Legal · Privacy
Privacy Policy
Version 1 · Effective July 7, 2026
Version 1.0 · Effective July 7, 2026. Covers signal-core.app and the SignalCore service. Atlantis LLC (Wyoming LLC), d/b/a SignalCore.
1. Who we are & the two roles we play
SignalCore provides B2B visitor intelligence: we help our business clients understand which companies visit their websites. We play two distinct roles, and this policy covers both:
- As a processor — when we process data on behalf of a client (the client's website event stream and any CRM data they connect), the client is the controller and we act on its instructions. Those individuals should consult that client's privacy notice; we route data-subject requests to the client. This is governed by our Data Processing Addendum.
- As a controller — we maintain a proprietary Identity Graph of world-facts (which company owns which IP address / network, plus public firmographics). We are the controller of that graph. It contains no individual person's data and no client's behavioral data.
This policy also covers data we collect from visitors to signal-core.app (our own site), where we are the controller.
2. Company-level, not person-level
We identify visitors at the level of the company, not the named individual. Our core resolution maps a (hashed) IP address to a business. We do not build profiles of identified natural persons from web browsing, and we do not merge area-level demographic data with any individual's identity.
3. What we collect
- From client websites (as processor): IP address (stored as a salted HMAC hash, per client), pages viewed, time on page, and on-site events; a hashed email only where a visitor submits it with consent. Used to resolve the visiting company and score intent for that client.
- In the Identity Graph (as controller): IP/network→company mappings and public firmographics (industry, size band, location). World-facts only.
- From signal-core.app visitors (as controller): standard web/analytics data, our own tracker data (company-level), and information you submit via forms (name, email, company — to respond to you).
- Sources: directly from client sites (with the client's consent framework), public records and registries, and licensed data providers (our sub-processors).
4. How we use data
To provide and improve the Service; to resolve companies and score intent for clients; to maintain the Identity Graph; to communicate with you; for security and legal compliance. We do not use any of this data for eligibility decisions (credit, employment, housing, insurance — see FCRA, below) and we do not sell client data.
5. Legal bases (GDPR/UK GDPR)
- Company-level resolution & the Identity Graph: legitimate interests (Art. 6(1)(f)) — B2B sales intelligence on business entities, supported by a documented Legitimate Interests Assessment. Company-level, cookieless identification is designed to be low-impact.
- Cookies / any device-level tracking on signal-core.app: consent, via our cookie banner.
- Client-controlled processing: on the client's legal basis, under our DPA.
6. Cookies & tracking (signal-core.app)
We use necessary cookies and, with consent, analytics/marketing cookies. Non-essential cookies are blocked until you consent, and we honor Global Privacy Control (GPC) signals. Manage choices via our cookie banner.
7. Your California rights (CCPA/CPRA)
Depending on our activities, certain processing may constitute a "sale" or "share" of personal information (e.g., sending data to advertising platforms). You may:
- Opt out of sale/share via our "Do Not Sell or Share My Personal Information" link (signal-core.app/privacy-choices), and we honor GPC.
- Request to know, delete, or correct your information, and not be discriminated against for exercising rights. For client-controlled data, we act as a service provider and route your request to the relevant client. Submit requests at hello@signal-core.app; we will verify and respond within the statutory window.
8. Your rights (GDPR/UK)
Access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent. Where we are processor, we forward your request to the controlling client. Contact: hello@signal-core.app. You may also opt out of being included in the Identity Graph / resolution at signal-core.app/privacy-choices.
Withdrawing consent. Withdrawal takes effect immediately and is as easy as giving consent: using the site's cookie/consent control to turn consent off signals us to stop enrichment and email capture for your browser going forward and to delete the contact identifier we had captured under consent. Aggregate, non-identifying facts about a business network address (e.g., that an IP range belongs to a company — public routing information) are not personal data and are unaffected. For a named "delete everything about me" request, contact the client or us at hello@signal-core.app and we will action erasure.
9. Sharing & sub-processors
We share data with vendors that help us operate, under contract (DPAs in place). Current categories (maintained list at signal-core.app/subprocessors):
- Infrastructure/hosting: Cloudflare (Workers, D1, storage, queues).
- IP/firmographic enrichment: IPinfo, Apollo, ipregistry / The Companies API.
- Email delivery: Resend. Payments: Stripe.
We do not sell client data. We may disclose data to comply with law or protect rights.
10. International transfers
Where data moves across borders, we rely on appropriate safeguards (e.g., EU/UK Standard Contractual Clauses, UK Addendum), as detailed in the DPA.
11. Retention & security
We retain data only as long as needed for the purposes above and per our retention schedule (e.g., raw events ~90 days; aggregates longer), then delete or de-identify. Security includes per-client HMAC peppers (so the same IP hashes differently per client), encryption in transit, access controls, and a crypto-shred erasure mechanism. No system is perfectly secure.
12. No FCRA / eligibility use
SignalCore data is for B2B sales and marketing only. It must not be used — by us or our clients — to determine any individual's eligibility for credit, insurance, employment, housing, or a government benefit, or as a "consumer report" under the Fair Credit Reporting Act.
13. Children
The Service is for businesses and not directed to children; we do not knowingly collect children's data.
14. Changes & contact
We'll post changes here with a new effective date and, where required, notify you. Contact: Atlantis LLC d/b/a SignalCore — contact us at hello@signal-core.app or via the privacy request form at signal-core.app/privacy-choices. SignalCore markets to US businesses and has not appointed an EU/UK representative or DPO; one will be appointed if EU/UK marketing begins.