Slobal
Legal

Privacy policy

Effective 24 September 2026 · Last updated 30 September 2026 · Slobal, Ireland

Key facts
Controller
Taher Laskar trading as Slobal
Supervisory authority
Irish Data Protection Commission

Slobal builds software that is self-hosted by default. The honest consequence, and the starting point of this policy, is that on the local and relay tiers most of the data our products touch never reaches us: the instance runs on your own machine, and what your agents read, write and remember stays there. On the three cloud tiers we run the instance for you, so we hold what it holds; that case is set out below. This page describes the data Slobal (“Slobal”, “we”) does process when you use slobal.com and hold a Slobal account, and it is written to be read.

Who is responsible

The data controller is Taher Laskar trading as Slobal, Ireland. Contact: support@slobal.com. Where we process personal data on your behalf as a processor, the data processing agreement applies.

What we collect, and why

What we do not do

Bug reports

The Report a bug control in Helmsly sends a report to Slobal. Slobal is the controller of that data, and we use it for support and to fix the product.

A bug report is data for which Slobal is the controller, so the data processing agreement does not cover it.

Messaging channels

You can connect WhatsApp, Slack or Telegram to an agent in your Helmsly instance. The three work differently.

Who processes data for us

Our services run on infrastructure hosted in the EU, and an instance we host for you runs in the EU too: the hosting layer refuses a provider region outside it. These processors act on our instructions. The sub-processor list gives the purpose, data and region of each, with a dated change log, and the data processing agreement sets the terms:

The model provider you choose for Helmsly, such as Anthropic, OpenAI or Google, is your own processor and not ours. We share data with no one else, unless the law requires it.

How long we keep it

Erasure and signed receipts

On erasure the receipt keeps its hash, its signature, its timestamp, and its lineage pointers. The payload that identifies a person is deleted and replaced with a tombstone. Verification still passes. The receipt reads as work occurred, signed by this agent, at this time, payload erased on request.

Your rights

Under the GDPR you can ask for access to, correction of, or deletion of your personal data; ask for a portable copy; object to or ask us to restrict processing; and withdraw consent where consent is the basis. Write to support@slobal.com and a person will answer. You can also lodge a complaint with the Irish Data Protection Commission, the supervisory authority for Ireland (dataprotection.ie), or with the authority where you live. You can also find how we use cookies on the cookie page: only the essential sign-in cookie is set, and no analytics run.

Governing law

This policy, and any dispute about the processing described in it, is governed by the laws of Ireland, and the Irish courts have jurisdiction. That does not remove any right you hold under the GDPR or under the law of the country you live in.

Changes

When this policy changes, the date at the top changes with it, and material changes are announced to account holders before they take effect.