For SignalGlobe customers

Put a compliant privacy policy in place

Fill in the fields below and we'll generate a privacy-policy section for your website, plus the checklist of what you need to do on your side to run SignalGlobe under GDPR. Everything is a starting point — read the notes and have your own counsel confirm it.

This is not legal advice. SignalGlobe is your data processor; you are the controller, and the wording you publish is your responsibility. SignalGlobe shows only anonymised, approximate activity that cannot identify a person, so the published data isn't personal data — you rely on legitimate interest (a notice plus an easy opt-out), not a consent gate. Have a DPO or lawyer review before publishing.

The regulator people can complain to — usually the DPA of the country you're established in.

Your privacy-policy section

Beyond the policy text

What you need to do on your side

  1. 01 / AGREEMENT

    Sign the Data Processing Agreement

    You and SignalGlobe (Studio DR, sp. z o.o.) need a written DPA under Article 28. It names the sub-processors — SignalGlobe, MaxMind (geolocation, USA) and OVHcloud (dedicated-server hosting, France).

  2. 02 / LAWFUL BASIS

    Rely on legitimate interest

    Because the globe shows only anonymised, non-identifiable activity, it isn't personal data — so no per-user consent is needed. Rely on legitimate interest (Article 6(1)(f)) and document a short Legitimate Interests Assessment (LIA).

  3. 03 / OPT-OUT

    Offer an easy opt-out

    No opt-in gate and no cookie banner are needed — the script stores nothing on the device and the map is anonymised. Give people a simple way to object (opt out) and honour it.

  4. 04 / PUBLISH

    Add the generated section to your policy

    Paste the text opposite into your existing privacy policy, fill every [bracketed] field, and link your sub-processor list.

  5. 05 / ASSESS

    Complete a DPIA

    A Data Protection Impact Assessment (Article 35) is still advisable given the scale and context. Record the anonymisation — IP truncation, coarsening, and rolling small or identifiable places up to a wider region — as the measures that keep the data non-identifiable.

  6. 06 / ANONYMISATION

    Anonymisation is built in

    You don't configure this: SignalGlobe coarsens locations, rolls small or identifiable places up to a wider region, coarsens organisation IPs, and keeps no identifiers — so markers can't single anyone out. Note these controls in your DPIA.

  7. 07 / RIGHTS

    Be ready for data-subject requests

    Have a route for access, erasure and objection. Because no IPs or identifiers are stored and the map is anonymised, there is usually little personal data to act on.

  8. 08 / REVIEW

    Get it signed off

    Have your DPO or counsel confirm the lawful basis, the transfer approach, and the DPIA before you go live. This tool is a starting point, not the final word.