Data Processing Addendum
Effective date: 18 July 2026 Version: 1.0
This Data Processing Addendum (the "DPA" or "Addendum") explains how Salieno ("Salieno", "we", "us") handles personal data in connection with Salieno Core and the services at salieno.com. It forms part of, and is governed by, our Terms of Service, and it should be read together with our Privacy Policy and Cookie Policy.
This Addendum is written for customers whose own compliance processes require a data processing agreement. You do not need to sign anything separately: by using Salieno under our Terms of Service, this Addendum applies automatically to your account. If your organisation needs a countersigned copy, contact us at [email protected].
Where this Addendum and our general Terms of Service disagree specifically on the handling of personal data, this Addendum controls.
1. The short version
Salieno Core is self-hosted software. You install and run it on your own server. Because of that design, the most sensitive data in your business — your end-clients' data (their identities, orders, services, tickets, invoices) — lives entirely on your infrastructure. Salieno never receives it, never stores it, and never has access to it.
The only personal data Salieno holds is the small amount needed to give you a licence and to bill you:
- Your account data — the identity of the person(s) who sign in to your Salieno account (email address, name, and authentication factors), managed through the Salieno identity provider (auth.salieno.com); and
- Your billing data — the subscription and payment records tied to your account. Card details themselves are handled by Stripe; Salieno never stores your card number.
Everything below explains this in full: what we process and why, how we protect it, who our sub-processors are, how quickly we tell you about a breach, how long we keep data, and your audit rights.
2. Key terms
For clarity, in this Addendum:
- "Account Data" means the personal data relating to the individuals who register for, sign in to, and administer your Salieno account — for example email address, name, and authentication factors (such as passwords, two-factor secrets, passkeys, and backup codes).
- "Billing Data" means the personal and commercial data used to bill your subscription — for example your billing contact details, subscription status, invoices, payment status, and the payment-method reference held by Stripe. It does not include your full card number, which Salieno never stores.
- "End-Client Data" means any personal data about your own customers, users, or other third parties that you collect, create, or process within your self-hosted installation of Salieno Core. This data resides on your server and is out of scope of Salieno's processing.
- "Data Protection Law" means the data protection and privacy laws that apply to a party's processing of personal data — which may include the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable US state privacy laws — as each applies to that party.
- "Personal Data", "Controller", "Processor", "Sub-processor", "Data Subject", and "Personal Data Breach" have the meanings given to them under applicable Data Protection Law.
3. Roles and responsibilities
Getting the roles right matters, so we set them out plainly and honestly rather than assuming a one-size-fits-all "processor" template.
3.1 Your end-clients' data stays with you
Salieno Core runs on your server. Your End-Client Data is created, stored, transmitted, and processed entirely within your own installation and infrastructure. Salieno has no technical access to it and never receives a copy of it as part of providing the software or the licence.
For that data, you are the Controller (or, where you host on behalf of others, the processor for your own customers). You are responsible for your own compliance in respect of it, including choosing a lawful basis, honouring data-subject rights, securing your server, and appointing and contracting with any of your own hosting providers, panels, gateways, or registrars that touch it. Salieno is not your processor for End-Client Data, because Salieno never processes it.
3.2 Your account and billing data
For the Account Data and Billing Data described in Section 2, Salieno determines the purposes and means of processing — to provide, license, secure, and support Salieno Core, and to bill your subscription. In respect of that limited data, Salieno acts as an independent Controller, and our processing is described in full in our Privacy Policy.
Where you add additional users to your Salieno account (for example other members of your team), the limited personal data you provide about them is processed by Salieno as part of operating your account, on the same basis.
3.3 Why this Addendum still gives you the assurances you need
You may have requested a DPA expecting a classic controller-to-processor arrangement. Because Salieno Core is self-hosted, there is no such arrangement over your business data — which is a privacy advantage, not a gap. This Addendum instead documents, transparently, exactly what data Salieno holds and gives you the same core protections you would expect from a processor: defined security measures (Section 5), a named sub-processor list (Section 6), fast breach notification (Section 8), clear retention and deletion terms (Section 9), and audit rights (Section 10).
3.4 Your responsibilities
- Keep your own server, operating system, PHP runtime, database, and network secure and up to date.
- Apply Salieno Core updates, which we provide free of charge for as long as your subscription is active.
- Configure Salieno Core, and any add-ons you install, in line with your own legal obligations.
- Manage the lifecycle of your End-Client Data, including retention and deletion, on your own infrastructure.
- Keep your Salieno account credentials confidential and enable the account-security features we offer.
4. What we process, and why
The following summarises Salieno's processing as an independent Controller of Account Data and Billing Data.
Categories of data subject
- The individual(s) who register, sign in to, and administer your Salieno account (you and any team members you add).
- Your billing contact(s).
Categories of personal data
- Identity and account: email address, name, and authentication factors (password hashes, two-factor secrets, passkeys, backup codes), plus account and security metadata such as sign-in events, device and approximate location signals derived from your connection, and support correspondence you send us.
- Billing: subscription plan and status, trial and renewal dates, invoices and amounts, currency, payment status, and a payment-method reference and card metadata (such as brand and last four digits) held by Stripe. We do not store your full card number.
Purposes
- Creating and authenticating your account and keeping it secure.
- Issuing and validating your Salieno Core licence and delivering updates and downloads while your subscription is active.
- Billing your $6.00 USD / month subscription, managing your 30-day free trial, processing renewals and cancellations, and issuing invoices.
- Fulfilling one-time marketplace add-on purchases.
- Providing support, and detecting, preventing, and responding to fraud, abuse, and security incidents.
- Meeting our legal, tax, and accounting obligations.
Lawful bases (as applicable to you)
Depending on the law that applies to you, our processing relies on the performance of our contract with you, our legitimate interests in operating and securing the service, and compliance with legal obligations. Our Privacy Policy has the detail.
Duration
We process this data for as long as your account is active, and afterwards only as described in Section 9 (Retention, return, and deletion).
What we never receive
- Your End-Client Data.
- Your full payment card number (held by Stripe).
5. How we protect your data
Salieno maintains technical and organisational security measures appropriate to the limited, sensitive data it holds. These include:
- Encryption in transit. All connections to salieno.com, auth.salieno.com, and our licence, update, and download services use HTTPS/TLS.
- Credential protection. Account passwords are hashed with a modern memory-hard algorithm (Argon2id) plus a secret pepper; they are never stored in plain text. Sensitive signing keys are encrypted. Payment card numbers are never stored by Salieno — they are handled by Stripe, a PCI-DSS Level 1 service provider.
- Strong authentication. We support and encourage multi-factor authentication (time-based one-time passwords, passkeys/WebAuthn, and backup codes), and we require step-up re-authentication before sensitive account changes (such as changing your email, managing security factors, or closing your account).
- Access control and least privilege. Access to production systems and data is restricted to what is necessary, using role-based controls and least-privilege database roles. Internal services are not exposed to the public internet.
- Network hardening. Our services sit behind a managed edge with no unnecessary open ports, plus rate limiting, lockout, and anti-enumeration protections to resist abuse and credential attacks.
- Enforced browser security policy. Our web surfaces ship a strict Content Security Policy and modern security headers (including clickjacking and framing protections).
- Tamper-evident logging and monitoring. Security-relevant events are recorded in append-only, tamper-evident audit logs, and our services are monitored for availability and errors. We alert account holders about sign-ins from new devices.
- Secure development. Changes are reviewed for security before release, and the platform undergoes regular adversarial security review.
We may update these measures over time, provided we do not materially reduce the overall level of protection.
6. Sub-processors
Salieno keeps its use of third parties deliberately small. We engage the following categories of sub-processor to help deliver the account and billing service:
| Sub-processor | Purpose | Data it handles | | --- | --- | --- | | Stripe | Payment processing and subscription billing | Card details, payment-method and transaction data, billing contact details | | Transactional email provider | Sending account and billing emails (verification, security alerts, receipts, notices) | Email address and name, and the contents of the message | | Monitoring provider | Availability and error monitoring of Salieno's own services | Operational and error telemetry, which may include limited technical identifiers |
Notes:
- None of these sub-processors receives your End-Client Data, because Salieno never has it.
- Each sub-processor is engaged under terms that require appropriate security and confidentiality, and is limited to the purpose above.
- The list above reflects our sub-processors as at the effective date of this version. For the current list, or to be notified of changes, contact [email protected].
Changes to sub-processors. If we add or replace a sub-processor that handles your Account Data or Billing Data, we will update this Addendum and, where required, give you advance notice so you can review the change.
7. International data transfers
Salieno and its sub-processors may process data in countries other than your own. Where personal data is transferred across borders, we rely on an appropriate transfer mechanism recognised under applicable Data Protection Law (such as the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision), together with appropriate safeguards. Details of a specific transfer mechanism are available on request.
8. Assisting you with data-subject and compliance requests
Because Salieno does not hold your End-Client Data, requests from your customers must be handled by you within your own installation — we cannot act on data we do not have.
For the Account Data and Billing Data that Salieno holds about you and your team, you can exercise your rights (such as access, correction, export, and deletion) directly through your account settings or by contacting [email protected], and we will assist as required by applicable Data Protection Law. Many of these actions — reviewing your data, updating your profile, changing your email, and closing your account — are self-service in the account portal.
9. Personal data breaches
If Salieno becomes aware of a Personal Data Breach affecting the Account Data or Billing Data it holds about you, we will notify the affected customer without undue delay, and in any case within 72 hours of becoming aware of it.
Our notification will, to the extent known at the time and updated as more information becomes available, describe:
- the nature of the breach and the categories and approximate volume of data and data subjects affected;
- the likely consequences;
- the measures we have taken or propose to take to address it and to mitigate harm; and
- a point of contact for further information.
Because Salieno has no access to your server, a security incident affecting your self-hosted installation or your End-Client Data is yours to detect, assess, and report to the relevant authorities and data subjects. We will reasonably assist on request.
10. Retention, return, and deletion
During your subscription. We keep your Account Data and Billing Data for as long as your account is active.
On cancellation or termination. You can cancel anytime; cancelling stops future charges. As explained in our Terms and Refund Policy, we do not refund amounts already paid. After your subscription ends:
- We retain your Account Data and Billing Data only for as long as we have a legitimate need — principally to reactivate a returning account, to resolve disputes, to prevent abuse, and to meet legal, tax, and accounting obligations (invoices and tax records, in particular, are kept for the period the law requires).
- Once no such need remains, we delete or irreversibly anonymise the data.
- You may ask us at any time to export or delete your account data, and we will do so subject to the legal retention obligations above.
Your End-Client Data. There is nothing for Salieno to return or delete here — it never leaves your server. Returning, exporting, or deleting your End-Client Data is fully within your control, on your own infrastructure.
11. Audits and demonstrating compliance
We want you to be able to satisfy your own compliance obligations without disrupting the service.
- On request, Salieno will make available the information reasonably necessary to demonstrate compliance with this Addendum — including this Addendum, our Privacy and Cookie Policies, a description of our security measures, and our current sub-processor list.
- Where available, an independent report or certification covering our sub-processors (for example Stripe's PCI-DSS attestation) may be provided to satisfy an audit request in respect of that sub-processor.
- If you reasonably require a further audit, you may request one no more than once per year (and additionally where required by a supervisory authority), on at least 30 days' prior written notice, during business hours, subject to confidentiality, at your own cost, and conducted so as not to disrupt Salieno's operations or compromise the security or data of other customers.
- Given the self-hosted architecture, an audit covers only the Account Data and Billing Data Salieno holds; it does not extend to your server or your End-Client Data, which are yours to audit.
12. Cookies
Salieno's own web services use a single essential session cookie to keep you signed in. We do not use analytics or advertising/tracking cookies on our account and licensing surfaces. See our Cookie Policy for details.
13. Liability, precedence, and changes
- This Addendum is subject to the limitations and exclusions of liability set out in our Terms of Service.
- If there is a conflict between this Addendum and any other agreement between us specifically regarding the processing of personal data, this Addendum prevails on that point.
- We may update this Addendum from time to time. If we make a material change affecting how we handle your Account Data or Billing Data, we will update the version and effective date above and, where appropriate, notify you. The current version always governs.
14. Governing law
This Addendum is governed by the law and subject to the jurisdiction stated in our Terms of Service: [GOVERNING LAW — owner to set jurisdiction].
Salieno's registered contact address is: [REGISTERED ADDRESS — owner to set].
15. Contact
Questions about this Addendum, requests for a countersigned copy, our current sub-processor list, or any data-protection request should go to:
- Email: [email protected]
- Web: salieno.com
We aim to respond promptly and within the timeframes required by applicable Data Protection Law.