Data Processing Agreement
Last updated August 2026. The DPA for business customers whose SlayTab use involves personal data they control.
This Data Processing Agreement applies where you use SlayTab as an organisation and, in doing so, put personal data into it for which you are the controller and we act as processor. It supplements the Terms & Conditions and takes precedence over them on data protection matters.
Using SlayTab as an individual, for your own work? You do not need this document — the privacy policy covers you. This page is for companies whose procurement or DPO asks for a DPA.
1. Roles
You are the controller: you decide what personal data goes into SlayTab and why. We are the processor: we process it on your instructions to provide the service. Where we determine our own purposes — account administration, billing, security — we act as controller and the privacy policy governs.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Providing the SlayTab workspace, extension, calendar sync and AI assistant |
| Duration | For as long as your account is open, plus the retention periods in the Data Policy |
| Nature and purpose | Storage, retrieval, display, synchronisation, and — where you use the assistant — transmission to the model provider |
| Personal data | Whatever your users place in files, links, notes, tasks, calendars and assistant conversations, plus their account details |
| Data subjects | Your staff, and any individuals appearing in the content they store |
3. Our obligations
- Process personal data only on your documented instructions, which your use of the service constitutes, unless the law requires otherwise — in which case we will tell you first unless prohibited.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply the technical and organisational measures set out in the Data Policy.
- Notify you without undue delay on becoming aware of a personal data breach, with the detail you need to meet your own notification duties.
- Assist you, so far as we reasonably can, with data subject requests, impact assessments and regulator consultations.
- On termination, delete your content within 30 days, or return it in a machine-readable form if you ask before deletion.
4. Sub-processors
You give general authorisation for the sub-processors listed in the Data Policy. We will give 30 days' notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within that period; if we cannot accommodate the objection you may terminate the affected service and receive a pro-rata refund of anything prepaid.
Each sub-processor is bound by terms no less protective than these.
5. International transfers
We operate from India. Sub-processors are in India, the United States and internationally. Where a transfer requires a safeguard under the GDPR or UK GDPR, it relies on the European Commission's Standard Contractual Clauses, or the relevant sub-processor's own approved mechanism. On request we will identify which applies to a given transfer.
6. The AI assistant
Content sent to the assistant leaves our infrastructure and is processed by a third-party model provider in the United States. If your instructions to us do not permit that, you must stop your users from using the assistant — the rest of SlayTab is fully usable without it. We can disable the feature for your account on request.
7. Audits
We will answer reasonable written questions about our security measures, once in any 12-month period, and provide any certifications or reports we hold. On-site audits are available where a regulator requires one, at your cost and on reasonable notice.
8. Liability
Liability under this DPA is subject to the limits in the Terms & Conditions, except where data protection law does not permit that.
9. Signing it
This DPA is effective without signature when you use SlayTab as an organisation. If your procurement needs a countersigned copy, or your own DPA reviewed, write to legal@slaytab.com with the document and we will come back to you.