Signal Privacy Policy

Last updated: August 21, 2026

This Privacy Policy describes how Signal (hereinafter also "Platform", "we", "our", or "Data Controller") collects, uses, stores and protects the personal data of users (hereinafter "you", "User") who access the site signal.elianor.org and use the Signal platform.

1. Data Controller

The Data Controller for personal data is:

Elianor
Calle Virgen del Coromoto 6, 38689 Guía de Isora, Tenerife, Canary Islands, Spagna
NIE/CIF: Z2365839H
Email: [email protected]
Telefono: +34 672 56 61 37
Sito: signal.elianor.org

2. Data collected

a) Registration data

  • Name (displayed publicly on the network)
  • Email address
  • Password (stored in encrypted form)
  • Bio and profile photo (optional)
  • Preferred language

b) Geolocation data

  • Geographic coordinates provided by the User, saved with a precision level chosen by the User (exact or reduced) and visible on the map only if the User enables sharing.
  • IP address used to estimate location and for security measures.
  • Location sharing requires explicit consent at first access to the map and can be revoked at any time from the profile settings.

c) Public profile data

  • Service Card (title, description, category, exchange mode, emergency availability).
  • SIG wallet balance (internal currency).
  • Risonanza (Resonance) status (outcome of the onboarding process).
  • Badges earned within the network.

d) Exchange data

  • History of exchanges initiated and received between Users (time, counterparty, card, amount in SIG, final rating).
  • SIG wallet movements, including credits, debits and escrow holds.

e) Internal messaging data

  • Content of 1-to-1 messages exchanged between Users through the Platform’s "Messages" feature.
  • Technical metadata (send and read timestamps, and participant identifiers).

f) Navigation and security data

  • IP address, browser, operating system.
  • Pages visited and access timestamps.
  • Security logs (logins, login failures, password changes, administrative actions).
  • Strictly necessary technical cookies for authentication and session preferences (see section 10).

3. Purposes of processing

Personal data are processed for the following purposes:

  • Service delivery — account management, map display, publication of Service Cards, initiation of exchanges between Users, 1-to-1 messaging.
  • Operational communications — sending verification emails, password resets, notifications about received exchanges, Resonance outcomes, nearby emergencies.
  • Resonance process — assessment of eligibility to join the network based on the questionnaire completed by the User.
  • Platform security — prevention of abuse, rate limiting, logging of critical events.
  • Legal obligations — compliance with obligations under Spanish and European law.
  • Service improvement — aggregated and anonymous analysis of Platform usage.

4. Legal basis for processing

  • Performance of a contract (Art. 6.1.b GDPR) — for account management, publication of Service Cards and management of exchanges.
  • Consent (Art. 6.1.a GDPR) — for sharing location on the map and for optional email notifications.
  • Legal obligation (Art. 6.1.c GDPR) — for the retention of data required by law.
  • Legitimate interest (Art. 6.1.f GDPR) — for Platform security and prevention of abuse.

5. Data retention

  • Account data — retained for the duration of the account and up to 12 months after deletion.
  • Exchange history and SIG movements — retained for the entire duration of the account; in aggregated form also beyond that period for ledger integrity.
  • 1-to-1 messages — retained as long as both participants keep their account active; they can be deleted by the individual User.
  • Security logs — retained for a maximum of 12 months.
  • Technical cookies — for the duration of the session or as indicated in section 10.

6. Data sharing

Personal data may be shared with:

  • Other Users of the network — limited to data made public by the User (name, bio, photo, Service Card, map location if enabled).
  • Technical infrastructure providers — hosting, database, job queues, transactional email service. Servers are located in the EU or in countries with an adequate level of protection.
  • Mapping services — map tiles come from CartoDB, based on OpenStreetMap data. They are requested directly by the User’s browser: the provider therefore sees the User’s IP address and the area being viewed, without Signal transmitting any data.
  • Address lookup (geocoding) — when the User sets their location by typing an address, that text is sent to Nominatim (OpenStreetMap Foundation) to be converted into coordinates. The transmission occurs only through an action of the User and is not linked to the User’s account.
  • Push notifications — if enabled, notifications pass through the service of the browser chosen by the User (Google for Chrome, Mozilla for Firefox, Apple for Safari). The content is encrypted between Signal and the device.
  • Distribution and protection network — Cloudflare, which routes and protects traffic directed to the Platform.
  • Email — Aruba, for service communications only.
  • Automatic translation — performed by an engine hosted on Signal’s servers: the texts remain on Signal’s infrastructure.
  • Competent authorities — when required by law or by a court order.

Donations. Signal does not sell goods or services and does not retain any commission. The Platform may host a link to an external fundraiser (GoFundMe), intended solely to support the costs of the project and not for profit. The donation takes place entirely on the provider’s site: Signal does not collect, process or store any payment data.

7. Emergency monitoring system

Signal integrates a multi-source monitoring system that aggregates in real time events relevant to civil safety. The system acquires data exclusively from public, institutional and open data sources, and shows them to Users on the map and in the Emergencies section.

a) External data sources

Active sources include:

  • USGS (United States Geological Survey) — global seismology
  • EMSC-CSEM — Euro-Mediterranean seismic network
  • GDACS (Global Disaster Alert and Coordination System) — European Commission + UN-OCHA
  • Meteoalarm (EUMETNET) — weather warnings from European national services
  • WHO (World Health Organization) — international health emergencies
  • ReliefWeb (UN-OCHA) — humanitarian crises
  • GDELT — monitoring of social and conflict events
  • Netblocks — network outages and digital blackouts
  • Official gazettes of Italy, Spain and France — emergency measures

Institutional sources are presented as verified. GDELT and Netblocks are monitored but unverified sources: the alerts derived from them state this explicitly, and their reliability is not guaranteed by Signal.

These data are public and contain no personally identifying information; they are processed for civil safety and community information purposes.

b) Personal data in the emergency context

  • Reports submitted by the User (Send alert feature) — category, description, approximate position, timestamp. The report is visible to other Users on the map and in the Emergencies section.
  • Distress calls (Ask for help feature) — approximate position, timestamp, call status (open / acknowledged / closed). The request is broadcast to Signal Users within a configurable radius.
  • Approximate position — used only to sort alerts by geographic proximity and to broadcast emergency reports; precision is the one chosen by the User in privacy settings.

c) Legal basis and purposes

  • Performance of a contract (Art. 6.1.b GDPR) — to provide the community alert function requested by the User.
  • Vital interests (Art. 6.1.d GDPR) — for distress calls, where processing is necessary to safeguard the User’s safety.
  • Legitimate interest (Art. 6.1.f GDPR) — for disseminating civil safety alerts based on public sources.

d) Retention

  • Alerts from external sources — retained until the technical expiry declared by the source, and in any case no longer than 90 days from publication.
  • User reports — retained for 12 months, after which they are anonymised or deleted.
  • Distress calls — metadata retained for 24 months for security, audit and legal purposes; descriptive content is deleted 90 days after closure.

e) Transparency and traceability

Each alert from an external source reports the original source, acquisition timestamp and public reference URL, where available. Signal performs no profiling, advertising ranking or engagement-oriented algorithmic mediation: alerts are ordered solely by declared technical criteria (geographic proximity and severity).

8. International transfers

Some technical providers may operate outside the European Economic Area (EEA). In such cases, transfers are covered by adequate safeguards (Standard Contractual Clauses approved by the European Commission, adequacy decisions, recognised codes of conduct).

9. User rights

Under the GDPR and the LOPDGDD (Ley Orgánica 3/2018), the User has the right to:

  • Access — obtain confirmation of the existence of processing and a copy of their data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request the deletion of their data when no longer necessary or upon withdrawal of consent.
  • Restriction of processing — in the event of a dispute over the accuracy of data or unlawful processing.
  • Portability — receive their data in a structured, commonly used and machine-readable format.
  • Objection — object at any time to processing for legitimate reasons.
  • Withdrawal of consent — withdraw previously given consent, without prejudice to the lawfulness of processing carried out before withdrawal.

In particular, profile photo and bio can be edited or removed at any time by the User from their own profile page. Removing the photo deletes the file from Signal’s servers within the time technically required.

To exercise these rights, write to [email protected].

You also have the right to lodge a complaint with the competent supervisory authority: in Spain, Agencia Española de Protección de Datos (AEPD).

10. Security

Signal adopts reasonable technical and organisational measures to protect personal data, including password encryption, dual-token JWT authentication, CSRF protection on all write operations, rate limiting and logging of critical events. The User undertakes to keep their credentials safe, to use up-to-date devices and to report any unauthorised access to their account promptly.

12. Changes

We reserve the right to update this Privacy Policy at any time. In the event of material changes, Users will be informed by email or via a notice on the Platform.

For any questions about the processing of your personal data, write to us at [email protected].

© 2026 Signal — Elianor — NIE/CIF Z2365839H — All rights reserved.