Template. This document is a starting point and has not been reviewed by counsel. Have a qualified lawyer review it before launch.

GDPR & CCPA Data Rights

Last updated July 3, 2026

This statement explains the rights you have over the personal data silobase processes and how to exercise them. It applies whether you are in the EU/EEA, the UK, California, or elsewhere. It is a process document, not a certification — silobase does not claim any compliance certification. For what we collect and why, read the Privacy Policy.

1. What silobase is (and is not)

silobase is an upload-only static analyzer for Salesforce metadata. You upload a metadata export (a zip or SFDX source) and it maps every email-sending path — Flows, workflow rules, email alerts, Apex senders, approval emails, and org-wide sender and deliverability settings — into a blast-radius manifest with a safe-test plan and an evidence ledger. It reads metadata only. It does not read email content, CRM records, or contact data; it does not connect to or write back to your org; and it never sends email — it maps the paths that would send, it does not trigger one. silobase is not a Salesforce product, is not endorsed by Salesforce, and is not a live-org connection.

2. Who the data controller is

The controller for the personal data described here is {{TODO: confirm legal operating entity — likely Peakure LLC}}, contactable at privacy@silobase.io. Registered address: {{TODO: registered business address of the operating entity}}.

  • EU/EEA representative (GDPR Article 27): {{TODO: appoint and name an EU/EEA Article 27 representative, or state one is not required}}
  • UK representative (UK GDPR): {{TODO: appoint and name a UK GDPR representative, or state one is not required}}

3. What data this covers

The personal data in scope, and the rights below, cover:

  • Uploaded metadata exports — the Salesforce metadata you upload, stored in Supabase (bucket metadata-uploads). Recipient resolution in v1 is heuristic and upload-only; there is no live-org OAuth.
  • Account details — name and email used for authentication.
  • Billing details — handled by Stripe as part of Report and Ledger purchases.
  • Org and sandbox identifiers — labels you enter to organize scans.

Risk classification is owned by a deterministic detector. The Anthropic Claude API is given the detector's findings — not your raw org data — and only writes plain-language explanations and drafts the safe-test plan. The full list of subprocessors (Supabase, Stripe, Vercel, Resend, Anthropic) is in the Privacy Policy.

4. Legal bases for processing (GDPR)

Where GDPR applies, we rely on the following bases:

PurposeLegal basis
Running the free scan, the $99 Report, and the $39/mo Release Ledger you asked forPerformance of a contract
Authenticating your account and securing uploaded metadataLegitimate interest — operating and securing the service
Cookieless product analytics (via Vercel Analytics)Legitimate interest — understanding usage without tracking cookies
Keeping billing and transaction recordsLegal obligation

5. Your rights under GDPR

If you are in the EU/EEA or the UK, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct data that is inaccurate or incomplete.
  • Erasure — ask us to delete your data. Uploaded metadata can be deleted.
  • Portability — receive data you gave us in a structured, machine-readable form. Your Report evidence exports (PDF and CSV) are yours to keep.
  • Restriction — ask us to pause processing while a request is worked out.
  • Objection — object to processing based on legitimate interest.
  • Complaint — lodge a complaint with your local data protection supervisory authority (in the EU/EEA) or the UK Information Commissioner's Office.

6. Your rights under CCPA/CPRA (California)

If you are a California resident, you have the right to:

  • Know — what personal information we collect and how it is used.
  • Delete — request deletion of personal information we hold.
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale or sharing — see the note below.
  • Non-discrimination — we will not treat you differently for exercising a right.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The subprocessors listed in the Privacy Policy process data only to run the service on our behalf.

7. How to exercise a right

Email privacy@silobase.io and tell us which right you want to exercise. You do not need to use a specific form. An authorized agent may submit a request on your behalf; we may ask for proof of that authorization.

Verification

We verify a request against the email on your silobase account, and may ask for additional information to confirm your identity before we act. Free scans can be run without an account; if a metadata upload is not tied to an account we may be unable to link a request to you, and we will tell you so.

Response window

We respond to a verifiable request within 30 days. Where the law allows and a request is complex, we may extend that period and will tell you why.

8. Automated decisions

The deterministic detector classifies email-risk in your metadata; the Claude API only explains those findings in plain language. silobase does not use this to make automated decisions that produce legal or similarly significant effects about you as an individual.

9. International transfers

silobase is hosted on Vercel, with data stored in Supabase; payments run through Stripe, transactional email through Resend, and explanations through the Anthropic Claude API. These providers may process data in regions outside the EEA or the UK. We rely on the data-processing terms each provider offers; we do not claim any specific transfer certification.

10. Security posture

Data is stored in Supabase with encryption at rest as provided by Supabase, protected by row-level security on data tables. Authentication is handled by Supabase, with optional two-factor (authenticator / 2FA) available. Uploaded metadata can be deleted. Analytics is cookieless. We do not hold or claim any security certification.

11. Contact

Questions about this policy? See Contact or read the Privacy Policy.
    GDPR & CCPA Data Rights — silobase