1. Subject matter & duration
Loki Build, Inc., a United States company operating as Silow (processor), processes personal data on behalf of the Customer (controller) in connection with the Service, for the term of the underlying agreement.
2. Roles
- Customer Workflow Data: Customer = controller; Silow = processor (GDPR Art. 28).
- Account / Website Data: Silow = controller.
- Zero-access deployments: Silow does not receive, access or store raw Customer Workflow Data; that data is processed inside the Customer’s own environment. Silow’s role for the limited metadata and support data it handles in this mode is set out in the applicable order form.
3. Nature & purpose of processing
Silow processes Customer Workflow Data to map how work is done and produce a ranked AI roadmap. Silow processes it only on the Customer’s documented instructions and for no independent purpose.
4. Deployment-specific annex — the core of this agreement
The processing facts differ by mode, and the DPA must annex both rather than blur them.
| Zero-access | Cloud-pipeline (default) | |
|---|---|---|
| Where raw captures are processed | Inside the Customer environment | Transmitted to Silow’s cloud |
| Silow’s access to raw captures | None | Transient, server-side, automated |
| Retention of raw captures | Silow holds none | Deleted within 48 hours |
| Data subprocessors | None | Named in the DPA (see §10) |
| Silow’s role | See §2 | Processor, GDPR Art. 28 |
| HIPAA / BAA | Available for regulated deployments | — |
5. Categories of data & data subjects
Data subjects: the Customer’s employees and other personnel whose work activity is captured through the Service.
Categories of personal data:
- application, window and document-title metadata;
- activity traces and interaction timestamps;
- the tasks, workflows and processes derived from the above.
Silow does not intentionally collect special-category data (GDPR Art. 9) and prohibits its inference (see §6). The controlling category list is set out in Annex I.
6. Prohibited processing — flow these down
Silow shall not, and shall bind subprocessors not to:
- sell or share personal data, or use it for advertising;
- use personal data to train or fine-tune any model;
- use one Customer’s data for any other Customer;
- retain, use or disclose personal data outside this agreement or outside the direct business relationship;
- infer emotions, mood, stress, sentiment, mental state, biometric traits or health;
- produce individual productivity scores, performance evaluations or employment recommendations.
7. Use restrictions binding the Customer
The Customer shall not use Silow’s outputs to make employment decisions, to score or rank individuals, for disciplinary purposes, to set productivity quotas, or for automated task allocation with employment consequences. These restrictions are what keep the system out of EU AI Act Annex III(4) high-risk territory.
8. Customer obligations before deployment
The Customer, as controller, is responsible for:
- identifying its own legal basis (usually GDPR Art. 6(1)(f) legitimate interest with a documented balancing test — not employee consent);
- giving employees all required notices and collecting acknowledgments where required (US: CT, DE, NY, ME);
- completing works-council co-determination before deployment where one exists (BetrVG §87(1) No. 6 — the objective capability to monitor is enough to trigger it);
- carrying out a DPIA where required (Art. 35). Silow assists with TOMs, data-flow descriptions and retention limits.
9. Security measures
Silow maintains technical and organizational measures appropriate to the risk (GDPR Art. 32), including: encryption of personal data in transit and at rest; role-based access control on a least-privilege basis; SSO / SAML for Customer authentication; audit logging of access to personal data; network and infrastructure controls at the cloud layer; and confidentiality obligations binding all personnel with access. The controlling list of measures is set out in Annex II and corresponds to the measures described on the /security page.
10. Subprocessors
Cloud-pipeline: a cloud infrastructure provider and a model-inference provider, each named in Annex I, and no others. The specific providers depend on the deployment and its jurisdiction, so they are fixed in the executed DPA rather than on this page. Zero-access: none.
Silow maintains a current list of subprocessors and gives the Customer prior notice of any intended addition or replacement of a subprocessor, allowing the Customer a reasonable period (draft: 30 days) to object on reasonable data-protection grounds before the new subprocessor begins processing. If a timely objection cannot be resolved, the Customer may terminate the affected Service. Silow imposes on each subprocessor data-protection obligations no less protective than those in this DPA — including the prohibited-processing flow-downs in §6 — and remains liable for its subprocessors’ performance.
11. Data-subject rights
Silow assists the Customer in responding to data-subject requests. Requests from the Customer’s employees are directed to the Customer as controller.
12. Breach notification
Silow notifies the Customer without undue delay after becoming aware of a personal data breach.
In any case, Silow notifies within 72 hours of becoming aware. The notice includes the nature of the breach, its likely consequences, and the measures taken or proposed.
13. Audit
Silow makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (or following a personal data breach, or where a supervisory authority requires it), allows for and contributes to audits — including inspections — conducted by the Customer or an independent auditor it mandates. Audits are subject to reasonable confidentiality and security constraints and must not compromise the security of other customers’ data. Silow may satisfy an audit request in the first instance through current third-party certifications and reports where these reasonably address the request. This audit right is mandatory under CPPA §7051 and is not omitted for California Customers.
14. International transfers
- EU/EEA Customer (controller) → Silow US (processor): SCC Module 2.
- Silow → subprocessor (each named in Annex I): SCC Module 3.
- UK: IDTA / UK Addendum — EU SCCs alone are not valid.
- Switzerland: EU SCCs with Swiss adaptations.
- EU–US DPF: in force and may provide an additional basis where Silow or a subprocessor is DPF self-certified.
SCC Modules 2 and 3 are the operative transfer mechanism for all EU/EEA transfers, supported by a transfer impact assessment (TIA). No transfer relies on the DPF alone.
15. California addendum
Silow acts as a service provider / contractor under CCPA/CPRA. Contract must satisfy CPPA §7051: limited and specified purpose; no selling or sharing; no retention, use or disclosure outside the contract; same level of privacy protection as the business; assistance with consumer requests; audit rights; notice if Silow can no longer comply.
Note: California’s employee and B2B exemptions sunset 1 January 2023 — employee data is fully in scope.
16. Deletion / return
Raw captures in cloud-pipeline mode are deleted within 48 hours as a matter of course. On termination, Silow deletes or returns remaining personal data per the Customer’s instruction, within 30 days, unless a longer period is required by law (in which case Silow continues to protect the data and processes it only as required by that law).
17. Annexes
- Annex I — details of processing
- Annex II — technical & organizational measures
- Annex III — subprocessors, by deployment mode
- Annex IV — SCCs (Module 2 + Module 3), UK Addendum, Swiss rider
- Annex V — deployment-mode annex (§4 above)