Privacy policy
Effective 24 September 2026 · Last updated 30 September 2026 · Slobal, Ireland
Key facts- Controller
- Taher Laskar trading as Slobal
- Contact
- support@slobal.com
- Data processors
- Contabo, Cloudflare, Resend, Stripe, Microsoft 365, GitHub, and the sign-in providers Google, Facebook, Apple, Microsoft and GitHub
- Supervisory authority
- Irish Data Protection Commission
Slobal builds software that is self-hosted by default. The honest consequence, and the starting point of this policy, is that on the local and relay tiers most of the data our products touch never reaches us: the instance runs on your own machine, and what your agents read, write and remember stays there. On the three cloud tiers we run the instance for you, so we hold what it holds; that case is set out below. This page describes the data Slobal (“Slobal”, “we”) does process when you use slobal.com and hold a Slobal account, and it is written to be read.
Who is responsible
The data controller is Taher Laskar trading as Slobal, Ireland. Contact: support@slobal.com. Where we process personal data on your behalf as a processor, the data processing agreement applies.
What we collect, and why
- Account data · your email address, the display name you choose, and a salted hash of your password (never the password itself). Your email is the identity key across every Slobal product. Lawful basis: performance of a contract.
- Workspace and billing records · workspace name, company name, licence orders, seats, and their payment state. Card details are held by Stripe, our payment processor, and not by us. We are not VAT registered, so we add no VAT to a price. Lawful basis: performance of a contract and our legal obligations to keep commercial records.
- Hosted instance content, on the cloud tiers only · if you buy a cloud tier we run your instance, so we hold what it holds: your sessions, memory and files. It sits in the EU in a container of its own, on a volume of its own, under an encryption key of its own that only that container's identity can use, with its own egress policy and nothing shared with another customer. We are your processor for personal data inside it and we process it on your instructions. Lawful basis: performance of a contract.
- Two-step verification · if you or your administrator enable it, an encrypted authenticator secret. Lawful basis: legitimate interest in securing accounts.
- Sign-in session · one strictly necessary cookie (
hmsly_id) that keeps you signed in. It is HttpOnly and Secure, and it lasts up to 30 days, or until you sign out. Your browser also keeps two preference keys in its own storage,slobal-themeandnav.*, which remember the theme and the navigation state you chose. They stay until you clear them. The cookie policy lists each one. There are no analytics, advertising, or tracking cookies on slobal.com, and nothing is set on the public pages before you sign in, so there is no cookie banner: nothing optional is set. - Service logs · Server logs are kept for 14 days with shortened IP addresses (the last part of the address is removed before it is written), for security and troubleshooting. Lawful basis: legitimate interest in running a secure service.
- Support mail · whatever you choose to send to our support address, kept for as long as the conversation needs.
What we do not do
- We do not sell or rent personal data, we do not profile you, and there are no advertising trackers, analytics scripts or third-party pixels anywhere on slobal.com.
- On the local and relay tiers we do not receive the content your Helmsly instance works with. It lives on the machine you run it on. When you use remote access, traffic passes through our relay encrypted, addressed to your own instance, and our relay stores no content of yours on either tier.
- AgnCred records evidence about agent work by cryptographic hash and attestation, designed so private company content is not carried forward.
Bug reports
The Report a bug control in Helmsly sends a report to Slobal. Slobal is the controller of that data, and we use it for support and to fix the product.
- What it sends · your name and email address from your session, the text you type, the page you were on, the versions of the software, your operating system and, if you add one, a screenshot.
- Personal data in a report · a report can contain personal data, including anything that is visible in the screenshot. Check the screenshot before you send it. Data protection (DLP) does not scrub bug reports.
- Lawful basis · our legitimate interest in fixing the product and, where you choose to send a report, your consent.
- Where it sits and who reads it · reports are stored on our server in the EU, hosted by Contabo. Only Slobal staff with vendor access can read them.
- How long we keep it · 180 days. Then the report and its screenshot are deleted automatically.
- Deletion on request · email support@slobal.com and we delete the report from the inbox.
A bug report is data for which Slobal is the controller, so the data processing agreement does not cover it.
Messaging channels
You can connect WhatsApp, Slack or Telegram to an agent in your Helmsly instance. The three work differently.
- WhatsApp · messages sent to your number pass through the Slobal relay in transit to your own Helmsly install. If your install is offline, the relay holds a message for at most 15 minutes. It stores nothing at rest after delivery.
- Slack and Telegram · messages go straight between the platform and your install. They do not pass through the relay.
- Who is the processor · Meta (WhatsApp), Slack and Telegram are your own processors, contracted by you. They are not Slobal’s sub-processors.
Who processes data for us
Our services run on infrastructure hosted in the EU, and an instance we host for you runs in the EU too: the hosting layer refuses a provider region outside it. These processors act on our instructions. The sub-processor list gives the purpose, data and region of each, with a dated change log, and the data processing agreement sets the terms:
- Contabo · our hosting provider. The servers that run slobal.com, sign-in, the relay and our databases are theirs, so everything described above sits on machines they operate for us.
- Cloudflare · DNS, CDN and security proxying for slobal.com. In doing that it processes visitor IP addresses and request metadata on our behalf.
- Resend · delivery of the transactional email we send you, such as sign-in, account and order messages. It processes your email address and the content of those messages for that purpose only. It sends from the EU (Ireland) region.
- Stripe · payment for licence orders. It processes your billing details, including the card, which we never hold. You pay on the Stripe hosted checkout page, and no Stripe script loads on slobal.com. Stripe is not yet in use. We add a dated line to the sub-processor list before Stripe processes a payment.
- Microsoft 365 · our company mail, including the support mail you send us.
- GitHub · hosting for our own code and documents. Customer content is not stored there.
- Google, Facebook, Apple, Microsoft and GitHub · sign-in providers, used only if you choose one on the sign-in or sign-up page. The provider receives the sign-in request and sees your IP address when your browser is sent to it. We receive the identity you approve, which is your email address and name as the provider returns them. Each provider also acts for itself under its own terms, for your account with it.
The model provider you choose for Helmsly, such as Anthropic, OpenAI or Google, is your own processor and not ours. We share data with no one else, unless the law requires it.
How long we keep it
- Account and workspace data · for the life of the account.
- A hosted instance whose licence lapses · 30 days. The container is suspended and its volume kept, we warn you 30, 14, 7 and 1 day before the licence lapses, and after the 30 days the volume and its key are destroyed and the record becomes a tombstone: hashes, key identifiers and timestamps, with no content behind them.
- Dormant personal accounts · two years, then deleted. If you close a personal account, or its licence lapses, the account goes dormant rather than being deleted: we withdraw its connection to our relay and keep only the account row itself, which is an email address, some hashes, some identifiers and some dates. Your install keeps its own data on your own machine throughout, and the licence key you paid for keeps working there offline. Two years after the account goes dormant we delete the record, and your install is then instructed to delete the account’s data at its next check-in. We email you 90 days, 30 days and 7 days before that date, and signing in and renewing at any point brings the account back with nothing reset.
- Inactive AgnCred records · two years, then erased. If a person’s AgnCred record shows no activity for two years, counted from the most recent of signing in or working in AgnCred, an agent filing a receipt in a workspace they belong to, and the day they left their last workspace, we erase it. We email 90 days, 30 days and 7 days before that date. Erasure removes names, email addresses and private evidence, and it deliberately does not touch the signed receipts, versions or attestations: those already carry pseudonymous identifiers only, they stay verifiable at agncred.com/verify forever, and a verification report simply discloses that the personal data behind it was erased. That is the design, so that erasing somebody cannot be used to destroy proof somebody else relies on.
- Bug reports · 180 days, then deleted automatically. We delete one earlier if you ask.
- Order and billing records · six years, because Irish tax law requires commercial records to be kept that long.
- Service logs · up to 30 days, then they rotate away automatically.
- Support mail · up to 24 months after the conversation ends.
- Sign-in cookie · lasts up to 30 days, or until you sign out.
- Theme and navigation keys · stay in your browser until you clear them. We never receive them.
On erasure the receipt keeps its hash, its signature, its timestamp, and its lineage pointers. The payload that identifies a person is deleted and replaced with a tombstone. Verification still passes. The receipt reads as work occurred, signed by this agent, at this time, payload erased on request.
Your rights
Under the GDPR you can ask for access to, correction of, or deletion of your personal data; ask for a portable copy; object to or ask us to restrict processing; and withdraw consent where consent is the basis. Write to support@slobal.com and a person will answer. You can also lodge a complaint with the Irish Data Protection Commission, the supervisory authority for Ireland (dataprotection.ie), or with the authority where you live. You can also find how we use cookies on the cookie page: only the essential sign-in cookie is set, and no analytics run.
Governing law
This policy, and any dispute about the processing described in it, is governed by the laws of Ireland, and the Irish courts have jurisdiction. That does not remove any right you hold under the GDPR or under the law of the country you live in.
Changes
When this policy changes, the date at the top changes with it, and material changes are announced to account holders before they take effect.