SIGNATELL

Privacy Policy

Version 1.0 · Last updated: August 1, 2026

1. Introduction and scope

SIGNATELL is a unified communications platform operated by PEOPLE E COMMERCE LLC, a limited liability company organized in the State of Florida, United States, with a business address at 3815 Arcade Trail, Suite 308, Lutz, Florida 33548.

This Privacy Policy explains what information we process, for what purpose, with whom we share it, and what controls exist over it. It applies to our public website, to the application available at app.signatell.com, and to the communications managed through the channels that each business connects to the platform.

This Policy is supplemented by the Terms of Service and the Data Deletion Instructions, both available on the SIGNATELL public website.

In this document, "Customer" means the business that contracts SIGNATELL; "User" means each person authorized by that business to access the platform; and "end client" means the person who communicates with the business through a connected channel.

2. Our dual role: controller and processor

This is the most important section for understanding how we handle information at SIGNATELL, because our position changes depending on whose data it is.

2.1 Where we act as a controller

With respect to the data of the Customer itself and its Users — account, administration, billing where applicable, and support data — we determine the purposes of processing and act as a data controller. This Policy directly describes that processing.

2.2 Where we act as a processor

With respect to end-client data processed through the platform — conversations, calls, messages, forms, and documents received through connected channels — we act as a data processor and handle that information solely on the Customer’s instructions, the Customer being the controller of that data.

This means that if a person communicated with a business and wishes to exercise rights over that information, the counterpart is that business, not SIGNATELL. We forward the request and provide the necessary technical assistance, but we cannot unilaterally decide about data that does not belong to us.

This separation is also a technical characteristic of the platform: each business’s information is isolated from that of all others, and no Customer can access another Customer’s data.

3. Information we collect

3.1 Account information

  • Name, email address, telephone number, and role of authorized Users.
  • Name, address, and identification details of the business.
  • Access credentials, in encrypted form, and permission settings within the Organization.

3.2 Connected channel information

  • Identifiers of the channels the Customer authorizes for connection, such as the WhatsApp Business number, the Instagram professional account, the Facebook Page, or the telephone line.
  • Authorization credentials issued by the relevant provider, which are stored encrypted and may be revoked by the Customer at any time.

3.3 Communications information

  • Messages, conversations, calls, and their metadata (date, time, duration, channel, sender, and recipient).
  • Call recordings and transcripts, where the Customer enables that functionality.
  • Attachments and documents sent or received through connected channels.
  • Contact details of end clients, which the Customer records or which are derived from the communication itself.

3.4 Technical and usage information

  • IP address, browser and device type, and language.
  • Access and activity logs within the platform, used for security and audit purposes.

3.5 Sensitive information submitted by end clients

Depending on each business’s activity, an end client may submit sensitive or identifying information through the platform — for example social security or tax identification numbers, identity documents, licenses, passports, or financial information — whether in a form, in an attached document, or in the body of a conversation.

SIGNATELL does not request such information on its own initiative and does not require it in order to provide the Service. When it arrives, we handle it as part of the Customer’s communications, under the conditions described in Section 8 of this Policy.

4. How we use information

We use information exclusively to:

  • Provide the Service: receive, display, organize, and send communications from the channels the Customer has connected.
  • Associate each communication with the corresponding contact within the Customer’s Organization.
  • Manage accounts, access, and User permissions.
  • Protect the security of the platform, prevent fraud and misuse, and maintain audit records.
  • Provide technical support and respond to inquiries.
  • Comply with legal obligations and respond to requests from competent authorities.
  • Maintain and improve the operation of the Service.

We do not use data obtained through connected channels for advertising, commercial profiling, sale to third parties, or any purpose unrelated to providing the Service to the Customer that authorized the connection.

We do not sell personal data and do not transfer it to third parties for advertising purposes.

5. Basis for processing

We process information because it is necessary to provide the service the Customer has contracted, to comply with legal obligations applicable to us, to pursue legitimate interests in security and fraud prevention, and, where applicable, on the basis of consent given.

Where we act as a processor, the basis for processing end-client data is for the Customer to determine, as the party that maintains the relationship with those individuals and that must obtain and retain their consent in accordance with the Terms of Service.

In particular, where the Customer collects sensitive or identifying information from its end clients through the platform, the Customer represents that it has the legal basis and authorizations necessary to do so and that it has adequately informed those individuals.

If specific regulations applicable to a Customer require an additional data processing agreement, we will enter into one at the Customer’s request.

6. Sharing data with third parties and integrations

We do not sell personal information. We share it only in the circumstances described below.

6.1 Providers that help us deliver the Service

We rely on hosting, infrastructure, and communications providers that process information on our behalf, with access limited to what is necessary for their function and subject to confidentiality obligations. The set of providers may change as the platform evolves.

6.2 Integrations with third-party platforms

SIGNATELL is an omnichannel platform and its value depends on the integrations each business chooses to enable. These integrations are never enabled on our initiative: it is always the Customer who expressly authorizes them, through the official process of the relevant provider, and who may revoke them at any time.

When an integration is active, only the information necessary for the channel to work is exchanged with that platform: the communications coming in and going out, and the associated technical identifiers. Any processing that platform carries out on its own account is governed by its own privacy policies.

Integrations currently available or in preparation:

  • Meta Platforms, Inc. — WhatsApp Business, Instagram, and Facebook, for receiving and sending messages from the channels the business connects.
  • Telephony and SMS providers, for calls and messages from the lines the business connects.
  • Email providers, for sending and receiving email from the accounts the business authorizes.

As the platform evolves we may add new integrations — for example with Google services, with other client management systems, or with productivity tools. In all cases the same principle applies: an integration is enabled only if the Customer authorizes it, and this Policy will be updated to reflect the integrations available.

6.3 Other circumstances

  • Where required by law or by a competent authority.
  • Where necessary to protect rights, the security of the platform, or that of third parties.
  • In the context of a corporate reorganization or transfer of business, giving prior notice to affected Customers and maintaining the protection of the information.

7. Information security

We apply reasonable technical and organizational measures to protect information against unauthorized access, alteration, or disclosure. These include:

  • Encryption of communications between the browser and the platform.
  • User authentication and permission-based access control within each Organization.
  • Isolation of each Organization’s data, so that no Customer can access another Customer’s information.
  • Access to documents and case files restricted by permissions within each Organization, so that only Users authorized by the Customer can view them.
  • Audit records of relevant actions carried out on the platform.
  • Encrypted storage of credentials and of authorizations issued by providers.

We work continuously to protect information with reasonable and up-to-date measures and to review our practices as the platform evolves. Even so, no system is completely secure. In the event of a security incident affecting personal data, we will notify affected Customers without undue delay and will cooperate with them on any notifications required.

The Customer contributes to security by keeping its credentials confidential, removing access for Users who should no longer have it, and informing us of any unauthorized use.

8. Handling of sensitive information

Some businesses that use SIGNATELL work with sensitive information because of the nature of their activity. When such information reaches the platform, the following rules apply:

  • The Customer is responsible for that information and decides what is requested, from whom, and for what purpose. SIGNATELL acts as a processor.
  • The information is used solely to provide the Service to the Customer that received it. It is not used for advertising, profiling, training of third-party commercial systems, or any other purpose.
  • It is not shared with third-party integrations, unless the Customer itself enables an integration that requires it in order to function.
  • Access is limited to the Users the Customer authorizes within its Organization, and relevant actions are recorded.
  • We recommend that the Customer request only the information strictly necessary and avoid collecting sensitive data through channels that do not offer sufficient safeguards.

Should a security incident affect this type of information, we will notify the Customer without undue delay and will cooperate on any notifications required by applicable law, including breach notification obligations under the laws of the State of Florida and of other jurisdictions that may apply.

The specific technical protection measures and retention periods for this type of information will be detailed in SIGNATELL’s security documentation and in the agreements entered into with each Customer.

9. Data retention and deletion

We retain information while the Customer’s account remains active and for as long as necessary for the purposes described in this Policy.

Following termination of the relationship, the Customer may request an export of its information within a reasonable period. After that period, the information may be deleted in accordance with the Data Deletion Instructions.

Documents and case files that a Customer stores on the platform are retained according to the Customer’s own instructions and retention obligations. SIGNATELL does not delete information belonging to the Customer on its own initiative, except in the circumstances described in this Policy or in the Data Deletion Instructions.

We may retain for longer the minimum information necessary to evidence compliance with a request, to meet legal retention obligations, or to defend against claims.

The detailed procedure for requesting deletion, the available channels, and the applicable timeframes are described in the Data Deletion Instructions published on the public website.

10. Rights and controls over data

Depending on the regulations applicable to them, a person may request access to their data, its correction, its deletion, a copy of it, or may object to or complain about its processing.

The counterpart depends on who holds the relationship:

  • If it is a SIGNATELL Customer or User, they may contact privacy@signatell.com directly.
  • If it is an end client who communicated with a business through SIGNATELL, they should contact that business, which is the controller of their information. If they write to us, we will forward the request to the relevant organization and provide the necessary technical assistance.

Before responding to a request we reasonably verify the identity of the person making it, to prevent a third party from accessing or requesting the deletion of someone else’s data. No retaliation is applied for exercising these rights.

The Customer also has direct controls in the platform: it can manage Users and their permissions, and revoke the authorization of a connected channel at any time.

11. Cookies and similar technologies

The SIGNATELL public website does not use third-party cookies, analytics tools, or advertising tracking technologies.

The application at app.signatell.com uses strictly necessary cookies for the operation of the service, principally to maintain the signed-in session and preserve the security of access. These cookies are not used for advertising or profiling purposes.

If we introduce analytics tools or other technologies in the future, we will update this Policy and provide the corresponding notice and consent mechanisms.

12. International data transfers

SIGNATELL is a service operated from the United States and information is processed principally in that country. The providers and integrations we use may operate from other jurisdictions.

Where information is transferred outside the data subject’s country of residence, we adopt the reasonable safeguards that apply and require our providers to commit to equivalent confidentiality and protection.

13. Children’s privacy

SIGNATELL is a service intended exclusively for businesses and professionals. It is not directed to minors and we do not knowingly collect information from minors.

If we become aware that information from a minor has been collected without the corresponding authorization, we will take reasonable steps to delete it.

14. Changes to this Policy

We may update this Policy to reflect changes in the Service, in the integrations available, or in applicable law. The version in force will always be published on the public website, showing its version number and effective date.

Where a change is material, we will communicate it with reasonable advance notice by email or through a notice on the platform.

15. Contact information

For any inquiry relating to this Privacy Policy or to the processing of personal data:

  • Privacy and data deletion: privacy@signatell.com
  • Legal inquiries: legal@signatell.com
  • General inquiries: contact@signatell.com
  • Postal address: PEOPLE E COMMERCE LLC, 3815 Arcade Trail, Suite 308, Lutz, Florida 33548, United States.

We respond to privacy inquiries within a reasonable period from receipt, in accordance with the procedure described in the Data Deletion Instructions where the matter concerns a deletion request.