Contents
- Who we are
- What this policy covers
- Information we collect
- What we do not collect
- How we use information
- Legal bases for processing
- Who we share information with
- The ControlLayer product and your Salesforce data
- How long we keep information
- Your rights
- Security
- International transfers
- Children
- Changes to this policy
- How to contact us
1. Who we are
ControlLayer is a product of Interactive Ties LLC, a limited liability company organized under the laws of the State of New York, with its place of business at 2379 Hobblebush Lane, Lake View, New York 14085-9447.
In this policy, “we,” “us” and “our” mean Interactive Ties LLC. “You” means anyone visiting this website or contacting us through it. For the purposes of the EU and UK General Data Protection Regulation, we are the controller of the personal data described in this policy.
2. What this policy covers
This policy covers this website (the pages, documentation and blog published at controllayer.app) and the email correspondence that follows if you contact us.
It does not describe how the ControlLayer managed package handles data once it is installed in your Salesforce org, because the short answer is that it does not send us any. That distinction matters enough to have its own section: see section 8.
3. Information we collect
3.1 Information you give us
The early access form on our Get Started page asks for four things:
- First name
- Last name
- Work email address
- Company name
The contact form asks for the same four things, plus two more:
- What you are contacting us about, chosen from a short list
- Your message, in your own words
Submitting the early access form sends those values, together with a record of which form they came from and which page of this site you were reading when you opened it, directly into our own Salesforce org, where they become a lead record. Submitting the contact form sends the same values to our own web server first, which stores a copy in a database on our hosting account and then creates the lead record in Salesforce. That copy exists for two reasons: so your message is not lost if Salesforce is unreachable at the moment you press send, and so we can tell an automated submission from a real one (see section 3.2). We ask for a work email rather than a personal one precisely because this is business correspondence and we would rather not hold personal addresses.
The message box is free text, so it holds whatever you decide to put in it. Please do not use it to send us anything sensitive (credentials, customer records, or personal data about anyone else) because it ends up in a lead record like everything else on the form. Reports of security vulnerabilities and requests about your own data are handled at the addresses in section 15 rather than through the form, for exactly this reason.
If you email us instead, we receive whatever you choose to put in the message.
3.2 Information collected automatically
Our web host records standard server access logs for every request to the site: IP address, the page requested, the date and time, the referring page and your browser's user-agent string. These logs are generated by the hosting infrastructure rather than by anything we wrote, and they exist so that outages, errors and abuse can be diagnosed. We do not use them to build a profile of you, and we do not attempt to connect them to any lead record.
The contact form is the one narrow exception to that last sentence. When you submit it, we store a keyed hash of your IP address and your browser's user-agent string alongside the copy of your message. The hash lets us limit how many messages one connection can send in an hour without keeping the address itself, and it cannot be reversed to recover the address. Submissions our checks identify as automated are kept in the same table, marked as such, and never become lead records. None of this is used for anything beyond keeping the form working and free of abuse.
3.3 Campaign attribution
Links to this site from our blog posts, newsletters and similar campaigns carry utm_source, utm_medium, utm_campaign and utm_content parameters in the URL. When your browser lands on a page carrying those parameters, a small script stores them in your browser's sessionStorage under the key cl_utm, so that if you submit one of our forms several pages later we can still tell which article sent you.
The same script fills in one further value when you submit a form; the path of the page on this site you were reading immediately before you opened it (for example, /pricing.php). Only the path, only when the previous page was on this site, and never the query string.
Three things are worth stating plainly about this:
- It is not a cookie. Nothing is transmitted to a server as you browse, and no third party can read it.
- It lasts for the browser tab only. Closing the tab erases it. It cannot follow you to another site or another session.
- It holds only values that were already in the URL you clicked, and only ones beginning with
utm_. Any other query parameter is ignored.
If you never submit the form, those values are never sent to us at all. If you do, they are attached to your lead record so we know which article to write more of. You can prevent this entirely by disabling site data for this domain in your browser, and nothing on the site will break.
4. What we do not collect
It is easier to describe this site by what is absent from it:
- No analytics. There is no Google Analytics, no Plausible, no Fathom, no heatmap or session-recording tool of any kind.
- No cookies. This site sets none. Not for analytics, not for advertising, not for preferences.
- No advertising or tracking pixels. No conversion pixels, no retargeting tags, no social media trackers.
- No third-party fonts or scripts. Every stylesheet, script and image is served from our own domain, so loading a page tells no one but our web host that you were here.
- No account, no password, no payment details. The site has nothing to log into and sells nothing directly.
Because we run no cross-site tracking, there is nothing for a Do Not Track header or a Global Privacy Control signal to switch off. We honor them by default in the only way that means anything: by not doing it in the first place.
Should this ever change, it changes here first, and the “last updated” date at the top of this page will move.
5. How we use information
We use what we collect to:
- Reply to you, and schedule and run the early access walkthrough you asked for.
- Answer whatever you asked us through the contact form.
- Provide onboarding and support during the early access program.
- Send occasional product news about ControlLayer (availability, pricing and release notes) to people who asked for access. Every such message carries an unsubscribe link, and unsubscribing stops them permanently.
- Understand which articles and campaigns bring people to the site, in aggregate.
- Keep the site working, secure and free of abuse.
- Meet our legal and accounting obligations.
We do not sell personal information, and we do not share it with anyone for their own marketing. We do not use it to train machine learning models.
6. Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR:
| What | Legal basis |
|---|---|
| Responding to an early access request you submitted | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Onboarding and supporting an early access customer | Performance of a contract (Art. 6(1)(b)) |
| Product news to people who requested access | Legitimate interests in marketing our product to business contacts who asked about it (Art. 6(1)(f)), subject to your right to object at any time |
| Server logs, security and abuse prevention | Legitimate interests in keeping the service available and secure (Art. 6(1)(f)) |
| Campaign attribution | Legitimate interests in knowing which of our own articles are worth writing (Art. 6(1)(f)) |
| Records we are required to keep | Compliance with a legal obligation (Art. 6(1)(c)) |
7. Who we share information with
We use a deliberately small number of service providers. Each one processes personal data only on our instructions, and only for the purpose listed:
| Provider | What it does for us |
|---|---|
| Salesforce, Inc. | Our own CRM. Holds lead and customer records, and receives the submissions from both forms. |
| InMotion Hosting, Inc. | Website hosting, the database that holds contact form submissions and unsubscribe records, and our business email. Generates the server logs in section 3.2 and carries our correspondence with you. |
The current list, with locations and a note on how we announce changes to it, is maintained at Sub-processors.
Beyond those providers, we disclose personal information only where we are legally required to (a valid legal process, or the establishment or defense of a legal claim) or where a business transfer such as a merger or acquisition of Interactive Ties LLC makes it necessary, in which case this policy continues to apply to the information transferred until you are told otherwise.
8. The ControlLayer product and your Salesforce data
ControlLayer is a 100% native Salesforce managed package. It runs entirely inside your own Salesforce org, on Salesforce infrastructure, under your own org's security model.
This has a consequence worth being explicit about: the product does not transmit your Salesforce data to us, and it has no ability to. There is no external service to call, no telemetry endpoint, no analytics beacon and no phone-home. Your records, your bypass windows, your audit trail and your configuration never leave your org. We could not read them from here if we wanted to.
There are two circumstances in which we may see data belonging to your organization, and both are ones you initiate:
- Hands-on onboarding and support. Early access includes guided installation. If you grant us login access to your org, or share your screen, or send us a screenshot, log excerpt or export while we are troubleshooting, we will see whatever that contains. Access of this kind is granted by you, is limited to the duration you set, and is revocable by you at any time through Salesforce.
- Material you send us. Anything you attach to a support email is held in our email system for as long as that correspondence is retained.
Where we process personal data contained in your Salesforce org in the course of supporting you, we do so as a processor acting on your instructions, and you remain the controller. Customers who need that relationship documented should use our Data Processing Addendum.
9. How long we keep information
| Information | Retention |
|---|---|
| Lead records that never become customers | 36 months from your last interaction with us, then deleted |
| Contact form submissions held on our server | 36 months from receipt, then deleted, including any identified as automated |
| Customer records | For the life of the relationship, then as long as needed for legal, tax and accounting purposes |
| Email correspondence | As long as needed for the matter it concerns, and then in line with our ordinary mailbox retention |
| Server access logs | The short rolling window kept by our host, typically a matter of weeks |
| Unsubscribe records | Indefinitely — keeping a record that you opted out is the only way to guarantee we do not contact you again |
| Campaign attribution in your browser | Until you close the tab |
You can ask us to delete your information sooner. See section 10.
10. Your rights
Wherever you are, you may ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, or delete it. We will not treat you any differently for asking.
10.1 If you are in the EEA or the UK
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, including an absolute right to object to direct marketing at any time. You also have the right to lodge a complaint with your national supervisory authority, though we would appreciate the chance to resolve the matter first.
10.2 If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and how we use it, to request its deletion or correction, and not to be discriminated against for exercising those rights. The categories we collect are identifiers (name, email address), professional information (company name) and internet activity (server logs, campaign parameters and, for the contact form, a hashed IP address), as described in section 3.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. We collect no sensitive personal information as that term is defined by the CPRA.
10.3 How to exercise any of this
Email privacy@controllayer.app. We will respond within 30 days, or within 45 days for California requests, and will tell you if we need longer. We may need to verify your identity first, which for a request about a lead record usually means replying from the address that submitted it. An authorized agent may act for you with written proof.
11. Security
The site is served exclusively over HTTPS. Directory listings are disabled and the site's include files refuse direct requests. Both forms post over an encrypted connection, and the contact form is checked on our server for automated submissions and rate-limited before anything reaches Salesforce. Our Salesforce org and our email are protected by multi-factor authentication, and access to lead and customer data is limited to the people who need it.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If you believe you have found a vulnerability in this site or in the ControlLayer package, we would genuinely like to hear about it. Please write to privacy@controllayer.app and we will acknowledge you.
12. International transfers
We are based in the United States and our service providers store data in the United States. If you contact us from outside the United States, the information you send will be transferred there, a jurisdiction whose data protection laws differ from those of the EEA and the UK.
Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where applicable, as the transfer mechanism. Our providers in section 7 are contractually bound to equivalent terms. A copy of the clauses we use is available on request.
13. Children
This is a business-to-business product for Salesforce administrators. The site is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@controllayer.app and we will delete it.
14. Changes to this policy
We will update this policy when what we do changes and, importantly, before the change takes effect rather than after. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle information you have already given us, we will email the address we hold for you rather than relying on you to notice.
15. How to contact us
For anything in this policy, including any request under section 10:
Interactive Ties LLC
2379 Hobblebush Lane, Lake View, New York 14085-9447
privacy@controllayer.app
For anything else, the contact form or early@controllayer.app reaches us just as well. The addresses above are given as addresses on purpose: a request about your own data should never depend on a form working.