Legal

Privacy Policy

This policy explains what personal information HiveSilo handles, how and why we use it, who we share it with, how long we keep it, how we protect it, and the rights you have. It is written to be read, not to hide behind. For how privacy is enforced in our architecture, see our privacy overview, data dictionary, and subprocessor register.

HiveSilo Inc. Effective 2026-07-21 Global

1. Who we are and what this policy covers

This Privacy Policy is issued by HiveSilo Inc. (“HiveSilo,” “we,” “us,” “our”), a Delaware corporation with its principal office at 1395 Brickell Avenue, Suite 800, Miami, FL 33131, USA. It applies to personal information we handle through hivesilo.com and its subdomains (the “Site”) and, as described below, to personal data processed through the HiveSilo platform.

HiveSilo acts in two distinct roles:

  • As a controller for the Site: for the limited information described in Section 2, HiveSilo determines the purposes and means and is the responsible party.
  • As a processor for the platform: our enterprise clients are the controllers of their customers’ personal data. HiveSilo operates on a principle of intelligence without custody — personal data submitted on a client’s own properties flows directly into a hardware-attested confidential-computing enclave the client controls, and HiveSilo never receives, stores, or can decrypt that personal data. For that data, this policy is informational; the client’s own privacy notice and our contractual Data Processing Agreement govern.

2. The information we collect

2.1 Information collected automatically on the Site

When you visit the Site, our first-party analytics may collect pseudonymous usage signals: a random identifier stored on your device, the pages you view, time on page, scroll depth, and the referring domain. We also process your IP address and browser user-agent for security and delivery — these identifiers are cryptographically hashed (SHA-256) at the point of collection and are never stored in raw form.

We use first-party analytics only. We do not use third-party advertising trackers or advertising cookies, and we do not build cross-site advertising profiles. Our analytics honor the Global Privacy Control (GPC) and Do Not Track (DNT) browser signals: if your browser sends either signal, our analytics do not run for your visit.

2.2 Information you give us

If you request a briefing or contact us, we collect the business contact details you provide (such as your name, work email, and company). The briefing form is for your own business contact details; please do not submit any third party’s personal data through it.

2.3 Platform data

HiveSilo’s intelligence layer processes non-PII behavioral signals only. Personal data entered on a client’s properties never touches HiveSilo’s control plane; it is confined to the client-controlled enclave. Where identifiers are needed for de-duplication, they are stored only as irreversible hashes or encrypted fields.

2.4 Children

The Site and the platform are directed to businesses, not to children. We do not knowingly collect personal information from children under 16.

3. How and why we use information

We use the information above to: operate, secure, and improve the Site; understand aggregate usage; respond to briefing and contact requests; provide and administer the platform for our clients; and comply with legal obligations. We do not use it to make decisions producing legal or similarly significant effects about you, and we do not sell it.

Legal bases (where GDPR/UK GDPR applies). We rely on: our legitimate interests in running a secure, well-functioning website with data-minimizing, signal-honoring analytics; your consent where required; the performance of a contract or steps taken at your request (e.g., arranging a briefing); and compliance with legal obligations.

4. Cookies, tracking, and your choices

We use only first-party, privacy-respecting analytics and essential storage. We set no third-party advertising cookies and run no advertising trackers. You can control tracking by enabling Global Privacy Control or Do Not Track in your browser (we honor both), by using your browser’s cookie controls, or by contacting us. We do not sell your personal information and do not share it for cross-context behavioral advertising.

5. When and with whom we share information

We share personal information only as follows:

  • Service providers / subprocessors. We use vetted providers for hosting, infrastructure, delivery, monitoring, and communications. Each is bound by contract to process data only on our instructions and to protect it. Our current subprocessors and what each handles are published on our subprocessor register, and we provide advance notice of changes as described there.
  • Authorized platform destinations (hashed only). Where a client directs personal data to its own authorized advertising or CRM destinations, that data is prepared inside the client’s enclave and exported only in hashed (irreversible) form; raw personal data does not leave the enclave.
  • Legal and safety. We may disclose information where required by law, to comply with legal process, or to protect the rights, safety, and security of HiveSilo, our clients, or the public.
  • Corporate transactions. In a merger, acquisition, or asset sale, information may transfer subject to this policy.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

5.1 International transfers

HiveSilo offers data-residency options so clients can determine where their data is processed. Where personal data is transferred across borders, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or a recognized transfer framework where a provider is certified — and on the data-minimizing, hashed, and enclave-confined design described above.

6. How long we keep information, and how we dispose of it

We keep personal information only as long as needed for the purposes above or as required by law, then delete or de-identify it. Representative platform retention periods (full detail is maintained in our internal data-lifecycle records):

DataRetentionDisposal
Behavioral session records180 days from last activityArchived then deleted by a scheduled purge worker
Device fingerprint (hashed)365 days from last activityScheduled delete
Short-term event streams7 daysAutomatic trim
Client PII (in the enclave)Client-controlledDeleted on client request or enclave teardown
Business contact detailsAs long as needed to respond and for our recordsDeleted on request or when no longer needed

Data minimization. Raw IP addresses and user-agents are never stored (they are hashed at collection); personal data entered on client forms never touches HiveSilo’s infrastructure.

7. How we protect information

We protect personal information with layered technical and organizational controls, including: encryption in transit and at rest; per-tenant confidential-computing enclaves that isolate each client’s data in hardware; database row-level isolation so one tenant’s data cannot be read by another; multi-factor authentication and least-privilege access for privileged operations; a strict outbound egress allowlist; hashing of identifiers; and append-only audit logging of consequential actions. No method of transmission or storage is perfectly secure, but our architecture is designed so that the most sensitive data is never in a place where it could be exposed in plaintext.

8. Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal information:

  • Access — obtain a copy of the personal information we hold about you.
  • Correction / rectification — have inaccurate or incomplete information corrected.
  • Deletion / erasure — ask us to delete your personal information.
  • Restriction and objection — limit or object to certain processing.
  • Portability — receive your information in a portable format.
  • Withdraw consent — where we rely on consent, withdraw it at any time.
  • Opt out of sale/sharing — we do not sell or share personal information for cross-context advertising, so there is nothing to opt out of, but the right is honored.
  • Non-discrimination — we will not treat you differently for exercising your rights.
  • Complain to a regulator — lodge a complaint with your data protection authority (for EU/EEA residents, under GDPR Article 77) or applicable state authority.

These rights are provided under the EU/UK GDPR, the Swiss nFADP, the California Consumer Privacy Act as amended (CCPA/CPRA), and comparable laws. Because much of the personal data in the platform is controlled by our enterprise clients, a request about that data is usually made to the client (the controller); HiveSilo assists the controller in fulfilling it.

9. How to exercise your rights, and how we handle requests

To make a request, contact us at legal@hivesilo.com. We will verify your identity, respond within the timeframe required by applicable law (generally within 30 days), and will not charge a fee except where the law permits. You may use an authorized agent where the law allows.

  • Access / portability. On a verified request, we export the relevant records we hold and provide them to the requester or the controlling client.
  • Deletion (right to be forgotten). On a verified deletion request, we delete the associated records from our systems and confirm completion within 30 days; the client deletes any enclave-held data it controls.
  • Inquiries, complaints, and disputes. We log privacy inquiries, complaints, and disputes and track each through to resolution.

10. Changes to this policy

We review this policy periodically and update it when our practices or the law change. The effective date below always reflects the current version, and we will post material changes here before they take effect. Where we act as a processor, a change to this policy never overrides a mutually executed agreement with a client.

11. Contact us

For any privacy question or to exercise a right, contact:

HiveSilo Inc. — Privacy
Email: legal@hivesilo.com
Post: 1395 Brickell Avenue, Suite 800, Miami, FL 33131, USA

Security issues should go to security@hivesilo.com under our responsible-disclosure policy. If you are in the EU/EEA, UK, or Switzerland, you also have the right to complain to your local data protection authority.


Effective date: July 21, 2026 (2026-07-21)

This policy governs personal information HiveSilo handles as a controller for its website and, on an informational basis, personal data it processes on behalf of its enterprise clients. For data HiveSilo processes as a processor, the client’s privacy notice and the mutually executed Data Processing Agreement govern.

See it, don’t take it on faith

Privacy as architecture, not just policy

Our zero-custody model is built into the system, not promised on a page. See how personal data stays in your enclave and only non-PII signals are scored.

See the model

Current verification status is published at the Trust Center.