Privacy Policy
Last updated: July 18, 2026
This policy explains what personal data Salieno collects when you license and use Salieno Core, why we collect it, how long we keep it, and the rights you have over it. We've written it in plain language, but it's meant to be legally sound — not marketing.
The short version: we collect only what we need to run your account, bill you, and ship you updates. We don't sell your data, we don't run advertising trackers, and — as explained below — we never touch your end-clients' data at all.
If anything here is unclear, email us at [email protected].
1. Who we are
Salieno ("Salieno", "we", "us", "our") operates the website salieno.com and licenses Salieno Core, self-hosted hosting-automation software that you install and run on your own server.
For the personal data described in this policy — your own account and billing information — Salieno is the data controller. Our registered address is:
[REGISTERED ADDRESS — owner to set]
This policy is governed by the laws of [GOVERNING LAW — owner to set jurisdiction], without prejudice to any mandatory data-protection rights you have under the laws of your own country.
2. The most important point: your end-clients' data never reaches us
Salieno Core is self-hosted software. You install it on infrastructure you control, and it runs entirely on your server.
That means all of the data your platform processes about your customers — your end-clients' names, contact details, orders, invoices, service credentials, support tickets, and everything else — lives exclusively on your own server. Salieno never receives it, never stores it, and never processes it.
For that data, you are the controller (and, where you use processors of your own, the party responsible for them). Salieno is neither a controller nor a processor of your end-clients' data, because the software runs on your side of the line, not ours. Nothing we do gives us access to it.
The rest of this policy is therefore only about the limited data we hold about you, our direct customer.
3. What personal data we collect
We collect three things, and no more than we need.
3.1 Account and identity data
When you create a Salieno account, we collect and store — through the Salieno Identity Provider (IdP) that powers sign-in across our services:
- your name;
- your email address;
- your authentication factors — a securely hashed password and, if you enable it, two-factor authentication details.
We never store your password in plain text.
3.2 Billing data
Your subscription (a $6.00 USD / month licence, billed monthly in advance after a 30-day free trial) and any one-time marketplace purchases are processed by Stripe.
- Stripe holds your card details. Card numbers, expiry dates, and security codes are entered directly into Stripe's systems. Salieno never sees, receives, or stores your full card number.
- We store only billing metadata: your subscription status and plan, invoice and receipt records, amounts and dates, the last purchases you made in the marketplace, and a Stripe customer reference so we can match payments to your account.
3.3 Your installation domain
When you activate Salieno Core, your installation tells us the domain it is running on. We store it against your licence, and we keep a small separate record of it for two purposes: enforcing the one-free-trial-per-installation rule, and recognising an unpaid balance if the same installation later appears under a different account.
- We store the domain name only — never the content of your installation, your configuration, or your end-clients' data (see Section 2).
- Because its whole purpose is to recognise an installation after an account has gone, this record outlives the account that created it. It is retained indefinitely unless we release it — which we do on request when a domain has legitimately changed hands.
- We do not use it for advertising, profiling, or any purpose other than the two above.
- Domains that identify no one in particular —
localhost, private addresses, and reserved test names — are not recorded at all.
Our legal basis is legitimate interests: preventing repeated free trials and unpaid balances is necessary to offer a free trial at all, and the least intrusive identifier that works is the one you already publish.
3.4 Support communications
When you contact us — a support ticket, an email, a bug report — we keep the message and our correspondence so we can help you and improve the product.
3.5 What we do not collect
- We do not run analytics, advertising, or behavioural-tracking tools.
- We do not build profiles, scores, or marketing segments about you.
- We do not use your data to train machine-learning models.
- We do not collect your end-clients' data (see Section 2).
4. Why we use it, and our legal basis
We only process your data for the purposes below. Where data-protection law (such as the GDPR or comparable regimes) requires a lawful basis, the applicable basis is shown alongside each purpose.
| What we do | Data used | Legal basis | |---|---|---| | Create and run your account; keep your licence active; deliver updates and downloads | Account and identity data | Performance of our contract with you | | Take payment, issue invoices and receipts, manage your trial, renewals, and cancellation | Billing data | Performance of our contract with you | | Meet tax, accounting, and other legal obligations | Billing data | Legal obligation | | Send you essential service messages — security notices, breaking-change warnings, licence and billing notifications | Account and identity data | Legitimate interests (keeping your install secure and your account informed) | | Answer your questions and provide support | Support communications | Legitimate interests / performance of our contract | | Keep our systems secure and prevent abuse or fraud | Account, billing, and limited technical logs | Legitimate interests |
Where we ever rely on consent — for example, an optional communication you opt into — you can withdraw it at any time without affecting anything we did before you withdrew it.
We send transactional and service messages because they're necessary to run your account. We don't send marketing email unless you've asked us to.
5. Who we share it with (sub-processors)
We do not sell your personal data, and we never have. We share it only with a small set of trusted providers who help us operate, each bound by a data-processing agreement and permitted to use your data only on our instructions:
- Stripe — payment processing and card storage.
- Our email provider — sending transactional and service email (receipts, security notices, account messages).
- Our monitoring provider — uptime and error monitoring for salieno.com's own services, so we can keep the licence, update, and download systems reliable.
Beyond these, we may disclose data:
- to professional advisors (such as accountants or legal counsel) under confidentiality obligations;
- where we're legally required to — in response to valid legal process — and we push back on requests that are overbroad;
- in connection with a merger, acquisition, or sale of our business, in which case we'll notify you and this policy will continue to protect your data.
A current list of sub-processors is available on request at [email protected].
6. International transfers
Some of our providers may process data outside your country. Where that happens and the law requires it, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism — so your data keeps the same level of protection wherever it's handled.
7. How long we keep it
We keep personal data only as long as we have a reason to.
- Account and identity data — for as long as your account is open. If you cancel and close your account, we delete or anonymise it within 90 days, except where we must keep certain records longer (see below).
- Billing records — retained for the period required by applicable tax and accounting law (commonly 6–10 years), then deleted.
- Support communications — kept while your query is open and for up to 24 months afterwards for reference, then deleted.
- Security and system logs — kept for a short period (typically up to 90 days) for security and troubleshooting.
- Installation domain records — kept indefinitely, because they exist to recognise an installation after the account behind it is gone (Section 3.3). Released on request where a domain has changed hands.
When a retention period ends, we securely delete or irreversibly anonymise the data.
8. How we protect it, and what happens if something goes wrong
We secure your data with industry-standard measures: encryption in transit (TLS) and at rest, hashed passwords, signed update payloads, access controls and audit logging on privileged actions, mandatory two-factor authentication for staff, and encrypted backups.
Breach notification. If a breach ever affects your personal data, we will notify affected customers — and any competent supervisory authority where required — within 72 hours of becoming aware of it, together with what happened and what we're doing about it.
9. Cookies
We use exactly one cookie: an essential session cookie (salieno_session) that keeps you signed in across salieno.com and our sign-in service.
- It's strictly necessary for the site to work — no consent banner is required for it.
- We use no analytics cookies, no advertising or tracking pixels, and no fingerprinting.
You can block cookies in your browser, but sign-in won't work without this one.
10. Your rights
Wherever you live, you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Rectify — correct anything inaccurate or incomplete.
- Erase — delete your account and associated data, except records we're legally required to keep (such as tax records).
- Restrict or object — limit or object to certain processing, including anything based on legitimate interests.
- Port — receive your data in a portable, machine-readable format (JSON or CSV).
- Withdraw consent — for anything you previously consented to.
To exercise any of these, email [email protected]. We'll respond within 30 days. We won't charge you or treat you differently for exercising your rights.
If you believe we've handled your data improperly, we'd like the chance to put it right — but you also have the right to lodge a complaint with your local data-protection authority.
11. Children
Salieno Core is a business product intended for professionals. It isn't directed at children, and we don't knowingly collect data from anyone under the age of 16. If you believe a child has given us personal data, contact us and we'll delete it.
12. Changes to this policy
If we update this policy, we'll change the "Last updated" date above and, for material changes, notify you by email or an in-account notice before they take effect. Continuing to use Salieno after a change means you accept the updated policy.
Contact
Questions, requests, or complaints about your privacy? Email us at [[email protected]](mailto:[email protected]) — we read and answer every message, usually within one business day.
- Website: salieno.com
- Registered address: [REGISTERED ADDRESS — owner to set]