Enterprise Security & Compliance Statement
SilaSend is architected from the bare metal up for isolated multi-tenant operation. We do not maintain unified data lakes, nor do we cross-contaminate lead records between organizations. Your uploaded prospect matrices, SMTP credentials, and dispatch logs remain cryptographically separated within dedicated tenant environments.
1. Data Processing Agreement (DPA) Framework
Under Article 28 of the GDPR, this section establishes the binding legal terms between Intequra Enterprise Solutions ("SilaSend") and the subscribing organization ("Customer"):
- Roles & Responsibilities: Customer acts as the Data Controller with respect to prospect and lead data uploaded into the platform. SilaSend acts strictly as the Data Processor.
- Instructions-Only Processing: SilaSend processes personal data solely under the explicit, automated instructions of the Customer through the workspace UI and API endpoints.
- No Monetization or Sale: SilaSend never sells, rents, licenses, or monetizes Customer lead databases to any third party under any circumstances.
- No Advertising Usage: Customer lead data is never analyzed, profiled, or transferred for marketing or third-party behavioral advertising purposes.
2. International Data Transfers & Subprocessors
To maintain reliable high-speed outbound email infrastructure, data may pass through approved infrastructure subprocessors under strict contractual safeguards:
- Standard Contractual Clauses (SCCs): Where data is processed or transferred outside the European Economic Area (EEA), SilaSend relies on EU Standard Contractual Clauses (Article 46 GDPR) integrated with processor agreements.
- Data Ownership Retention: Customers maintain absolute intellectual and legal ownership over all uploaded CSV flat files, segmented records, and historical engagement metrics.
3. Data Subject Rights (DSR) Protocols
SilaSend provides native interface tools and administrative support to allow Data Controllers to satisfy data subject requests within required statutory timelines:
4. Technical & Organizational Security Controls
Pursuant to Article 32 GDPR, SilaSend enforces physical, technical, and operational safeguards to protect against unauthorized access, destruction, or data breaches:
- Cryptographically Isolated Tenants: Workspace databases are partitioned logically and cryptographically, rendering cross-tenant data leakage impossible.
- Double-Gate Governance & RBAC: Administrators restrict team user capabilities, enforcing master SMTP locking and seat limit caps.
- Credential Encryption at Rest: Third-party SMTP app passwords and API secret tokens are encrypted using AES-256 primitives.
- Session Authentication: Authentication utilizes cryptographically signed JSON Web Tokens (JWT) with strict timeout windows.
- Audit Logging & Monitoring: System actions, login attempts, and dispatch pipelines generate automated activity logs for security auditing.
5. AI Processing & LLM Disclosures
SilaSend incorporates artificial intelligence via the Sila Asset Forge (SAF) for dynamic Spintax rewriting and email copy generation:
6. Legal Contact & DPO Inquiries
For GDPR Data Processing Agreements (DPA execution), standard contractual clauses, or Data Subject Requests, contact our Data Protection Team: