Legal Center
Data Processing Addendum
How we process personal data on a campaign's behalf: roles, instructions, sub-processors, security, and deletion.
1. Roles
For personal data of supporters, volunteers, and staff entered into the Platform, the campaign or organization is the controller (or business) and determines the purposes and means of processing. We act as processor (or service provider) and process that data only on documented instructions from the campaign.
For account registration data, billing data, and product telemetry we collect to run our own business, we act as controller.
2. Scope of processing
- Subject matter: provision of the SignCommand 360 platform.
- Duration: the subscription term plus the retention windows described below.
- Categories of data subjects: supporters who request signs, volunteers and field staff, campaign administrators, and public portal submitters.
- Categories of personal data: names, postal addresses, email addresses, phone numbers, geolocation coordinates, photographs of sign placements, volunteer availability and training records, and activity and audit logs.
- Prohibited data: government identification numbers, payment card data, financial account data, and health data must not be entered into the Platform.
3. Our obligations
- Process personal data only on the campaign's documented instructions, including the settings the campaign configures, unless required otherwise by law.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational measures, including tenant isolation enforced in the database, role-based access, private photo storage with expiring links, encryption in transit, and append-only audit logging.
- Assist the campaign, at its reasonable request, with data subject requests, impact assessments, and regulator inquiries.
- Notify the campaign without undue delay of a confirmed personal data breach affecting its data.
- Delete or return personal data at the end of the relationship in line with the Platform Subscription Agreement.
4. Sub-processors
The campaign authorizes us to engage sub-processors to deliver the Platform. Each sub-processor is bound by data protection obligations no less protective than these. The current categories are listed below; we will give notice before adding a new category and the campaign may object on reasonable data protection grounds.
- Cloud application hosting and edge delivery.
- Managed database, authentication, and object storage (supporter records, photographs, audit logs).
- Mapping and geocoding services for map display and address lookup.
- Transactional email delivery for invitations, alerts, and notifications.
- SMS and push delivery, where the campaign enables those channels.
- Error monitoring and product analytics limited to operational telemetry.
5. Data subject rights
Requests from supporters or volunteers to access, correct, delete, or restrict their data are handled by the campaign as controller. The Platform provides deletion request intake on the public portal and a review workflow in the campaign's Security and Privacy console. If a request reaches us directly, we will forward it to the campaign rather than respond on its behalf, unless the law requires otherwise.
6. Retention and deletion
Each campaign configures its own retention periods for supporter records, photographs, location data, incident records, and audit logs. When automatic purging is enabled, records older than the configured window are removed on a scheduled basis. Audit and security logs are append-only and are removed only when their retention window expires. Backups expire on their normal cycle.
7. International transfers
The Platform is operated from the United States, and personal data entered into it is processed in the United States. Where data originates in a jurisdiction that restricts international transfers, the parties will put an appropriate transfer mechanism in place before that data is transferred.
8. Audits
On reasonable written notice and no more than once per year, we will respond to a reasonable security questionnaire and provide documentation describing the controls in place. On-site audits are available only if agreed in writing in an order form.
Contact and notices
Legal notices to SignCommand Technologies must be sent to legal@signcommand360.com and to 965 Cameron Ave, Pontiac, MI 48340, United States. Notices to you may be sent to the email address on your account or posted inside the platform.
Privacy requests: privacy@signcommand360.com. Security reports: security@signcommand360.com. Product support: support@signcommand360.com.