Privacy Policy

Last updated: 30 September 2026

1. Who we are

Signio AB ("Signio", "we", "us") provides Signio, a software service that helps commercial real estate professionals read, compare and work with lease documents and related material. Signio is available as a web application at eu.getsignio.com and as an add-in for Microsoft Outlook, also called Signio.

Signio AB
Organisation number 559579-7779
Långholmsgatan 17, 117 33 Stockholm, Sweden
info@getsignio.com

This policy explains what personal data we process, why, where it is kept, for how long, and what rights you have. If anything here is unclear, write to info@getsignio.com.

2. What this policy covers

This policy applies when you:

  • visit www.getsignio.com;
  • sign in to and use the Signio application;
  • use the Signio add-in for Microsoft Outlook;
  • upload documents, write notes, or ask questions in Signio;
  • contact us, request a demo, or report an issue.
3. Our role: controller or processor

For the documents, notes, questions and answers that your organisation puts into Signio (we call this "customer content"), your organisation is the controller and Signio is the processor. We process that content only to provide the service to your organisation and on its instructions.

For your account details, our website, and our communication with you, Signio is the controller.

4. What personal data we process

Depending on how you use Signio, we may process:

Account data

You sign in with your organisation's Microsoft account or its Google Workspace account. When you do, we receive four pieces of information from that sign-in: an identifier for your organisation (with Microsoft, your organisation's tenant identifier; with Google, your organisation's email domain), your user identifier, your email address, and your display name. Signio never holds a password. Personal Microsoft accounts and personal Google accounts (such as @gmail.com addresses) are refused. Your organisation's record in Signio is created the first time someone from that organisation signs in, once Signio has given your organisation access.

Signio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Customer content

Documents you upload, the text we extract from them, notes you write, the questions you ask, and the answers Signio gives. Documents such as leases often contain personal data about third parties, for example names, signatures, email addresses and phone numbers. We process that data as part of the document, on your organisation's behalf.

Some data in this category is generated by Signio rather than typed by you: the title of a conversation is generated from your first question, and an answer may quote passages from your documents.

Mailbox data (Outlook add-in only)

See section 6.

Usage and technical data

Records of actions taken in Signio (for example that a document was uploaded or deleted, or a conversation was removed), and the technical information needed to run the service securely: browser type, screen size, application version, and server logs. We also keep records of how much AI and document processing is used, per user and per organisation. These hold counts only, never the content of documents, questions or answers. Our logs are designed not to contain the content of your documents or conversations.

Issue reports

If you report an issue from inside Signio, we receive your description, the page you were on, your browser details, and, only if you choose to attach one, a screenshot. A screenshot may show document content or answers that were on your screen at the time.

Contact and demo requests

Your name, email address, company, and what you write to us.

5. Why we process personal data, and on what legal basis

We do not use your data for advertising, and we do not sell it.

6. The Signio add-in for Microsoft Outlook

When your organisation's administrator has approved it and you sign in, the Signio add-in can read your mailbox to help you work with lease matters from your email. In detail:

  • Permission requested: read-only access to your mail (Microsoft Graph Mail.Read; Office permission "read item"). Signio cannot write to, move, delete, or send email from your mailbox.
  • What is read: for the messages relevant to what you are working on, the sender, recipients, date, folder, and subject line. Message bodies are read when you ask Signio to work with a message and are not stored by default.
  • What is kept: for each answer that used your mail, the counterparty domains consulted, the period of mail covered, and how many messages were read. Message bodies are not stored. If Signio asks you to confirm a recipient, that email address is held with the conversation until you answer. Two further exceptions: the subject of a message may become the title of a conversation, and any passage that Signio quotes into an answer is stored with that answer.
  • What is never done: Signio never sends email, never modifies your mailbox, and never retains your mail credentials.

Your organisation's administrator can revoke the add-in's access at any time from the Microsoft 365 admin centre.

7. Where your data is kept, and who processes it

Storage. Your documents, extracted text, notes, conversations and account data are stored in Microsoft Azure data centres in Sweden (region Sweden Central).

Processing. Signio runs on Microsoft Azure. The services that handle your data are:

Today, all AI processing of your content takes place within the European Union. If we decide to use AI models that process data outside the EU, we will update this policy and the Signio Trust Centre before any customer content is processed that way, and appropriate transfer safeguards (such as the standard contractual clauses in Microsoft's data protection terms) will apply. Storage of your content stays in the EU.

Operational notifications. When an organisation requests access to Signio or a user reports an issue, Signio sends a notification to our internal Slack workspace. For an access request, the notification contains a reference number and your organisation's Microsoft tenant identifier. For an issue report, it contains the report's reference number, the Signio version, the screen the report came from, and an internal organisation identifier. It never contains a person's name, email address, or any content.

We use no analytics providers, no advertising or tracking services, and no third-party scripts in the application.

AI models and training. Signio does not use your documents, questions or answers to train AI models. Under Microsoft's Azure OpenAI Service terms, Microsoft does not use your inputs or outputs to train its models either. Answers are produced only from the documents in your organisation's library.

8. How long we keep data

When an organisation's account ends, we remove its data on request within 30 days, apart from what we must keep to meet legal obligations.

9. How we protect your data
  • Each organisation's data is isolated from every other organisation's at the database level, and the Signio application itself cannot read across that boundary.
  • Data is encrypted in transit and at rest.
  • Sign-in is through your organisation's Microsoft or Google Workspace account; Signio holds no passwords. Access to stored files is identity-based; shared access keys are disabled.
  • A small number of Signio staff have administrative access to production systems for operations and support. Where Signio staff view customer content through Signio's support tools, each view is recorded in the affected organisation's activity log.

A fuller description of our security measures is published at security.getsignio.com.

10. Your rights

Under the GDPR you may have the right to access your personal data, have it corrected or erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. Write to info@getsignio.com; we respond within one month.

If your request concerns customer content that your organisation put into Signio, we will forward it to your organisation, which as controller is responsible for answering it, and we will assist them.

You may also complain to a supervisory authority. In Sweden, that is the Swedish Authority for Privacy Protection (IMY), www.imy.se.

11. Cookies

The Signio application uses essential cookies only: to keep you signed in and to protect the sign-in process. None are used for tracking. Our website does not use analytics or advertising cookies.

12. Children

Signio is a business service and is not directed at anyone under 18.

13. Changes to this policy

If we change this policy in a way that matters to you, for example a new sub-processor or a change to where processing takes place, we will update the date above and, for customers, give notice before the change takes effect.

14. Contact

Signio AB, Långholmsgatan 17, 117 33 Stockholm, Sweden

info@getsignio.com