Legal
Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Servicebetween the customer (“Controller”) and Sigmora (“Processor”) and applies whenever Sigmora processes personal data on the Controller’s behalf. Where the GDPR, UK GDPR, or CCPA/CPRA applies, this DPA governs that processing. A countersigned copy is available on request at privacy@sigmora.org.
1. Roles and scope
The Controller determines the purposes and means of processing the personal data it submits to Sigmora (“Customer Data”). Sigmora processes Customer Data only as a Processor, solely to provide the service and on the Controller’s documented instructions (including via configuration in the product). Sigmora does not sell Customer Data and does not use it to train AI models.
2. Subject matter and duration
The subject matter is the provision of Sigmora’s content-marketing platform. Processing continues for the term of the agreement and any wind-down period. On termination, Customer Data is deleted or returned as described in section 8.
3. Nature and purpose; categories
Nature/purpose: hosting, storage, generation, scheduling, and publishing of marketing content and related account operations. Data subjects:the Controller’s personnel, collaborators, and audience contacts. Categories: names, email addresses, account identifiers, workspace/organization membership, content and its metadata, and usage/telemetry. Sigmora does not intend for special categories of data to be submitted.
4. Sub-processors
The Controller authorizes Sigmora to engage sub-processors to provide the service. The current list is published at sigmora.org/legal/subprocessors. Sigmora imposes data-protection terms on each sub-processor no less protective than this DPA and remains responsible for their performance. Sigmora will give notice of new sub-processors and a reasonable window to object.
5. Security
Sigmora maintains technical and organizational measures appropriate to the risk, including encryption in transit (TLS 1.2+), encryption of sensitive credentials at rest, per-tenant access controls, least-privilege administrative access, audit logging of privileged actions, and rate limiting. See sigmora.org/security for the current posture.
6. Confidentiality
Sigmora ensures that personnel authorized to process Customer Data are bound by confidentiality obligations and process the data only as instructed.
7. Assistance
Taking into account the nature of processing, Sigmora will assist the Controller by appropriate measures with data-subject requests (access, correction, deletion, portability — the product’s per-workspace export and deletion tooling supports this) and with the Controller’s obligations around security, breach notification, and data-protection impact assessments. Sigmora will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data.
8. Return and deletion
On termination, and at the Controller’s choice, Sigmora will delete or return Customer Data. Customers can export their data at any time from within the product and can request deletion, which Sigmora completes within 30 days, subject to any legal retention requirement.
9. International transfers
Customer Data is hosted in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, the parties rely on the applicable Standard Contractual Clauses / UK Addendum, which are incorporated into this DPA by reference for such transfers.
10. Audits
Sigmora will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and frequency limits.
Contact
Data protection enquiries and countersignature requests: privacy@sigmora.org.