For SignalGlobe customers
Fill in the fields below and we'll generate a privacy-policy section for your website, plus the checklist of what you need to do on your side to run SignalGlobe under GDPR. Everything is a starting point — read the notes and have your own counsel confirm it.
This is not legal advice. SignalGlobe is your data processor; you are the controller, and the wording you publish is your responsibility. SignalGlobe shows only anonymised, approximate activity that cannot identify a person, so the published data isn't personal data — you rely on legitimate interest (a notice plus an easy opt-out), not a consent gate. Have a DPO or lawyer review before publishing.
Beyond the policy text
01 / AGREEMENT
You and SignalGlobe (Studio DR, sp. z o.o.) need a written DPA under Article 28. It names the sub-processors — SignalGlobe, MaxMind (geolocation, USA) and OVHcloud (dedicated-server hosting, France).
02 / LAWFUL BASIS
Because the globe shows only anonymised, non-identifiable activity, it isn't personal data — so no per-user consent is needed. Rely on legitimate interest (Article 6(1)(f)) and document a short Legitimate Interests Assessment (LIA).
03 / OPT-OUT
No opt-in gate and no cookie banner are needed — the script stores nothing on the device and the map is anonymised. Give people a simple way to object (opt out) and honour it.
04 / PUBLISH
Paste the text opposite into your existing privacy policy, fill every [bracketed] field, and link your sub-processor list.
05 / ASSESS
A Data Protection Impact Assessment (Article 35) is still advisable given the scale and context. Record the anonymisation — IP truncation, coarsening, and rolling small or identifiable places up to a wider region — as the measures that keep the data non-identifiable.
06 / ANONYMISATION
You don't configure this: SignalGlobe coarsens locations, rolls small or identifiable places up to a wider region, coarsens organisation IPs, and keeps no identifiers — so markers can't single anyone out. Note these controls in your DPIA.
07 / RIGHTS
Have a route for access, erasure and objection. Because no IPs or identifiers are stored and the map is anonymised, there is usually little personal data to act on.
08 / REVIEW
Have your DPO or counsel confirm the lawful basis, the transfer approach, and the DPIA before you go live. This tool is a starting point, not the final word.