Last updated: April 30, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Silo and the customer (“Customer”) governing Customer’s use of the Silo platform (the “Agreement”), as set out in our Terms of Use and Privacy Policy. By using the Service, Customer agrees to this DPA. Where Customer requires a counter-signed copy for its records, Customer may request one by contacting team@siloag.com.
This DPA reflects the parties’ agreement on the processing of Personal Data in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”), the EU General Data Protection Regulation (“GDPR”) and the UK GDPR where applicable, and other applicable data protection laws.
Capitalised terms used but not defined in this DPA have the meanings given in the Agreement. For the purposes of this DPA:
Customer is the Controller of Customer Personal Data. Silo acts as the Processor and processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers of Personal Data, unless required to do so by law.
Customer’s use of the Service in accordance with the Agreement constitutes Customer’s documented instructions to Silo. Silo will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in Schedule 1. Processing continues for the term of the Agreement and any additional period during which Silo is required to retain Customer Personal Data under Section 12.
Silo will:
Customer warrants and represents that:
Silo implements and maintains the technical and organisational measures described in Schedule 3, which include encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256), tenant isolation at the database level, multi-factor authentication on all administrative access, role-based access control, continuous vulnerability monitoring, and audit logging.
These measures are designed to ensure a level of security appropriate to the risk and to comply with the requirements of the GDPR (Art. 32), APP 11, and other applicable data protection laws. Silo will review and update its security measures as the threat landscape evolves; updates will not materially diminish the level of protection.
Customer authorises Silo to engage Sub-processors to process Customer Personal Data, subject to the conditions in this Section. The current list of Sub-processors is published at /subprocessors and forms part of Schedule 2.
Before engaging a new Sub-processor with access to Customer Personal Data, Silo will:
Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period by emailing team@siloag.com. If the parties cannot agree on a resolution, Customer may terminate the Agreement on written notice and receive a pro-rata refund of any prepaid fees for the unused portion of the term.
Silo remains liable for the acts and omissions of its Sub-processors to the same extent as for its own.
Customer selects the region in which its dedicated warehouse database is provisioned at the time of warehouse creation. Silo offers warehouse regions in the United States, the European Union (Germany), and Australia (Sydney). Customer warehouse data is stored exclusively in the selected region.
Where Customer selects an Australian warehouse region, Customer warehouse data (including Personal Data synchronised from connected integrations) is stored at rest in Australia. Operational metadata (authentication tokens, audit logs, application telemetry) and processing performed by certain Sub-processors may occur outside the selected region; the locations of such processing are disclosed in the sub-processor list.
Where transfers of Personal Data outside the EEA, UK, or Switzerland are necessary, Silo will rely on an appropriate transfer mechanism, including the Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. The SCCs are incorporated by reference into this DPA, with Module 2 (Controller-to-Processor) applying.
Silo will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be made by direct email to Customer’s nominated account owner and will include, to the extent then known:
Where information is not available at the time of the initial notification, Silo will provide it in subsequent updates as the investigation progresses. Silo will provide reasonable assistance to Customer in meeting Customer’s own breach notification obligations, including under the Notifiable Data Breaches scheme, GDPR Articles 33 and 34, and any contractual obligations Customer owes to its Data Subjects.
Silo’s incident response process is documented in its Incident Response Policy, a summary of which is available on request.
Taking into account the nature of the processing, Silo will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer’s obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction, portability, and objection).
If Silo receives a request from a Data Subject directly, Silo will, unless prohibited by law, redirect the Data Subject to Customer and notify Customer without undue delay. Silo will not respond to the request directly except on Customer’s instructions or as required by law.
Silo will assist Customer in carrying out data protection impact assessments and prior consultations with supervisory authorities where required by applicable data protection law, taking into account the nature of the processing and the information available to Silo.
Silo will make available to Customer, on reasonable request, the information necessary to demonstrate compliance with this DPA. This includes:
Where Customer reasonably believes that the information made available is insufficient to demonstrate compliance, Customer may request an audit no more than once in any twelve (12) month period (or more frequently if required by a supervisory authority or following a Personal Data Breach). The audit will be conducted at Customer’s expense by Customer or a mutually agreed independent auditor bound by appropriate confidentiality obligations, on reasonable prior notice, during business hours, and in a manner that does not unreasonably interfere with Silo’s operations.
Upon termination or expiry of the Agreement, Customer may request a full export of Customer warehouse data (SQL dump) within seven (7) days of termination. Silo will provide the export within seven (7) days of receipt of the request via an encrypted channel.
After the export period, or if no export is requested:
Silo may retain Customer Personal Data to the extent required by applicable law, in which case Silo will continue to ensure the confidentiality and security of such data and will not actively process it for any other purpose.
Silo uses AI providers to power agent-based analytics within the Service. AI model requests are routed through the Vercel AI Gateway, which Silo configures to mandate zero data retention with every downstream provider. Model providers currently include Anthropic (Claude), Google (Gemini), and OpenAI (GPT). The current list is maintained at /subprocessors and updated under the sub-processor change procedure in Section 7.
Customer Personal Data processed by these providers as part of providing the Service is not used to train, improve, or develop AI models. This commitment is contractually enforced with each AI Sub-processor.
AI interactions are ephemeral: Customer queries and the schema or data context provided to support them are processed for the immediate purpose of returning a result and are not retained by the AI provider for training purposes. Silo does not use Customer Personal Data to train its own models.
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law, including under the Privacy Act, the GDPR, or the Competition and Consumer Act 2010 (Cth).
Provision of the Silo data warehouse and analytics platform.
The term of the Agreement, plus the retention periods set out in Section 12.
Synchronising data from Customer’s connected sources to a dedicated warehouse database; storing, querying, and visualising that data; generating analytics and AI-assisted insights; supporting Customer’s use of the Service.
Personal Data contained in Customer’s connected data sources and synchronised to the warehouse, which may include: contact details (names, email addresses, phone numbers, postal addresses); account identifiers; transaction and donation records; behavioural and analytics data; and other categories of Personal Data Customer chooses to import.
Customer’s end users, customers, donors, employees, and other individuals whose Personal Data is contained in Customer’s connected data sources.
Customer is responsible for determining whether to import special categories of Personal Data (sensitive information under the APPs, or special categories under GDPR Art. 9). Where Customer does so, the same technical and organisational measures apply.
The current list of Sub-processors authorised under Section 7 is maintained at /subprocessors and incorporated by reference into this DPA.
Silo implements the following measures to protect Customer Personal Data. Detailed implementation is documented in Silo’s internal security policies, summaries of which are available on request.
Questions about this DPA, or requests for a counter-signed copy, should be sent to:
Email: team@siloag.com
Errinundra Pty Ltd t/a Silo Ag ABN: 29 680 843 814