Data Processing Addendum
Last updated July 2026
This Data Processing Addendum ("DPA") describes how Sillops processes personal data on behalf of the organizations that use our platform. It supplements our Terms of Service and applies whenever we act as a processor of personal data that a customer controls.
This document is a plain-English template provided for transparency on our v1 site. It is not legal advice and has not been reviewed by counsel; the definitive, executed version governs any commercial relationship with Sillops.
01
Definitions
"Controller", "processor", "data subject", "personal data", and "processing" have the meanings given in applicable data-protection law. "Customer Data" means personal data that a customer, as controller, submits to the Sillops platform.
"Subprocessor" means a third party engaged by Sillops to process Customer Data in the course of providing the service.
02
Roles and scope
For Customer Data, the customer is the controller and Sillops is the processor. Sillops processes Customer Data only on the customer's documented instructions, including as set out in the Terms, this DPA, and the customer's use of the platform.
For data we collect about our own account holders and website visitors, Sillops acts as an independent controller under our Privacy Policy.
03
Details of processing
The subject matter is the provision of the Sillops ERP platform. The duration is the term of the customer's subscription plus any retention period described below.
The nature and purpose of processing is hosting, storing, and operating the customer's business records across the platform's modules. The categories of data subjects and personal data are determined by the customer and typically include the customer's employees, contractors, and business contacts.
04
Subprocessors
The customer authorizes Sillops to engage subprocessors — such as hosting, database, email, and monitoring providers — to help deliver the service. We impose data-protection obligations on each subprocessor no less protective than those in this DPA.
We maintain a current list of subprocessors and will give notice of any intended additions or replacements so the customer has an opportunity to object on reasonable grounds.
05
Security measures
Sillops implements appropriate technical and organizational measures to protect Customer Data, including multi-tenant isolation, role-based access control resolved on every request, encryption in transit, least-privilege production access, and a signed audit trail of significant actions.
We review these measures regularly and update them as risks and best practices evolve.
06
Data subject requests
Taking into account the nature of the processing, Sillops provides tools within the platform — access, correction, export, and deletion — that help the customer respond to data-subject requests.
If we receive a request directly from a data subject relating to Customer Data, we will, unless legally prohibited, direct that person to the relevant customer rather than respond on the customer's behalf.
07
Breach notification
If Sillops becomes aware of a personal-data breach affecting Customer Data, we will notify the affected customer without undue delay and provide the information reasonably needed to meet their own notification obligations.
We will cooperate with the customer and take reasonable steps to mitigate and remediate the breach.
08
Audits
On reasonable request and subject to confidentiality, Sillops will make available information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the customer or an agreed independent auditor.
Audits must be scheduled in advance, conducted during business hours, and must not disrupt the platform or the data of other customers.
09
Deletion and return of data
On termination of the service, Sillops will, at the customer's choice, return or delete Customer Data within a reasonable period, except to the extent retention is required by law.
Because Sillops runs on plain PostgreSQL with open export, customers can retrieve their own data through the documented API or CSV export at any time before deletion.
10
Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA does not expand either party's aggregate liability beyond those limits.
11
Contact us
For questions about this DPA or to raise a data-protection matter, email legal@sillops.com or book a demo and we'll connect you with the right contact.