Privacy Policy

Sillage Labs, Inc. · Version 2.1 · 9 September 2026

This policy explains what we do with personal data. We have tried to write it plainly. If anything is unclear, ask us at privacy@getsillage.com.

1. Which policy applies to you

Sillage handles personal data about three different groups of people, and the rules are different for each. Find yourself below.

Who you areWhat applies
You use Sillage, or you work at a company that does, or you contacted usThis policy. We are the controller. Read on.
Your details were uploaded into Sillage by one of our customersThat customer is the controller and its own privacy notice applies. We act only as its processor, under our Data Processing Agreement. Section 8 explains, and we will help you identify the customer.
Your professional details appear in Sillage because we sourced them ourselvesOur Notice to individuals in Sillage data applies. That is our Article 14 notice and it explains what we hold, where it came from, and how to have it removed.

2. Who we are

Sillage Labs, Inc. is the controller for the processing described in this policy. Registered office: 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States. We operate in Europe through our French affiliate Sillage SAS, 58 rue de Monceau, 75008 Paris, registered with the Paris Trade and Companies Register under number 945 335 099.

Data protection contact: privacy@getsillage.com.

3. What we collect about you

3.1 When you create an account or use the platform:

  • your name, work email address and the organisation you work for;
  • your role and the permissions granted to you in the platform;
  • authentication data, including single sign-on identifiers and session tokens;
  • usage data: pages viewed, features used, searches run, dates and times, and technical logs including IP address and browser type.

3.2 When you contact us: the content of your message, your contact details, and our reply.

3.3 When your organisation buys from us: billing contact details, invoices and payment records. Card details are handled by our payment processor and we never see or store the full card number.

3.4 When we talk to you about buying: your professional contact details and notes of our conversations, held in our own CRM.

We do not collect special category data as defined in Article 9 GDPR, and we do not want it.

4. The Sillage browser extension

If you install our Chrome extension, it works as follows.

  • What it reads. On pages of the CRM systems you have authorised, it reads the company or contact currently displayed, so it can look up matching signals.
  • What it stores locally. Your session token and interface preferences are held in your browser's local extension storage. They stay on your device and we cannot read them remotely.
  • Permissions. The extension requests storage, activeTab, tabs, scripting and host permissions limited to the CRM domains it supports. It does not read pages on other sites.
  • Where data goes. Lookups go to the Sillage API over HTTPS and nowhere else. The extension contains no third-party analytics or advertising code.
  • Removing it. Uninstalling the extension clears its local storage. Logging out clears the session token.

5. Cookies

We use only cookies that are strictly necessary to run the platform, keep you signed in and keep it secure. Cookies of that kind do not require your consent.

We do not use advertising cookies, and we do not use third-party tracking or analytics cookies.

If that ever changes, we will update this policy and ask for your consent before setting any non-essential cookie.

6. Why we process your data, and our legal basis

PurposeLegal basis
Giving you access to the platform and providing the ServicesPerformance of the contract with you or your organisation (Article 6(1)(b))
Authenticating you and keeping accounts secureContract, and our legitimate interest in securing the Services (Article 6(1)(f))
Providing support and answering your questionsContract, and our legitimate interest in supporting users (Article 6(1)(f))
Improving and debugging the platformOur legitimate interest in improving our product (Article 6(1)(f))
Preventing fraud, abuse and security incidentsOur legitimate interest in protecting the Services and our users (Article 6(1)(f))
Billing, invoicing and keeping accounting recordsContract, and our legal obligations (Article 6(1)(c))
Sending you service messages about your accountContract (Article 6(1)(b))
Marketing to business contacts about our productsOur legitimate interest in promoting our business, subject to your right to object at any time (Article 6(1)(f)). Where the law requires consent, we ask for it.
Establishing or defending legal claimsOur legitimate interest in protecting our rights (Article 6(1)(f))

We do not sell personal data, and we do not share it with data brokers.

7. Who we share it with

We use the following service providers. They act on our instructions and under contract.

ProviderWhat they doWhere
Digital OceanHosting of the application and databaseEuropean Union (Amsterdam)
VercelHosting and delivery of the web frontendUnited States
CrispCustomer support messagingFrance / European Union
StripePayment processing and billingEuropean Union and United States
OpenAIAI models used for signal analysisUnited States
AnthropicAI models used for signal analysisUnited States
FullEnrichBusiness contact data enrichmentDigital Ocean infrastructure

We require these providers not to use data for their own purposes, and we require our AI providers not to use data submitted through the Services to train their models.

We also share data with our professional advisers where needed, and with authorities where we are legally required to. If we are compelled to disclose data, we will tell the person or customer concerned in advance unless the law forbids it, disclose only what is required, and challenge any request we consider overbroad.

8. Data our customers upload

Our customers upload their own contact lists and CRM data into Sillage. For that data the customer decides what to upload and why, so the customer is the controller and we act only as its processor. Our Data Processing Agreement governs that processing.

If your details reached Sillage that way and you want them changed or removed, the customer is the right place to ask. Write to privacy@getsillage.com and we will help you work out who that is and pass your request on.

9. Data we source ourselves

Separately from anything our customers upload, we build our own dataset of professional information about companies and the people who hold commercial roles in them. For that data we are an independent controller.

If that is why you are reading this, our Notice to individuals in Sillage data is the document you want. It sets out what we hold, where we got it, our legal basis, how long we keep it, and how to have yourself removed. It is published alongside this policy.

10. Where your data is held

Our platform and databases are hosted in the European Union, in Amsterdam.

Sillage Labs, Inc. is established in the United States and our staff there access data to operate and support the Services. Some of the providers in section 7 are also in the United States. Those transfers are covered by the Standard Contractual Clauses adopted by the European Commission, with additional measures where we judge them necessary. You can ask us for a copy of the safeguards that apply.

11. How long we keep it

DataRetention
Account and profile dataWhile the account is active, then deleted or anonymised twelve (12) months after last activity
Technical logsTwelve (12) months
Support conversationsThree (3) years from the last exchange
Prospect and CRM records about potential customersThree (3) years from our last contact with you
Invoices and accounting recordsTen (10) years, as required by law
Data uploaded by a customerAs set out in the Data Processing Agreement: deleted or returned within thirty (30) days of the contract ending
BackupsPurged on a cycle not exceeding ninety (90) days from deletion

12. How we protect it

We encrypt data in transit (TLS 1.2 or above) and at rest. We use individual accounts and least-privilege access controls, log access to sensitive data, separate our environments, review code before release, and follow a documented incident and breach procedure. Our staff are bound by confidentiality obligations and receive data protection training.

No system is completely secure. If a breach affects your personal data and is likely to result in a high risk to you, we will tell you without undue delay.

13. Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy;
  • have it corrected if it is wrong or incomplete;
  • have it deleted in the circumstances the law allows;
  • restrict our processing while a question about accuracy or our legal basis is resolved;
  • object to processing based on our legitimate interests, including profiling. Where you object to direct marketing we stop, always and without exception;
  • portability, meaning you can receive certain data in a machine-readable format;
  • withdraw consent at any time where we rely on it, without affecting what we did before;
  • give directions about what happens to your data after your death, under French law.

Write to privacy@getsillage.com. We answer within one month. If a request is complex we may take up to two further months, and we will tell you within the first month if that happens. Exercising your rights is free. We may ask for enough information to identify you, but no more than we need.

14. Complaints

If you are unhappy with how we have handled your data, please tell us first at privacy@getsillage.com so we can try to fix it.

You can also complain to a data protection authority, in the country where you live, where you work, or where you think the problem happened. Because our European operations are in France, you may complain to the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

15. Children

Sillage is a business tool. It is not intended for anyone under 16 and we do not knowingly collect data about children. If you believe we hold data about a child, tell us and we will delete it.

16. Changes to this policy

If we change how we handle personal data, we update this policy and change the version date at the top. Where a change is significant, we will say what changed and, if you have an account, tell you by email.

17. Contact

privacy@getsillage.com

Sillage Labs, Inc., 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States

Sillage SAS, 58 rue de Monceau, 75008 Paris, France