Terms of Service

Sillage Labs, Inc. · Version 2.1 · 9 September 2026

These terms govern your use of the Sillage platform. Please read them before using the Services. They form a contract between you and Sillage.

1. Who we are

Sillage Labs, Inc., a Delaware C Corporation, registered office 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States, operating in Europe through its French affiliate Sillage SAS, 58 rue de Monceau, 75008 Paris, registered with the Paris Trade and Companies Register under number 945 335 099.

Contact: hello@getsillage.com. For anything concerning personal data: privacy@getsillage.com.

2. Acceptance, and how these terms relate to a signed agreement

2.1 You accept these terms when you create an account. The signup screen tells you, next to the button you click, that creating an account means accepting these terms and our Privacy Policy, and links to both. We record which version you accepted and the date.

2.2 The Services are for business use only. By accepting these terms you confirm that you are acting on behalf of a business and that you have authority to bind it. The Services are not intended for consumers.

2.3 Signed agreements prevail. If your organisation has signed a Software Licence and Services Agreement with us, that agreement governs your use of the Services and prevails over these terms in full. These terms apply only where no signed agreement is in place.

2.4 These terms incorporate the following documents:

  • our Data Processing Agreement, which governs how we process personal data on your behalf, and which prevails over these terms on any question of personal data;
  • our Privacy Policy, which explains how we handle data about you and your users;
  • the plan and pricing you selected when subscribing.

3. The Services

3.1 Sillage is a software-as-a-service platform that detects, qualifies and prioritises sales opportunities from multi-source signals. It gives business-to-business revenue teams a view of which organisations are worth approaching and when.

3.2 We grant you a non-exclusive, non-transferable right to access and use the Services for your own internal business purposes, for as long as your subscription is active.

3.3 The features available to you depend on the plan you have selected. Plan details and current pricing are published on our website.

4. Accounts

4.1 You are responsible for keeping your access credentials confidential and for all activity under your account.

4.2 You are responsible for your users' compliance with these terms.

4.3 Tell us promptly at hello@getsillage.com if you believe your account has been accessed without authorisation.

5. Fees, billing and credits

5.1 Subscription fees are those published for your plan at the time you subscribe. All amounts are exclusive of VAT and other applicable taxes, which are added at the rate in force at the time of invoicing.

5.2 Fees are billed in advance on the anniversary of your subscription start date, by card through our payment processor, Stripe. By providing payment details you authorise us to charge the applicable fees on a recurring basis.

5.3 Credits. Where your plan uses credits, the number included and how they are consumed are set out on our pricing page. Unused credits roll over for ninety (90) days from the end of the period in which they were granted, and expire after that. Credits have no cash value, are not exchangeable for money, and are not refundable.

5.4 Late payment. If a payment fails we may suspend access under section 12 until it is resolved. Amounts more than two weeks overdue bear interest at the statutory rate plus five percentage points, together with the fixed recovery indemnity of EUR 40 provided by applicable law.

5.5 Refunds. Fees are non-refundable, except that we refund the unused prepaid portion of your subscription, pro rata, where:

  • we terminate your subscription other than for your breach of these terms;
  • we materially reduce the Services and you terminate as a result under section 14.3;
  • you reject a price increase under section 5.6;
  • a refund is required by applicable law.

5.6 Price changes. We may change our prices. We will give you at least thirty (30) days' notice by email before a change applies to you, and the change takes effect at your next renewal. If you do not accept it, you may cancel before the new price takes effect and we refund any prepaid amounts covering the period after cancellation, pro rata.

6. Free plans and trials

Free plans and trials are provided as they are, without any availability commitment or support undertaking. We may change or withdraw a free plan or trial at any time. We will give you reasonable notice before doing so and, where possible, an opportunity to export your data.

7. Acceptable use

You agree not to:

  • scrape, crawl or extract data from the Services other than through features we provide;
  • reverse engineer, decompile or attempt to derive the source code of the platform;
  • resell, redistribute or make the Services or the Signals available to third parties as a data product;
  • share your credentials, or allow access by anyone other than your authorised users;
  • use the Services unlawfully, or in breach of applicable data protection, marketing or anti-spam law;
  • upload personal data you have no lawful basis to provide to us, or data that is excessive for the purpose;
  • upload special category data as defined in Article 9 GDPR. Our Services are not designed for it and we exclude it;
  • use the Services to make decisions about individuals in regulated contexts, including hiring, credit, insurance or eligibility assessments;
  • interfere with the security or integrity of the platform.

8. Intellectual property and your data

8.1 Ours. We own all intellectual property rights in the Services, including the software, algorithms, features, documentation and the Signals. Nothing in these terms transfers ownership to you.

8.2 Yours. Data you provide to or generate in the Services, such as contact lists and CRM exports ("Customer Data"), remains your exclusive property. We acquire no ownership in it and use it only to provide the Services, in accordance with our Data Processing Agreement.

8.3 Using Signals. You may use the Signals delivered to you for your own internal business purposes, during and after your subscription. You may not resell or redistribute them.

8.4 Feedback. We may freely use suggestions and feedback you give us to improve the Services, without obligation to you and without acquiring any rights in your Customer Data.

8.5 No training on your data. We do not use Customer Data to train, fine-tune or otherwise improve any general purpose or foundation artificial intelligence model, whether ours or a third party's. We require the AI providers we use to accept the same restriction.

9. Where Signals come from

9.1 Signals are generated by us from sources we obtain independently of you. Those sources are:

  • company websites and job postings, including team pages, leadership pages and career pages;
  • news, press coverage, funding announcements, and public regulatory and company registry filings;
  • third-party data providers that license business contact and company data to us. We require them to confirm that they obtained the data lawfully and have met their own transparency obligations.

9.2 Signals concern organisations and the people who hold commercial roles in them. They cover those people in their professional capacity only. We do not build profiles of people's private lives and we exclude special category data.

9.3 For that source data we act as an independent controller, not as your processor. Our obligations to the individuals concerned are set out in our Notice to individuals in Sillage data. Where you upload your own contacts, you are the controller and we act as your processor under the Data Processing Agreement.

9.4 We do not access private inboxes, private messages or your CRM unless you connect them to the Services yourself.

10. AI outputs

10.1 The Services use machine learning and other automated methods to produce insights, rankings, signals, summaries and recommendations ("AI Outputs"). These are generated automatically and are not reviewed by a person unless we say otherwise.

10.2 AI Outputs are informational. They may contain errors, omissions, approximations or out-of-date information. We do not guarantee their accuracy, completeness or relevance. You are responsible for reviewing and validating them before acting.

10.3 The Services do not carry out automated decision-making within the meaning of Article 22 GDPR. Every decision taken using the Services is yours.

10.4 You are responsible for ensuring that any outreach informed by AI Outputs complies with applicable marketing, privacy and anti-spam law, and that a person reviews any message before it is sent.

11. Personal data

11.1 Where we process personal data on your behalf, our Data Processing Agreement applies. It forms part of these terms and prevails over them on any question of personal data. It sets out our roles, the description of processing, our security measures, our sub-processors and the Standard Contractual Clauses that apply to international transfers.

11.2 You confirm that you have a lawful basis for the personal data you provide to us, and that you have met your own transparency obligations towards the people concerned.

11.3 Data we hold as an independent controller is covered by our Privacy Policy and our Notice to individuals in Sillage data.

12. Availability, support and suspension

12.1 We use reasonable technical means to keep the Services available, and we may carry out planned maintenance. A contractual availability commitment with service credits is available under a signed Software Licence and Services Agreement.

12.2 Standard support is provided by email at hello@getsillage.com, Monday to Friday, 09:00 to 18:00 CET.

12.3 Suspension. We may suspend your access where:

  • an undisputed payment is overdue;
  • you are in breach of section 7;
  • continued access presents a genuine security risk or a risk of unlawful use.

Except where an immediate security risk requires otherwise, we give you seven (7) days' notice and a chance to put things right first. We lift the suspension once the cause is resolved. Suspension is not termination, and we will not suspend indefinitely without either resolving the issue with you or terminating under section 14.

13. Confidentiality

Each of us keeps the other's non-public information confidential and uses it only in connection with the Services. If we are legally compelled to disclose your confidential information, we will tell you in advance unless the law forbids it, disclose only what is required, and challenge any request we consider overbroad or unlawful.

14. Term, cancellation and termination

14.1 Cancellation by you. You may cancel at any time by email to hello@getsillage.com or in the platform. You keep access until the end of the billing period you have paid for, and you are not charged again.

14.2 Termination for breach. Either of us may terminate if the other is in material breach and has not put it right within thirty (30) days of written notice. We may terminate immediately where your use is unlawful or presents a serious security risk.

14.3 Material reduction of the Services. If we materially reduce the overall functionality of the Services during a period you have paid for, we will give you thirty (30) days' notice and you may terminate with a pro rata refund.

14.4 Your data on exit. If you ask us within thirty (30) days after termination, we provide your Customer Data in a commonly used machine-readable format, at no charge. After that period we delete it in accordance with the Data Processing Agreement.

14.5 Sections 8, 13, 15, 16 and 19 survive termination.

15. Warranties

We warrant that:

  • we hold the rights and licences necessary to provide the Services;
  • the platform is supplied free of any known virus, malware or malicious code;
  • we will provide the Services in a professional manner consistent with industry standards;
  • we will comply with applicable data protection, information security and privacy law.

These are our only warranties. All other express or implied warranties are excluded to the extent permitted by law. In particular, and as set out in section 10, we do not warrant the accuracy of AI Outputs.

16. Liability

16.1 General cap. Except as set out in section 16.3, our total liability for any claim arising out of or relating to the Services is limited to the fees you paid in the twelve (12) months preceding the event giving rise to liability.

16.2 Indirect loss. We are not liable for indirect or consequential loss, including lost profits, lost revenue, lost customers, lost data or reputational damage, except in the case of gross negligence or wilful misconduct affecting our security or confidentiality obligations.

16.3 Data protection, security and confidentiality. For breach of our personal data protection obligations, for security breaches, and for breach of confidentiality, the cap in section 16.1 is replaced by a cap equal to three (3) times the fees you paid in the twelve (12) months preceding the event giving rise to liability. Where you use the Services on a free plan or trial, section 16.1 applies without increase. Within that cap we remain liable for the actual damage caused, excluding indirect loss save in the case of gross negligence or wilful misconduct.

16.4 Nothing in these terms excludes or limits liability that cannot be excluded or limited under applicable law. In particular, these caps do not apply where the law does not permit them, and they do not affect any right you may have to compensation directly from us under Article 82 GDPR.

16.5 You are liable to us for claims arising from your Customer Data or from your use of the Services in breach of section 7.

16.6 A higher or uncapped liability position for data protection and security is available under a signed Software Licence and Services Agreement.

17. Changes to these terms

17.1 We may update these terms. We will notify you by email at least thirty (30) days before a change takes effect, and we will say what changed.

17.2 If you do not accept a change, you may cancel before it takes effect and we refund any prepaid amounts covering the period after cancellation, pro rata. Continuing to use the Services after the change takes effect means you accept it.

17.3 We keep previous versions available on request, so you can see what you agreed to.

18. Changes to the Services

We improve the platform continuously and may change or retire individual features. We will not materially reduce the overall functionality of the Services during a period you have paid for without giving you the notice and termination right in section 14.3.

19. General

19.1 Assignment. You may not assign these terms without our written consent. We may assign them to an affiliate or to a successor in connection with a merger, reorganisation or sale of substantially all of our assets, on notice to you.

19.2 Subcontracting. We may use subcontractors and remain responsible for their performance. Subcontractors processing personal data are listed in the Data Processing Agreement.

19.3 Notices. We contact you at the email address on your account. You contact us at hello@getsillage.com.

19.4 Export controls and sanctions. Each of us complies with applicable export control and economic sanctions law. You confirm you are not established in, and will not make the Services available to, a person or territory subject to such sanctions.

19.5 Force majeure. Neither of us is liable for a failure to perform caused by an event beyond our reasonable control. This does not excuse payment for Services already delivered.

19.6 Entire agreement, waiver and severability. These terms and the documents they incorporate are the entire agreement between us on their subject matter. Failure to enforce a provision is not a waiver of it. If a provision is held invalid, the rest stays in force.

19.7 Independent parties. We are independent contractors. Nothing here creates a partnership, joint venture or employment relationship.

20. Governing law and disputes

20.1 These terms are governed by French law.

20.2 If a dispute arises, please contact us first at hello@getsillage.com. We will try to resolve it with you in good faith.

20.3 Any dispute that cannot be resolved falls within the exclusive jurisdiction of the competent courts of Paris.

21. Contact

Questions about these terms: hello@getsillage.com

Questions about personal data, or to ask us to remove you from our data: privacy@getsillage.com

Sillage Labs, Inc., 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States.

Appendix - Data Processing Agreement

Sillage Labs, Inc. · Version 1.1 · 4 September 2026

This Data Processing Agreement (the "DPA") forms an integral part of the Software Licence and Services Agreement entered into between the parties (the "Agreement").

It supersedes and replaces any privacy policy or data processing terms previously annexed to the Agreement. In the event of any conflict between the Agreement and this DPA concerning the processing of personal data, this DPA prevails.

A signature-ready counterpart, including the party details and signature blocks, is available on request from hello@getsillage.com.

The Parties

The Customer - Controller. The entity entering into the Agreement, identified in the signed counterpart, hereinafter the "Controller" or the "Customer".

The Provider - Processor. Sillage Labs, Inc., a Delaware C Corporation incorporated on 13 October 2025 under Delaware file number 10364414, EIN 61-2301333, with its registered office at 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States of America, acting through itself and through its affiliate Sillage SAS (share capital EUR 6,000, registered office 58 rue de Monceau, 75008 Paris, France, registered with the Paris Trade and Companies Register under number 945 335 099), represented by Arnaud Weiss, President, hereinafter "Sillage" or the "Processor".

Together the "Parties", each a "Party".

Article 1 - Purpose

This DPA sets out the conditions under which the Processor processes, on behalf of and on the documented instructions of the Controller, the personal data necessary for the performance of the Services described in the Agreement, in accordance with Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and French Law no. 78-17 of 6 January 1978 as amended.

Article 2 - Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them in Article 4 GDPR. Capitalised terms not defined in this DPA have the meaning given to them in the Agreement.

"Customer Personal Data" means personal data submitted, uploaded, transmitted or otherwise provided by the Customer or its users to Sillage in connection with the Services, including data relating to the Customer's prospects and contacts.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021.

"Sub-processor" means any third party engaged by Sillage to process Customer Personal Data.

Article 3 - Roles of the Parties

3.1 The Customer acts as controller for Customer Personal Data that it or its users enter, import or process by means of the platform.

3.2 Sillage acts as processor for that processing. A detailed description of the processing appears in Annex A.

3.3 Independent controller data. Sillage independently sources, generates and maintains publicly available business information, enrichment data, insight data and buying intent signals. That data is not derived from Customer Personal Data and is not processed on the Customer's instructions. In respect of that data, Sillage acts as an independent controller and is solely responsible for establishing its own lawful basis and for meeting its own obligations under applicable data protection law. This Article 3.3 does not reduce Sillage's obligations as processor in respect of Customer Personal Data.

3.4 Where the Parties act as independent controllers, neither Party is a joint controller with the other, and each Party is responsible for its own compliance.

Article 4 - Documented instructions

4.1 Sillage processes Customer Personal Data only on the documented instructions of the Controller, including as regards transfers to a third country, unless required to do so by a law to which Sillage is subject. In that case Sillage informs the Controller of that legal requirement before processing, unless the law prohibits it.

4.2 The Agreement and this DPA constitute the Controller's initial documented instructions. Any subsequent instruction is given in writing.

4.3 Sillage informs the Controller without delay if, in its opinion, an instruction infringes the GDPR or any other applicable data protection provision.

Article 5 - Purpose limitation and use restrictions

5.1 Sillage processes Customer Personal Data solely for the following purposes:

  • delivering, operating and maintaining the Services;
  • providing customer support;
  • securing the Services and preventing fraud and abuse;
  • troubleshooting and debugging;
  • complying with applicable law.

5.2 Sillage will not:

  • sell, rent, licence or otherwise make available Customer Personal Data to any third party for that third party's own commercial purposes;
  • use Customer Personal Data for its own purposes, except where required by law;
  • combine Customer Personal Data with data from other sources except on the Customer's instruction or as necessary to deliver the Services to that Customer;
  • use Customer Personal Data to train, fine-tune or otherwise improve any general purpose or foundation artificial intelligence model, whether its own or a third party's.

5.3 Sillage contractually requires each AI model provider listed in Annex C not to use Customer Personal Data submitted through the Services for model training.

Article 6 - Confidentiality

Sillage ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and have received the necessary data protection training. This obligation survives the end of their duties and the expiry of the Agreement.

Article 7 - Security of processing

Sillage implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Those measures are described in Annex B. They may evolve, provided that the level of security is maintained at an equivalent or higher standard.

Article 8 - Sub-processors

8.1 The Controller gives its general authorisation to Sillage to engage the Sub-processors listed in Annex C for the performance of the Services.

8.2 Sillage informs the Controller of any intended addition or replacement of a Sub-processor with at least thirty (30) days' prior notice, so as to give the Controller the opportunity to object on legitimate grounds.

8.3 The Controller may object on legitimate grounds within that period. The Parties will discuss the objection in good faith. If the objection cannot be resolved, the Controller may terminate the Agreement in respect of the part of the Services concerned, without penalty and with a pro rata refund of any prepaid fees for that part.

8.4 Sillage imposes on each Sub-processor, by contract, data protection obligations equivalent to those set out in this DPA. Sillage remains fully liable to the Controller for the performance by each Sub-processor of its obligations.

Article 9 - International transfers

9.1 Customer Personal Data is hosted within the European Union. Sillage Labs, Inc. is established in the United States and accesses Customer Personal Data from that country for the purposes set out in Article 5.

9.2 Transfers of Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to Sillage Labs, Inc. are governed by the Standard Contractual Clauses, Module Two (controller to processor), which are incorporated into this DPA by reference and completed as set out in Annex D.

9.3 For transfers subject to the UK GDPR, the SCCs apply as supplemented by the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018. For transfers subject to Swiss law, the SCCs apply with the adaptations set out in Annex D.

9.4 Where a Sub-processor is located in a third country that does not ensure an adequate level of protection within the meaning of Article 45 GDPR, the transfer is governed by appropriate safeguards within the meaning of Article 46 GDPR, as identified for each Sub-processor in Annex C, supplemented by additional measures where necessary.

9.5 Sillage has carried out, and will keep under review, a transfer impact assessment in respect of the transfers described in this Article. A copy is available to the Controller on request.

Article 10 - Assistance with data subject rights

10.1 Taking into account the nature of the processing, Sillage assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights under Articles 12 to 23 GDPR, including the rights of access, rectification, erasure, restriction, objection and portability.

10.2 If a data subject makes a request directly to Sillage, Sillage forwards it to the Controller without undue delay and does not respond itself, unless instructed otherwise by the Controller or required by law.

Article 11 - Assistance with security, breaches and impact assessments

Taking into account the nature of the processing and the information available to it, Sillage assists the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, including security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments and, where applicable, prior consultation of the supervisory authority.

Article 12 - Personal data breach notification

12.1 Sillage notifies the Controller of any personal data breach without undue delay after becoming aware of it, and in any event within forty-eight (48) hours, so as to allow the Controller to meet its own seventy-two (72) hour notification obligation under Article 33 GDPR.

12.2 The notification includes, so far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and the contact point for further information. Where the information cannot be provided at the same time, it is provided in phases without undue delay.

12.3 Sillage does not notify any third party of a breach affecting Customer Personal Data by name of the Customer without the Controller's prior written consent, unless required by law.

Article 13 - Return and deletion of data

13.1 On expiry or termination of the Agreement, for whatever reason, Sillage will, at the Controller's written choice, return or delete all Customer Personal Data processed on its behalf, and destroy existing copies, within thirty (30) days of the end of the Agreement, unless retention is required by law.

13.2 If the Controller expresses no choice within thirty (30) days of the end of the Agreement, Sillage deletes the data.

13.3 Backups containing Customer Personal Data are purged in accordance with standard retention cycles, which do not exceed ninety (90) days from the date of deletion. Data held in backup remains subject to this DPA until purged.

13.4 Retention periods applicable during the term of the Agreement:

  • inactive user account data: twelve (12) months from last activity, then deleted or anonymised;
  • technical logs: twelve (12) months;
  • commercial data processed on behalf of the Customer (prospects, email addresses): retained for the term of the Agreement and deleted or returned as set out above.

13.5 Sillage may retain the minimum personal data required by law, for example for invoicing or statutory record keeping, for the period required by that law and for no other purpose.

Article 14 - Records, audits and information

14.1 Sillage maintains a record of the categories of processing activities carried out on behalf of the Controller in accordance with Article 30(2) GDPR.

14.2 Sillage makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it.

14.3 Audits are limited to one (1) per twelve (12) month period, save in exceptional circumstances such as a security incident affecting Customer Personal Data or a request from a supervisory authority. Audits are subject to thirty (30) days' reasonable prior notice, are conducted during business hours, and are carried out so as to respect confidentiality and the continuity of the Services.

14.4 Sillage may satisfy an audit request by providing a current independent third party audit report or certification covering the Services, where such a report addresses the scope of the Controller's request.

Article 15 - Liability

Each Party is liable for damage caused by processing in accordance with Article 82 GDPR. The limitations and exclusions of liability set out in the Agreement apply to this DPA, without prejudice to the mandatory provisions of the GDPR.

Article 16 - Final provisions

16.1 This DPA takes effect on the date of signature of the Agreement and remains in force for as long as Sillage processes Customer Personal Data.

16.2 This DPA may be amended only by written agreement of the Parties. Where an amendment is required by a change in applicable data protection law, Sillage will propose the amendment in writing with thirty (30) days' notice, and the Parties will negotiate in good faith to give effect to it.

16.3 The invalidity of any provision does not affect the validity of the remainder of this DPA.

16.4 This DPA is governed by French law. Any dispute relating to its interpretation or performance falls within the exclusive jurisdiction of the competent courts of Paris.

16.5 Data protection contact for the Processor: hello@getsillage.com, +1 (229) 600-5266, Sillage Labs, Inc., 1111b South Governors Ave, STE 40784, Dover, DE 19904, United States.

Annex A - Description of the processing

ItemDescription
Subject matterDetection, qualification and prioritisation of sales leads from multi-source signals, by means of the Sillage SaaS platform.
Nature of the operationsCollection, recording, structuring, storage, analysis, enrichment, scoring, retrieval, hosting and erasure.
PurposeTo provide the Customer with qualified prospect lists and B2B sales prospecting functionality.
Categories of data subjectsPlatform users (the Customer's personnel); business contacts and B2B prospects processed by the Customer.
Categories of personal dataIdentification data: first name, last name. Business contact details: professional email address, professional telephone number where provided. Professional data: job title, role, employer, professional social network profile URL. Platform activity metadata. Data entered or imported by users into the platform.
Special categories of dataNone. The processing of special category data within the meaning of Article 9 GDPR is not envisaged and is excluded.
Frequency of the transferContinuous, for the duration of the Agreement.
Duration of the processingThe term of the Agreement, followed by deletion or return within thirty (30) days (Article 13).
Controller's contact pointAs notified by the Customer in writing.
Processor's contact pointhello@getsillage.com

Annex B - Technical and organisational security measures

Sillage implements at least the following measures in accordance with Article 32 GDPR.

Access control and authentication

  • Access to the platform by individual user identifier and secure sign-in.
  • Privilege management on a least privilege basis.
  • Logging of access and of sensitive operations.
  • Multi-factor authentication for administrative access to production systems.

Data and transmission security

  • Encryption of data in transit (TLS 1.2 or above).
  • Encryption of data at rest.
  • Regular backups and documented restoration procedures.

Operational and organisational security

  • Segregation of environments and vulnerability management, including security updates.
  • Secure development practices and code review.
  • Confidentiality undertakings from personnel and data protection awareness training.
  • Documented incident and personal data breach management and notification procedure.
  • Continuous monitoring and threat evaluation.
  • Engagement only of Sub-processors providing sufficient guarantees (Annex C).

A current detailed description of these measures is available to the Controller on request.

Annex C - List of Sub-processors

Sub-processorService providedHosting locationTransfer mechanism
Sillage SAS (France)Intra-group provision of the Services, support and operationsEuropean UnionN/A (EU/EEA)
Digital OceanServer infrastructure (application and database hosting)European Union (Amsterdam)N/A (EU/EEA)
VercelFrontend hosting and deliveryUnited StatesStandard Contractual Clauses
CrispCustomer support messagingFrance / European UnionN/A (EU/EEA)
OpenAIAI model provider (signal analysis and enrichment)United StatesStandard Contractual Clauses
AnthropicAI model provider (signal analysis and enrichment)United StatesStandard Contractual Clauses
FullEnrichBusiness contact data enrichment (email and telephone lookup)Digital Ocean infrastructureStandard Contractual Clauses

Where a Sub-processor is certified under the EU-U.S. Data Privacy Framework, that certification applies in addition to the Standard Contractual Clauses.

The current list is available on request from hello@getsillage.com.

Annex D - Standard Contractual Clauses

D.1 Incorporation. The Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and completed as follows.

D.2 Module. Module Two (controller to processor) applies to transfers of Customer Personal Data from the Controller to Sillage Labs, Inc.

D.3 Optional clauses.

  • Clause 7 (docking clause): applies.
  • Clause 9 (use of sub-processors): Option 2, general written authorisation, applies. The notice period is thirty (30) days as set out in Article 8.2 of this DPA.
  • Clause 11 (redress): the optional independent dispute resolution paragraph does not apply.
  • Clause 17 (governing law): the law of France.
  • Clause 18(b) (forum): the courts of France.

D.4 Annex mapping.

  • Annex I.A (list of parties): the Parties identified at the head of this DPA. Data exporter: the Controller. Data importer: Sillage Labs, Inc.
  • Annex I.B (description of transfer): Annex A of this DPA.
  • Annex I.C (competent supervisory authority): the supervisory authority of the Controller's place of establishment. Where the Controller is established in France, the Commission Nationale de l'Informatique et des Libertes (CNIL).
  • Annex II (technical and organisational measures): Annex B of this DPA.
  • Annex III (list of sub-processors): Annex C of this DPA.

D.5 UK transfers. For transfers subject to the UK GDPR, the SCCs apply as supplemented by the ICO International Data Transfer Addendum, version B1.0. Table 1 is completed by reference to Annex I.A above. Tables 2 and 3 are completed by reference to this Annex D. In Table 4, neither Party may terminate under section 19 of the Addendum.

D.6 Swiss transfers. For transfers subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR are read as references to the FADP, the competent authority is the Federal Data Protection and Information Commissioner, and the term "member state" does not prevent data subjects in Switzerland from bringing proceedings in their place of habitual residence.