Draft pending counsel review — last updated 2026-09-29. This is a working draft published for transparency. It is not final legal advice and will change after review.
Data processing agreement
For business customers who use SlideDeck to process personal data on their own behalf. Individual consumers are covered by the privacy notice instead.
When this applies
This agreement applies where a business or institution (“Customer”) determines why and how personal data in its SlideDeck content is processed, and SlideDeck processes it on the Customer’s documented instructions. Institution-managed workspaces are not yet offered; until then this applies to business accounts that request it.
Parties and roles
Processor: Sansa Group AB, organisation number 559111-9507. Registered address: to be confirmed. Controller: the Customer. For account administration, billing and security of the service itself, Sansa Group AB acts as an independent controller under its privacy notice.
Schedule 1: processing details
| Item | Description |
|---|---|
| Subject matter | Providing the SlideDeck presentation preparation and practice service |
| Duration | The term of the Customer's agreement, plus the return and deletion period |
| Nature and purpose | Hosting, storage, AI-assisted drafting and verification, transcription, practice feedback, export |
| Personal data | User account identifiers; content uploaded by users, which may contain personal data of third parties; rehearsal audio and transcripts; practice feedback |
| Data subjects | Customer's authorised users; people mentioned in content users upload |
| Special categories | Not intended. Customer should not upload special-category data unless necessary and lawful |
| Retention | As set out in the privacy notice retention schedule, or as configured by the Customer |
Processor obligations
- Process personal data only on the Customer’s documented instructions, including regarding transfers.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement the security measures in Schedule 2.
- Assist the Customer with data subject requests, security, breach notification, impact assessments and prior consultation.
- Make available the information necessary to demonstrate compliance, and allow for reasonable audits.
- Not use Customer data to train models, and not sell or share it.
- Rehearsal reports are not visible to workspace administrators unless the user shares them.
Subprocessors
The Customer authorises the subprocessors listed on the subprocessors page. We impose equivalent data protection obligations on each, give advance notice of changes, and the Customer may object on reasonable grounds.
International transfers
Transfers outside the EU/EEA rely on an adequacy decision or the Standard Contractual Clauses, with supplementary measures where required. Mechanisms are listed per provider on the subprocessors page (to be confirmed).
Schedule 2: security measures
The technical and organisational measures are described on the security page, including tenant isolation, encryption in transit, private storage, passwordless authentication, redacted logs and audited support access.
Personal data breaches
We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data, with the information available.
Return and deletion
At the end of the service, the Customer can export its data; we then delete it in line with the retention schedule, unless the law requires otherwise.
Requesting a signed copy
Email privacy@slidedeck.my with your organisation’s name and account email. The final agreement, including the Standard Contractual Clauses where needed, is subject to counsel review.