Privacy Policy
Last updated: 11 October 2026
SigHQ (“we”, “us”, or “our”) operates the SigHQ email signature management platform (“Service”). This Privacy Policy explains how we collect, use, store, and protect personal data when you use our Service, and describes your rights under applicable data protection law.
1. Who We Are
SigHQ is a B2B software-as-a-service platform that enables organisations to manage and deploy branded email signatures for their Microsoft 365 and Google Workspace users. The organisation that subscribes to SigHQ (“Customer”) acts as a data controller for its employees’ personal data; SigHQ acts as a data processor on the Customer’s behalf for that data, and as a data controller for account and billing data.
2. Data We Collect
2.1 Administrator Account Data
When an IT administrator signs in to SigHQ using Microsoft Entra ID or Google Workspace OAuth, we collect and store:
- Name and email address
- Organisation (tenant) identifier — the Azure tenant GUID or Google Workspace Customer ID
- Authentication provider (Microsoft or Google)
- Account role (admin)
- Sign-in timestamps
2.2 End-User Profile Data
To generate email signatures for your organisation’s users, SigHQ fetches profile information from Microsoft Graph API or Google Workspace Directory. This may include:
- Full name and display name
- Work email address
- Job title and department
- Office location and address
- Phone numbers (direct, mobile)
- Profile photo (retrieved from your organisation’s directory and re-served by SigHQ)
Your organisation controls which fields appear in signatures via the Settings page. Profile data is synced on login and refreshed at most every 24 hours per user during active usage.
2.3 Cached Copies at the Edge
To deliver signatures quickly, two kinds of content are served from the public content delivery network (CDN) cache operated by our hosting provider, Vercel, rather than being regenerated on every request:
- Rendered signature HTML (the fields included in a user’s signature, such as name, job title, email address, phone numbers and address) is cached for about 5 minutes, plus a stale-while-revalidate window of up to 1 minute.
- Profile photos are cached for about 24 hours, plus a stale-while-revalidate window of up to 1 hour. Photos are served from a SigHQ web address, so they may be displayed wherever a recipient’s email client renders the signature.
These responses are keyed to a per-user web address that is not publicly listed, but they are intentionally retrievable without signing in, because email clients and the Outlook add-in must be able to load them. Changes to a user’s profile, signature or directory photo, or removal of a user, therefore take effect in cached copies within the periods above (at most roughly 6 minutes for signatures and roughly 25 hours for photos). Cached copies expire automatically and are not retained beyond these periods.
2.4 Usage Data
We record monthly signature deployment activity per user for billing and reporting purposes. This includes: canonical user identifier, organisation identifier, month/year, and signature delivery count.
2.5 Technical and Log Data
Our hosting infrastructure (Vercel) automatically collects standard server logs including IP addresses, browser type, request paths, and response times. This data is used solely for performance monitoring and security purposes and is not used to identify individual users.
3. How We Use Your Data
- Service delivery — authenticating users, rendering personalised email signatures, and deploying them via the Outlook add-in or Google Workspace integration.
- Account management — maintaining your organisation’s account, managing administrators, and responding to support requests.
- Billing — calculating monthly active user counts for subscription billing.
- Security and fraud prevention — rate limiting, detecting abuse, and protecting the integrity of the Service.
- Service improvement — aggregated, anonymised analytics to understand feature usage and improve the platform.
4. Legal Bases for Processing
Where GDPR applies, we rely on the following legal bases:
- Contract performance — processing necessary to provide the Service under our agreement with your organisation.
- Legitimate interests — security monitoring, fraud prevention, and platform analytics, where our interests are not overridden by your rights.
- Legal obligation — where we are required to process data to comply with applicable law.
5. Data Sharing and Third Parties
We do not sell personal data. We share data only with the following processors:
- Vercel Inc. — cloud hosting, edge network, serverless compute, and analytics. Data processed in the United States under Standard Contractual Clauses.
- Microsoft Corporation — via Microsoft Graph API to read user profile data from your Azure Active Directory tenant. Subject to your organisation’s Microsoft agreement.
- Google LLC — via Google Workspace APIs to read organisational profile data. Subject to your organisation’s Google Workspace agreement.
- Neon / Vercel Postgres — managed PostgreSQL database for storing application data. Hosted in Vercel’s infrastructure.
We may disclose data if required by law, court order, or to protect the rights and safety of SigHQ, our customers, or the public.
6. International Data Transfers
SigHQ is hosted on Vercel infrastructure, which operates globally. Where personal data of EU/EEA residents is transferred outside the EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent mechanisms) as required by GDPR Chapter V.
7. Data Retention
We retain personal data for as long as your organisation’s subscription is active. Before you leave, the account owner can download a copy of your organisation’s data at any time using “Export your data” on the Configure page. The export is a ZIP of plain CSV and HTML files, delivered by a single-use download link emailed to the owner that expires after 48 hours; the file is then deleted. Account deletion is currently handled manually. On termination, or at any time on written request to privacy@sighq.app:
- Administrator account data is deleted within 30 days of your written request.
- End-user profile data is deleted within 30 days of your written request.
- Signatures and assignment rules that you delete in the control panel are held for 30 days so you can recover them, and are then permanently deleted automatically.
- Usage records may be retained for up to 7 years for financial reporting obligations.
- Anonymised, aggregated analytics data may be retained indefinitely.
- Cached copies of signatures and profile photos held on the CDN (see section 2.3) expire automatically within about 25 hours of the underlying data being removed.
8. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. Authentication is handled via industry-standard OAuth 2.0 / OpenID Connect flows with Microsoft and Google — we never store passwords.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your data, subject to legal obligations.
- Restriction — request that we limit processing of your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@sighq.app. We will respond within 30 days. End users wishing to exercise rights over profile data should contact their employer (the data controller) directly, as we process that data on the employer’s behalf.
10. Cookies
SigHQ uses cookies and similar technologies. See our Cookie Policy for details.
11. Children’s Privacy
SigHQ is a business service and is not directed at children under 16. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions or to exercise your rights, contact us at: privacy@sighq.app