1.Encryption
All traffic between your browser and Datasigma is encrypted in transit with TLS. Data — including the contact index, account details, and exports — is encrypted at rest on our infrastructure.
2.Access Control
- Production systems are accessible only to authorized engineers, over authenticated, encrypted connections
- Account passwords are individually salted and hashed — we never store them in plain text
- Sign in with Google or Microsoft is supported, so you can rely on your existing identity provider and its protections
- Sessions expire automatically and can be ended by logging out at any time
3.Data Retention
Account data is retained while your account is active. If you close your account, we delete your personal account data within 30 days, except where we are required to retain records (for example, billing records for tax purposes).
Records removed from the contact index through an opt-out or erasure request are processed within 30 days and suppressed so they are not re-indexed.
4.Breach Notification
If we confirm a security incident affecting your personal data, we will notify affected customers and, where required, the relevant supervisory authority without undue delay and within the timelines required by applicable law.
5.Reporting a Vulnerability
If you believe you have found a security issue in Datasigma, we want to hear about it: