Sig

Sig Privacy Policy

Effective Date: June 26, 2025
Company: Protocol LLC
Service: Sig AI Mental Health Coach
Last Updated: June 26, 2025
Legal Basis: GDPR Article 6(1)(b) - Contract Performance; CCPA Business Purpose
Compliance Framework: GDPR, CCPA, HIPAA Security Rule, SOC 2 Type II

1. Legal Framework and Binding Nature

1.1 Policy Authority

This Privacy Policy is incorporated by reference into the Sig Use Policy and constitutes a legally binding agreement. By accessing Sig, you irrevocably consent to the data practices described herein.

1.2 Regulatory Compliance

1.3 Data Controller Status

Protocol LLC acts as the data controller for all personal information collected through Sig services.

2. Comprehensive Data Collection Matrix

2.1 Authentication and Access Data (Mandatory)

2.2 Conversation and Interaction Data (Core Service)

2.3 AI-Inferred Analytics (Automated Processing)

2.4 Technical and Security Data (Operational)

2.5 Explicitly Excluded Data

We do NOT collect:

3. Data Processing Legal Bases and Purposes

3.1 Contract Performance (GDPR Article 6(1)(b))

3.2 Legitimate Interests (GDPR Article 6(1)(f))

3.3 Consent (GDPR Article 6(1)(a))

3.4 Legal Obligations (GDPR Article 6(1)(c))

4. Data Storage and Security Architecture

4.1 Infrastructure Security

4.2 Data Isolation and Compartmentalization

4.3 Advanced Security Measures

4.4 Data Retention and Lifecycle Management

5. Data Sharing and Disclosure Framework

5.1 Prohibited Sharing

We do NOT sell, rent, or trade personal information to third parties for marketing purposes.

5.2 Authorized Service Providers

All service providers operate under strict data processing agreements with equivalent security and privacy protections.

5.3 Legal Disclosures

Information may be disclosed when required by law:

5.4 Business Transfers

6. Individual Rights and Control Mechanisms

6.1 Access Rights

6.2 Correction and Deletion Rights

6.3 Processing Control Rights

6.4 Rights Exercise Procedures

7. International Data Transfers and Safeguards

7.1 Transfer Mechanisms

7.2 Additional Safeguards

8. Specialized Privacy Protections

8.1 Sensitive Data Handling

8.2 Vulnerable Population Protections

9. Breach Notification and Incident Response

9.1 Detection and Assessment

9.2 Notification Procedures

10. Children's Privacy Protection

10.1 Age Verification

10.2 COPPA Compliance

Although not directed at children, we maintain COPPA-compliant procedures for inadvertent collection of data from minors.

11. Policy Updates and Change Management

11.1 Material Changes

11.2 Minor Updates

12. Contact Information and Regulatory Compliance

Data Protection Officer: hello@protocolhq.dev Subject: DPO
Privacy Inquiries: hello@protocolhq.dev Subject: Privacy
Security Incidents: hello@protocolhq.dev Subject: Security
Rights Requests: hello@protocolhq.dev Subject: Rights Request
Attorney General (California): privacy@oag.ca.gov
Physical Address:
Protocol LLC
30 N Gould St. Sheridan, WY 82801

13. Compliance Certifications and Audits

Current Certifications:

Audit Schedule:

IMPORTANT NOTICE: This Privacy Policy contains binding arbitration provisions that may affect your legal rights. Processing of personal data is subject to the terms of the Sig Use Policy. By using our service, you acknowledge that you have read and understood this policy and consent to the data practices described herein.