Silia, Inc.
This Privacy Policy explains how Silia, Inc. ("Silia", "we") collects, uses, shares, and protects personal data in connection with its website, business activities, and SaaS services available globally. It also describes the rights and choices of the users, customers, prospects, site visitors, and organizational representatives who interact with Silia.
1. Who we are and scope
Silia, Inc., a company incorporated in the State of Texas, United States of America, with its registered office at 1501 S MOPAC EXPY STE 220, Austin, TX 78746, USA, is the controller of the personal data it collects and determines for its own purposes, including data obtained through the website, contact forms, demonstration requests, event registrations, commercial communications, billing, account administration, and commercial support.
This Policy does not govern the content, data, or documents that customers upload, process, or manage within the Silia platform on their own behalf or on behalf of their end users ("Customer Content" or "Customer Data"). In those cases, unless the contract states otherwise, Silia acts as the customer's processor or service provider, and the processing is governed by the services agreement, the data processing agreement (DPA), the customer's documented instructions, and the applicable service documentation.
If you are an end user of a Silia customer and your inquiry concerns data uploaded or managed by that customer within the platform, you should normally direct your request to the relevant customer. Silia will support the customer in handling rights requests when it is appropriate to do so under the contract or applicable law.
2. Personal data we process
We may process the following categories of personal data, depending on how you interact with Silia:
| Category | Examples |
|---|---|
| Identification and contact | First name, last name, email, phone, country, city, language, company information, and professional contact details. |
| Professional data | Company, job title, department, industry, organization size, business needs, and communications with Silia. |
| Account and service administration | Username, credentials or authentication identifiers, role, permissions, account settings, associated organization, and preferences. |
| Site and service usage | Pages visited, date and time of access, clicks, usage events, logs, IP address, device identifiers, browser, operating system, referral URL, and diagnostic data. |
| Support and communications | Inquiries, tickets, files or information you send to support, meeting recordings or transcripts when disclosed and permitted, and product feedback. |
| Billing and commercial relationship | Tax information, billing address, purchase orders, payment details, payment history, and data necessary to administer contracts. Card payments are processed by specialized providers; Silia does not store the full card number. |
| Marketing and events | Communication preferences, registration for webinars or events, campaign interactions, downloadable forms, and survey responses. |
| Cookies and similar technologies | Cookie identifiers, pixels, tags, local storage, analytics, preferences, and opt-out signals such as Global Privacy Control when available. |
| Third-party or public source data | Commercial information obtained from distributors, partners, customers, authorized integrations, business directories, or public sources, where permitted by law. |
Sensitive data. Silia does not seek to collect sensitive personal data through the website or commercial forms. Do not send us sensitive information unless it is strictly necessary and there is a valid legal basis or contractual instruction. If in any case Silia needs to process sensitive data for its own purpose, it will do so on the applicable legal basis, including express consent where required.
3. How we obtain data
Directly from you, for example when you complete forms, request a demonstration, create an account, contact sales or support, register for an event, or respond to communications.
From your organization, customer, employer, or account administrator, when they create or administer your access to the service.
Automatically, through logs, cookies, SDKs, pixels, or other similar technologies when you visit the site or use the service.
From partners, distributors, commercial enrichment providers, authorized integrations, or public sources, to the extent permitted by applicable law.
4. Purposes and legal bases
We process personal data for the following purposes. Where the GDPR, UK GDPR, LGPD, or another similar regulation applies, we also indicate the main legal basis. Depending on the jurisdiction, more than one legal basis may apply.
| Purpose | Legal basis or main grounds |
|---|---|
| Respond to requests, quotes, demonstrations, and pre-contractual communications. | Pre-contractual measures, performance of a contract, consent, or legitimate interest in handling inquiries. |
| Create, configure, provide, administer, and support accounts and SaaS services. | Performance of a contract, legitimate interest in operating the service, and, where applicable, the customer's instructions as controller. |
| Administer the commercial relationship, contracts, renewals, billing, collections, accounting, and tax obligations. | Performance of a contract and compliance with legal obligations. |
| Authenticate users, manage permissions, protect accounts, prevent fraud, abuse, unauthorized access, incidents, and illegal activities. | Legitimate interest, legal compliance, and performance of a contract. |
| Monitor availability, performance, debug errors, maintain logs, and improve the security, quality, and functionality of the site and service. | Legitimate interest in maintaining and improving secure and reliable services; performance of a contract where applicable. |
| Analyze site and service usage, generate aggregate metrics, research trends, and develop product improvements. | Legitimate interest, consent for non-essential cookies or technologies where required, and equivalent bases under local laws. |
| Send commercial communications, newsletters, event invitations, surveys, or information about products and services. | Consent where required, legitimate interest for proportionate B2B communications, and the right to object or unsubscribe at any time. |
| Personalize content, measure campaigns, and conduct targeted advertising or retargeting when these tools are enabled. | Consent or opt-out option, depending on the jurisdiction; compliance with cookie preferences and recognized signals. |
| Comply with laws, respond to requests from authorities, exercise or defend claims, and conduct internal audits. | Compliance with legal obligations and legitimate interest in protecting rights and operating the business. |
| Manage corporate operations, financing, audits, mergers, acquisitions, reorganizations, or asset sales. | Legitimate interest, performance of a contract, and legal compliance, with appropriate safeguards. |
Withdrawal of consent and objection. Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Where processing is based on legitimate interest, you may object in accordance with applicable law.
5. Customer Data within the SaaS platform
Silia's customers determine what data they upload or process within the platform, as well as the purposes and means of that processing. With respect to that Customer Data, Silia acts as a processor, subprocessor, or service provider, as applicable. Silia will process that data solely in accordance with the contract, the DPA, the customer's documented instructions, and applicable law.
Administrators of the customer organization may manage users, permissions, settings, and certain usage records associated with their account.
Silia may access Customer Data when necessary to provide support, maintain security, resolve incidents, comply with legal obligations, or carry out authorized instructions.
Silia will not use Customer Data for behavioral advertising or for purposes incompatible with the contract. Any aggregated, anonymized, or de-identified use will be carried out in a manner that does not reasonably identify a person or reveal confidential customer content.
Where artificial intelligence features, automation, or third-party integrations exist, their operation, responsibilities, and controls must be described in the service documentation, the DPA, or the applicable contract.
6. Cookies and similar technologies
We use cookies, pixels, tags, local storage, and similar technologies to operate the site, maintain security, remember preferences, measure usage, improve the experience, and, when enabled and permitted, carry out marketing or targeted advertising. Strictly necessary cookies may be used without consent when they are indispensable to provide the requested site or service. Non-essential analytics cookies, non-essential functionality, advertising, or equivalent technologies will be activated in accordance with your consent or the applicable opt-out options.
| Type | Use |
|---|---|
| Necessary | Operate the site, log in, balance load, remember security settings, and prevent fraud. |
| Functional | Remember preferences, language, region, or settings that improve the experience. |
| Analytics | Measure visits, performance, traffic sources, errors, and aggregate use of the site or service. |
| Advertising or campaign measurement | Measure campaigns, cap frequency, personalize ads, or perform retargeting when permitted. |
You can manage your preferences at [Cookie Preference Center URL] or from your browser settings. You can also review the details of cookies, providers, purposes, and duration in our Cookie Policy: [Cookie Policy URL]. Where applicable law requires, we will honor universal opt-out or preference signals, such as Global Privacy Control (GPC), on the browser or device from which they are sent.
7. Commercial communications
We may send you commercial communications about Silia's products, services, events, content, or news when we have a legal basis to do so. You can unsubscribe using the link included in each email, adjusting your preferences at [Preference Center URL], or by writing to XXX@silia.com. Even if you unsubscribe from commercial communications, we may send you transactional or service communications, such as security notices, support, billing, or relevant changes to applicable terms.
8. With whom we share personal data
We may share personal data with the following categories of recipients, to the extent necessary for the purposes described:
| Recipient | Reason |
|---|---|
| Providers and subprocessors | Cloud hosting, infrastructure, security, authentication, support, payment processing, billing, analytics, communications, CRM, event management, customer service, auditing, and internal tools. |
| Customers and account administrators | When you use the service associated with an organization, that organization may administer your account, permissions, activity, and data related to the use of its environment. |
| Group companies, distributors, and authorized partners | Management of commercial opportunities, implementation, support, billing, regional sales, or customer service, including distributors authorized for Latin America or other regions. |
| Integrations and third parties chosen by the customer | When a customer or authorized user connects the service with third-party applications, APIs, or tools. |
| Professional advisors | Auditors, lawyers, accountants, banks, insurers, and consultants, subject to confidentiality where applicable. |
| Authorities, courts, and third parties in legal proceedings | Compliance with laws, valid requests, defense of rights, fraud prevention, security, or incident response. |
| Counterparties in corporate transactions | Evaluation or execution of a merger, acquisition, financing, reorganization, asset sale, or similar transaction, with appropriate safeguards. |
We do not sell personal data for money. However, certain United States privacy laws define "sale", "sharing", or "targeted advertising" broadly, which may include the use of cookies, pixels, or third-party advertising tools. Where applicable, you may opt out of such activities through [Do Not Sell/Share My Personal Information URL], the cookie preference center, or a recognized GPC signal.
9. International transfers
Silia is established in the United States and uses providers, infrastructure, teams, distributors, and partners that may be located in various countries. As a result, your personal data may be processed outside your country of residence, including the United States and other countries that may not offer the same level of protection as your jurisdiction.
Where the law requires, we use appropriate transfer mechanisms, such as the European Union's Standard Contractual Clauses, the United Kingdom's Addendum or IDTA, contractual clauses or other local mechanisms, transfer assessments, and supplementary security measures. Where a recipient in the United States holds a valid certification under a recognized adequacy framework, such as the EU-U.S. Data Privacy Framework, we may rely on that mechanism; nevertheless, this Policy should not be construed as a declaration of certification unless Silia expressly publishes it.
You may request reasonable information about the applicable safeguards by writing to [xxxxx@silia.com].
10. Data retention
We retain personal data for as long as necessary to fulfill the purposes described, provide the service, handle requests, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. The specific periods depend on the type of data, the purpose, and applicable law. In general:
| Type of data | Retention criteria |
|---|---|
| Prospect and marketing data | Until you withdraw your consent, object, request to unsubscribe, or it ceases to be necessary for a legitimate commercial purpose, subject to suppression lists necessary to honor your opt-out. |
| Account and service data | While the account is active and for the necessary period thereafter for support, security, auditing, contractual or legal compliance. |
| Billing, payment, and contract data | During the commercial relationship and for the periods required by applicable tax, accounting, commercial, or statute-of-limitations laws. |
| Security and diagnostic logs | For reasonable periods for security, fraud prevention, auditing, incident investigation, and service continuity. |
| Customer Data | In accordance with the contract, DPA, customer instructions, retention settings, and applicable legal obligations. |
When it is no longer necessary to retain personal data, we will delete, anonymize, or block it in accordance with applicable law and our internal procedures.
11. Security
We apply reasonable and proportionate administrative, technical, and physical measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include access controls, authentication, encryption in transit or at rest where applicable, monitoring, logging, vulnerability management, training, confidentiality agreements, and provider assessment.
No system is completely secure. If we detect a security breach affecting personal data, we will assess its scope and notify customers, affected persons, or authorities when required by law or contract.
12. Your rights and choices
Depending on your location and applicable law, you may have the right to:
Access or know the personal data we process about you.
Request rectification, correction, or updating of inaccurate data.
Request deletion, cancellation, or erasure of data.
Object to processing or request its restriction.
Request data portability where applicable.
Withdraw your consent at any time.
Opt out of direct marketing.
Opt out of the sale, sharing, or use of your data for targeted advertising, where those options are enforceable.
Limit the use of sensitive data where applicable.
Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, where that right exists.
Lodge a complaint with a competent authority.
Appeal our response where applicable state or local law provides for that right.
How to exercise rights. Write to [ xxxxx@silia.com] or use [Privacy Request Form URL]. To protect your information, we may verify your identity and, if you act on behalf of another person, request proof of authorization. We will respond within the timeframes provided by applicable law.
Non-discrimination. We will not discriminate against you for exercising your privacy rights. This does not prevent us from offering different features, prices, or services when the difference is reasonably related to the value or characteristics of the data and is permitted by law.
Requests related to Customer Data. Where Silia acts as a processor for a customer, we may refer your request to the relevant customer or act in accordance with its instructions.
13. Automated decisions, analytics, and artificial intelligence
Silia may use analytics, automation, or artificial intelligence tools to operate, secure, improve, or support its services, always in accordance with the contract and applicable law. Unless expressly stated otherwise, Silia does not make decisions based solely on automated processing regarding site visitors or business contacts that produce legal effects or similarly significant effects. If a service feature allows the customer to configure automated decisions or high-impact processing about its own users or data, the customer is responsible for assessing and documenting the applicable legal bases, notices, rights, and controls.
14. Minors
Silia's site and services are directed at organizations and professional users. They are not directed at minors, and we do not knowingly collect personal data from minors. If you believe that a minor has provided us with personal data, contact us at [ xxxxx@silia.com] so that we can assess and delete the information where appropriate.
15. Region-specific provisions
The following provisions supplement the rest of this Policy and prevail in the event of a conflict for persons located in the corresponding regions.
15.1 Mexico - Privacy Notice under the LFPDPPP
For persons in Mexico, Silia, Inc. is the controller of the personal data it processes for its own purposes. You may exercise ARCO rights (access, rectification, cancellation, and objection), revoke consent, and limit the use or disclosure of your data by writing to [ xxxxx@silia.com] or using [Privacy Request Form URL]. Your request must include your name, contact method, identification or reasonable means of verification, and a clear description of the right you wish to exercise.
The primary purposes include handling requests, providing services, administering accounts, billing, collections, complying with legal obligations, maintaining security, support, and operation of the service. The secondary purposes include commercial communications, event invitations, surveys, prospecting, and non-essential advertising. You may object to secondary purposes at any time through [Preference Center URL] or xxxxx@silia.com
We will respond within the timeframes provided by the LFPDPPP and other applicable provisions. The competent authority for the protection of personal data held by private parties is the Anti-Corruption and Good Governance Secretariat, without prejudice to subsequent regulatory changes.
15.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR, UK GDPR, or equivalent legislation applies, Silia acts as controller with respect to data processed for its own purposes and as processor with respect to Customer Data processed on behalf of the customer. The legal bases are described in Section 4. You may exercise rights of access, rectification, erasure, objection, restriction, portability, withdrawal of consent, and complaint to a supervisory authority. You may also object to direct marketing at any time.
For international transfers, Silia uses the mechanisms indicated in Section 9, including Standard Contractual Clauses and equivalent United Kingdom mechanisms where applicable.
15.3 United States
Silia does not sell personal data for money. We may use or have used cookies, pixels, or advertising/analytics tools that certain laws consider a "sale", "sharing", or "targeted advertising". You may exercise your opt-out at [Do Not Sell/Share My Personal Information URL], in the cookie preference center, or through a recognized GPC signal.
In the last 12 months, we may have collected and disclosed to providers or partners the categories indicated in this Policy, including identifiers, professional or commercial information, internet or network activity, approximate geolocation derived from IP, limited commercial inferences, and limited sensitive data such as account credentials when necessary for authentication and security. We do not use sensitive data to infer characteristics about individuals, unless indicated and permitted by applicable law.
15.4 Brazil
For persons located in Brazil, where the Lei Geral de Proteção de Dados (LGPD) applies, you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data or data processed in noncompliance, portability, information about sharing, review of automated decisions where applicable, withdrawal of consent, and deletion of data processed on the basis of consent, subject to legal exceptions. You may contact us at [ xxxxx@silia.com
15.5 Canada
For persons located in Canada, we will process personal information in accordance with the applicable principles of accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, transparency, individual access, and the ability to challenge compliance. You may request access to or correction of your personal information by writing to [ xxxxx@silia.com].
16. Third-party sites, integrations, and services
The site or service may contain third-party links, integrations, or features. This Policy does not cover the privacy practices of third parties that we do not control. If you connect the platform with third-party services or authorize integrations, the processing by those third parties will be governed by their own terms and policies, in addition to the instructions or settings established by your organization.
17. Changes to this Policy
We may update this Policy to reflect legal, regulatory, technical, operational, or service-related changes. We will publish the current version on the website with the date of the last update. When the changes are material and the law requires, we will provide additional notice, for example by email, in-service notice, or a prominent notice on the site.
18. How to contact us
Controller: Silia, Inc.
Address: 1501 S MOPAC EXPY STE 220, Austin, TX 78746, USA
Privacy email: [ xxxxx@silia.com
Rights form: [Privacy Request Form URL]
Preference and opt-out center: [Preference Center URL]