This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Silaar Terms of Service. It applies where Silaar processes personal data on behalf of a Customer in the Customer’s capacity as a data controller or processor. Accepting the Terms constitutes acceptance of this DPA.
1. Scope & Applicability
This DPA applies to the extent that the Services process personal data for which the Customer (or an entity the Customer represents) is a controller or processor under applicable data-protection law (“Customer Personal Data”). It complies with Article 28(3) of the EU GDPR and the equivalent Article 28 of the UK GDPR.
2. Roles of the Parties
- Customer acts as the data controller (or as a processor instructing Silaar) and determines the purposes and means of processing.
- Silaar acts as a data processor on behalf of the Customer and processes Customer Personal Data only on the Customer’s documented instructions.
3. Processing Details (Art. 28(3))
| Subject matter | Provision and use of the Silaar B2B API Gateway. |
|---|---|
| Duration | The term of the underlying Terms of Service. |
| Nature & purpose | Hosting, transmitting, and making available Customer data submitted through the Services, including API requests, configuration, and account settings. |
| Types of personal data | Identification and contact data, account credentials, usage and technical data, and any data the Customer chooses to submit through the API. Silaar does not knowingly process special categories of data under GDPR Art. 9. |
| Categories of data subjects | The Customer’s authorized users, employees, and end users, as applicable. |
4. Processor Obligations
Silaar will:
- Process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers, unless required by law (in which case Silaar will inform the Customer unless prohibited);
- Ensure that personnel authorized to process the data are subject to confidentiality obligations;
- Implement appropriate technical and organizational measures (Art. 32) to ensure a level of security appropriate to the risk;
- Not engage another processor without prior specific or general written authorization and, for general authorization, give the Customer the ability to object (Section 5);
- Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures in fulfilling the Customer’s obligations to respond to data-subject requests;
- Assist the Customer in ensuring compliance with security-of- processing, breach-notification, and data-protection-impact- assessment obligations; and
- At the Customer’s choice, delete or return Customer Personal Data after the end of the Services, and delete existing copies, unless storage is required by law.
Silaar makes available to the Customer all information necessary to demonstrate compliance and allows for and contributes to audits.
5. Sub-processors
The Customer grants Silaar general authorization to engage sub-processors for cloud hosting, email delivery, error monitoring, analytics, and customer support. Silaar imposes data-protection terms on each sub-process at least as protective as those in this DPA.
Silaar will give notice of intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object. To receive notices, subscribe via privacy@silaar.com. The current list of sub-processors is available on request.
6. International Transfers
Where Customer Personal Data is transferred outside the EEA, UK, or Switzerland, Silaar will ensure the transfer is subject to an appropriate safeguard, such as the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Agreement/Addendum, or another recognized transfer mechanism.
7. Data-Subject Rights & Assistance
Taking into account the nature of the processing, Silaar will assist the Customer in fulfilling its obligations to respond to requests from data subjects exercising their rights. The Customer is responsible for responding to such requests; Silaar will provide reasonable assistance, including by making data available for export or deletion.
8. Security Incidents & Personal Data Breaches
Silaar will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, will provide information reasonably required for the Customer to meet its breach-notification obligations, and will take reasonable steps to mitigate and remediate the breach.
9. Audits & Records
Silaar will maintain records of processing and make available information necessary to demonstrate compliance with this DPA. The Customer may audit once per year upon reasonable notice, or more often if required by a supervisory authority, subject to confidentiality.
10. Deletion & Return of Data
Upon termination or at the Customer’s request, and after the end of any migration period, Silaar will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless storage is required by law.
11. Changes to This DPA
We may update this DPA to reflect changes in law, regulatory guidance, or our practices. We will post the updated version here with a revised “Last updated” date.
Questions about this document?
We’re happy to clarify any part of this policy. For legal or privacy inquiries, contact our team:
- Email: legal@silaar.com (legal) · privacy@silaar.com (privacy / DPA)
- Phone: +213 675 295 494
- Mail: Silaar LLC 30 N Gould St, Ste R Sheridan, WY 82801 United States
© 2026 Silaar LLC. All rights reserved.