Template. This document is a starting point and has not been reviewed by counsel. Have a qualified lawyer review it before launch.

Data Processing Agreement

Last updated July 3, 2026

This template DPA supplements the silobase Terms of Service. It applies where you upload Salesforce metadata that contains personal data and where data-protection law requires a written processing agreement. The customer is the controller; {{TODO: confirm legal operating entity — likely Peakure LLC}} (“silobase”) is the processor. Where this DPA and the Terms conflict on the handling of personal data, this DPA governs.

1. Definitions

Controller, processor, processing, personal data, and data subject carry the meanings given under applicable data-protection law (for example the GDPR and the CCPA/CPRA). Metadata means a Salesforce metadata export you upload — a zip or SFDX source tree of component definitions. Subprocessor means a third party engaged by silobase to process personal data on the customer’s behalf.

2. Roles and subject matter

The customer determines the purposes and means of processing and is the controller. silobase processes personal data only to provide the service and only on the customer’s documented instructions, and is the processor. The subject matter is a static, upload-only analysis of Salesforce metadata.

silobase parses an uploaded metadata export and detects every email-sending path — Flows, workflow rules, email alerts, Apex senders, approval emails, and org-wide sender and deliverability settings — then produces a blast-radius manifest, a safe-test plan, a deliverability checklist, and an exportable evidence ledger. What the service does not do bounds the processing:

  • It reads metadata only. It does not read email content, CRM records, or contact data.
  • It never writes back to your org.
  • It never sends email. It maps paths that would send; it does not trigger one.
  • Recipient resolution is heuristic. v1 is upload-only, with no live-org OAuth connection.

silobase is an independent tool. It is not a Salesforce product, is not endorsed by Salesforce, and is not Mailtrap or a live-org connection.

3. Duration

Processing lasts for the term of your use of the service and until uploaded metadata is deleted or returned under Section 9. Uploaded metadata can be deleted on request or from the account.

4. Categories of data subjects and personal data

The customer controls what an uploaded export contains. In normal use the processing covers:

CategoryDataData subjects
metadataUploaded Salesforce metadata exports — component definitions that may reference addresses, org-wide sender addresses, or names embedded in configuration.Your Salesforce admins, users, and any people named in the metadata.
accountAccount details for authentication: name and email.Your users of silobase.
billingBilling details, handled by Stripe (silobase does not store card data).Your billing contact.
org_idsOrg and sandbox identifiers you enter.Not personal data by itself.

The service is not designed to process special-category data. Do not upload metadata whose sole purpose is to convey special-category personal data. The deterministic detector owns risk classification; the Claude API is given detector findings only, to explain them — not your raw org data.

5. Subprocessors

The customer authorizes silobase to engage the subprocessors listed on the Subprocessors page. That list is the current, real set and includes their processing purpose:

  • Supabase — Postgres database, authentication, and file storage for uploaded metadata (bucket metadata-uploads).
  • Stripe — payment and subscription processing.
  • Vercel — application hosting and Vercel Analytics, which is cookieless.
  • Resend — transactional email delivery.
  • Anthropic (Claude API) — generates plain-language explanations of detected risk and drafts the safe-test plan from the deterministic detector output. It receives detector findings, not your raw org data.

silobase imposes data-protection obligations on each subprocessor no less protective than this DPA. Before adding or replacing a subprocessor, silobase will update the Subprocessors page. If you object to a change on reasonable data-protection grounds, email privacy@silobase.io; if the objection cannot be resolved, your remedy is to stop using the service and request deletion under Section 9.

6. Processor obligations

  1. Instructions. silobase processes personal data only on the customer’s documented instructions, including as to transfers, unless required otherwise by law — in which case silobase notifies the customer first unless the law forbids it. Uploading metadata to the service, and the account’s configuration, are documented instructions.
  2. Confidentiality. Personnel authorized to process personal data are bound by confidentiality.
  3. Security. silobase maintains the technical and organizational measures in Section 7.
  4. Data-subject requests. silobase assists the customer, by appropriate measures and taking account of the nature of the processing, in responding to data-subject requests (Section 8).
  5. Assistance. silobase assists the customer with security, breach notification, and, where applicable, data-protection impact assessments, taking account of the information available to it.
  6. Personal-data breach. silobase notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer’s data.
  7. Deletion or return. On termination, silobase deletes or returns personal data under Section 9.
  8. Demonstrating compliance. silobase makes available information reasonably necessary to demonstrate compliance with this Section.

7. Security measures

silobase maintains measures appropriate to the risk. This section states only what is in place; it does not claim any certification, audit, or penetration test.

  • The application is hosted on Vercel.
  • Data is stored in Supabase, with encryption at rest as provided by Supabase.
  • Authentication is handled by Supabase, with optional two-factor / authenticator (2FA) available.
  • Row-level security is applied on data tables.
  • Uploaded metadata can be deleted.
  • Analytics (Vercel) is cookieless.

8. Data-subject rights

Taking account of the upload-only nature of the processing, silobase assists the controller in meeting its obligation to respond to data-subject requests to exercise rights under applicable law — such as access, correction, deletion, restriction, portability, and objection. Because silobase acts on the customer’s instruction, requests received directly from a data subject are referred to the customer. Direct the customer’s own data requests to privacy@silobase.io. This process describes how rights are exercised; it is not a claim of regulatory certification.

9. Return and deletion on termination

On expiry or termination, and at the customer’s choice, silobase deletes or returns the personal data it processes for the customer and deletes existing copies, unless retention is required by law. Uploaded metadata can be deleted on request or from the account. Send deletion requests to privacy@silobase.io.

10. International transfers

Subprocessors in Section 5 may process personal data outside the customer’s country. Where a transfer mechanism is required by applicable law, the parties rely on: {{TODO: confirm international data-transfer mechanism — e.g. EU Standard Contractual Clauses (SCCs) / UK IDTA — do not assume}}. silobase will use the transfer safeguards identified there for onward transfers to subprocessors.

11. Liability and governing terms

This DPA is governed by, and each party’s liability is subject to, the silobase Terms of Service, including its limitation-of-liability provisions. Governing law and jurisdiction: {{TODO: confirm governing law and jurisdiction — do not assume a city, state, or country}}. The processor’s registered business address: {{TODO: confirm registered business address}}.

12. Signature

To execute this DPA, complete the block below. It takes effect on the effective date once signed by both parties.

FieldProcessorController (customer)
Entity{{TODO: confirm legal operating entity — likely Peakure LLC}}{{TODO: customer legal entity — completed by customer}}
Signatory{{TODO: authorized signatory name and title for the processor}}{{TODO: customer authorized signatory name and title}}
Effective date{{TODO: effective date}}

Template version July 3, 2026

13. Contact

Questions about this policy? See Contact or read the Privacy Policy.
    Data Processing Agreement — silobase