July 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, our Terms of Service. It applies whenever Sygna processes personal data on your behalf as a processor under applicable data protection law (including the GDPR, UK GDPR, and Israel's Privacy Protection Law).
Status of this page: Sygna is currently an early-access pilot operated from Israel, ahead of forming a registered legal entity. This DPA reflects our current processing practices and commitments in good faith. Once Sygna forms its registered entity, we will reissue this DPA under that entity's name — the commitments below will not become less protective for you as a result.
1. Roles
You ("Merchant", "Controller") are the controller of personal data belonging to your site visitors and customers. Sygna ("Processor") processes that personal data solely on your behalf and instructions, as described in this DPA and our Privacy Policy.
2. Processing instructions
Sygna will process personal data only: (a) to provide the service as configured by you (event forwarding, strategy recommendations, health monitoring); (b) as further documented in the Terms and Privacy Policy; and (c) as required by applicable law, in which case Sygna will inform you before processing unless the law prohibits this. Sygna will inform you if, in its opinion, an instruction infringes applicable data protection law.
3. Confidentiality
Sygna ensures that personnel authorized to process personal data are bound by confidentiality obligations.
4. Security measures
Sygna implements appropriate technical and organizational measures, including those listed in Annex 3. These measures may be updated over time provided they do not materially decrease the overall level of security.
5. Sub-processors
You provide general authorization for Sygna to engage sub-processors to help deliver the service. The current list is maintained at our Sub-processors page. During the pilot, we will keep that page updated and will use reasonable efforts to notify active accounts of material new sub-processors before they begin processing customer data. If you have a reasonable data-protection concern about a sub-processor, contact us; if we cannot resolve it, you may stop using the affected part of the service. Sygna remains responsible for selecting sub-processors under written terms appropriate for the data they process.
6. International transfers
Sygna is operated from Israel, which the European Commission has recognized as providing an adequate level of data protection — transfers from the EEA/UK to Sygna do not require additional safeguards. Where Sygna engages sub-processors outside Israel and the EEA/UK, it puts appropriate safeguards in place (such as Standard Contractual Clauses or the sub-processor's own certified transfer mechanism), as described on our Sub-processors page.
7. Assistance with data subject rights
Sygna will assist you, insofar as reasonably possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection) under applicable data protection law. If Sygna receives such a request directly from a data subject, it will redirect the request to you and may inform the data subject that you are the controller, unless otherwise required by law.
8. Personal data breach notification
Sygna will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide information reasonably necessary for you to meet your own notification obligations, to the extent that information is known.
9. Audits
On reasonable request, Sygna will make available written information reasonably necessary to demonstrate compliance with this DPA, such as a summary of its security practices and relevant sub-processor information. Formal audits, on-site reviews, or third-party assessments require mutual agreement on scope, confidentiality, timing, and cost, unless applicable law requires otherwise.
10. Deletion and return of data
On termination, Sygna will delete or return personal data as described in our Data Deletion policy, unless applicable law requires continued storage.
11. Liability
Liability under this DPA is subject to the limitations set out in our Terms of Service, except where such limitation is not permitted under applicable data protection law.
12. Precedence and term
This DPA applies for as long as Sygna processes personal data on your behalf under the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
Annex 1 — Details of processing
- Subject matter: Sygna's provision of conversion-signal tracking, strategy recommendations, and related services to the Merchant.
- Duration: for as long as the Merchant has an active Sygna account, plus the retention periods in our Privacy Policy and Data Deletion policy.
- Nature and purpose: receiving conversion events from the Merchant's store, forwarding them to the ad/analytics platforms the Merchant connects, generating strategy recommendations and health alerts (including with the assistance of hosted AI providers), and maintaining the Merchant's account.
- Categories of data subjects: the Merchant's site visitors and customers; the Merchant's own account users.
- Types of personal data: SHA-256 hashed email/phone/name, order value and currency, product identifiers, UTM parameters and ad click IDs, session and event identifiers, consent state, IP address, and — for the Merchant's own account — name, email, and business profile details. No special categories of data or payment card data are processed.
Annex 2 — Sub-processors
See our Sub-processors page for the current, up-to-date list.
Annex 3 — Security measures
- Ad platform and AI provider credentials encrypted at rest with AES-256-GCM.
- All data in transit encrypted via HTTPS/TLS.
- Site-to-API traffic authenticated with per-site credentials and HMAC signatures.
- Logging infrastructure configured to redact sensitive fields (tokens, API secrets, passwords) automatically.
- Customer identifiers hashed (SHA-256) before use in destination matching.
- Internal access to customer data limited to what is necessary for support or operations.
- High-impact strategy changes require explicit Merchant approval before activation.
