1. Who controls what
ESSORIX LTD, trading as GreenSlope, is controller for account, billing, website, and support data. For customer telemetry sent to GreenSlope by a customer, that customer is controller and GreenSlope acts as processor.
Privacy requests can be sent to privacy [at] greenslope [dot] io.
2. Data we process
- Account data: names, email addresses, organisation details.
- Billing data: subscription, invoice, tax, and Paddle customer IDs.
- Telemetry: OpenTelemetry traces and release/incident metadata.
- Support data: messages you send to support, legal, or security.
- Website analytics: consented, pseudonymous page and campaign events.
- Product analytics: minimized authenticated usage events linked to pseudonymous user and organisation identifiers.
- Diagnostics and security data: route templates, error codes, stack traces, audit events, and abuse-control signals.
3. Telemetry and personal data
GreenSlope receives OpenTelemetry traces from customer systems. Trace attributes may contain personal data if customers instrument their systems that way. Customers should redact sensitive fields before export.
GreenSlope does not currently perform ingest-side PII redaction. Short retention reduces exposure, but it is not a substitute for customer-side data minimisation.
4. Purposes and lawful bases
We process personal data to:
- provide, secure, and support GreenSlope;
- manage trials, subscriptions, billing, and account access;
- respond to support, legal, privacy, and security requests;
- understand use of the GreenSlope Website and Account Access Pages with your consent under Article 6(1)(a);
- understand signed-in feature use through In-App Usage Analytics under our legitimate interests in improving and securing the service under Article 6(1)(f);
- comply with legal obligations;
- protect GreenSlope, customers, and users from abuse.
5. Region and transfers
Customer telemetry is processed in a single EU region for launch. Some account, billing, support, and integration providers may process data outside the EEA or UK. Transfer bases are listed in the Sub-processors page.
6. Retention
| Data kind | Retention |
|---|---|
| Hot spans | 24 hours on Solo, 48 hours on Starter |
| Warm span archive | 30 days |
| Change and deploy events | 90 days |
| Alerts and incident activity | 180 days |
| In-App Usage Analytics | 12 months at event level; anonymised aggregates may be kept longer |
| Sanitised security and rate-limit logs | 12 months |
| Sentry error and performance diagnostics | 90 days, subject to provider capability |
| Administrative audit events | 365 days |
| Billing records | As required by Paddle, tax, and accounting obligations |
Live rate-limit buckets expire after their operational window. Account erasure overrides the periods above where the law requires deletion or anonymisation.
7. AI-assisted triage
GreenSlope uses AI-assisted triage to summarise likely cause and draft incident context. Customer data is not used to train third-party models. AI output is a draft for human review, not an autonomous operational decision.
8. Your rights
Depending on your location and role, you may have rights to access, correct, delete, restrict, or object to processing of your personal data. Authenticated users can object to In-App Usage Analytics at any time under Account → Privacy; disabling Product analytics stops future PostHog capture, identify, and alias operations. Email privacy [at] greenslope [dot] io to exercise other rights. If your data was provided by a GreenSlope customer, we may need to route the request to that customer.
9. Children
GreenSlope is a B2B engineering tool and is not directed at children.
10. Contact
Privacy: privacy [at] greenslope [dot] io. Legal: legal [at] greenslope [dot] io. Support: support [at] greenslope [dot] io.