Information for Due Diligence and DPIAs

This document is designed to assist schools and organisations in conducting supplier due diligence, monitoring ongoing compliance, and completing a Data Protection Impact Assessment (DPIA) when implementing Signal's safeguarding platform.

Last updated: March 2026. This document is not a DPIA itself — it provides the information you need to complete your own assessment.

Terms and Conditions

Where can I find Signal's Terms and Conditions?

Our Terms and Conditions are available on our website. They cover the full service agreement including subscription terms, acceptable use, and termination provisions.

Do I need a separate Data Processing Agreement (DPA)?

We provide a standalone Data Processing Agreement that meets the requirements of UK GDPR Article 28. This DPA forms part of the overall service agreement and governs how we process personal data on your behalf as Data Processor.

Do I need a separate Data Sharing Agreement (DSA)?

No. Signal acts as a Data Processor, not a co-Controller. Your organisation instructs Signal to process data on its behalf — there is no data sharing arrangement. The DPA covers the controller-processor relationship.

Governance and Accountability

Does Signal have a Data Protection Officer?

Yes. Signal maintains a designated Data Protection Officer contactable at dpo@signalschools.co.uk. The DPO oversees our data protection compliance programme and is the primary point of contact for data protection enquiries.

Does Signal maintain Records of Processing Activities (ROPAs)?

Yes. We maintain Records of Processing Activities as both a Controller (for our own business data) and as a Processor (for customer safeguarding data), in accordance with UK GDPR Article 30.

What data protection training do Signal staff receive?

All staff with access to customer data receive data protection and security awareness training. This training covers UK GDPR principles, data handling procedures, incident reporting, and the specific sensitivity of safeguarding data.

Implementation and Data Import

How is Signal set up for a new school?

After receiving your setup information, we provision a dedicated tenant for your organisation. Your school decides which categories of personal data to import. Data can be imported via secure file upload or entered manually by your staff.

What training is available?

We provide comprehensive onboarding including video tutorials and documentation. Our support team is available to assist with setup and ongoing use of the platform.

Data to be Processed

What categories of personal data does Signal process?

The categories depend on what your organisation chooses to record. Typically this includes:
  • Student information: Names, dates of birth, identifiers, year groups
  • Safeguarding records: Incident descriptions, categories, severity levels, concerns
  • Special category data: Health information, safeguarding concerns, wellbeing data
  • Staff information: Names, roles, contact details
  • Parent/guardian data: Contact information and relationship details
  • Documents: Uploaded files and attachments

Full details are set out in our Data Processing Agreement.

Where is data stored?

All customer data is encrypted and stored in the United Kingdom using Microsoft Azure UK South and UK West data centres. Data is never transferred outside the UK without explicit consent and appropriate safeguards.

Is data encrypted?

Yes. All data is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.3 or higher.

Sub-processors

What sub-processors does Signal use?

Sub-processorPurposeLocation
Microsoft AzureCloud infrastructure, hosting, database, and storageUnited Kingdom
InboundEmail delivery (3-day retention)United States (SCCs in place)

All sub-processors are bound by data processing agreements compliant with UK GDPR Article 28. We provide at least 30 days' notice before engaging new sub-processors.

Can sub-processors access customer data?

Microsoft Azure hosts our infrastructure but does not have access to unencrypted customer data. Resend processes only the email addresses and content necessary for transactional email delivery, with a 30-day retention period.

Data Subject Requests

How are Data Subject Access Requests (DSARs) handled?

As Data Processor, Signal supports schools in responding to DSARs. Requests received directly by Signal are referred to the relevant school as Data Controller. We provide tools within the platform to facilitate data export and search capabilities to assist with DSAR fulfilment.

Can data subjects contact Signal directly?

Data subjects (students, parents, staff) should direct their requests to the school as Data Controller. If Signal receives a request directly, we will promptly refer it to the relevant school and assist as needed.

Personal Data Breaches

What is Signal's breach notification process?

Signal will notify affected customers without undue delay and within 24 hours wherever possible of becoming aware of any personal data breach. Notification will be made by email to the designated contact. We will provide details of the nature of the breach, affected data categories, and measures taken or proposed to mitigate harm.

Will Signal assist with breach investigations?

Yes. We will investigate the breach, take appropriate measures to contain and remediate it, and provide reasonable assistance to the school in meeting their breach notification obligations to the ICO and data subjects.

Security

What security certifications does Signal hold?

Signal's security practices are informed by industry standards including ISO 27001 principles. We are not currently ISO 27001 certified. We implement comprehensive technical and organizational measures covering:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Role-based access control with granular permissions
  • Multi-factor authentication and passwordless login (WebAuthn/passkeys)
  • Comprehensive audit logging
  • Web Application Firewall protection
  • DDoS mitigation and rate limiting

Microsoft Azure, our hosting provider, maintains SOC 2 Type II and ISO 27001 certifications.

Does Signal conduct security testing?

Yes. Automated security testing is integrated into our software development lifecycle. This includes static code analysis, vulnerability scanning, and automated dependency scanning to ensure third-party components remain secure and up to date.

Who has access to customer data within Signal?

Access to customer data within Signal is strictly limited to personnel who require it for service delivery and support. All access is subject to role-based controls and comprehensive audit logging. All staff undergo DBS (Disclosure and Barring Service) checks and receive data protection training.

Business Continuity and Disaster Recovery

How does Signal ensure service availability?

Signal targets 99.9% uptime using Microsoft Azure's multi-region UK infrastructure with automated failover. We maintain 24/7 monitoring with automated alerting. Our Recovery Time Objective (RTO) is 4 hours and Recovery Point Objective (RPO) is 1 hour.

How are backups managed?

Automated daily backups are performed with point-in-time recovery capability. Backups are encrypted and stored in geographically separate Azure UK regions to protect against regional outages.

Data Retention and Deletion

What happens to data when a school leaves Signal?

Upon termination, customer data is retained for 60 days to allow for data retrieval or transition to another system. After this period, all customer data is permanently and irreversibly deleted, including backups (which may persist for up to 90 days from the deletion date due to Azure backup schedules). Schools may request early deletion at any time.

How long are safeguarding records retained?

As Data Processor, Signal retains data for as long as the school instructs. Schools typically retain safeguarding records until a student reaches age 25, in line with statutory guidance. The school as Data Controller determines the appropriate retention period.

Completing Your DPIA

Does my school need to complete a DPIA for Signal?

We recommend that organisations conduct a Data Protection Impact Assessment when implementing any system that processes children's safeguarding data, as it involves special category data and data relating to vulnerable individuals. This document, along with our DPA and supplier information page, provides the information you need to complete your assessment.

What documentation does Signal provide to support a DPIA?

We provide comprehensive documentation including:

If you require any additional information for your DPIA, please contact us.

Contact Information

For additional information to support your due diligence or DPIA, or to request specific documentation, please contact:

Company: Signal Education Ltd (Company No. 17014216)

Address: 12 Cooper Road, Bristol, BS9 3RA

Email: support@signalschools.co.uk

Data Protection Officer: dpo@signalschools.co.uk

ICO Registration: [TODO]