Legal
Privacy policy
Effective 23 August 2026 · Slobal Ltd, Ireland
Slobal builds self-hosted software. The honest consequence, and the starting point of this policy, is that most of the data our products touch never reaches us: a Helmsly instance runs on your own machine, and what your agents read, write and remember stays there. This page describes the data Slobal Ltd (“Slobal”, “we”) does process when you use slobal.com and hold a Slobal account, and it is written to be read.
Who is responsible
Slobal Ltd, registered in Ireland, is the data controller for the processing described here. Contact: info@slobal.com.
What we collect, and why
- Account data · your email address, the display name you choose, and a salted hash of your password (never the password itself). Your email is the identity key across every Slobal product. Lawful basis: performance of a contract.
- Workspace and billing records · workspace name, company name, licence orders, seats, and their payment state. Lawful basis: performance of a contract and our legal obligations to keep commercial records.
- Two-step verification · if you or your administrator enable it, an encrypted authenticator secret. Lawful basis: legitimate interest in securing accounts.
- Sign-in session · one strictly necessary cookie (
hmsly_id) that keeps you signed in. It is HttpOnly, Secure, and expires with the session. There are no analytics, advertising, or tracking cookies on slobal.com, so there is no cookie banner: nothing optional is set. - Service logs · IP addresses and request metadata, kept for up to 30 days for rate limiting, abuse prevention and incident response. Lawful basis: legitimate interest in running a secure service.
- Support mail · whatever you choose to send to our support address, kept for as long as the conversation needs.
What we do not do
- We do not sell or rent personal data, we do not profile you, and there are no advertising trackers, analytics scripts or third-party pixels anywhere on slobal.com.
- We do not receive the content your Helmsly instance works with. It lives on the machine you run it on. When you use remote access, traffic passes through our relay encrypted, addressed to your own instance.
- AgnCred records evidence about agent work by cryptographic hash and attestation, designed so private company content is not carried forward.
Who processes data for us
Our services run on infrastructure hosted in the EU. Three processors act on our instructions:
- Contabo · our hosting provider. The servers that run slobal.com, sign-in, the relay and our databases are theirs, so everything described above sits on machines they operate for us.
- Cloudflare · DNS, CDN and security proxying for slobal.com. In doing that it processes visitor IP addresses and request metadata on our behalf.
- Resend · delivery of the transactional email we send you, such as sign-in, account and order messages. It processes your email address and the content of those messages for that purpose only.
Payment confirmation is handled through the payment method named on your order. We share data with no one else, unless the law requires it.
How long we keep it
- Account and workspace data · for the life of the account. If you close a personal account, its record and connection tokens are revoked and your install is instructed to delete the account’s data at its next check-in; what we hold is removed within 30 days.
- Order and billing records · six years, because Irish tax and company law requires commercial records to be kept that long.
- Service logs · up to 30 days, then they rotate away automatically.
- Support mail · up to 24 months after the conversation ends.
- Sign-in cookie · expires with the session.
Your rights
Under the GDPR you can ask for access to, correction of, or deletion of your personal data; ask for a portable copy; object to or ask us to restrict processing; and withdraw consent where consent is the basis. Write to info@slobal.com and a person will answer. You can also lodge a complaint with the Irish Data Protection Commission, the supervisory authority for Ireland (dataprotection.ie), or with the authority where you live.
Governing law
This policy, and any dispute about the processing described in it, is governed by the laws of Ireland, and the Irish courts have jurisdiction. That does not remove any right you hold under the GDPR or under the law of the country you live in.
Changes
When this policy changes, the date at the top changes with it, and material changes are announced to account holders before they take effect.