SLOE Labs Inc. — Sloe Laboratory
Version 1.0 · 3 August 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between SLOE Labs Inc., a corporation incorporated under the Canada Business Corporations Act (corporation number 1781545-0) and registered in Ontario, with registered office at to be completed on execution ("SLOE Labs", "we"), and the customer identified in the Agreement ("Customer", "you").
Where this DPA conflicts with the Agreement on the subject of personal data, this DPA governs.
1. Definitions#
"Data Protection Law" means every privacy or data protection law applicable to the processing under this DPA, including as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and Data Protection Act 2018; the South African Protection of Personal Information Act 4 of 2013 ("POPIA"); the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA") and provincial equivalents; US state privacy laws; and the data protection laws of Bahrain and the UAE.
"Customer Personal Data" means personal data contained in Customer Data that SLOE Labs processes on Customer's behalf under the Agreement.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. Under POPIA, "Controller" corresponds to responsible party, "Processor" to operator, and "Data Subject" to data subject.
"Sub-processor" means a third party engaged by SLOE Labs to process Customer Personal Data.
"Service" means Sloe Laboratory, comprising the Studio at sloelabs.com and any operating system provisioned for Customer at a sloelabs.com subdomain.
2. Roles of the parties#
2.1 Customer is the Controller. Customer determines the purposes and means of processing Customer Personal Data. SLOE Labs is the Processor and processes Customer Personal Data only on Customer's documented instructions.
2.2 Customer's own end users. Where Customer uses a provisioned operating system to serve Customer's own customers, staff, or contacts, Customer remains Controller of those individuals' personal data. Customer is responsible for having a lawful basis for that processing, for providing those individuals with a privacy notice, and for honouring their rights. SLOE Labs provides a template notice for this purpose (docs/legal/tenant/) as an accommodation, not as legal advice, and Customer is responsible for its accuracy.
2.3 SLOE Labs as Controller for limited purposes. SLOE Labs acts as a Controller in its own right only for account administration, billing, security and abuse prevention, and aggregate service analytics that do not identify a Data Subject. That processing is governed by our Privacy Policy, not by this DPA.
2.4 Instructions. The Agreement, this DPA, and Customer's configuration and use of the Service constitute Customer's complete documented instructions. SLOE Labs will notify Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until resolved.
3. Processing#
3.1 Scope. Annex A sets out the subject matter, duration, nature and purpose of processing, the categories of Data Subjects, and the types of Personal Data.
3.2 Restrictions on SLOE Labs. SLOE Labs will not:
- (a) process Customer Personal Data for any purpose other than performing the Service and complying with law;
- (b) sell or share Customer Personal Data, or disclose it to a third party except to Sub-processors under clause 5 or where legally compelled;
- (c) use Customer Personal Data for advertising or profiling;
- (d) use Customer Personal Data, or permit any Sub-processor to use it, to train, fine-tune, or otherwise improve any artificial intelligence or machine learning model. SLOE Labs will procure AI processing on commercial terms under which the provider is contractually barred from training on submitted content and from human review of it, except where strictly necessary for security or legal compliance;
- (e) combine Customer Personal Data with data from another customer or source except as necessary to provide the Service to Customer.
3.3 Confidentiality. SLOE Labs ensures that every person authorised to process Customer Personal Data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only on a need-to-know basis.
4. Security#
4.1 Measures. SLOE Labs implements and maintains the technical and organisational measures in Annex B, which are designed to meet GDPR Art. 32 and POPIA s19. SLOE Labs may update those measures provided the overall level of protection is not reduced.
4.2 Personal Data Breach. SLOE Labs will notify Customer without undue delay and in any event within 48 hours of confirming a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. SLOE Labs will provide reasonable cooperation to enable Customer to meet its own notification obligations — including to the Information Regulator under POPIA s22 and to a supervisory authority under GDPR Art. 33, for which Customer's own deadline is 72 hours.
4.3 No admission. Notification under 4.2 is not an acknowledgement of fault or liability.
5. Sub-processors#
5.1 General authorisation. Customer grants SLOE Labs general authorisation to engage Sub-processors, subject to this clause. The current list is published at https://sloelabs.com/subprocessors and reproduced at sub-processors.md.
5.2 Notice and objection. SLOE Labs will update the published list before a new Sub-processor begins processing Customer Personal Data, and will offer a mechanism for Customer to subscribe to notifications of changes. Customer may object on reasonable data-protection grounds within thirty (30) days. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused term.
5.3 Flow-down and liability. SLOE Labs imposes on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for a Sub-processor's performance.
6. Assistance to Customer#
6.1 Data Subject requests. Taking into account the nature of the processing, SLOE Labs will assist Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise rights of access, correction, deletion, restriction, portability, and objection. Where SLOE Labs receives such a request directly, it will not respond substantively but will redirect the Data Subject to Customer and inform Customer promptly.
6.2 Impact assessments. SLOE Labs will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority under GDPR Arts. 35–36, taking into account the information available to it.
6.3 Audit. SLOE Labs will make available the information reasonably necessary to demonstrate compliance with this DPA. Customer may audit no more than once per twelve (12) months, on thirty (30) days' written notice, during business hours, subject to confidentiality, and in a manner that does not compromise other customers' data or the security of the Service. SLOE Labs may satisfy an audit request by providing a current third-party audit report or completed security questionnaire where one adequately addresses the request. Customer bears its own audit costs; a for-cause audit following a confirmed Personal Data Breach is at SLOE Labs' cost.
7. International transfers#
7.1 Customer acknowledges that provision of the Service involves transfer of Customer Personal Data outside the country of origin, including to the recipients identified in sub-processors.md.
7.2 Transfers are made under the mechanisms in Annex C.
7.3 SLOE Labs will not transfer Customer Personal Data to a jurisdiction lacking an adequacy decision or equivalent safeguards without either an appropriate transfer mechanism or Customer's prior written consent.
8. Deletion and return#
8.1 On termination or expiry of the Agreement, SLOE Labs will, at Customer's election, delete or return Customer Personal Data.
8.2 Customer may export Customer Data at any time during the term and for thirty (30) days after termination, in a structured, commonly used, machine-readable format.
8.3 SLOE Labs will delete Customer Personal Data within ninety (90) days of the end of the export window, including from backups on their ordinary rotation cycle, except where retention is required by law. Data retained under this exception remains subject to clauses 3 and 4 for as long as it is held.
9. Liability#
9.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
9.2 Nothing in this DPA limits either party's liability to a Data Subject under Data Protection Law, or excludes liability that cannot lawfully be excluded.
10. General#
10.1 Term. This DPA takes effect on the date of the Agreement and continues until SLOE Labs has deleted or returned all Customer Personal Data.
10.2 Governing law. This DPA is governed by the law stated in the Agreement, except where Data Protection Law requires otherwise — in which case the mandatory provisions of that law prevail for the processing they govern.
10.3 Order of precedence. Annex C's regional terms prevail over the body of this DPA for processing subject to the law in question.
Annex A — Details of processing#
| Subject matter | Provision of the Sloe Laboratory Service, comprising the Architect (design of an operating system) and the tenant runtime (operation of that system, including agent actions, scheduled work, and long-term memory). |
| Duration | The term of the Agreement, plus the deletion window in clause 8. |
| Nature of processing | Collection, storage, structuring, retrieval, generation of vector embeddings, LLM inference on submitted content, transmission to connected third-party services at Customer's direction, and deletion. |
| Purpose | To operate the Service for Customer, including agent responses, automated actions on Customer's connected accounts, scheduled tasks, and persistent memory across sessions. |
| Categories of Data Subject | Customer's personnel and authorised users; Customer's own customers, clients, prospects, and contacts; any individual whose personal data Customer imports into or connects to the Service. |
| Types of Personal Data | Identifiers (name, email, phone); business contact and relationship data; content of documents, records, and messages Customer creates or imports; content accessible through connected services within the scopes Customer grants; authentication identifiers and OAuth access tokens; usage and audit logs. |
| Special category data | Not required by the Service and not solicited. Customer must not submit special category data (GDPR Art. 9), or POPIA "special personal information" (s26) including health, biometric, religious, political, or criminal-behaviour data, or children's data, without first agreeing additional written terms with SLOE Labs. |
| Retention | for 24 months — proposed defaults: account and content data for the term plus clause 8's windows; audit and action logs 24 months; error-monitoring data 90 days; backups on a rolling 30-day cycle. Confirm against actual system behaviour before signature. |
| Frequency | Continuous for the term. |
Annex B — Technical and organisational measures#
These are the measures in force. Each is evidenced in the codebase or in docs/security-audit.md so it can be verified rather than assumed.
B.1 Access control and tenant isolation#
- Every customer-data table enforces row-level ownership in the database itself. As at the 2026-05-22 internal audit: 31 of 31 tables have row-level security enabled, with 47 policies, binding each row either directly to the owning account or by join to the owning operating system.
- The tenant runtime additionally enforces ownership in application code on every request, resolving the authenticated user and verifying ownership before returning data. Row-level security operates as defence in depth beneath it.
- Every use of the elevated service-role database credential is inventoried and annotated in source (45 sites as at the audit), and is server-side only.
B.2 Encryption#
- In transit: TLS for all external connections.
- At rest: storage-level encryption provided by our database and infrastructure providers.
- Third-party credentials: for most integrations the OAuth grant to Customer's connected services is held by the connector sub-processor (Composio) rather than by SLOE Labs, which retains only a connection reference; SLOE Labs remains liable for that sub-processor under clause 5.3. Where SLOE Labs holds a credential directly, it is encrypted with AES-256-GCM using a purpose-derived key (
sha256(master ‖ purpose), so the token-encryption key is cryptographically distinct from other uses of the master secret), with a fresh random 12-byte initialisation vector per token and an authentication tag verified on decrypt. Source:apps/tenant/server/connectors/crypto.ts.
B.3 Secret handling#
- No AI provider credential is ever exposed to the browser. All model calls are proxied server-side through
/api/llm-gateway. Naming is load-bearing and enforced by convention: onlyVITE_-prefixed variables are inlined into the client bundle, and provider keys are prohibited from carrying that prefix.
B.4 Agent action controls#
- Every action an agent takes on a connected service is recorded in an audit log (
os_actions) attributable to the operating system and the actor. - An independent verifier audits the agent's claims about actions taken against the actual tool responses, so a reported action is corroborated rather than trusted.
- Outbound email may be sent only from a domain the Customer has verified, never from a model-chosen address, and send actions are gated behind an explicit confirmation step.
B.5 Least privilege on integrations#
- Connector scopes are the minimum required for the feature. For Google:
gmail.sendconfers send-only access and no inbox read;spreadsheets.readonlyis limited to sheets the Customer explicitly connects. - Customer may revoke any connection at any time from settings, which revokes SLOE Labs' access.
B.6 Monitoring, resilience, and personnel#
- Application error and performance monitoring with alerting.
- Health checks covering dependent services.
- Backups on a rolling cycle with restoration capability.
- Access to production systems is limited to personnel who require it, under confidentiality obligations.
Known limitations, stated deliberately. SLOE Labs does not hold SOC 2 or ISO 27001 certification. There is no formal, independently attested penetration test on the current architecture. Customers requiring certification should treat these as gaps rather than assume equivalence.
Annex C — Regional terms and transfer mechanisms#
C.1 European Union and United Kingdom (GDPR / UK GDPR)#
- This DPA is intended to satisfy GDPR Art. 28(3)(a)–(h).
- For transfers of Customer Personal Data from the EEA to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), with: Clause 7 (docking) included; Clause 9 option 2 (general written authorisation) with the 30-day period in clause 5.2; Clause 11 optional redress clause excluded; Clause 17 governed by the law of Ireland; Clause 18(b) forum Ireland. Annexes I, II and III are populated by Annexes A and B of this DPA and by
sub-processors.md. - For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated, with the EU SCCs as the approved addendum, governing law and forum England and Wales.
- ⚠️ privacy@sloelabs.com — with no establishment in the EU or UK and customers there, an Art. 27 representative may be required. Confirm with counsel.
C.2 South Africa (POPIA)#
This section is an operator agreement for the purposes of POPIA s20–21, for which a written contract is a statutory requirement rather than a commercial option.
- SLOE Labs is an operator processing personal information on behalf of Customer as responsible party.
- SLOE Labs processes personal information only with the knowledge or authorisation of Customer (s20(a)) and treats it as confidential, not disclosing it except as required by law or in the proper performance of its duties (s20(b)).
- SLOE Labs establishes and maintains the security measures required by s19, as set out in Annex B, and will identify reasonably foreseeable risks, maintain safeguards against them, verify their effective implementation, and update them in response to new risks.
- Where SLOE Labs has reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, it will notify Customer immediately (s21(2)), in accordance with clause 4.2, so that Customer can notify the Information Regulator and affected data subjects under s22.
- Cross-border transfer (s72). Customer authorises transfer of personal information outside South Africa to the recipients in
sub-processors.md, on the basis that this DPA binds each recipient to a standard of protection substantially similar to POPIA's conditions for lawful processing and to the further-transfer restriction in clause 5.3. This authorisation is given in writing here and is not inferred from use of the Service. - Information Officer. privacy@sloelabs.com — POPIA s55 requires a registered Information Officer. Confirm registration with the Information Regulator.
- Customer remains responsible as responsible party for the s11 lawful basis, the s18 notification to data subjects, and s26 restrictions on special personal information.
C.3 Canada (PIPEDA and provincial law)#
- SLOE Labs processes Customer Personal Data as a service provider under Customer's control and does not use it for its own purposes.
- Customer acknowledges that data may be processed outside Canada and is therefore subject to the legal jurisdiction of those countries, and is responsible for notifying its own individuals of that fact where required.
- SLOE Labs will report to Customer any breach of security safeguards creating a real risk of significant harm, in accordance with clause 4.2.
C.4 United States#
- SLOE Labs acts as a service provider / processor under applicable state privacy law. It will not sell or share Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service, and will not combine it with data from other sources except as permitted for a service provider.
C.5 Gulf (Bahrain PDPL, UAE)#
- Where Bahrain's Personal Data Protection Law or UAE federal or free-zone data protection law applies, SLOE Labs processes as a data processor on Customer's documented instructions, applies the Annex B measures, and will support Customer with any registration, notification, or transfer-approval obligation applicable to Customer as controller.
- ⚠️ Confirm with local counsel whether Customer's sector or the data types involved trigger a local-hosting or prior-approval requirement, which the current architecture does not accommodate.
Signature#
Executed by the parties' authorised representatives.
| SLOE Labs Inc. | Customer |
|---|---|
| Name: | Name: |
| Title: | Title: |
| Date: | Date: |
| Signature: | Signature: |
Notices to SLOE Labs: privacy@sloelabs.com · to be completed on execution