Skip to content

Draft pending counsel review — last updated 2026-09-29. This is a working draft published for transparency. It is not final legal advice and will change after review.

Data processing agreement

For business customers who use SlideDeck to process personal data on their own behalf. Individual consumers are covered by the privacy notice instead.

When this applies

This agreement applies where a business or institution (“Customer”) determines why and how personal data in its SlideDeck content is processed, and SlideDeck processes it on the Customer’s documented instructions. Institution-managed workspaces are not yet offered; until then this applies to business accounts that request it.

Parties and roles

Processor: Sansa Group AB, organisation number 559111-9507. Registered address: to be confirmed. Controller: the Customer. For account administration, billing and security of the service itself, Sansa Group AB acts as an independent controller under its privacy notice.

Schedule 1: processing details

Processing details
ItemDescription
Subject matterProviding the SlideDeck presentation preparation and practice service
DurationThe term of the Customer's agreement, plus the return and deletion period
Nature and purposeHosting, storage, AI-assisted drafting and verification, transcription, practice feedback, export
Personal dataUser account identifiers; content uploaded by users, which may contain personal data of third parties; rehearsal audio and transcripts; practice feedback
Data subjectsCustomer's authorised users; people mentioned in content users upload
Special categoriesNot intended. Customer should not upload special-category data unless necessary and lawful
RetentionAs set out in the privacy notice retention schedule, or as configured by the Customer

Processor obligations

  • Process personal data only on the Customer’s documented instructions, including regarding transfers.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Implement the security measures in Schedule 2.
  • Assist the Customer with data subject requests, security, breach notification, impact assessments and prior consultation.
  • Make available the information necessary to demonstrate compliance, and allow for reasonable audits.
  • Not use Customer data to train models, and not sell or share it.
  • Rehearsal reports are not visible to workspace administrators unless the user shares them.

Subprocessors

The Customer authorises the subprocessors listed on the subprocessors page. We impose equivalent data protection obligations on each, give advance notice of changes, and the Customer may object on reasonable grounds.

International transfers

Transfers outside the EU/EEA rely on an adequacy decision or the Standard Contractual Clauses, with supplementary measures where required. Mechanisms are listed per provider on the subprocessors page (to be confirmed).

Schedule 2: security measures

The technical and organisational measures are described on the security page, including tenant isolation, encryption in transit, private storage, passwordless authentication, redacted logs and audited support access.

Personal data breaches

We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data, with the information available.

Return and deletion

At the end of the service, the Customer can export its data; we then delete it in line with the retention schedule, unless the law requires otherwise.

Requesting a signed copy

Email privacy@slidedeck.my with your organisation’s name and account email. The final agreement, including the Standard Contractual Clauses where needed, is subject to counsel review.