1.Who we are
1.1Slate OS is a trading name of Slate Systems Ltd, registered in England and Wales under company number 17243517, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
1.2For the purposes of UK data protection law, Slate Systems Ltd is the data controller in respect of the processing described in clause 5, and a data processor in respect of the processing described in clause 6.
1.3You can contact us about privacy at privacy@slateos.co.uk. We have not appointed a statutory Data Protection Officer, as we are not required to.
2.Our two roles — this distinction matters
The short version
Your data: we are the controller. We decide what to do with your account, billing and usage information, and this policy explains it.
Your customers' data: you are the controller and we are your processor. We hold and move it on your instruction. What you may do with it is governed by your own privacy notice, not this one.
2.1If you are a customer of one of our customers and you want to know why a tradesperson holds your details, contact that business directly. They decide what data to collect and why. We can pass your request to them but we cannot answer for them.
2.2Our obligations as a processor are set out in Schedule 1 of the Terms of Service, which forms our Article 28 data processing agreement.
3.What we collect about you
| Category | Fields |
|---|---|
| Identity and contact | First and last name, email address, mobile and business telephone numbers, profile image, and the business telephone number provisioned for you. |
| Business profile | Company name, trading name, business type (limited company or sole trader), company registration number or Unique Taxpayer Reference, trade or niche, team size, fleet size, business address, website, business email, logo and banner images. |
| Financial and billing | Subscription tier and cycle, billing status, renewal date, payment card identifiers held by our payment processor (we never see or store full card numbers), invoice history, and the wallet balance, transaction ledger and lifetime usage counters. |
| Bank details you choose to enter | Account holder name, sort code and account number, stored solely so they can be printed on invoices and quotes you generate. We do not initiate payments from them and we do not verify them. |
| Credentials and connections | Encrypted access and refresh tokens for platforms you connect, identifiers for your workspace on our communications platform, and where you choose to supply them, your own payment provider API keys held in encrypted form. |
| Configuration and preferences | Message templates, document settings, cost rates, auto top-up thresholds, do-not-disturb hours, review platform links, competitor website addresses you enter, onboarding progress and tutorial state. |
| Usage and technical | Log records of requests to our systems, IP address, device and browser information, timestamps, error reports, feature usage, and identifiers used for rate limiting and abuse prevention. |
| Support and feedback | Support tickets, feature requests, and correspondence with us. |
| Marketing enquiries | If you request a demonstration, the name and mobile number you submit, and the time of the request. |
| Administrative records | Audit logs of administrative actions taken on your account by our staff, and records evidencing any erasure we have carried out. |
Please do not store what you do not need
The Service is not designed to hold special category data (health, ethnicity, religion, biometrics, sexual orientation, trade union membership, political opinions) or criminal offence data, and our Terms prohibit submitting it. Free-text fields such as job notes are not monitored, so please keep them to what is necessary for the work.
4.Where we get it from
- Directly from you — at registration, during onboarding, and whenever you use the Service.
- Automatically — through your use of the Service, including logs and technical identifiers.
- From our payment processor — subscription status, payment outcomes and card metadata.
- From platforms you connect — where you authorise a connection, we receive identifiers and the data necessary to operate the integration.
- From your inbound channels — where you configure email forwarding for enquiry capture, we receive the forwarded messages.
- From public sources — where you supply a competitor or review platform address, we may retrieve publicly available information about it.
5.Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating your account, authenticating you and providing the Service | Performance of a contract |
| Taking subscription payments, managing renewals, dunning and refunds | Performance of a contract |
| Operating the messaging wallet, metering usage and applying plan allowances | Performance of a contract |
| Despatching messages, generating documents and running automations you configure | Performance of a contract |
| Providing support and responding to your enquiries | Performance of a contract; legitimate interests in running a support function |
| Securing the platform, preventing fraud and abuse, rate limiting, and investigating incidents | Legitimate interests in protecting our service, our customers and third parties |
| Maintaining audit logs of administrative actions | Legitimate interests in accountability and security; legal obligation |
| Understanding how the product is used in order to improve it | Legitimate interests in developing our service |
| Sending service and administrative messages about your account | Performance of a contract |
| Sending you marketing about our own products | Legitimate interests where you are an existing customer and the soft opt-in applies; otherwise consent |
| Responding to a demonstration request you submitted | Consent, given when you submit the form |
| Keeping financial and tax records | Legal obligation (Companies Act 2006, VAT and tax legislation) |
| Establishing, exercising or defending legal claims, and responding to regulators | Legitimate interests; legal obligation |
5.1Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your rights. You may object at any time — see clause 15.
5.2Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.
6.Your customers’ data
6.1When you use the Service you enter details about your own customers and prospects — names, telephone numbers, email addresses, job addresses and postcodes, service descriptions, appointment times, quotation and invoice values, message history, review responses and any notes you record.
6.2We process that information solely on your instruction, to provide the Service to you. We do not use it for our own purposes, we do not sell it, we do not share it with other customers, and we do not use it to train AI models.
6.3Access is scoped to your account. Every request is authorised server-side and every record is checked against its owning account before it is returned.
6.4A small number of our staff can access customer accounts for support, incident investigation and account administration. Administrative actions are recorded in an audit log.
6.5Some fields are configurable as to whether they are visible to your End Customer — for example job notes. You are responsible for setting those correctly.
7.Messaging, calls and call recording
7.1Messages and calls are delivered through a third-party communications platform and onward through mobile network operators. Message content, recipient numbers, delivery status and timestamps are processed by those providers to deliver the communication.
7.2We retain metadata about each message — recipient, direction, channel, segment count, cost and timestamp — for billing, dispute resolution and abuse prevention. Message content is retained within your account so that you can see the conversation.
7.3Where call recording is available and you enable it, you are responsible for notifying callers and for establishing a lawful basis for recording. We do not enable recording by default.
7.4Missed-call text-back operates automatically when enabled. The reply is sent in your name from your number. See clause 8 of the Terms of Service for your responsibilities as sender.
8.AI processing and automated decisions
8.1Some analytical features send a structured summary of your business information to a third-party AI provider in order to generate written analysis and recommendations. That summary can include aggregate financial figures, job and quotation statistics, postcode-level performance, review platform presence, and competitor website addresses you have entered.
8.2We instruct our AI provider under terms that prohibit the use of submitted data to train general-purpose foundation models, and we use enterprise endpoints configured for zero data retention where the provider offers them.
8.3We do not send your End Customers' names, telephone numbers or email addresses to AI providers for analytical features. Where an AI feature operates on a record you have selected, only the fields necessary for that feature are transmitted.
AI output is not fact
Analysis produced by AI features is generated automatically and can be wrong. It does not produce any legal effect and is not used to make decisions about you. It is informational only — see clause 11 of the Terms of Service.
8.4We do not carry out automated decision-making producing legal or similarly significant effects concerning you within the meaning of Article 22 of the UK GDPR. Automated controls that suspend messaging on an empty wallet, or apply rate limits, are contractual and operational rather than evaluative, and can be reviewed by contacting us.
10.Sub-processors
The following third parties process personal data on our behalf. We give at least 30 days' notice before adding or replacing a sub-processor, as set out in Schedule 1 of the Terms.
| Provider | Function | Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting, edge network, and file storage for uploaded documents and images | All data in transit; uploaded files at rest | USA / global edge |
| Neon Inc. | Managed PostgreSQL database — the primary record store | All account and Customer Data | EU / USA |
| Clerk Inc. | Authentication, session management and user identity | Name, email, telephone, profile image, session and device data | USA |
| Stripe, Inc. / Stripe Payments Europe Ltd | Subscription billing, wallet top-ups, and card payments taken by you from your customers | Billing contact details, payment card metadata, transaction records | Ireland / USA |
| HighLevel Inc. (LeadConnector) | Communications platform: telephony, SMS and email delivery, contact and conversation records | Contact details and message content for you and your End Customers | USA |
| Upstash Inc. | Redis cache for connection tokens, and QStash for scheduling timed messages | Encrypted tokens, scheduled job payloads and identifiers | EU / USA |
| Google LLC (Gemini API) | AI analysis features | Aggregated business metrics and configuration; no End Customer contact details | USA / EU |
| Svix Inc. | Webhook signature verification for identity events | Webhook payload metadata | USA |
| Ideal Postcodes / postcodes.io | Postcode lookup and geocoding for job addresses | Postcode only | United Kingdom |
| OpenStreetMap Foundation | Map tiles for the coverage and heat map views | Approximate coordinates requested by the browser; no identity data | EU / UK |
10.1Where a provider is also an independent controller for its own purposes — notably Stripe for payment processing and fraud prevention, and Clerk for identity security — that processing is governed by their own privacy notices.
11.International transfers
11.1Several of our sub-processors are located in, or transfer data to, the United States. Personal data is therefore transferred outside the United Kingdom.
11.2Where we transfer personal data outside the UK, we rely on one or more of:
- UK adequacy regulations, including the UK Extension to the EU–US Data Privacy Framework;
- the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner;
- the International Data Transfer Agreement, where an addendum is not appropriate.
11.3We carry out a transfer risk assessment for each restricted transfer and apply supplementary measures where appropriate, including encryption in transit and at rest.
11.4You may request a copy of the relevant safeguard by writing to privacy@slateos.co.uk. We may redact commercially confidential terms.
12.How long we keep it
| Data | Retention period | Reason |
|---|---|---|
| Account and profile data | For the life of the account, then deleted within 30 days of termination | Contract performance |
| Customer Data (your customers’ records) | Available for export for 30 days after termination, then deleted from production; residual backup copies removed within 90 days | Contract performance; your instruction |
| Financial records — invoices, wallet ledger, payment records | 7 years from the end of the relevant accounting period | Companies Act 2006, VAT and tax legislation |
| Message and call metadata | 24 months | Billing, dispute resolution and abuse prevention |
| Message content held in your account | Life of the account, then deleted with Customer Data | Contract performance |
| Security and application logs | 90 days, or longer where an incident is under investigation | Security and incident response |
| Administrative audit logs | 6 years | Accountability and defence of legal claims |
| Erasure records (evidence that a deletion took place) | 6 years — the record itself contains identifiers only, not the erased content | Demonstrating compliance under Article 5(2) |
| Support tickets and correspondence | 3 years from closure | Service quality and defence of claims |
| Demonstration requests that do not become customers | 12 months from the request | Legitimate interests; consent |
| Marketing suppression list (people who opted out) | Indefinitely | To ensure we continue to honour the opt-out |
12.1Where data is no longer needed but full deletion is impractical — for example within a rolling backup — we isolate it and delete it when the cycle completes.
13.How we protect it
Our current technical and organisational measures include:
- encryption of all data in transit using TLS, with HTTP Strict Transport Security enforced;
- encryption at rest at the database and object storage layer;
- application-layer encryption of specified high-sensitivity credentials, including integration refresh tokens and stored payment provider keys, using authenticated encryption;
- server-side authorisation on every request, with ownership checks that scope every record to its account;
- role-based administrative access, with privileged actions recorded in an audit log;
- cryptographic signature verification on all inbound webhooks, and signed, expiring links for any document shared with an End Customer;
- rate limiting, a content security policy, and standard hardening headers including frame-ancestor and content-type protections;
- idempotency controls and an append-only double-entry ledger on all financial operations, with nightly reconciliation;
- a documented erasure process that removes data across every system and records evidence that it did so;
- least-privilege access for staff, and confidentiality obligations in staff contracts.
An honest word on security
No system is perfectly secure, and we do not claim to be. We describe the measures we actually operate rather than a certification we do not hold. We are not currently certified to ISO 27001 or SOC 2. If that matters to your procurement process, tell us and we will be straight with you about where we are.
15.Your rights
Under the UK GDPR you have the right to:
- Be informed — which is the purpose of this policy;
- Access — obtain a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected;
- Erasure — have data deleted where there is no overriding reason to keep it;
- Restriction — limit how we use your data while a matter is resolved;
- Portability — receive data you gave us in a structured, machine-readable format;
- Object — object to processing based on legitimate interests, and to direct marketing at any time and without qualification;
- Withdraw consent — where processing is based on consent.
15.1To exercise a right, write to privacy@slateos.co.uk. We will respond within one month, which we may extend by two further months for complex requests, telling you if we do.
15.2We may ask you to verify your identity before we act, to make sure we do not disclose data to the wrong person.
15.3There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it, explaining why.
15.4If your request concerns data held by one of our customers about you as their customer, we will forward it to them, as they are the controller.
16.Data breaches
16.1We maintain an incident response process. Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner within 72 hours of becoming aware of it.
16.2Where a breach is likely to result in a high risk to you, we will notify you without undue delay.
16.3Where a breach affects Customer Data for which you are the controller, we will notify you without undue delay with the information available to us, so that you can meet your own obligations.
16.4If you believe you have found a security vulnerability, please report it to security@slateos.co.uk. We will not pursue action against researchers who report in good faith and do not access, modify or exfiltrate data beyond what is necessary to demonstrate the issue.
17.Children
17.1The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a user of the Service.
17.2If you become aware that a child's data has been entered into the Service, tell us and we will delete it.
18.Complaints
18.1If you are unhappy with how we have handled your personal data, please tell us first at privacy@slateos.co.uk so we can try to put it right.
18.2You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113; ico.org.uk.
19.Changes to this policy
19.1We may update this policy. The version number and effective date at the top of this page show when it last changed.
19.2Where a change is material — for example a new purpose, a new lawful basis, or a new category of recipient — we will notify you by email or in-product notice before it takes effect.
19.3We keep previous versions and will supply one on request.
Questions about this document? Write to legal@slateos.co.uk, or by post to Slate Systems Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.