This Privacy Policy (hereinafter referred to as the „Policy") was posted on and is effective as of 1 July, 2026 for certain Commsignia tools.
Cookie means a small text file, which is placed on your hard disk by a web server, and is used by the Tool as set forth in section 2 below.
Communication means any comment, feedback, information or document provided by User to Commsignia via any channel.
Commsignia means Commsignia Inc.
Organization means the entity the User represents when requesting access to or accessing the Tool (if the User is using the Tool with regards to their legal relationship with an Organization).
Product means hardware, software products and connected services marketed and sold by Commsignia, whether manufactured by Commsignia or a third party.
Tool means any online tool made available by Commsignia, regarding which this Policy is applied and published (including without limitation: over the air update management platform and website) as made available by Commsignia to Users, including all functionality and documentation.
User or "you" means the natural person accessing and using the Tool.
User Activity means actions a User takes when interacting with a Tool, e.g., logins, clicks, views, onsite browsing history, feature usage (frequency, workflows) and other information derived from such information.
This Policy sets out the terms and conditions of how the User's personal data is processed in relation to the Tools. Please read the information below carefully.
Data processing detailed herein are permitted under the agreement governing the provision of the services to Your Organization.
Commsignia reserves the right to amend this Policy unilaterally at any time. We suggest visiting this Policy time to time for the latest information, however, you will also be informed of this Policy being amended in case of significant changes (e.g. legal basis of processing, scope of processed data, person of data processor) of the Policy.
2.3.1. Commsignia, acting as data controller, processes the personal data you provide or that is generated in connection with your use of the Tool for the purpose of operating, maintaining, and delivering the Tool's services and functionality.
2.3.2. The provided or generated personal data of the User is accessible to the following persons within Commsignia:
Commsignia's employees involved in the data processing (including IT specialists performing a variety of IT tasks related to the operation and maintenance of Commsignia's computer system and the Tool, support staff, sales and account specialists who are in contact with the User) as part of their role within Commsignia in connection with performing their duties associated with the purpose of this Policy.
Personal data is processed as necessary for providing access to the Tool and its functionality (thus fulfilling obligations and exercising rights based the legal relationship between Commsignia and the Organization or the User). The data is processed in compliance with all relevant local laws.
User's personal data specified in point 2.4.1.2 is processed for the period until registration of the User is deleted, or rejected.
User Activity data will not automatically be deleted by Data Controller upon the deletion of the registration. Unless User otherwise indicates (e.g. clicking the necessary statement when deleting registration) all User Activity will be irreversibly anonymized (any references to User removed) and stored and used by Data Controller indefinitely.
Notwithstanding the above, Commsignia shall immediately delete your personal data if you specifically request the deletion thereof and there is no valid legal ground for data processing.
We conduct NPS surveys and collect similar customer feedback and other Communication, and use technology to monitor User Activity, to utilize the acquired information to improve the Tool, and (other) Products, other services, offers, strategy, marketing and/or overall operations of Commsignia, and to better understand user preferences and needs.
Personal data is processed based on the consent of the User. The data is processed in compliance with all relevant laws. The data processing is permitted under the agreement governing the provision of the services to Your Organization, and any required consent is obtained by Your Organization.
For the purpose set forth in point 2.4.2.1., User's personal data specified in point 2.4.2.2. is processed until the registration of the User is deleted, or rejected or the consent to process personal data for the purpose set forth in 2.4.2.1. is withdrawn (whichever occurs first). Those parts of Communication and other information received from or gathered regarding the User that does not constitute personal data (under applicable law) will be retained and used indefinitely by Commsignia for the same purpose as set forth in point 2.4.2.1. User Activity data will not automatically be deleted by Data Controller upon the deletion of the registration. Unless User otherwise indicates (e.g. clicking the necessary statement when deleting registration) all User Activity will be irreversibly anonymized (any references to User removed) and stored and used by Data Controller indefinitely.
Notwithstanding the above, Commsignia shall immediately delete your personal data if you specifically request the deletion thereof or withdraw your consent and there is no valid legal ground for data processing. If the User withdraws their consent, this does not affect the lawfulness of data processing based on their consent and conducted before such withdrawal.
In order to fulfill its purposes as a data controller Commsignia cooperates with the data processors listed below. Commsignia reserves the right to change the data processors at any time.
Amazon Web Services, Inc.
Address: 410 Terry Avenue North, Seattle, WA 98109-5210, ATTN: AWS Legal
Website: aws.amazon.com
Contact: aws.amazon.com/contact-us
Amazon Web Services provides the platform for Tool and therefore it processes all Data on behalf and based on the instructions of Commsignia.
More information: https://aws.amazon.com/privacy/
Pendo.io, Inc.
Address: 301 Hillsborough St., Suite 1900, Raleigh, NC 27603
Website: https://www.pendo.io/
Contact: [email protected]
Pendo.io analyzes the User Activity therefore it processes User Activity data on behalf and based on the instructions of Commsignia.
More information: https://www.pendo.io/legal/privacy-policy/
Commsignia Ltd.
Address: 4-20 Irinyi József utca, Budapest 1117, Hungary
Commsignia engages its wholly owned subsidiary, Commsignia Ltd. to perform tasks related to data processing detailed herein.
2.6.1. Commsignia hereby informs you that if you use the Tool, small data files ("Cookies") will be automatically sent by the web server to your electronic device. In certain cases, these data files may be considered as personal data under the applicable data protection laws. These data files are necessary for the proper operation of the Tool, and are used to collect information on the User's use of the Tool.
2.6.2. The User can accept or refuse Cookies by adjusting their browser settings. To find out how to do this and learn more on Cookies, please visit: https://www.youronlinechoices.eu/. If the User chooses to refuse all Cookies, access to some features of the Tool may be limited.
| Type of Cookie | Purpose of Cookies | Legal basis of data processing | Cookie retention period |
|---|---|---|---|
| Session | Session Cookies allow the User to be recognized within the Tool whether the User has accepted the Cookie policy. | User's consent. | The information is saved until the end of the current session. After that, the collected information will no longer be available. |
Commsignia observes all applicable regulations regarding the security of personal data, therefore both Commsignia and its authorized data processors implement appropriate technical and organizational measures to protect personal data, and establish adequate procedural rules to enforce all relevant laws concerning confidentiality and the security of data processing.
2.8.1. Data Controller is obliged to ensure data security, it must take technical and organizational measures and establish procedural rules which ensure that the recorded, stored and processed data are protected, and which prevent their destruction, unauthorized use or unauthorized alteration. Data Controller also draws the attention of third parties – which the data subject's data have been transferred to – to the fact that they have to comply with the data security requirements.
2.8.2. Data Controller shall ensure that the processed data cannot be accessed, disclosed, transmitted, modified or deleted by unauthorized persons. Data Controller shall make its best efforts to ensure that the data cannot be damaged or destroyed. The above obligation is also prescribed by Data Controller for the employees participating in its data processing activities and for the data processors acting on its behalf.
2.8.3. The Data Controller stores personal data in its own systems and the systems of the data processors in the course of the processing of the data, and the employees of the Data Controller access and download the data on a case-by-case basis, if data processing is needed.
2.8.4. In order to prevent unauthorized access to the data, Data Controller ensures the protection of personal data and prevents unauthorized access to them on its tools as follows: the access to the server and to the computers is protected by passwords and a firewall and antivirus software is applied.
2.9.1. In the following, the regulation of some general issues shall be presented. Thus, the procedure used to ensure the security of the data, the action to be taken in the event of a personal data breach, as well as the rights of the data subject and the means of redress.
2.9.2. Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored or otherwise processed.
2.9.3. If the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, Data Controller shall communicate the personal data breach to the data subject without undue delay in clear and plain language.
2.9.4. The communication to the data subject shall not be required if any of the following conditions are met:
In addition to the rights defined above, the data subjects may exercise the following rights in relation to the data processing set forth in the present Policy:
The data subject has the right to obtain confirmation from Data Controller as to whether or not personal data concerning him or her are being processed, and, if that is the case, to have access to the personal data and the following information:
If personal data are transferred to a third country or to an international organization, the data subject has the right to be informed of the appropriate safeguards relating to the data transfer.
Data Controller shall provide the data subject with a copy of his or her personal data undergoing the data processing. For any further copies requested by the data subject, Data Controller may charge a reasonable fee based on administrative costs. If the data subject submits the request by electronic means, the information shall be provided in a commonly used electronic form, unless otherwise requested by the data subject.
The right to obtain a copy referred to in the previous paragraph shall not adversely affect the rights and freedoms of others.
The rights mentioned above can be exercised through the Data Controller's contact details indicated above.
Based on the data subject's request, Data Controller shall without undue delay rectify any inaccurate personal data related to the data subject. Taking into account the purposes of the data processing, the data subject has the right to have his or her incomplete personal data completed, including by providing a supplementary statement.
The data subject has the right to obtain the erasure of personal data concerning him or her from the Data Controller without undue delay if any of the following reasons exists:
Erasure of data cannot be initiated if data processing is necessary:
The data subject has the right to obtain the restriction of data processing from Data Controller if one of the following conditions applies:
If processing has been restricted according to the above, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
A data subject who has obtained restriction of data processing according to the above shall be informed by Data Controller before the restriction of data processing is lifted.
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to Data Controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another data controller without hindrance from Data Controller to which the personal data have been provided, if the data processing is based on consent or on a contract and the processing is carried out by automated means.
In exercising his or her right to data portability defined above, the data subject has the right to have the personal data transmitted directly from one controller to another, if it is technically feasible.
The exercise of the right referred to data portability shall be without prejudice to the right to erasure („right to be forgotten"). That right shall not apply to data processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in Data Controller.
The right to data portability shall not adversely affect the rights and freedoms of others.
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her, if the legal ground of data processing is to perform a task carried out in the public interest or in the exercise of official authority vested in Data Controller, or the data processing is necessary for the purposes of the legitimate interests pursued by Data Controller or by a third party, including profiling based on these provisions. Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the data processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.
If personal data are processed for direct marketing purposes, the data subject has the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. If the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
If personal data are processed for scientific or historical research purposes or statistical purposes, the data subject, on grounds relating to his or her particular situation, has the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
If the data processing of Data Controller is based on the data subject's consent, the data subject has the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of data processing based on consent before its withdrawal.
Data Controller shall provide information to the data subject on action taken on the data subject's request related to the rights defined in the present Policy without undue delay and in any event within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity and number of the requests.
Data Controller shall inform the data subject of any such extension within one month of receipt of the request, with the reasons for the delay. If the data subject makes the request by electronic means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.
If Data Controller does not act on data subject's request, Data Controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Any information and communication requested by data subject shall be provided by Data Controller free of charge, unless requests from the data subject are manifestly unfounded or excessive, in particular because of their repetitive character. In this case, Data Controller may either charge a reasonable fee taking into account the administrative costs of providing the information or communication requested or refuse to act on the request.
Data Controller shall communicate any rectification or erasure of personal data or restriction of data processing carried out by Data Controller to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. Data Controller shall inform the data subject about those recipients if the data subject requests it.
Persons under the age of 16 may not provide their personal data unless consent is given by the holder of parental responsibility. By making the personal data available to Data Controller, the parent, as a data subject, declares and guarantees that he or she will act in accordance with the above, and his or her capacity to act is not limited in connection with the provision of these information.
If you are not legally entitled to make any personal data available on your own, you must obtain the consent of the third parties concerned (e.g. legal representative, guardian, other person acting as representative of the consumer) or provide another legal ground for making the data available. In this context, you must consider whether the consent of a third party is required in connection with the provision of the personal data in question. It can happen that Data Controller does not get into personal contact with you, so you are obliged to ensure compliance with the present section and Data Controller is not liable in this aspect. Regardless of this, Data Controller is always entitled to check whether the appropriate legal ground for the processing of any personal data is available. For example, if you are acting on behalf of a third party, such as a consumer, we are entitled to request your authorization and/or the data subject's appropriate consent to the data processing in question.
Data Controller makes its best effort to delete any personal data which has been made available to Data Controller without authorization. Data Controller ensures that if it becomes aware of the non-authorized availability of any personal data, this personal data shall not be transferred to another person or used by Data Controller. Please, let Data Controller know immediately by any of the contacts indicated in the Contact Details section if you become aware of the fact that a third party has unauthorizedly provided any personal data to Data Controller.
Any questions or requests related to our data processing and to your personal data stored in the system should be sent to the [email protected] e-mail address, or in writing to the address of 5201 Great America Parkway, Suite 320, Santa Clara, CA 95054, United States of America. Please note that – in your own interest – concerning the data processing related to your personal data we are only able to provide information or take any action if you have credibly proven your identity. Data Controller can be contacted with any questions or remarks related to data processing by any of the contact details indicated in the present Policy.