Trust & GDPR pack: DPA, sub-processors, security overview
A complete compliance pack for your legal team: Data Processing Agreement that applies automatically to every account, sub-processor list with 30-day change notice, Art. 32 security overview, and a pre-filled Legitimate Interests Assessment template.
Legal and compliance teams reviewing Salience now have everything in one place at salience.com/trust.html:
- Data Processing Agreement (GDPR Art. 28), processing details, breach
notification, deletion commitments, transfers. It is incorporated into the Terms of Service and applies automatically from signup, nothing to sign (countersigned copies available for procurement teams on request).
- Sub-processor list, who processes what, where, under which safeguards,
with a 30-day advance-notice commitment for changes.
- Security overview, the Art. 32 technical and organisational measures we
actually run: UK (London) data residency, encryption in transit and at rest, hashed API keys, least-privilege access, per-tenant isolation.
- Legitimate Interests Assessment template, a pre-filled ICO-style LIA your
DPO can adapt, covering the Recital 49 network-security basis for server-log analysis.
The short version, for the impatient: you are the controller, we are your processor, your logs stay in the UK, nothing runs in your visitors' browsers, and we never sell or pool your data.