Effective Date: August 2026
This Addendum governs all reverse proxy routing, packet inspection, and WAF telemetry provided by SEOSiri Enterprise Labs.
The Client acts as the Data Controller. SEOSiri acts strictly as a Data Processor providing automated network boundary defense.
Legitimate, unflagged HTTP requests pass through edge memory without persistent disk logging. IP addresses of non-malicious visitors are never retained.
In the event of an active threat signature (SQLi, XSS, BOLA, CSRF, DDoS), telemetry including source IP, network ASN, and payload fragments is logged under EU GDPR Article 6(1)(f) and Recital 49 (Legitimate Interest for Network Security) and California Consumer Privacy Act (CCPA) ยง 1798.145(a)(1).
All security incident records are automatically purged after thirty (30) calendar days. Security telemetry is strictly prohibited from being sold, leased, or utilized for behavioral targeting.