Data Processing Addendum
Last updated July 10, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and SignalForge ("Processor") and applies whenever we process personal data on the Controller's behalf in the course of providing the Service.
Processor: B&K Investment Group LLC, a Michigan limited liability company (USA), operating the SignalForge platform.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as incorporated into UK law. "CCPA" means the California Consumer Privacy Act as amended by CPRA. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Sub-processor" have the meanings given in the GDPR. "Standard Contractual Clauses" or "SCCs" means Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
Customer is the Controller and SignalForge is the Processor with respect to Customer Personal Data submitted to the Service. Categories of Data Subjects include Customer's authorised users. Categories of Personal Data include identifiers, account and authentication data, usage logs, and any Personal Data Customer chooses to submit through the Service.
3. Processor obligations
- Process Personal Data only on documented instructions from the Controller, including with regard to international transfers.
- Ensure persons authorised to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see Annex II — Security Measures).
- Assist the Controller with data-subject requests, DPIAs, and breach notification.
- Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Data.
- At the Controller's choice, delete or return Personal Data at the end of the service, and delete existing copies unless retention is required by law.
4. Sub-processors
The Controller provides general authorisation for the sub-processors listed at signal4ge.com/subprocessors. We will give at least 15 days' notice of new or replacement sub-processors and provide a mechanism to object on reasonable data-protection grounds.
5. International transfers
Where personal data of EEA, UK, or Swiss data subjects is transferred to a country not benefiting from an adequacy decision, the parties incorporate the SCCs (Module 2 — Controller to Processor), the UK International Data Transfer Addendum, and the Swiss addendum as applicable. Docking clause, governing law, and forum are those of the Controller's jurisdiction unless otherwise required.
6. CCPA / CPRA (California)
With respect to Personal Information of California residents, SignalForge acts as a "Service Provider" under the CCPA. We do not sell or share Personal Information, will not retain, use, or disclose it for any purpose other than the specific purpose of performing the Service or as permitted by the CCPA, and will not combine it with Personal Information received from other sources except as permitted by the CCPA.
7. Audit
On reasonable prior notice and no more than once per year, we will make available information necessary to demonstrate compliance with this DPA, which may take the form of third-party attestations, summary audit reports, or written responses to a security questionnaire.
Annex I — Details of processing
- Subject matter: provision of the SignalForge trading automation Service.
- Duration: for the term of the Terms of Service.
- Nature and purpose: hosting, authenticating, and displaying Customer Data; running strategies and backtests initiated by authorised users; billing and support.
- Data subjects: Customer's authorised users.
- Personal Data: identifiers, contact data, authentication data, usage and audit logs, and any Personal Data Customer submits via the Service.
- Sensitive categories: we do not intentionally process special-category data; Customer must not upload such data without a separate agreement.
Annex II — Security measures
- TLS 1.2+ for data in transit; encryption at rest for databases and backups.
- Encryption of broker/exchange API credentials with per-record keys.
- Role-based access controls, row-level security on tenant data, least-privilege service accounts.
- Audit logging of privileged and sensitive actions.
- MFA required for administrative access; hardware-key-preferred for production.
- Dependency scanning, vulnerability triage, and staged rollout of security patches.
- Incident response plan with 72-hour breach-notification target.
Contact
DPA execution and privacy contacts: privacy@signal4ge.com.