· · · ·
For Productions For Engineers Modules Downloads Live demo Request a demo
Legal

Privacy

SYGNAL is three separate things: an app on a phone, software running on your own servers, and this website. Who holds your data is different in each case. This page says which is which, in plain terms.

LAST UPDATED 20 SEPTEMBER 2026  ·  CONTROLLER: SYGNAL TV LTD, UNITED KINGDOM

Scope

Three surfaces, two controllers

Almost everything SYGNAL touches lives on hardware you operate, and we never see it. The exception is this website and the licence portal, where we do hold an account and a record of what we issued you.

01

The iOS app

Turns a phone into a camera, a talkback panel and a tally light on a production network. Everything it captures goes to the SYGNAL server you sign in to. Nothing goes to us. Controller: whoever runs that server — normally your facility.

What the app asks for
02

The SYGNAL software

Runs on your hardware, on your network. Accounts, media, comms and logs are written to your storage and stay there. We are not in the path and receive none of it. Controller: the organisation operating the server.

What a server holds, and the two times it talks to us
03

sygnal.tv, downloads and the licence portal

The marketing pages carry no analytics and no tracking. The portal is a real account: an email address, a password, your units and the licences we issued for them. Controller: Sygnal TV Ltd.

What we hold, and for how long

01 · iOS app

The app asks for what it needs to be a camera.

iOS asks before any of these, and it asks once. Decline any of them and the rest of the app still works — you just lose the part that needs it.

Permissions
CameraTo produce the picture you are contributing. Nothing is captured or sent until you start a stream or a recording.
MicrophoneTo carry programme audio and talkback.
Local networkTo find SYGNAL servers on the same network and to receive tally over TSL UMD v5.0.
Photo libraryAdd-only, and only for clips and stills you choose to export. The app does not read your photographs.
Held on the device
Sign-inServer address, user ID and password, in the iOS Keychain, which encrypts them at rest. Signing out clears them.
SettingsCamera settings and stored framing presets.
RecordingsLocal recordings stay on the phone until you export or upload them.
RemovalDeleting the app removes all of the above.

What leaves the phone, and where it goes

When you connect, the app sends video, audio, camera state and talkback to the server you signed in to, and carries tally back. Who operates that server is a matter of your deployment: for most customers it is a machine in their own gallery, truck or data centre. Sygnal TV Ltd does not receive, store or have any access to that traffic, unless you are on a server we host for you under a separate agreement.

If you installed the app from the App Store, the download itself is Apple's transaction and Apple's own privacy terms apply to it. We do not receive an identity from Apple.


02 · SYGNAL software

Your server, your data, your responsibility.

A SYGNAL server holds a lot about the people using it and the show it is making. All of it is written to your storage. Under UK GDPR the organisation operating the server is the controller for every row of it; where we handle any of it during support, we act on your instructions.

What a SYGNAL server holds — on your infrastructure
User accountsUsernames, credentials, multi-factor secrets, groups and permissions.
Sessions & tokensSign-in sessions and API tokens issued by your server, with last-used stamps.
MediaContributed feeds, ISO records, clips and replay material.
CommsTalkback and partyline audio, routed live. Recorded only if you choose to record it.
MonitoringControl values and flow statistics in your time-series database.
Location moduleIf you licence and enable it: BLE beacon readings from tags and devices, triangulated positions and heatmaps. That is presence data about identifiable people, and enabling it makes you responsible for telling them. It is written to your database and never reaches us.
The only times the software reaches us
Update checkThe macOS companion app fetches a signed update manifest from sygnal.tv. It sends no identifier, no serial and no licence details. As with any web request, our host and Cloudflare see the IP address and user agent that made it.
LicensingLicences are files, issued and installed by hand — the software never calls home to check one. To issue a licence we need a machine report you send us: a hardware fingerprint (a SHA-256 hash), its binding ID, the core version and a component inventory of the unit. It identifies a machine, not a person.
SupportLogs, exports or reports you decide to send us. Nothing is collected automatically.

03 · Website & portal

The one place we do hold your data.

These marketing pages set no cookies, run no analytics and carry no advertising. They store a single item in your browser, sygnal_lang, to remember the language you chose. The typefaces come from Google Fonts, so Google receives your IP address as part of serving them. Cloudflare sits in front of the site and sees request metadata, including your IP address, for delivery and security.

What a portal or downloads account holds
Sign-inYour email address and a hashed password. Administrator accounts also carry a time-based one-time-password secret, stored encrypted.
OrganisationYour company name, and a contact name and email address for it.
SessionA cookie holding a session identifier. We record the IP address and browser user agent against that session. It is strictly necessary, so we do not ask for consent to set it.
Audit logWhat was done, by whom, when and from which IP address. Every administrative and licensing action is attributed.
Machine reportsHardware fingerprints, binding IDs, core versions and component inventories of the units you register.
LicencesYour requests, the licences we issued, and their history.
EmailAddress verification, account approval, expiry warnings and service notices, sent through Google Workspace. We send no marketing email.

The licence ledger is permanent, on purpose

Every licence we issue is also written to an append-only ledger, mirrored to a private repository, before the licence is released to you. It records the customer, the unit and the machine fingerprint the licence was bound to. That record is the proof of what was licensed to whom, so it is not erased on request — deleting it would destroy the provenance of a licence that is still in service. It holds no contact details.


What we never do

No trackers, anywhere in the product.

  • No analytics SDK, no crash-reporting service and no advertising identifier in the app.
  • No tracking across apps or websites, and no advertising anywhere.
  • No profiling and no automated decision-making.
  • We do not sell or share personal data, and we never look at your programme material.
How it is protected
PasswordsStored hashed, never in plain text. Repeated failed sign-ins lock the account.
AdministratorsA second factor is required, and the administrative surface is reachable only over our private network.
Signing keysThe licence root key is encrypted at rest with a passphrase held by one person.
AccountabilityEvery administrative action is attributed in the audit log.

The legal part

Why we are allowed to hold it, and for how long.

Lawful bases
Your accountPerformance of our contract with you or your employer.
Issuing licencesContract, and our legitimate interest in protecting licensed software.
Security & auditLegitimate interests: keeping the mint authority and your licences safe.
CorrespondenceLegitimate interests: answering the email you sent us.
Retention
SessionsDeleted when they expire: 12 hours, or 60 minutes idle.
AccountsKept while the account is in use. Ask us and we will close and delete it.
Audit logsKept as a security record for as long as the account exists.
Licence recordsPermanent, for the reason given above.
EmailKept in our mailbox while it is useful. Ask us and we will delete it.
Who else processes it
CloudflareTLS, CDN and firewall in front of sygnal.tv. Sees request metadata and IP addresses.
DigitalOceanHosts the server running this site, the downloads app and the portal.
GoogleWorkspace carries our email. Google Fonts serves the typefaces on these pages and receives your IP address.
GitLabHosts our private repositories, including the licence ledger mirror.
AppleDistributes the iOS app, under its own terms, if you installed it from the App Store.

Some of these providers process data outside the United Kingdom. Where they do, the transfer relies on the UK's approved safeguards — an adequacy decision, or the UK Addendum to the Standard Contractual Clauses.


Your rights

Under UK GDPR you can ask us for a copy of the personal data we hold about you, or ask us to correct it, delete it, restrict what we do with it, or hand it to someone else. You can object to processing we base on legitimate interests. Write to us and we will answer within one month.

In practice such a request will concern your portal account or your correspondence with us, because the app and the software collect nothing for us in the first place. If your data sits on a customer's SYGNAL server, that customer is the controller and the request belongs with them — we will help them answer it.

If you think we have got it wrong you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.

Children

SYGNAL is professional broadcast equipment. It is not directed at children and we do not knowingly collect data from them.

Changes

If this policy changes materially we will move the date at the top and, where the change affects you, say so in the release notes and in the portal.

Contact

Email [email protected] about anything on this page, or to make a request about your data.

Email [email protected]