Legal
Privacy Policy
This Privacy Policy explains how Apollo Advisors Pty Ltd ABN 34 346 108 139 handles personal information in connection with Signum, including signumos.com and the Signum application.
Apollo Advisors Pty Ltd is located at International Tower 3, Level 17, 300 Barangaroo Ave, Barangaroo NSW 2000, Australia. We aim to handle personal information in a clear and practical way and in accordance with applicable Australian privacy law.
Last updated 12 August 2026
1. Scope and roles
This policy covers our handling of personal information when you visit our public site, create or use an account, contact us, take the attention assessment, or otherwise interact with Signum.
We are generally responsible for the personal information we collect for our own business purposes, such as account administration, billing, support, marketing, security and operation of the public site. Where a workspace uploads or enters personal information about its contacts, clients or other people (“Customer Data”), that workspace decides why and how to use that data. We process Customer Data to provide and secure Signum and on the workspace's instructions, subject to applicable law.
2. Personal information we collect
Depending on how you use Signum, we may collect:
- Account and workspace information: name, email address, account identifier, workspace membership, role, preferences and login or security events.
- Customer Data: contact and company details, relationship records, notes, interaction summaries, tasks, time entries, pipeline and billing context, and other content a workspace enters or generates in the service.
- Communications and support information: messages sent to us, support-chat requests, email delivery events, and information needed to respond to a request or administer email preferences.
- Assessment, lead and marketing information: information submitted through our attention assessment, contact, demo or waitlist forms, including an optional marketing preference where offered.
- Billing information: subscription, plan, entitlement, invoice and payment-status information. Card details are handled by our payment provider rather than stored by us.
- Technical and usage information: device and browser information, IP-derived technical information, session and security signals, page paths, feature events, diagnostics and error information.
3. How we collect information
We collect information directly from you when you register, are invited to a workspace, use the service, enter Customer Data, make a payment, complete a form or contact us.
Workspaces may add information about people who are not Signum users, such as contacts, clients, prospects and relationship participants. If you add that information, you are responsible for having an appropriate basis to do so and for giving any notices required by law.
We also receive information through connected providers where enabled, such as payment, email delivery, authentication, hosting, security, analytics and optional enrichment services. We may collect publicly available professional profile or company information through the enrichment service when a workspace requests enrichment.
4. How we use information
- to provide, authenticate, secure, support and administer Signum;
- to maintain workspace membership, invitations, permissions and billing;
- to create and display the records, priorities, workflow history and other features requested by a workspace;
- to respond to enquiries, deliver requested emails and manage communication preferences;
- to prevent fraud, misuse and security incidents, and investigate errors;
- to analyse aggregated or de-identified service performance and improve reliability; and
- to comply with legal, regulatory and record-keeping obligations.
5. Priority Engine and automated assistance
Signum uses a rules-based priority and attention system to organise workspace records and surface suggested next actions. It uses workspace information such as overdue actions, interaction recency, deal value, client-health indicators and relationship strength. It is designed to assist a user's work planning; it does not make decisions about an individual's legal rights, employment, credit, insurance, eligibility or access to a service.
Some authenticated features send a limited workspace context to OpenAI to generate guidance, contact-question answers, outreach drafts or daily-briefing audio. These features are optional product assistance, not professional advice. We do not use Customer Data to train our own general-purpose models. We do not represent that OpenAI will not retain or use data unless that is covered by the applicable OpenAI service terms and account configuration.
You should review AI-generated output before relying on or acting on it. Do not submit special-category, highly sensitive or regulated information to an AI feature unless you have assessed that use and have an appropriate basis to do so.
6. How we disclose information
We disclose personal information only as reasonably necessary to operate Signum, where you or your workspace direct us to do so, or where law permits or requires it. Recipients can include other authorised workspace members and service providers that provide hosting, database and authentication services, payment processing, email delivery, AI assistance, optional enrichment, analytics and error monitoring.
Current provider categories used or supported by the product include Supabase (database, authentication and storage), Vercel (application hosting), Stripe (payments), Resend (email delivery), OpenAI (AI assistance), RocketReach (optional enrichment), Sentry (error monitoring), PostHog (product analytics) and Google Analytics (public-site analytics). A provider may not receive your information unless the relevant feature is enabled or used.
We do not sell personal information.
7. Storage, security and international handling
Signum uses hosted infrastructure, including Supabase and Vercel, to run the service. Workspace records are protected by authentication and database row-level security designed to limit ordinary product access to authorised members of the relevant workspace. We also use access controls, logging and other reasonable safeguards appropriate to the service. No online service is completely secure.
Our linked Supabase project is hosted in the Asia Pacific (Seoul) region. Some providers named above operate internationally and may process information outside Australia, including in the United States and other locations in which they or their subprocessors operate. We do not publish a fixed country list because provider processing locations and account configurations can change; we will take reasonable steps to use providers with appropriate safeguards for the service.
8. Retention and deletion
We retain account and Customer Data while the relevant account or workspace is active and for as long as reasonably necessary to provide the service, resolve support or security matters, meet legal obligations, establish or defend legal claims, or maintain appropriate business records.
Signum does not currently offer a general self-service export or automatic deletion workflow for all Customer Data. The product does provide a limited workspace activity export to authorised workspace managers. Requests for other deletion or access assistance are assessed case by case, taking account of the requester's authority, other users' data, backups, legal obligations and security needs. Operational-telemetry retention has been designed but is not enabled as an automatic production process.
9. Cookies, analytics and error monitoring
We use essential cookies or similar technologies for authentication, session security and service operation. Where configured, we use PostHog for limited product pageviews and selected product events, Google Analytics for public-site page measurement, and Sentry for error monitoring. The implementation disables PostHog autocapture, session recording and person profiles; it removes query strings and URL fragments from captured page paths. Sentry is configured to redact common sensitive fields and email addresses from error events.
Browser-based PostHog and Google Analytics do not load when your browser sends a Global Privacy Control or Do Not Track signal. You can also manage cookies through browser settings, though essential cookies are required for sign-in and some product functions.
10. Your choices, access, correction and complaints
You may ask us for access to, or correction of, personal information we hold about you. You may also ask us to delete information where appropriate, or unsubscribe from optional marketing communications. To protect privacy, we may need to verify your identity and authority. A workspace member should normally direct requests about Customer Data to the workspace that entered it; we will assist that workspace where appropriate.
To make a privacy complaint or request, email support@signumos.com with enough detail for us to identify the request. We aim to acknowledge and respond within 30 days. If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
11. Eligible data breaches and policy changes
We will assess suspected data breaches and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the OAIC as required by law.
We may update this policy when our practices or legal obligations change. The current version will be published here. Your use of Signum is also subject to our Terms of Service.
12. Contact
Apollo Advisors Pty Ltd
ABN 34 346 108 139
International Tower 3, Level 17
300 Barangaroo Ave, Barangaroo NSW 2000, Australia
Privacy enquiries: support@signumos.com