Trust, GDPR & Data Protection
The short version: your logs stay yours, stay in the UK, and we process them only on your instructions. This page is written to be sent to your legal or compliance team.
Why your lawyers will ask about IP addresses
IP addresses are personal data under GDPR (Recital 30; CJEU Breyer C-582/14). Your CDN or web server already records them in its access logs: Salience analyses that existing operational dataset on your behalf. The correct legal footing, and the one we operate on, is:
You (controller) already collect server logs as an unavoidable part of operating a website, with legitimate interests (security monitoring, fraud prevention, service integrity: Recitals 47 & 49) as the lawful basis. We (processor) analyse them strictly on your documented instructions under our DPA, which is incorporated into our Terms and applies from signup without any signature.
Common questions from legal & compliance teams
Where is the data processed and stored?
Stored in AWS London (eu-west-2). For customers who ingest via AWS CloudFront, log records transit AWS US infrastructure (us-east-1) momentarily before storage in London, covered by AWS's GDPR Data Processing Addendum and Standard Contractual Clauses. Full detail: sub-processor list.
Who are your sub-processors?
AWS (hosting), Anthropic (optional AI features, can be disabled for your organisation), Stripe (billing only; never sees log data), Google (only if you connect Search Console). See the current list, including our 30-day advance-notice commitment.
Do you need our visitors' consent?
No consent banner is required for Salience: we place nothing on the visitor's device. Your lawful basis for the underlying log processing is legitimate interests, we provide a Legitimate Interests Assessment template your team can adapt and file.
What if we can't share full IP addresses?
Options today: (1) enable your platform's PII exclusion (Vercel and Netlify can strip IP and user-agent before anything is sent: Salience handles the reduced records gracefully); (2) use retention filters to store only bot/crawler traffic and discard human visitor records. An ingest-time IP-masking option is on our roadmap, ask us.
How long do you keep our data?
Per your plan (30 days to 2 years) and your configuration. On termination, data is deleted per the DPA (30 days, with backup purge within a further 35).
What happens in a breach?
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the detail you need for your own Art. 33 assessment. See the DPA.
What security controls do you run?
Summarised in our security overview: encryption everywhere, hashed API keys, least-privilege IAM, per-customer data partitioning, point-in-time recovery on core stores, and more.
Are you SOC 2 / ISO 27001 certified?
Not yet, certification is on our roadmap. We run on AWS inherited controls and document our own measures honestly in the security overview; most SME counsel find this sufficient for a processor of pseudonymous traffic data.
CCPA/US clients?
We operate as a “service provider”, we process personal information only to provide the service, and do not sell or share it.
The lawyer pack
Everything your counsel needs, in one place:
• Data Processing Agreement (GDPR Art. 28, applies automatically, countersigned copy on request)
• Sub-processor list
• Security overview (Art. 32 measures)
• Legitimate Interests Assessment template
• Privacy policy · Terms of service