Data processing agreement
Effective 24 September 2026 ยท Slobal, Ireland
This agreement forms part of the terms of service. It applies when Taher Laskar trading as Slobal (“Slobal”) processes personal data on your behalf, and it meets Article 28 of the GDPR. No signature is needed. It applies from the day you start to use a service that involves such processing. A signed copy is available on request from support@slobal.com.
1. Parties and roles
- Controller. You, the customer: the person or organisation that owns the Helmsly instance or workspace and decides why and how its personal data is processed.
- Processor. Taher Laskar trading as Slobal, at the address in the footer of this page, Ireland.
- For account, sign-in and billing data about you, Slobal is a controller in its own right. The privacy policy covers that data. This agreement covers only personal data that Slobal handles for you as a processor.
2. Subject matter and duration
The subject matter is the operation of Helmsly services for you. The main case is a hosted instance on a cloud tier, where Slobal runs the instance and so holds its sessions, memory and files. On the local and relay tiers your instance runs on your own machine, and the relay carries traffic addressed to it without storing content. The agreement lasts as long as Slobal processes this data for you.
3. Data and data subjects
- Nature and purpose. Hosting, storing, transmitting and backing up your instance content so that you can use the service.
- Categories of data. Whatever you and your agents put into the instance. This can include names, email addresses, work content and messages. You decide what goes in. We do not want special category data, and you must not put it in unless you have a lawful basis and tell us.
- Data subjects. Your members, staff, customers and contacts whose data is in the instance.
4. Instructions
Slobal processes the data only on your documented instructions. The terms, this agreement and your use of the product settings are those instructions. Slobal tells you at once if it thinks an instruction breaks data protection law.
5. Confidentiality and security
- Everyone who can access the data at Slobal is bound by confidentiality.
- Slobal applies technical and organisational measures suited to the risk, under Article 32 of the GDPR. A hosted instance runs in the EU in its own container, on its own volume, under its own encryption key, with its own egress policy and nothing shared with another customer. The security page describes the measures.
6. Sub-processors
You give Slobal general written authorisation to use the sub-processors listed at slobal.com/subprocessors. Slobal binds each one to obligations equal to these. Slobal adds a dated line to the change log and emails the account holder before a new sub-processor starts to handle your data. You can object by writing to support@slobal.com. If the objection cannot be resolved, you can cancel the affected service. The model provider you choose is your own processor and is not a sub-processor of Slobal.
7. Assistance to you
Slobal helps you answer requests from data subjects, and helps you meet your duties under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information we hold. Send requests to support@slobal.com. The export and delete routes in the product let you act on many requests yourself.
8. International transfers
Slobal hosts a hosted instance in the European Union. Where a sub-processor handles personal data outside the European Economic Area, the transfer relies on an adequacy decision or on the EU standard contractual clauses (Commission Implementing Decision 2021/914), module two or module three as fits. Slobal only transfers data on your instructions.
9. Breach notification
Slobal tells you without undue delay after it becomes aware of a personal data breach that affects your data. The notice says what happened, what data it touched, what Slobal has done and what it advises you to do, so that you can meet your own duty to notify.
10. Deletion and return
When the service ends, Slobal deletes your personal data or returns it to you, at your choice, and deletes existing copies unless the law requires it to keep them. A hosted instance whose licence lapses is suspended for 30 days. After that its volume and key are destroyed. You can export your data before then. Backups are removed on their normal rotation.
11. Audit
Slobal gives you the information needed to show that it meets this agreement, and allows audits by you or an auditor you appoint, with reasonable notice, during normal working hours and without disrupting other customers. Slobal can meet an audit request first with written answers and its documentation.
12. Liability and precedence
Liability is as set out in the terms of service. If this agreement and the terms conflict on the processing of personal data, this agreement applies.