Privacy Policy

Slaeb is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights — in line with GDPR, UK GDPR, and applicable regulations in France, the Caribbean, the United States, and Asia.

Effective date
12 May 2026
Last updated
12 May 2026
Version
1.0
Governing law
Multi-jurisdiction
ON THIS PAGE
01 Who we are

Slaeb is a SaaS development company registered at Immeuble EQUINOXES, 12 rue des Arts et Métiers, Lot Dillon Stade, Fort-de-France 97200, Martinique, with associated entities serving customers in France, the United Kingdom, the United States, the Caribbean and Asia.

For data protection law, Slaeb acts as a data controller for personal data we collect directly from website visitors, prospects and account holders. We act as a data processor for personal data that our customers upload into the platform about their own employees, clients or contacts.

02 What data we collect

We only collect the personal data we need to deliver our service. We never sell your data.

Data you give us directly

Account data: name, email, password (hashed), phone number, job title, company name

Billing data: billing address, VAT number, payment method (processed by our payment provider — we never store full card numbers)

Communications: messages you send through our contact forms, support tickets, demo bookings or chat

Data your organisation uploads into Slaeb

When you use Slaeb to manage HR, CRM, QHSE or business operations, your organisation may upload personal data about employees, clients or contacts (the “Customer Data”). For this data, your organisation is the controller — we process it on their behalf under our Data Processing Agreement.

Data we collect automatically
  • Technical data: IP address, browser type, device identifiers, operating system, time zone
  • Usage data: pages visited, features used, clicks, session duration, referring URL
  • Cookies: see our Cookie Policy for full details
03 How and why we use it

We keep personal data only as long as we need it for the purpose it was collected, plus any period required by law.

Purpose What we use Lawful basis
Create and manage your account
Account data, billing data
Contract
Deliver the platform and its modules
Account data, usage data
Contract
Process payments and invoicing
Billing data
Contract / legal obligation
Customer support and onboarding
Account data, communications
Contract / legitimate interest
Improve our product and detect bugs
Usage data, technical data
Legitimate interest
Send service emails (security, billing)
Account data
Contract
Send marketing communications
Account data
Consent (opt-in)
Comply with legal obligations
All categories as required
Legal obligation
Prevent fraud and abuse
Technical data, usage data
Legitimate interest
04 Lawful basis for processing

Under the EU and UK GDPR, we rely on one of the following lawful bases for every processing activity:

Contract — we need your data to provide the service you signed up for

Legitimate interest — to operate, secure and improve our business (balanced against your rights)

Consent— for marketing emails and non-essential cookies (you can withdraw at any time) 

Legal obligation — to comply with tax, accounting and other applicable laws

For users in California, we comply with the CCPA/CPRA. For users in the Caribbean and Asia, we apply the highest applicable local standard alongside our global baseline.

05 Who we share data with

We share personal data only with vetted third parties who help us run Slaeb. Every sub-processor is contractually bound to the same data-protection standards we apply ourselves.

Category Examples Location
Cloud hosting
GoDaddy
EU / US
Payment processing
Stripe
EU / US (SCCs)
AI features
OpenAI / Anthropic for in-product AI
EU / US (SCCs)
Analytics
Privacy-friendly analytics
EU
Customer support
Email
EU

We will also disclose personal data if legally required to do so (court order, regulatory request), or to protect the safety, rights or property of Slaeb, our users or the public.

An up-to-date list of sub-processors is available on request from info@slaeb.com.

06 International transfers
Slaeb operates across five regions: Caribbean, France, the UK, the US and Asia. When we transfer personal data outside the EU/EEA or the UK, we use one of the following safeguards:Transfers to countries with an adequacy decision from the European Commission or the UK ICOStandard Contractual Clauses (SCCs) with the additional UK Addendum where applicableBinding Corporate Rules where in placeYou can request a copy of the safeguards in place for any specific transfer by contacting our DPO.
07 How long we keep data

We keep personal data only as long as we need it for the purpose it was collected, plus any period required by law.

08 How we protect your data

We take security seriously and apply industry-standard technical and organisational measures, including:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Role-based access control and the principle of least privilege internally
  • Multi-factor authentication available for all customer accounts
  • Regular vulnerability scans and annual penetration tests
  • Documented incident response procedures with 72-hour breach notification
  • Staff training on data protection and security

Breach notification — If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR.

09 Your rights

Whatever country you are in, you have the following rights over your personal data. We respond to all requests within one month (sometimes extendable to three).

Right to access

Get a copy of the personal data we hold about you.

Right to rectification

Correct any data that is inaccurate or incomplete.

Right to erasure

Ask us to delete your data ("right to be forgotten").

Right to portability

Receive your data in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interest or direct marketing.

Automated decisions

Request human review of decisions made by AI features.

Right to complain

Lodge a complaint with your local data protection authority.

To exercise any of these rights, email info@slaeb.com. We may ask you to verify your identity before responding.

10 Cookies and tracking

We use cookies to operate the platform, remember your preferences, measure performance and (with your consent) personalise marketing. For the full list of cookies we use, their purposes and how to manage them, see our Cookie Policy.

11 Children's data

Slaeb is a B2B platform designed for business users. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

12 Changes to this policy

We may update this policy from time to time to reflect changes in our practice, the law, or our service. We will always post the new version on this page with an updated “Last updated” date, and notify account holders by email if the change is significant.

13 How to contact us

For any question, request or complaint relating to this policy or your personal data, our Data Protection Officer is the first point of contact.

Contact our Data Protection Officer

We aim to respond to every privacy request within 30 days.

Email
 
Postal address
Immeuble EQUINOXES, 12 rue des Arts et Métiers, Lot Dillon Stade, Fort-de-France 97200, Martinique
 
Supervisory authority (EU)CNIL (France)
 
Supervisory authority (UK)
Information Commissioner’s Office (ICO)