Back to sign in
Silver LeafAgency

Privacy policy

How Silver Leaf Agency handles personal information in the client platform — what we collect about you as a user, what we process on behalf of our clients, and what you can ask us to do about it.

Last updated 8 September 2026

1.What this policy covers

This policy explains how Silver Leaf Agency ("Silver Leaf", "we", "us") handles personal information in connection with the Silver Leaf client platform at app.silverleafagency.com (the "platform").

The platform is a private client portal. There is no public sign-up: accounts are created by Silver Leaf for people at client organisations we work with, and for our own staff. If you have an account, someone at Silver Leaf created it for you.

This policy does not cover the public Silver Leaf website, our advertising, or anything a client does on its own website. It also does not replace the privacy notice a client is responsible for publishing on its own site.

2.The two roles we play

Almost every question about this platform has a different answer depending on whose information is being asked about, so the distinction is worth setting out before anything else.

  • For information about you as a platform user — your account, how you sign in, what you do in the portal — we decide why and how it is processed. In data protection terms we are the controller, and this policy is the notice for it.
  • For information a client loads into its own workspace — enquiries from its website, analytics about its visitors, data from its advertising accounts — the client decides why and how it is processed, and we process it under our agreement with that client. We are the processor, or a service provider, and the client is the controller.

The practical consequence is in section 12: if you submitted an enquiry on a client’s website and want it removed, the request belongs with that client, not with us. We will act on it, but on their instruction.

3.Information we collect about platform users

We collect only what running an account requires. There is no advertising, no profiling, and no third-party analytics on the portal itself.

WhatWhy we hold it
Your name and email addressTo identify your account, address you in the interface, and send operational email such as a new lead notification or an invoice.
A hash of your passwordTo let you sign in. Passwords are stored only as a hash; we cannot read yours, and nobody at Silver Leaf can tell you what it is.
Which client workspaces you belong to, and your role in eachTo decide what you are allowed to see. This is the check that keeps one client’s data out of another client’s portal.
Session recordsTo keep you signed in. A session carries an identifier, its expiry, and the browser it was issued to.
Interface preferences, such as your light or dark themeSo the portal looks the same the next time you open it.
Records of significant actions in a workspaceAssigning a lead, editing an invoice, connecting an advertising account and similar events are recorded with who did them and when, so a client can see the history of its own account.
Messages you send usSupport and account correspondence, kept so we can answer it and refer back to it.

We do not ask you for, and the platform has nowhere to put, a payment card number, a bank account number, a government identifier, or any special category of personal data such as health or biometric information. Clients are invoiced outside the platform; the platform records that an invoice was paid, and never takes a payment.

4.Cookies on the portal

The portal sets only the cookies it needs to work. There is no consent banner here because there is nothing here to consent to.

  • A session cookie, set when you sign in and cleared when you sign out. It expires after seven days, and is refreshed as you keep using the portal.
  • A preference cookie holding your theme choice, so the first frame of the page is painted correctly rather than flashing the wrong one.

Web fonts are served from our own origin rather than a font CDN, so opening the portal does not make a request to a third party on your behalf. The portal carries no advertising pixels, no session recording, and no cross-site tracking of any kind.

The tracking cookie described in section 6 is a different thing entirely: it is set on a client’s own website by a script that client installs, and it is never set on this portal.

5.Information collected automatically when you use the portal

Our hosting and network layer records ordinary server logs: the IP address a request came from, the time, the path requested, the response status, and the browser’s user agent string. These exist to keep the service running and to defend it — rate limiting, blocking abuse, and diagnosing faults — and are retained on a short rolling window.

We may also record technical error reports when something in the application fails. These are diagnostic; we do not use them to build a picture of you.

6.Information we process on behalf of clients

This is the material a client’s workspace exists to hold. We process it on that client’s instructions, under our services agreement with them, and we do not sell it, share it for advertising, or use it to build any product other than that client’s own reporting.

CategoryWhat it consists of
Enquiries and leadsThe name, email address, phone number and message a person submits through a form on the client’s website that the client has marked as an enquiry form, plus what the client later records about the outcome and value of that enquiry.
AttributionWhich advertising click or campaign brought a visitor to the client’s site: advertising click identifiers from Google, Microsoft, Meta, TikTok and LinkedIn, campaign tagging parameters, and the referring website.
Website analyticsPages viewed, clicks on outbound and contact links, scroll depth, form interactions, device type and country, associated with a visit and a first-party visitor identifier.
Proof of consentWhere a client has enabled it, an enquiry is stored alongside a record of the consent state at the time: the page it was submitted from, the browser’s user agent, what the site’s consent tool reported, and the IP address the submission came from.
Advertising and search platform dataCampaign, cost and performance figures read from accounts the client connects, together with the credentials that authorise those reads.
Deliverables and reportingDrafts, audits, content and scheduled reports produced for the client, and the files attached to them.
Commercial recordsWhat the client subscribes to, the invoices we issue, and the payments we record against them.

What the tracking script deliberately never collects, wherever it is installed: the value of any field outside a form the client has marked as an enquiry form; password, hidden and file inputs, and any field named like a card number, a security code, an account number or a national identifier, anywhere on the page; keystrokes; the fragment of a URL; and query parameters other than campaign tags and advertising click identifiers. It collects nothing at all about browsing once a visitor has declined consent.

IP addresses are not stored with analytics events. The only place an IP address is retained is on the consent record attached to an enquiry, because that record’s entire purpose is to evidence the circumstances of a specific submission.

Where a visitor’s consent state is unknown because no consent tool on the client’s site said anything, the client’s own privacy notice is what covers that visit. A client can configure its sites so that nothing is collected until consent is granted.

7.How we use information

  • To operate the platform: authenticate you, show you your workspace, and keep the two apart from anyone else’s.
  • To deliver the services a client has bought: reporting, dashboards, deliverables and scheduled reports.
  • To send operational email — lead notifications, service request updates, invoices, and messages about your account or about changes to the service.
  • To keep the platform secure and available: rate limiting, filtering automated traffic, investigating faults and abuse.
  • To bill for the services, and to keep the financial records that billing requires.
  • To meet legal obligations, and to establish or defend legal claims.

We do not sell personal information, and we do not share it with anyone for cross-context behavioural advertising. We do not use client data to train machine learning models.

Where the UK or EU GDPR applies to our own processing of your account information, our legal bases are the performance of our contract with you or your organisation, our legitimate interests in securing and improving the platform, and compliance with legal obligations. Marketing email, if we ever send it, would rest on consent you can withdraw at any time.

8.AI processing

Parts of the platform generate drafts — copy, content, audits and summaries — by sending the relevant material to Anthropic’s API. That material can include a client’s campaign data, website content and brief.

  • Output is a draft. It is reviewed by a person before anything is published or sent.
  • We record the tenant, feature, model, token counts, computed cost and latency of each call, so a client can see what it is being charged for. That log holds usage figures, not the content of the request.
  • We do not send enquiry contact details to a model as part of generating deliverables.

You should not paste anything into a free-text field in the platform that you would not want processed this way.

9.Google user data

When a client connects a Google account, Google asks it to approve a specific, narrow set of permissions. We request only the ones the services that client has bought actually need:

ServicePermission requested
Google AdsAccess to the Google Ads API. Google publishes no read-only version of this permission. Silver Leaf staff use it to manage the advertising we run for a client: creating and editing campaigns, budgets, keywords and ads. Nobody signing in from a client organisation can change anything in a Google Ads account through the platform — the client side of the portal only reads.
Google Analytics 4Read-only access to Analytics data.
Search ConsoleRead-only access to Search Console data.

We also receive the email address of the Google account that gave the approval, so the client can see whose grant is in use and revoke it deliberately.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use that data only to provide and improve the reporting and campaign management the client asked for. We do not transfer it to third parties except as needed to provide those features, to comply with law, or as part of a merger or acquisition; we do not use it for advertising; and no human reads it except with the client’s permission, for security purposes, or where the law requires it.

A connection can be revoked at any time, either from the client’s workspace or from the Google account’s own permissions page. Revoking it stops future syncing; figures already reported remain in the client’s reporting history.

10.Who we share information with

We use a small number of service providers to run the platform. Each is bound to process data only on our instructions.

ProviderWhat it doesWhere
Google CloudHosting, the database, file storage, scheduled jobs, DNS and network security.United States
AnthropicThe model behind AI-generated drafts (section 8).United States
ResendDelivery of transactional email.United States
Advertising and analytics platformsGoogle, Microsoft, Meta and similar platforms, when a client connects an account so we can read its reporting.United States and elsewhere

Beyond that, we disclose information only where the law requires it, where it is necessary to establish or defend a legal claim, or to protect the safety or rights of a person. If the business is ever sold or merged, information may transfer as part of that transaction; we would tell affected clients.

A client’s data is never disclosed to another client. That separation is enforced in the software at two independent layers, not by convention.

11.How long we keep information

WhatHow long
Your account and workspace membershipFor as long as the account exists.
Sign-in sessionsSeven days from issue, or until you sign out.
Individual website analytics eventsNinety days, after which they are deleted automatically by a scheduled job. The daily totals derived from them are kept for long-run reporting and identify nobody.
Enquiries and leadsFor the life of the client engagement, unless the client asks us to redact one sooner.
Raw responses from advertising platformsA short rolling window, kept for reconciling and re-deriving reports.
Invoices and financial recordsRetained for as long as tax and accounting rules require. Invoices are never deleted; an invoice that should not stand is voided, which keeps its number and removes it from every balance.
Server and security logsA short rolling window.

When a client engagement ends, we keep the workspace for an agreed wind-down period so the client can export what it needs, and then delete or redact it in line with our agreement and the retention rules above.

12.Your rights, and how to exercise them

Depending on where you live you may have the right to ask for a copy of your personal information, to correct it, to delete it, to restrict or object to how it is used, to receive it in a portable form, and to complain to a data protection authority. Where a right applies, we will not treat you differently for exercising it.

For your own platform account, write to daniel@silverleafagency.com. We will ask you to verify that the request is yours, and we aim to respond within thirty days.

For an enquiry you submitted on a client’s website, the client is the controller and the request belongs with them. If you send it to us we will pass it on and act on their instruction. You are usually better served going to the business you contacted, because they can also reach the copy of your enquiry in their own inbox and CRM.

A deletion request against an enquiry is honoured by redaction rather than by deleting the record: the name, email address, phone number, message and consent details are erased, and the fact that an enquiry happened, when it happened, and what it was worth remain. The reason is that deleting the row would silently restate a lead count and a revenue figure the client has already been shown and reported on. After redaction you are no longer identifiable or contactable from that record, which is what the request is asking for.

Visitors to a client’s website can also decline tracking through the consent tool on that site, or clear the first-party cookie the tracking script uses. Declining stops analytics collection; it does not stop a form you deliberately submit from reaching the business you sent it to.

13.How we protect information

  • Every request is served over TLS, and data is encrypted at rest by our hosting provider.
  • Credentials for connected advertising and analytics accounts are encrypted with an application key before they reach the database, are never written to a log, and are never returned by any part of the interface — not even to our own staff.
  • Client separation is enforced twice over: every query runs through a tenant-scoped connection, and the database independently refuses rows belonging to another tenant. Either alone would be sufficient; both are kept so that a mistake in one is not a breach.
  • Passwords are stored as hashes, with a minimum length of twelve characters. The sign-in form deliberately gives the same answer whether an email address is unknown or a password is wrong, so it cannot be used to discover who has an account.
  • Access to production systems is limited to staff who need it, using per-service identities rather than shared passwords.

No system is perfectly secure. If a breach affects your personal information we will notify you and any relevant regulator as required by law.

14.Where information is held

The platform and its database run in Google Cloud regions in the United States, and our service providers are United States companies. If you are in the United Kingdom, the European Economic Area or Switzerland, using the platform involves transferring your information to the United States. Where those transfers require a safeguard, we rely on the European Commission’s standard contractual clauses and the UK addendum with the providers concerned.

15.Children

The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to us and we will remove it.

16.Changes to this policy

We update this policy when the platform changes. The date at the top is the date of the current version. If a change materially affects how we handle your information we will tell account holders by email before it takes effect, rather than relying on you to notice a new date.

17.Contact us

Questions, requests and complaints about this policy go to daniel@silverleafagency.com, addressed to Silver Leaf Agency. If you are in the UK or EEA and are not satisfied with our answer, you may complain to your local supervisory authority.