SilowsilowBook a demo
Legal

Privacy Policy

Last updated 14 July 2026

Draft — pending review by legal counsel

This document is a working draft, not a final or binding agreement. The substance is complete; a few clauses still carry notes for our legal counsel to confirm before publication.

1. Who we are

This Privacy Policy explains how Loki Build, Inc. (“Silow”, “we”, “us”), a United States company operating the Silow product, handles personal data. For any privacy question, or to request our registered US business address, contact team@silow.ai.

Silow is US-based and does not currently maintain an establishment in the EU. If you have questions about how we handle EU personal data, contact us at team@silow.ai.

2. The data we handle, by name

Different data has different rules, so we name it separately rather than lumping it together.

  • Customer Workflow Data — what the recorder captures on a customer’s machines: application and window metadata, activity traces, and the derived tasks and processes built from them. This is employee data. The customer is the controller; Silow is a processor.
  • Account Data — names, work emails, company, and administrative records of the people who buy and administer Silow. Silow is the controller.
  • Telemetry — product and service operating data used to keep the service running, secure and reliable. Where telemetry contains personal data of a customer’s users, Silow processes it as a processor on the customer’s behalf; where it concerns the operation of our own service, Silow may act as controller.
  • Support Data — what customers send us when they ask for help.
  • Website Data — what we collect at silow.ai. Silow is the controller.

3. Deployment modes — this section governs everything below

What is true about your data depends on which mode you deploy in. We do not publish claims that hold in one mode as if they held in both.

Zero-access deployment

Silow runs air-gapped on-premise or inside the customer’s own VPC. Processing happens inside the customer environment. Silow does not receive, access, store or transmit Customer Workflow Data. Raw captures never leave the customer’s perimeter, and there are no data subprocessors for workflow data.

This is the only place we say “your data never leaves your perimeter”, and it is the mode regulated buyers take.

Cloud-pipeline deployment (the default)

Raw captures are transmitted to Silow’s cloud, where they are filtered and anonymized server-side, and are then deleted within 48 hours. Silow acts as a processor under GDPR Art. 28, under a DPA, with the subprocessors named in §6.

In this mode it is not true that Silow never sees your data. It is true that raw captures are transient, that no human reviews them, that filtering and anonymization remove personal identifiers, and that raw captures are deleted within 48 hours. Filtering and anonymization run server-side in Silow’s cloud pipeline.

4. What we do not do — in any mode

These are product constraints, not policy preferences.

  • We do not train on your data. Customer Workflow Data is not used to train or fine-tune any model, ours or anyone else’s.
  • We do not sell or share personal data, and we do not use it for advertising.
  • We do not use one customer’s data for another customer.
  • No keystroke logging. We do not record what is typed.
  • No camera, no microphone. Nothing is captured from either.
  • No reading of message content. Private communications are not read.
  • No emotion recognition. We do not infer emotions, mood, stress, sentiment, mental state, biometric traits or health. (EU AI Act Art. 5(1)(f) prohibits workplace emotion inference; that prohibition has applied since 2 February 2025.)
  • No scoring of people. No individual productivity scoring, no performance evaluation, no ranking of employees, and no automated decision about anyone’s employment.
  • No human at Silow reviews raw captures.

5. Retention

  • Zero-access: we hold no Customer Workflow Data, so there is nothing for us to retain.
  • Cloud-pipeline: raw captures are deleted within 48 hours of processing. Derived, anonymized insights persist for the term of the customer agreement.
  • Account Data: for the term of the customer relationship and up to 12 months after, then deleted or anonymized, unless a longer period is required by law.
  • Website Data: aggregate analytics for up to 14 months.
  • Support Data: up to 24 months after a request is closed.

6. Subprocessors

For cloud-pipeline deployments, Customer Workflow Data is processed by a limited set of subprocessors — a cloud infrastructure provider for hosting and processing, and a model-inference provider for filtering and anonymization — and no others. Which providers these are depends on the deployment and its jurisdiction, so we do not fix the list on this page. The current, named list is set out in our Art. 28 DPA and is available on request from team@silow.ai. We give prior notice of any intended addition or replacement, with a period to object, as described in the DPA.

For zero-access deployments there are no data subprocessors for workflow data.

In neither deployment mode is Customer Workflow Data used to train any model.

For Website, Account and Support Data, we use service providers for hosting, email and customer-support tooling, and for privacy-friendly, aggregate website analytics. These providers process data only on our instructions and do not use it for their own purposes. We will publish the specific vendors in this section as our subprocessor register is finalized; contact team@silow.ai for the current list.

7. International transfers

Silow is a US company. Where personal data moves out of the EEA, UK or Switzerland:

  • EU/EEA customer (controller) → Silow (processor): Standard Contractual Clauses, Module 2.
  • Silow → subprocessor: Standard Contractual Clauses, Module 3.
  • EU–US Data Privacy Framework: adopted 10 July 2023. We rely on Standard Contractual Clauses as our primary transfer mechanism regardless of DPF status.
  • UK: the UK IDTA / UK Addendum is required — EU SCCs alone are not sufficient for UK restricted transfers.
  • Switzerland: EU SCCs with Swiss adaptations.

In cloud-pipeline mode, processing (including anonymization) may occur in the United States. EU-only processing is available in zero-access deployments.

For Customer Workflow Data, the customer (the employer) is the controller and determines the legal basis. Silow processes on documented instructions and cannot supply the employer’s legal basis for it.

We say this plainly because it matters:

  • Employee consent is generally not a valid basis in the EU — the EDPB treats it as not freely given, given the power imbalance. Customers should not rely on it.
  • The usual basis is GDPR Art. 6(1)(f) legitimate interest, with a documented balancing test.
  • In Germany, §26 BDSG is legally uncertain after CJEU C-34/21; document Art. 6 directly.
  • Works councils: BetrVG §87(1) No. 6 gives a works council co-determination over technical systems capable of monitoring behaviour or performance. The BAG holds that the objective capability is enough — the employer’s intention is not decisive. German customers with a works council must complete co-determination before deployment. We ship a works-council packet to support this.
  • DPIA: a data protection impact assessment (Art. 35) is the customer’s responsibility as controller. We supply the technical and organizational measures, the data-flow description and the retention limits.
  • US employee-monitoring notices: the customer is responsible for giving employees all required notices and collecting acknowledgments — including Connecticut, Delaware, New York and Maine, which have specific notice and acknowledgment regimes.

For our own website and account data, our bases are: consent (marketing emails and any non-essential cookies), performance of a contract (providing the product and support), legitimate interests (securing, operating and improving the service), and legal obligation (tax, accounting and regulatory records).

9. California

California’s employee and B2B exemptions sunset on 1 January 2023 — employee personal information is now fully in scope of the CCPA/CPRA. For Customer Workflow Data, Silow acts as a service provider (and, where applicable, a contractor) under the CCPA/CPRA: we process that data only to provide the service under our written agreement, and we do not sell it, share it for cross-context behavioral advertising, or retain, use or disclose it for any other purpose.

10. Your rights

Depending on where you are, you may have rights to access, rectify, erase, restrict, port or object to processing, and to withdraw consent. For Customer Workflow Data, direct your request to your employer — they are the controller. We assist them in responding. For Account or Website Data, contact us at team@silow.ai. US residents (including California) may exercise the rights their state grants; you may also complain to your state Attorney General or, in the EU, your local data protection authority.

11. Security incidents

We notify the affected customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach.

12. Cookies

We use essential cookies required for the site to function, and privacy-friendly, aggregate analytics. We do not sell your data, and we do not use advertising or cross-site tracking cookies.

13. Compliance status

  • GDPR: processor DPA under Art. 28 available today.
  • EU AI Act: aligned by design; the product boundaries in §4 are the mechanism.
  • SOC 2 Type II: in progress. We do not claim it and we show no badge until an audit completes.
  • ISO 27001: on the roadmap. Not claimed.

14. Changes

We may update this policy; we will post the new version here with a revised “last updated” date.

15. Contact

Loki Build, Inc. — operating as Silow. Contact: team@silow.ai. For our registered US business address, or to reach a data protection contact, email team@silow.ai.