Information for Due Diligence and DPIAs
This document is designed to assist schools and organisations in conducting supplier due diligence, monitoring ongoing compliance, and completing a Data Protection Impact Assessment (DPIA) when implementing Signal's safeguarding platform.
Last updated: March 2026. This document is not a DPIA itself — it provides the information you need to complete your own assessment.
Terms and Conditions
Where can I find Signal's Terms and Conditions?
Do I need a separate Data Processing Agreement (DPA)?
Do I need a separate Data Sharing Agreement (DSA)?
No. Signal acts as a Data Processor, not a co-Controller. Your organisation instructs Signal to process data on its behalf — there is no data sharing arrangement. The DPA covers the controller-processor relationship.
Governance and Accountability
Does Signal have a Data Protection Officer?
Yes. Signal maintains a designated Data Protection Officer contactable at dpo@signalschools.co.uk. The DPO oversees our data protection compliance programme and is the primary point of contact for data protection enquiries.
Does Signal maintain Records of Processing Activities (ROPAs)?
Yes. We maintain Records of Processing Activities as both a Controller (for our own business data) and as a Processor (for customer safeguarding data), in accordance with UK GDPR Article 30.
What data protection training do Signal staff receive?
All staff with access to customer data receive data protection and security awareness training. This training covers UK GDPR principles, data handling procedures, incident reporting, and the specific sensitivity of safeguarding data.
Implementation and Data Import
How is Signal set up for a new school?
After receiving your setup information, we provision a dedicated tenant for your organisation. Your school decides which categories of personal data to import. Data can be imported via secure file upload or entered manually by your staff.
What training is available?
We provide comprehensive onboarding including video tutorials and documentation. Our support team is available to assist with setup and ongoing use of the platform.
Data to be Processed
What categories of personal data does Signal process?
- Student information: Names, dates of birth, identifiers, year groups
- Safeguarding records: Incident descriptions, categories, severity levels, concerns
- Special category data: Health information, safeguarding concerns, wellbeing data
- Staff information: Names, roles, contact details
- Parent/guardian data: Contact information and relationship details
- Documents: Uploaded files and attachments
Full details are set out in our Data Processing Agreement.
Where is data stored?
All customer data is encrypted and stored in the United Kingdom using Microsoft Azure UK South and UK West data centres. Data is never transferred outside the UK without explicit consent and appropriate safeguards.
Is data encrypted?
Yes. All data is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.3 or higher.
Sub-processors
What sub-processors does Signal use?
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure, hosting, database, and storage | United Kingdom |
| Microsoft Azure OpenAI Service | AI model hosting for safeguarding analysis features (incident analysis, summaries, action plans, AI assistant). Prompts and completions are processed but not stored by the model. See AI Data Processing section below. | United Kingdom |
| Rebound | Transactional email delivery (30-day log retention) | Ireland (EU) |
All sub-processors are bound by data processing agreements compliant with UK GDPR Article 28. We provide at least 30 days' notice before engaging new sub-processors.
Can sub-processors access customer data?
Microsoft Azure hosts our infrastructure but does not have access to unencrypted customer data. Azure OpenAI processes prompts and generates responses to power AI features — prompts and completions are not stored by the model and are not used to train or improve any models (see AI Data Processing below). Rebound processes only the email addresses and content necessary for transactional email delivery, with a 30-day log retention period.
AI Data Processing
Who hosts Signal's AI models?
Signal uses Microsoft Azure OpenAI Service to host all AI models. Azure OpenAI is an enterprise-grade service hosted entirely within Microsoft's Azure environment. It does not interact with OpenAI's consumer services (such as ChatGPT or the OpenAI API).
Is our data used to train AI models?
No. Under Microsoft's enterprise data privacy commitments for Azure OpenAI, your data is protected by the following guarantees:
- Your prompts (inputs) and completions (outputs) are not used to train, retrain, or improve any AI foundation models
- Your data is not available to OpenAI or any other third party
- Your data is not available to other customers
- Your data is not used to improve Microsoft or third-party products or services
These commitments are set out in Microsoft's data privacy documentation and the Microsoft Products and Services Data Protection Addendum.
How are AI prompts and responses handled?
When Signal's AI features process your data (for example, analysing an incident description or generating an action plan), your input is sent as a prompt to the Azure OpenAI Service, which generates a response. The AI models are stateless:
- No prompts or completions are stored in the AI model
- Prompts and responses are processed within the customer-specified geography (UK)
- Content is filtered through Microsoft's built-in guardrails to prevent harmful content generation
- No data from the AI processing is retained by the model after the response is generated
What about Microsoft's abuse monitoring?
Azure OpenAI includes an abuse monitoring system designed to detect misuse. Signal has opted in to Microsoft's managed customer programme, which means prompts and completions are not stored for human review. Automated abuse detection may still occur at the time of processing, but no data is retained by the abuse monitoring system.
Data Subject Requests
How are Data Subject Access Requests (DSARs) handled?
As Data Processor, Signal supports schools in responding to DSARs. Requests received directly by Signal are referred to the relevant school as Data Controller. We provide tools within the platform to facilitate data export and search capabilities to assist with DSAR fulfilment.
Can data subjects contact Signal directly?
Data subjects (students, parents, staff) should direct their requests to the school as Data Controller. If Signal receives a request directly, we will promptly refer it to the relevant school and assist as needed.
Personal Data Breaches
What is Signal's breach notification process?
Signal will notify affected customers without undue delay and within 24 hours wherever possible of becoming aware of any personal data breach. Notification will be made by email to the designated contact. We will provide details of the nature of the breach, affected data categories, and measures taken or proposed to mitigate harm.
Will Signal assist with breach investigations?
Yes. We will investigate the breach, take appropriate measures to contain and remediate it, and provide reasonable assistance to the school in meeting their breach notification obligations to the ICO and data subjects.
Security
What security certifications does Signal hold?
Signal's security practices are informed by industry standards including ISO 27001 principles. We are not currently ISO 27001 certified. We implement comprehensive technical and organizational measures covering:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Role-based access control with granular permissions
- Multi-factor authentication and passwordless login (WebAuthn/passkeys)
- Comprehensive audit logging
- Web Application Firewall protection
- DDoS mitigation and rate limiting
Microsoft Azure, our hosting provider, maintains SOC 2 Type II and ISO 27001 certifications.
Does Signal conduct security testing?
Yes. Automated security testing is integrated into our software development lifecycle. This includes static code analysis, vulnerability scanning, and automated dependency scanning to ensure third-party components remain secure and up to date.
Who has access to customer data within Signal?
Access to customer data within Signal is strictly limited to personnel who require it for service delivery and support. All access is subject to role-based controls and comprehensive audit logging. All staff undergo DBS (Disclosure and Barring Service) checks and receive data protection training.
Business Continuity and Disaster Recovery
How does Signal ensure service availability?
Signal targets 99.9% uptime using Microsoft Azure's multi-region UK infrastructure with automated failover. We maintain 24/7 monitoring with automated alerting. Our Recovery Time Objective (RTO) is 4 hours and Recovery Point Objective (RPO) is 1 hour.
How are backups managed?
Automated daily backups are performed with point-in-time recovery capability. Backups are encrypted and stored in geographically separate Azure UK regions to protect against regional outages.
Data Retention and Deletion
What happens to data when a school leaves Signal?
Upon termination, customer data is retained for 60 days to allow for data retrieval or transition to another system. After this period, all customer data is permanently and irreversibly deleted, including backups (which may persist for up to 90 days from the deletion date due to Azure backup schedules). Schools may request early deletion at any time.
How long are safeguarding records retained?
As Data Processor, Signal retains data for as long as the school instructs. Schools typically retain safeguarding records until a student reaches age 25, in line with statutory guidance. The school as Data Controller determines the appropriate retention period. This is dependant on the school remaining a Signal subscriber — if a school leaves Signal, all customer data is permanently deleted after 60 days (see above).
Completing Your DPIA
Does my school need to complete a DPIA for Signal?
We recommend that organisations conduct a Data Protection Impact Assessment when implementing any system that processes children's safeguarding data, as it involves special category data and data relating to vulnerable individuals. This document, together with our Data Processing Agreement and Privacy Policy, provides the information you need to complete your assessment.
What documentation does Signal provide to support a DPIA?
- This due diligence information document (what you're reading now)
- Data Processing Agreement — controller-processor obligations
- Privacy Policy — how we handle personal data
- Terms and Conditions — full service agreement
If you require any additional information for your DPIA, please contact us.
Contact Information
For additional information to support your due diligence or DPIA, or to request specific documentation, please contact:
Company: Signal Education Ltd (Company No. 17014216)
Address: 12 Cooper Road, Bristol, BS9 3RA
Email: support@signalschools.co.uk
Data Protection Officer: dpo@signalschools.co.uk
ICO Registration: ZC136329
