← Signal MCAT Data Processing Addendum

Data Processing Addendum

For EU/EEA Users — GDPR Compliance  |  Effective Date: June 13, 2025  |  Last Updated: June 13, 2025

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Signal MCAT ("Data Controller" or "Controller") and the user ("Data Subject") and applies where Signal MCAT processes personal data of individuals in the European Economic Area (EEA), United Kingdom, or Switzerland under the General Data Protection Regulation (EU) 2016/679 ("GDPR") or equivalent applicable law.

1. Definitions

Terms used in this DPA that are defined in GDPR have the same meaning. "Personal Data," "Processing," "Data Subject," "Data Controller," and "Data Processor" each have the meanings assigned in GDPR Article 4.

2. Roles of the Parties

For purposes of GDPR, Signal MCAT acts as:

OpenAI, Supabase, and Stripe each act as Data Processors under written data processing agreements with Signal MCAT.

3. Legal Basis for Processing

Processing ActivityLegal Basis (GDPR Art. 6)Details
Account creation and authenticationArt. 6(1)(b) — ContractNecessary to perform the service contract
Study data storage and spaced repetitionArt. 6(1)(b) — ContractCore function of the Service
Screenshot processing for AI analysisArt. 6(1)(b) — ContractUser-initiated; necessary to provide mirror questions
Subscription billingArt. 6(1)(b) — ContractNecessary to process payment for Pro tier
Anonymous usage analyticsArt. 6(1)(f) — Legitimate InterestProduct improvement; no identifiable data retained
Security and fraud preventionArt. 6(1)(f) — Legitimate InterestProtection of users and the Service

4. Data Subject Rights

We will respond to valid data subject rights requests within 30 days (extendable to 60 days for complex requests with notice). Your rights under GDPR include:

RightHow to Exercise
Access (Art. 15)Contact legal@signalmcat.com to request a copy of your personal data
Rectification (Art. 16)Update in account settings, or contact us
Erasure / Right to be Forgotten (Art. 17)Use "Delete account" in account settings or submit request to legal@signalmcat.com
Restriction of Processing (Art. 18)Contact us with your specific restriction request
Data Portability (Art. 20)Use "Export study data" in account settings, or request via email
Objection to Processing (Art. 21)Contact us; applies where processing is based on legitimate interest
Lodge a Complaint (Art. 77)Contact your national Data Protection Authority (DPA)

5. International Data Transfers

Signal MCAT is headquartered in the United States, which is outside the EEA. Your personal data may be transferred to and stored in the United States. We rely on the following transfer mechanisms to ensure adequate protection:

6. Sub-Processors

Signal MCAT uses the following sub-processors that may process EEA personal data:

Sub-ProcessorLocationProcessing ActivityTransfer Mechanism
OpenAI, LLCUnited StatesScreenshot analysis; question generationSCCs
Supabase, Inc.United States / EU optionsDatabase hosting; authenticationSCCs
Stripe, Inc.United StatesPayment processingSCCs / Adequacy

We will notify you of any material changes to sub-processors with at least 14 days' notice.

7. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will:

8. Retention Periods

We retain personal data only as long as necessary for the purposes described:

Data TypeRetention Period
Account dataUntil account deletion, then deleted within 30 days
Study dataUntil account deletion
Screenshot imagesDeleted within minutes of processing (not stored)
Security/fraud logsUp to 12 months
Billing recordsAs required by applicable tax and financial law (typically 7 years)

9. Contact for Data Protection Inquiries

Data ControllerSignal MCAT
Emaillegal@signalmcat.com
Response TimeWithin 30 days of receipt