Legal
GDPR Compliance
Last updated: April 12, 2026 · Effective immediately
The General Data Protection Regulation (GDPR) is a European Union regulation that gives individuals control over their personal data. Even though Matrix Studios Software is based in the United States, we serve users worldwide — including the EU and EEA — and we are committed to fulfilling our obligations under the GDPR.
This page supplements our Privacy Policy with specific information about how we handle personal data of EU/EEA residents.
1. Data Controller
Matrix Studios Software acts as the data controller for personal data processed through the Platform. This means we determine the purposes and means of processing your personal data.
Data Controller
Matrix Studios Software
Email: [email protected]
2. Lawful Bases for Processing
Under Article 6 of the GDPR, we process personal data based on the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation & authentication | Contract performance (Art. 6(1)(b)) |
| Hand landmark data for sign recognition | Consent (Art. 6(1)(a)) |
| Aggregated landmark data for model training | Legitimate interest (Art. 6(1)(f)) |
| Anonymized usage analytics | Legitimate interest (Art. 6(1)(f)) |
| Product update emails | Consent (Art. 6(1)(a)) |
| Security monitoring & fraud prevention | Legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments at any time.
3. Your GDPR Rights
As an EU/EEA resident, you have the following data protection rights under the GDPR:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you, along with information about how and why we process it.
- Right to Rectification (Art. 16): Request that we correct any inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict Processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to Withdraw Consent (Art. 7(3)): Where we process data based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint (Art. 77): You have the right to file a complaint with your local data protection authority (e.g., the Irish Data Protection Commission, the French CNIL, etc.).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, as required by the GDPR. If your request is complex or we receive a large number of requests, we may extend this period by an additional 60 days with prior notice.
4. International Data Transfers
Signpost is hosted on infrastructure provided by Vercel, which may process data in the United States and other countries. When transferring personal data outside of the EU/EEA, we rely on:
- Standard Contractual Clauses (SCCs): Pre-approved contractual terms adopted by the European Commission that provide adequate safeguards for data transfers.
- Adequacy Decisions: Where the European Commission has determined that a country provides an adequate level of data protection.
You may request a copy of the relevant transfer mechanisms by emailing [email protected].
5. Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to pose a high risk to individuals. Our hand landmark data processing pipeline has undergone a DPIA to confirm that appropriate safeguards are in place — including on-device processing, de-identification, and strict access controls.
6. Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all sub-processors that handle personal data on our behalf. These agreements ensure that each sub-processor meets GDPR standards for data security, confidentiality, and lawful processing.
7. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. If the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
8. Children Under GDPR
Under Article 8 of the GDPR, processing of a child’s personal data based on consent requires authorization from the holder of parental responsibility. The age threshold varies by EU member state (between 13 and 16). We follow a baseline age of 16 for EU/EEA users and require parental or guardian consent for users below this threshold.
9. Contact Our Data Protection Team
Matrix Studios Software
Data Protection Inquiries
Email: [email protected]


