necessary Cookies (Required)
Purpose: Enable basic site functions (OAuth authorization, CSRF protection)
Name: oauth_state, csrf_token
Lifespan: Session (deleted after closing browser)
Legal basis: Art. 6(1)(b) GDPR (contract performance)
✓ You cannot refuse - they are necessary for operation
Google Analytics 4 (Optional)
Purpose: Website traffic analysis, usage statistics, UX optimization
Name: _ga, _ga_*, _gid
Lifespan: Up to 2 years (_ga), 24 hours (_gid)
Provider: Google LLC (USA)
Legal basis: Art. 6(1)(a) GDPR (consent)
ⓘ You can opt out in the cookie banner or browser settings
8.3 Managing Cookies
Cookie Banner: On your first visit, we display a banner allowing you to choose which cookies to accept.
Browser Settings: You can block cookies in your browser settings:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Settings → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
Note: Blocking strictly necessary cookies may prevent OAuth authorization.
8.4 Google Analytics 4 - Details
Google Analytics 4 collects the following data:
- Anonymous user identifier (not linked to specific individuals)
- Device and browser type
- Approximate location (country, city)
- Traffic source (where you came from)
- Pages visited and time spent
- Button and link clicks
IP Anonymization: IP addresses are anonymized (last octet masked).
Opt-out: You can opt out of GA4 by installing:
- Google Analytics Opt-out Browser Add-on
- Or by rejecting analytics cookies in our banner
9. Data Storage and Security
9.1 Retention Period
- OAuth tokens (Google/Microsoft): Until authorization is revoked or contract termination
- Message content: Not permanently stored - real-time processing only
- System logs: 30 days (for diagnostics and security)
- Categorization metadata: 12 months (for reporting purposes)
- Invoices and accounting documents: 5 years (legal requirement)
- GA4 data: 14 months (Google's default setting)
9.2 Security Measures
We implement the following technical and organizational measures:
- Encryption: TLS 1.3 for data transmission, AES-256 for token storage
- Access control: Data access only for authorized employees (principle of least privilege)
- Monitoring: 24/7 infrastructure security monitoring
- Backups: Automated OAuth token backups (encrypted)
- Security testing: Regular audits and penetration tests
- Procedures: Documented security incident response procedures
- Multi-factor authentication (MFA): Required for administrative access
OAuth Security:
OAuth tokens are stored in an encrypted database. We do not have access to your Google/Microsoft account password - authorization is performed directly by the provider (Google/Microsoft).
10. Your Rights (GDPR)
As a data subject, you have the following rights:
Right of Access (Art. 15 GDPR)
You can obtain confirmation of whether we process your data and a copy of that data.
Right to Rectification (Art. 16 GDPR)
You can request correction of inaccurate data or completion of incomplete data.
Right to Erasure "Right to be Forgotten" (Art. 17 GDPR)
You can request deletion of data when it is no longer necessary for the purposes collected.
Right to Restriction of Processing (Art. 18 GDPR)
You can request restriction of processing in certain circumstances.
Right to Data Portability (Art. 20 GDPR)
You can receive your data in a structured format (e.g., JSON, CSV).
Right to Object (Art. 21 GDPR)
You can object to processing for marketing purposes or based on legitimate interests.
Right to Withdraw Consent (Art. 7(3) GDPR)
If processing is based on consent (e.g., GA4, newsletter), you can withdraw it at any time.
Right to Lodge a Complaint (Art. 77 GDPR)
You can file a complaint with the President of the Personal Data Protection Office (PUODO).
How to Exercise Your Rights?
To exercise the above rights, contact us at:
- Email: contact@signuply.io
- Subject line: "GDPR - [type of request]"
We will respond to your request without undue delay, but no later than one month from receiving it. In case of complex requests, we may extend this period by an additional two months, informing you beforehand with reasons.
11. Revoking Email Access
You can revoke our authorization to your email account at any time:
Gmail (Google)
- Go to Google Account Permissions
- Find "Signuply Email Router"
- Click "Remove Access"
Outlook/Microsoft 365
- Go to Microsoft App Permissions
- Find "Signuply Email Router"
- Click "Remove these permissions"
After revoking access:
- We will immediately stop processing your email messages
- We will delete stored OAuth tokens within 24 hours
- The service will stop working
- We will retain accounting data (invoices) for the legally required period
Revoking OAuth access is equivalent to terminating the service agreement.
12. Profiling and Automated Decisions
As part of the service, we use automated processing (AI) to categorize email messages.
We do not make automated decisions that produce legal effects or similarly significantly affect you (Art. 22 GDPR).
Email categorization is purely auxiliary and does not affect:
- Contract terms
- Service access
- Rights and obligations of the parties
Profiling by Google Analytics 4
GA4 may create user profiles based on website behavior (so-called "audience segments"). This data is:
- Anonymous (not linked to specific individuals)
- Used only for site optimization
- Does not affect service terms
You can withdraw consent for GA4 profiling at any time (see section 8.3).
13. Contact with Supervisory Authority
If you believe that the processing of your personal data violates GDPR provisions, you can file a complaint with the supervisory authority:
Personal Data Protection Office (PUODO)
Address: ul. Stawki 2, 00-193 Warsaw, Poland
Phone: +48 22 531 03 00
Email: kancelaria@uodo.gov.pl
Website: https://uodo.gov.pl
14. Changes to Privacy Policy
We may periodically update this Privacy Policy to reflect changes in our practices or for legal reasons.
We will inform you of significant changes through:
- Email notification (sent to the email address associated with the service)
- Notice on the connect.signuply.io website
- At least 30 days before the changes take effect
The date of the last update is always visible at the top of this document.
15. Contact
If you have questions about this Privacy Policy or the processing of your personal data, please contact us:
Contact Details:
Email: contact@signuply.io
Postal address: Signuply.io Sp. z o.o., ul. Semaforowa 9, 92-632 Łódź, Poland
Subject: "Data Protection"