Data Processing Agreement

Last Updated: July 2, 2026
Version: 1.1

DPA Options

Download Template

Standard DPA template for immediate use

Download PDF

Request Signed DPA

Custom agreement with electronic signature

Contact Legal Team

This Data Processing Agreement ("DPA") forms part of the Terms of Use ("Agreement") between:

Data Controller: The entity identified in the Agreement ("Customer", "Controller")

Data Processor:

  • For Middle East/Asia customers: Incredible Pods Technologies Ltd, DIFC, Dubai, UAE
  • For other regions: Slick AI Technologies, Inc., Delaware, USA

(collectively "Slick", "Processor", "we", "us")

1. Definitions

1.1 "Applicable Data Protection Law" means all laws and regulations relating to data protection and privacy applicable to the processing of Personal Data under this DPA, including:

  • EU General Data Protection Regulation (Regulation 2016/679) ("GDPR")
  • UK General Data Protection Regulation ("UK GDPR")
  • California Consumer Privacy Act ("CCPA/CPRA")
  • Other US state privacy laws (CPA, CTDPA, VCDPA, UCPA)
  • Turkish Personal Data Protection Law ("KVKK")
  • DIFC Data Protection Law No. 5 of 2020
  • Any implementing legislation and regulatory requirements

1.2 "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Sub-processor" shall have the meanings given in the GDPR, and equivalent terms in other Applicable Data Protection Laws shall be interpreted accordingly.

1.3 "Customer Data" means Personal Data submitted to or collected through the Services by or on behalf of Customer.

1.4 "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.

2. Scope and Roles

2.1 Relationship: This DPA applies when Processor processes Customer Data on behalf of Controller in the course of providing the Services.

2.2 Controller Responsibilities: Controller is responsible for:

  • The lawfulness of Personal Data processing
  • Providing necessary notices to Data Subjects
  • Obtaining required consents
  • Ensuring processing instructions comply with Applicable Data Protection Law

2.3 Processor Role: Processor shall process Customer Data only as a Processor acting on behalf of Controller.

3. Processing Details

3.1 Nature and Purpose of Processing:

  • Providing AI-powered conversational interfaces and automation
  • Processing messages across communication channels (WhatsApp, Instagram, web)
  • Voice and image recognition processing
  • Executing business workflows (Slickflows)
  • Analytics and service improvement

3.2 Categories of Data Subjects:

  • Controller's employees and staff
  • Controller's customers and end users
  • Controller's prospects and leads
  • Controller's business partners and vendors

3.3 Types of Personal Data:

  • Identification data (names, usernames, IDs)
  • Contact information (email, phone, messaging IDs)
  • Communication content (messages, voice recordings, images)
  • Transaction and interaction history
  • Behavioral and preference data
  • Technical data (IP addresses, device information)
  • Business system data (CRM records, customer profiles)

3.4 Duration of Processing: For the term of the Agreement plus any retention period as configured by Controller or required by law.

4. Processor Obligations

4.1 Compliance: Processor shall process Customer Data in compliance with:

  • Controller's documented instructions
  • This DPA and the Agreement
  • Applicable Data Protection Law

4.2 Instructions:

  • Processor shall process Customer Data only on documented instructions from Controller
  • The Agreement and Controller's use of the Services constitute Controller's complete instructions
  • If required by law to process beyond instructions, Processor shall inform Controller (unless prohibited)

4.3 Confidentiality: Processor shall ensure that personnel authorized to process Customer Data:

  • Are subject to appropriate confidentiality obligations
  • Process Customer Data only as necessary for their duties
  • Receive appropriate training on data protection

4.4 Data Isolation: Processor shall implement technical and organizational measures to ensure Customer Data is isolated from other customers' data through:

  • Per-tenant logical isolation (AES-256 at rest via AWS KMS; customer-managed keys (BYOK) available on request)
  • Logical data segregation
  • Access control restrictions
  • Network segmentation where appropriate

5. Security Measures

5.1 Security Program: Processor shall implement and maintain appropriate technical and organizational measures to protect Customer Data, including:

Technical Measures:

  • Encryption at rest (AES-256 using AWS KMS, HSM-backed)
  • Encryption in transit (TLS 1.2+, TLS 1.3 supported)
  • Customer-managed keys (BYOK) available on request; keys rotated on a defined schedule
  • Multi-factor authentication for administrative access
  • Automated security patching and updates
  • Intrusion detection and prevention systems
  • Regular vulnerability scanning

Organizational Measures:

  • Information security policies and procedures
  • Access control and authorization procedures
  • Regular security training for personnel
  • Incident response procedures
  • Business continuity and disaster recovery plans
  • Vendor security assessment program
  • Regular security audits and assessments

5.2 Updates: Processor may update security measures provided that such updates do not materially decrease the overall security of the Services.

6. Sub-processors

6.1 Authorized Sub-processors: Controller consents to Processor's use of Sub-processors listed at www.getslick.ai/sub-processors

6.2 New Sub-processors:

  • Processor shall notify Controller of new Sub-processors at least 30 days in advance
  • Controller may object within 14 days of notification with reasonable grounds
  • If objection cannot be resolved, Controller may terminate affected Services

6.3 Sub-processor Requirements: Processor shall:

  • Enter into written agreements with Sub-processors imposing equivalent data protection obligations
  • Remain fully liable for Sub-processor performance
  • Conduct appropriate due diligence on Sub-processors

6.4 Current Sub-processors (as of agreement date):

Sub-processorPurposeLocation
Amazon Web ServicesInfrastructure & database (DocumentDB)EU-West (Ireland)
Amazon Bedrock (AWS)AI/LLM inference (Claude) — primary path for Claude-based tenantsEU-West (Ireland)
AnthropicClaude AI models (direct API; also served via Bedrock)USA/EU
Microsoft Azure (AI Foundry)Supplementary AI model hosting (fallback for specific model tiers)Region-specific
OpenAIAI Language Processing (other products/models)USA/EU
Google Cloud (Vertex AI)AI Processing (other products/models)Global (region-specific)
Meta PlatformsWhatsApp Business APIGlobal (region-specific)

7. Data Subject Rights

7.1 Assistance: Processor shall provide reasonable assistance to enable Controller to respond to Data Subject requests, including:

  • Access requests
  • Rectification requests
  • Erasure requests
  • Restriction of processing
  • Data portability
  • Objection to processing

7.2 Response Timeline:

  • Acknowledgment: Within 24 hours
  • Initial response: Within 7 days
  • Full compliance: Within 30 days (or as required by law)

7.3 Direct Requests: If Processor receives requests directly from Data Subjects:

  • Processor shall not respond except as required by law
  • Processor shall promptly notify Controller
  • Controller shall handle the request

8. Data Transfers

8.1 Transfer Mechanisms: For transfers of Personal Data outside the EEA/UK, parties shall rely on:

  • Standard Contractual Clauses (incorporated as Schedule 1)
  • Adequacy decisions where applicable
  • Other valid transfer mechanisms under Applicable Data Protection Law

8.2 Data Residency:

  • Customer Data is processed in the active EU-WEST-1 (Ireland) region
  • US-EAST-1 (Virginia) and other regions are not currently active; they may be enabled for eligible customers on request
  • Where an additional region is enabled, Customer Data remains in the region selected by Controller during onboarding

8.3 Transfer Restrictions: Processor shall not transfer Customer Data outside the selected region except:

  • With Controller's explicit written consent
  • As required by law (with notice to Controller where permitted)
  • To authorized Sub-processors under appropriate safeguards

9. Contact Information

Legal Team

For DPA questions and contract matters

[email protected]

Privacy Team

For data protection and privacy matters

[email protected]

Response Time: Within 48 hours for all inquiries
Document Reference: DPA-2025-001

This DPA incorporates EU Standard Contractual Clauses, UK IDTA, and other international transfer mechanisms as required by applicable law.