1. Introduction
This Privacy Policy explains how Slick AI Technologies, Inc. ("Slick AI") and our affiliate, Incredible Pods Technologies Ltd ("Incredible Pods"), (collectively "Slick", "we", "us", or "our") collect, use, disclose, and protect personal data when you use our websites, applications, WhatsApp/Instagram integrations, and enterprise platform (collectively, the "Services").
We are committed to protecting your privacy and ensuring transparency about our data practices. This Privacy Policy applies to all users of our Services, including:
- Individual Users who use Slick for personal productivity through our Free, Plus, or Pro plans
- Team Users who are members of organizations using Slick Teams for internal collaboration
- Business customers who contract with us ("Customers")
- Employees and authorized users of our Customers ("Users")
- End consumers who interact with our Customers through Slick ("End Users")
- Visitors to our websites and marketing materials ("Visitors")
2. Data Controller Information
2.1 Primary Entities
- For US/Global (except ME/Asia): Slick AI Technologies, Inc., a Delaware corporation, 1111B S Governors Ave STE 34221, Dover, DE 19904, United States
- For ME/Asia: Incredible Pods Technologies Ltd, Unit 02, Level 7, Gate Village Building 10, Dubai International Financial Centre, Dubai, UAE
2.2 Controller vs Processor Roles
We act in different capacities depending on the data processing activity:
- As Controller for Individual and Team Users: For personal data of Individual and Team users, we act as the data controller
- As Processor: For Customer Content (conversations, files, workflow data), we process strictly under Customer instructions per our Data Processing Agreement (DPA)
- As Independent Controller: For security, fraud prevention, diagnostics, billing, and product analytics that don't rely on Customer Content for model training
2.3 Contact Information
Data Protection Officer
Email: [email protected]
Response Time: Within 48 hours
Security Team
Email: [email protected]
For urgent security issues, mark email as "URGENT - SECURITY"
3. Data We Collect
3.1 Account & Business Information
- Organization details (company name, size, industry) - for Business and Teams customers
- User account information (name, email, phone, role, title)
- Authentication credentials and security settings
- Billing information (subscription tier, token usage, payment details via processors)
- Subscription tier (Free/Plus/Pro for Individual; Plus/Pro/Enterprise for Teams; Starter/Business/Enterprise/Enterprise Max for Business)
3.2 Customer Content (Processed as Processor)
- Conversation data across channels (WhatsApp, Instagram, web, SMS, email)
- Voice recordings and transcriptions
- Images and media files
- Slickflow configurations and business logic
- API integrations and webhook data
- Files and documents uploaded to the platform
3.3 Usage & Technical Data
- Service interaction logs and analytics
- Device and browser information
- IP addresses and approximate location
- Performance metrics and error reports
- Feature usage patterns
- Slick Token (ST) usage and consumption patterns
- Proactive Activation settings and triggers
- Multi-Agent Mode orchestration data
- Session recordings (enterprise customers only, with notice)
3.4 Cookies & Similar Technologies
See our Cookie Policy for detailed information about cookies, tracking technologies, and your choices.
4. How We Collect Data
4.1 Direct Collection
- When you register for an account or subscribe to Services
- When you communicate with us for support or sales
- When you participate in surveys or provide feedback
4.2 Automatic Collection
- Through your use of the Services
- Via cookies and similar tracking technologies
- Through integrated third-party services
4.3 From Third Parties
- From your organization (if you're a User or Team Member)
- From integrated platforms (WhatsApp, Meta, Twilio, etc.)
- From service providers acting on our behalf
- From public sources for business intelligence
5. How We Use Your Data
5.1 Service Delivery & Operations
- Provide, maintain, and improve the Services across Individual, Teams, and Business products
- Execute Slickflows and process conversations
- Enable cross-channel communication
- Process Slick Token consumption and manage usage limits
- Enable Proactive Activation features and Multi-Agent Mode orchestration
- Provide customer support and technical assistance
- Process transactions and manage billing
5.2 Security & Compliance
- Detect, prevent, and address fraud and abuse
- Monitor and ensure platform security
- Comply with legal obligations
- Respond to legal requests and prevent harm
- Enforce our terms and policies
5.3 Communication
- Send service-related notices and updates
- Respond to inquiries and requests
- Provide technical alerts and security notifications
- Send marketing communications (with consent where required)
5.4 Analytics & Improvement
- Analyze usage patterns and trends
- Develop new features and services
- Conduct research and development
- Create aggregated and anonymized insights
- Important: We do NOT use Customer Content or Individual/Team conversation data for AI model training unless explicitly opted-in
6. Legal Bases for Processing
6.1 Under GDPR/UK GDPR
We process personal data based on:
- Contract Performance: To provide Services to Customers, Individual Users, and Teams
- Legitimate Interests: For security, fraud prevention, and service improvements
- Consent: For marketing communications and non-essential cookies
- Legal Obligations: To comply with applicable laws
- Vital Interests: In rare cases involving safety
6.2 Under Other Frameworks
- CCPA/CPRA: Processing for business purposes as defined under California law
- KVKK: Processing based on explicit consent or contractual necessity
- DIFC DPL: Processing per applicable DIFC regulations
7. Data Sharing & Disclosure
7.1 Service Providers & Sub-processors
We share data with carefully selected third parties who help us provide the Services. See our Sub-processor List for details. Key categories include:
- Cloud infrastructure providers (AWS)
- AI model providers (OpenAI, Google Vertex AI, Anthropic — including Anthropic served via Amazon Bedrock and Microsoft Azure AI Foundry)
- Communication platforms (Meta/WhatsApp, Twilio)
- Payment processors (Stripe)
- Analytics and monitoring tools
All sub-processors, including the third-party AI model providers listed above, are contractually bound under data processing agreements to protect your data with safeguards equivalent to those described in this Privacy Policy, to use it only to provide the Services on our behalf, and not to use it for their own purposes (including training their models) except as you explicitly authorize.
7.2 Legal & Safety
We may disclose data when required to:
- Comply with legal obligations or valid legal requests
- Protect rights, property, or safety
- Detect, prevent, or address fraud and security issues
- Enforce our terms and policies
7.2.1 Government & Legal Request Procedures
When we receive requests from public authorities for personal data or information:
Legality Review Process:
- All government requests undergo immediate legal review to verify authority and scope
- We require valid legal process (warrant, court order, or subpoena) unless emergency circumstances apply
- Requests must identify specific legal basis and be signed by authorized officials
- We verify the requesting agency's identity and jurisdiction
Challenging Unlawful or Overbroad Requests:
- We reserve the right to challenge requests that appear unlawful, overbroad, or procedurally defective
- We may seek to narrow scope to protect user privacy while meeting legal obligations
- Where permitted by law, we will contest requests lacking proper legal basis
- We may involve legal counsel to oppose or modify inappropriate requests
Data Minimization for Legal Requests:
- We disclose only the minimum information necessary to satisfy valid legal requirements
- We apply the principle of proportionality to all disclosures
- Where possible, we provide anonymized or aggregated data instead of personal information
- We will not provide data beyond the specific scope and timeframe requested
Documentation & Transparency:
- All government requests are logged with: date received, requesting agency, legal basis, data scope, our response, and disclosure date
- We maintain records of our responses and any data disclosed for audit purposes
- Where legally permitted, we notify affected users of government requests
- We publish transparency reports when feasible and legally permissible
- Documentation retained for minimum 3 years or as required by law
Emergency Requests:
Emergency disclosures without standard legal process only occur when:
- Imminent danger of death or serious physical injury
- Risk to child safety
- Properly documented emergency request from verified law enforcement
7.3 Business Transfers
In the event of merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction with appropriate safeguards.
7.4 With Consent
We may share data for other purposes with your explicit consent.
7.5 What We DON'T Do
- We do NOT sell personal information
- We do NOT share for cross-context behavioral advertising without opt-out rights
- We do NOT use Customer Content for AI training without explicit opt-in
8. International Data Transfers
8.1 Transfer Mechanisms
When we transfer personal data internationally, we use appropriate safeguards:
- EU/UK to US: Standard Contractual Clauses (Module 2) + UK IDTA
- Switzerland: Swiss Federal Data Protection Act Addendum
- DIFC: Appropriate transfer mechanisms per DIFC Commissioner requirements
- Turkey (KVKK): Board-approved undertakings or explicit consent with documented assessments
8.2 Data Residency
Customer Content is currently processed in our active region:
- EU Region (active): EU-WEST-1 (Ireland)
- US Region: US-EAST-1 (Virginia) — not currently active; may be enabled for eligible customers on request
- ME Region: ME-SOUTH-1 (UAE) — not currently active
Customer Content remains in the active region except as permitted in the DPA or required by law.
Data Residency by Plan:
- Individual and Teams Plus/Pro: Served from global infrastructure with appropriate safeguards
- Teams Enterprise: Data residency control available
- Business (all tiers): Data residency control available
- Enterprise Max: Custom data residency options
9. Data Retention
How long we keep your data. We retain your conversation history for up to 24 months from the date each message is created, after which it is automatically deleted. You can delete your account and associated conversation data at any time from your account settings, and we will erase it on request. Operational and diagnostic logs, which do not contain your conversation content, are retained for 30 days. Business (enterprise) customers may be subject to a different retention period as set out in their agreement.
9.1 Retention Periods
| Data Type | Individual/Teams | Business Default | Business Configurable |
|---|
| Conversation transcripts | Up to 24 months | Up to 24 months | Configurable per contract (may differ by agreement; extendable for regulated record-keeping) |
| Voice recordings | 7 days | 7 days | 0-30 days |
| Customer profiles | 12 months | 12 months | 6 months - 3 years |
| Usage analytics | 24 months | 24 months | 12-36 months |
| Billing records | 7 years | 7 years | As required by law |
| Security logs | 90 days | 90 days | 30-180 days |
| Audit logs | N/A | 30 days | 30 days - 1 year (Enterprise: Custom) |
9.2 Retention Principles
- We retain data only as long as necessary for stated purposes
- Customers can configure retention within specified ranges
- Conversation data is retained for up to 24 months from message creation, then automatically deleted; operational and diagnostic logs (which contain no conversation content) are retained for 30 days
- For customers with a regulatory record-keeping obligation (e.g. financial-services clients), the configurable retention ceiling may be extended by agreement
- Backups are time-limited and securely deleted
- Upon account termination, data is deleted per our DPA terms
10. Your Privacy Rights
10.1 Universal Rights
Depending on your location, you may have the right to:
- Access: Obtain copies of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion ("right to be forgotten"). To delete your account and associated data, use our Delete Account page
- Restriction: Limit how we process your data
- Portability: Receive data in machine-readable format
- Objection: Object to certain processing activities
10.2 CCPA/CPRA Rights (California)
- Right to know categories and specifics of data collected
- Right to delete personal information
- Right to opt-out of sale/sharing (we don't sell, but you can opt-out of any sharing)
- Right to limit use of sensitive personal information
- Right to non-discrimination
- Do Not Sell/Share: Use our Cookie Preference Center or email [email protected]
10.3 GDPR/UK GDPR Rights
- Right to lodge complaints with supervisory authorities
- Right to withdraw consent
- Right not to be subject to automated decision-making
- Right to be informed about processing
10.4 Turkey (KVKK) Rights
- Right to learn whether data is processed
- Right to request information about processing
- Right to request rectification
- Right to apply to the Personal Data Protection Board
10.5 How to Exercise Your Rights
To delete your account: use our Delete Account page.
For all other requests: [email protected]
Response timeline:
- Acknowledgment: Within 24 hours
- Identity verification: 3-5 business days
- Completion: Within 30 days (may extend to 60 days for complex requests)
For urgent privacy matters, please mark your email as "URGENT - PRIVACY RIGHTS"
11. Cookies & Tracking
11.1 Cookie Usage
We use cookies as detailed in our Cookie Policy. Key points:
- Essential cookies: Always active for functionality
- Analytics cookies: Help us understand usage
- Marketing cookies: For relevant advertising (with consent)
11.2 Your Controls
- Cookie Preference Center: www.getslick.ai/cookie-preferences
- Global Privacy Control (GPC): We honor GPC signals where legally required
- Do Not Track: Currently not recognized, but you can manage preferences
- EU/UK Default: Only essential cookies load without consent
12. AI Model Providers & Data Processing
To deliver our AI features, we send relevant conversation content, prompts, and related media to third-party AI model providers (OpenAI, Google Vertex AI, and Anthropic — including Anthropic's Claude models served via Amazon Bedrock (AWS) and, as a fallback for specific model tiers, Microsoft Azure AI Foundry) that process this data to generate responses on our behalf. We share only the data necessary to provide the requested AI functionality. Each of these providers is bound by a data processing agreement requiring data protection safeguards equivalent to those described in this Privacy Policy, prohibiting use of your data for their own purposes (including model training) unless you explicitly opt in, and honoring the retention limits described below.
Provider applicability is scoped by product and plan. Claude-based tenants run on Anthropic via Amazon Bedrock (with Anthropic's direct API and Azure AI Foundry as fallback); OpenAI and Google Vertex AI apply to other products and models. The providers that apply to your deployment are identified in your tenant or contract documentation.
12.1 Model Selection
Customers can select among supported AI model providers and regions for processing. We maintain transparency about:
- Available providers (OpenAI, Google Vertex AI, Anthropic, Amazon Bedrock, Microsoft Azure AI Foundry, etc.)
- Regional endpoints for processing
- Data retention by providers
12.2 Zero-Retention Commitment
We enable zero-retention modes where available:
- OpenAI: Zero retention via API mode
- Anthropic: Zero retention via enterprise API
- Amazon Bedrock (AWS): Transient — not retained, not used for training
- Microsoft Azure AI Foundry: Transient — not retained, not used for training
- Google Vertex AI: 55-day anti-abuse telemetry only
12.3 Opting Out
Customers can opt-out of specific model providers via:
13. Data Security
We implement comprehensive security measures including:
13.1 Technical Safeguards
- Encryption at rest (AES-256 via AWS KMS, HSM-backed) and in transit (TLS 1.2+, TLS 1.3 supported)
- Customer-managed keys (BYOK) available on request; keys rotated on a defined schedule
- Multi-factor authentication for administrative access
- Regular security assessments and penetration testing
13.2 Organizational Safeguards
- Security awareness training
- Access controls and least privilege principles
- Incident response procedures
- Business continuity planning
13.3 Compliance & Certifications
- SOC 2 Type II: In progress (targeted 2026 Q4 / 2027 Q1)
- GDPR/CCPA: Aligned with requirements
- ISO 27001: Roadmap target (2027 Q2)
For detailed security information, see our Security Overview.
14. Children's Privacy
Our Services are not directed to individuals under 16. We do not knowingly collect personal data from children. If we learn of collection from a child, we will promptly delete such information and terminate the account.
15. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting notice on our website
- Sending email to account administrators
- In-app notifications for Individual and Teams users
- Updating the "Last Updated" date
Your continued use after changes constitutes acceptance of the updated policy.
17. Contact Us
For privacy-related questions, requests, or concerns:
Data Protection Officer
Incredible Pods Technologies Ltd
Email: [email protected]
Response Time: Within 48 hours
Address: Unit 02, Level 7, Gate Village Building 10, DIFC, Dubai, UAE
Document Version: 2.1
Internal Reference: PRIV-POL-2025-002