Draft pending counsel review — last updated 2026-09-29. This is a working draft published for transparency. It is not final legal advice and will change after review.
Privacy notice
How SlideDeck handles personal data. Private by default: no public decks, no saved raw recordings, and no training on your content unless you opt in to something separate.
Who is responsible
The controller for personal data processed by SlideDeck is Sansa Group AB (organisation number 559111-9507), operating SlideDeck through its Sansavision subdivision. Registered address: to be confirmed. Privacy contact: privacy@slidedeck.my.
In short
- We use your data to provide the presentations and practice you ask for, to bill you, and to keep the service secure.
- Your microphone is streamed for transcription; a raw recording is saved only if you explicitly opt in.
- We don’t sell personal data, don’t use advertising trackers, and don’t train models on your content.
- You can export or delete your data, and exercise your other rights, from your account or by writing to us.
What we collect
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email address, account ID, sign-in records, session tokens | You; generated by the service |
| Contact and support | Messages you send us and our replies | You |
| Commercial | Offer purchased, invoices, payment status (card details are held by Stripe, not us) | You; Stripe |
| Project content | Briefs, uploaded documents, links, notes, rubrics, slides, scripts, questions | You; public web retrieval you enable |
| Audio and transcripts | Microphone stream during rehearsal, uploaded recordings, transcripts | You |
| Practice feedback | Explainable observations about content, structure, timing and answers | Generated by the service |
| Technical | IP address, device and browser details, request and error logs | Your device |
We don’t ask for precise location, government ID or health data, and we don’t create voiceprints to identify you. If such information appears in material you upload, it is processed only to do what you asked.
Purposes and legal bases
This mapping is proposed and subject to counsel review against our actual processing.
| Purpose | Legal basis | How we limit it |
|---|---|---|
| Your account, the presentations you buy, and the practice you request | Performance of our contract with you | Only the identifiers and content needed; access is limited to the purpose |
| Fraud prevention and security diagnostics | Legitimate interests, with a documented balancing test | Minimised signals, short retention, no covert behavioural profiling |
| Invoices and tax records | Legal obligation | Kept separately from presentations and audio, so deleting those doesn't break statutory records |
| Optional saved recordings | Your specific opt-in (consent) | No recording by default, visible recording indicator, easy deletion |
| Optional analytics or marketing | Consent where required | Off until you choose; withdrawal honoured. Not in use at present |
| Optional research or model improvement | Separate explicit opt-in | Never bundled with the basic service; no default reuse of private data. Not in use at present |
| Institution-managed workspaces (future) | Roles determined per purpose | Covered by a data processing agreement |
Browser microphone permission is not treated as consent to anything beyond the processing you start. You can withdraw any consent at any time, without affecting processing before withdrawal.
Recipients
We share personal data only with service providers that process it on our behalf: Cloudflare (hosting, database, storage, email), OpenRouter and the model providers it routes to (AI features), Deepgram (transcription), Stripe (payments), Brave Search (only if you enable web research) and Google (only if you connect it for export). The full list, with data categories and locations, is on the subprocessors page.
We may disclose data where required by law, or to protect the rights and safety of users and the service. We do not sell personal data or share it for cross-context behavioural advertising.
International transfers
Some providers process data outside the EU/EEA. Where they do, we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, together with supplementary measures where needed. The mechanism for each provider and model route is to be confirmed and will be listed on the subprocessors page. If no route meets our privacy requirements, the affected feature is unavailable rather than sending data elsewhere.
Retention
Our intended retention schedule, subject to legal and operational validation:
| Data | Default | Your control / exception |
|---|---|---|
| Live microphone audio | Streamed for the processing you request; no raw recording is saved by default | Saving a recording requires an explicit opt-in |
| Batch-upload audio | Temporary processing copy deleted within 24 hours of the job completing or failing | A separately opted-in saved recording follows its own policy |
| Opted-in recordings | 7 days by default; optionally 30 days within your storage allowance | Delete immediately at any time; export locally |
| Detailed transcripts | 30 days by default | Delete earlier, or explicitly retain within the disclosed project policy |
| Rehearsal reports | 90 days by default | Export; opt in to keep selected progress summaries |
| Active decks and source packets | While your entitlement and storage policy allow | Export, per-project delete, retention settings |
| Post-entitlement archive | Up to 12 months, with a 500 MB total archive cap per account | Advance notices, local export; recordings not included |
| General security logs | 30-day working retention | Longer only for a documented incident or legal need |
| Billing and statutory records | Kept for the applicable statutory period, separately from product content | Erasure rights and legal retention exceptions explained on request |
| Backups | Target rolling deletion within 30 days after primary deletion | Legal holds disclosed where they apply |
Your rights
Depending on where you live, you have the right to:
- access your personal data and receive a copy;
- correct inaccurate data;
- delete your data, subject to legal retention exceptions such as tax records;
- receive your data in a portable format;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent at any time.
To exercise them, use privacy requests, delete your account, or write to privacy@slidedeck.my. We verify your identity before acting, handle requests auditably, and explain any legal exception that applies. We cannot recall files you have already exported or shared yourself. California residents: see California privacy.
Automated feedback
Rehearsal feedback is generated automatically but is private practice feedback with no legal or similarly significant effect. We do not infer emotions, personality or nervousness, and we do not grade accent or disability. Each assessment records the model and presentation version used.
Age
Self-service accounts are intended for people aged 16 and over, subject to country-specific review. Institution-managed access for younger users would need separate consent and safeguarding arrangements and is not offered.
Contact and complaints
Write to privacy@slidedeck.my. You also have the right to complain to a data protection supervisory authority, in particular in the country where you live or work. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).