1. Categories of Data Processed
To maintain platform security, execution logic, and analytical reports, SilaSend processes four distinct categories of information:
Full Operator Names, Business Email Addresses, bcrypt-hashed passwords, assigned User Roles, and Workspace Identity parameters.
Uploaded prospect CSV datasets, personalization attributes, custom schema columns, and Segment Matrix filter rules.
Chronological telemetry logs including open events, link clicks, soft/hard bounces, unsubscribes, and intent scores.
Login timestamps, originating IP addresses, user-agent strings, JWT authentication tokens, and SMTP transaction status codes.
2. Credential Handling & Relational Security
SilaSend operates on a Bring Your Own SMTP (BYO-SMTP) architecture. Your third-party relay credentials (e.g., Google Workspace App Passwords, Microsoft Office365 OAuth tokens, or dedicated SendGrid relays) are treated with maximum isolation:
- Encryption at Rest: All master and individual App Passwords are encrypted in database tables using AES-256 encryption.
- Strict Usage Boundary: Credentials are accessed dynamically by background dispatches strictly for executing authorized campaign sequences.
- Double-Gate Lockdown: Workspace administrators maintain lock-state controls over master SMTP relays, preventing unauthorized operators from viewing raw secrets.
3. Authorized Subprocessor Directory
SilaSend relies on specialized enterprise subprocessors to fulfill critical data processing functions:
| Subprocessor | Operational Purpose | Data Transfer Safeguard |
|---|---|---|
| OpenAI LLC | AI Spintax generation & tone detection (Asset Forge) | Zero Data Retention API; No LLM Training |
| ZeroBounce Inc. | Pre-flight lead verification & bounce prevention | Encrypted API Data Processing Addendum |
| Cloud Infrastructure | Primary application hosting, storage & database backups | AES-256 Storage; Isolated Partitioning |
| Customer SMTP Providers | Outbound message delivery routing (Google/M365) | Customer Managed Authentication |
4. Data Retention Schedule
We maintain strict data destruction timelines to ensure customer data is not retained beyond necessity:
5. Privacy Contacts & Compliance
For questions regarding data processing, privacy audits, or compliance verification: