GDPR Compliance
How we protect your data
BuySignal is fully compliant with the European Union's General Data Protection Regulation (GDPR). We take data privacy seriously and have implemented comprehensive measures to protect personal data.
Your Rights Under GDPR
Right to Access
Request a copy of all personal data we hold about you or your customers.
Right to Rectification
Request correction of any inaccurate personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Data Portability
Receive your data in a structured, machine-readable format.
Data Processing
What data we process
- Customer first name (anonymized, e.g., "Maria D.")
- City/location (optional)
- Product purchased
- Purchase timestamp
What we do NOT collect
- Full customer names
- Email addresses of your customers
- Payment information
- IP addresses
Data Anonymization
By default, all customer data displayed in notifications is anonymized. We only show the first name and last initial (e.g., "Maria D.") and general location (city level only, no precise addresses).
You can configure additional anonymization settings in your dashboard, including disabling names entirely or showing only "Someone from [City]".
Cookie Consent Integration
BuySignal widget respects cookie consent preferences. When integrated with your consent management platform, our widget will:
- Wait for consent before setting any cookies
- Function in "cookieless" mode when consent is denied
- Integrate with popular CMPs (OneTrust, Cookiebot, etc.)
Data Processing Agreement
We offer a Data Processing Agreement (DPA) for customers who require one. Our standard DPA covers:
- Sub-processor list and notifications
- Technical and organizational measures
- Data breach notification procedures
- Audit rights
Contact legal@buysignal.app to request a DPA.
Data Deletion Requests
To request deletion of data, you can either use the self-service option in your dashboard, or contact us at privacy@buysignal.app. We process all requests within 30 days as required by GDPR.