← All Documents
Legal · Document 04
Revision 2026.08 · Confidential
Data Protection & Pricing Privacy
Data
Processing
Agreement.
SlabOS processes Customer Data only on Customer's instructions, with tenant isolation, encryption, audit logging, and absolute pricing confidentiality. PIPEDA-compliant for Canadian customers. Standard Contractual Clauses where applicable.
Roles
Customer is Controller, SlabOS is Processor
Companion
Master Subscription Agreement
Annexes
A. Security Measures · B. Subprocessors
Regulatory Scope
US, Canada (PIPEDA), CCPA

Binding legal agreement between the parties, incorporated into the Master Subscription Agreement. Accepted by electronic signature under the U.S. ESIGN Act and UETA; acceptance is server-stamped by date, time, and IP address. Confidential & proprietary to SlabOS LLC

SLBOS-LEGAL-04

1.Parties and Scope

This Data Processing Agreement (“DPA”) supplements the Master Subscription Agreement (“MSA”) between SlabOS LLC (“Processor”) and Customer (“Controller”). It governs Processor's processing of Personal Information on Controller's behalf in connection with the Service. In any conflict between the MSA and this DPA, this DPA prevails for personal-information matters.

2.Definitions

Applicable Data Protection Laws means all laws applicable to processing of personal information, including the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”), the California Consumer Privacy Act (“CCPA”), and analogous US state and Canadian provincial laws.

Personal Information means information relating to an identified or identifiable individual, processed by Processor on Controller's behalf.

Processing has the meaning given in Applicable Data Protection Laws.

Data Subject means the individual to whom Personal Information relates.

Subprocessor means any third party engaged by Processor to process Personal Information.

Personal Data Breach means a confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information.

3.Subject Matter and Duration

Processing is limited to that necessary to provide the Service to Controller under the MSA. This DPA is coterminous with the MSA; obligations relating to deletion, audits, and survival continue thereafter as expressly stated.

4.Nature and Purpose of Processing

Processor stores, transmits, displays, backs up, and analyzes Controller's Personal Information solely to provide the Service to Controller, including: rendering the application UI, generating AI-assisted outputs requested by Controller, calculating analytics for Controller's tenant, and producing reports.

5.Categories of Data Subjects & Personal Information

Data Subjects: Controller's employees, contractors, customers, end-clients, leads, and other contacts whose information Controller submits to the Service.

Categories of Personal Information: Names, business and personal addresses, phone numbers, email addresses, business contact details, job-related notes, signed contract metadata, and payment-adjacent information (no full card numbers are stored by Processor — payments route to third-party processors).

6.Processor Obligations

6.1 · Documented instructions

Processor processes Personal Information only on Controller's documented instructions, as set out in the MSA, this DPA, and Controller's use of the Service. Processor will inform Controller if instructions appear to violate Applicable Data Protection Laws.

6.2 · Personnel confidentiality

Processor ensures that personnel with access to Personal Information are bound by written confidentiality obligations and have received appropriate training.

6.3 · Security measures

Processor implements and maintains the technical and organizational measures set out in Annex A.

6.4 · Pricing & commercial-data protection

Processor commits that Controller's price lists, customer-specific pricing rules, margin data, supplier discounts, and any related commercially-sensitive information will never be:

Tenant isolation is enforced at every layer of the Service (row-level scoping, application-level authorization, audit logging, and infrastructure separation). Any aggregate, anonymized industry benchmarks derived from many customers will be calculated only in a form that cannot identify Controller or reconstruct specific rates.

7.Subprocessors

7.1 · Approved list

Controller authorizes Processor to engage the subprocessors listed in Annex B. Processor remains liable for subprocessors' compliance with this DPA.

7.2 · New subprocessors

Processor will give Controller at least thirty (30) days advance notice of any new subprocessor. Controller may object in writing within that period on reasonable grounds related to data protection, in which case Processor will either remediate or allow Controller to terminate the affected portion of the Service without penalty.

7.3 · Written agreements

Processor will impose data-protection terms on each subprocessor at least as protective as those in this DPA.

8.Data Subject Rights

Taking into account the nature of the processing, Processor will assist Controller, by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise rights under Applicable Data Protection Laws (access, correction, deletion, restriction, portability, objection). Processor will route any direct requests from Data Subjects to Controller without responding (except to confirm receipt).

9.Personal Data Breach Notification

Processor will notify Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Controller's Personal Information. The notification will include, to the extent known: nature of the breach, categories and approximate number of Data Subjects and records, likely consequences, and measures taken or proposed.

10.Cross-Border Transfers

Personal Information is hosted in North America (United States and Canada). For any transfer outside North America, Processor will implement Standard Contractual Clauses or equivalent safeguards. Controller acknowledges that subprocessors may operate globally; Processor will ensure appropriate safeguards are in place per Annex B.

11.Return or Deletion of Personal Information

Upon termination of the MSA or on Controller's written request at any time during the term, Processor will, at Controller's election, return Personal Information to Controller in JSON or CSV format or delete it. Deletion will be complete across production and backup systems within sixty (60) days, except where retention is required by law. Processor will certify deletion in writing on Controller's request.

12.Audits

Once per twelve (12) month period, on at least thirty (30) days written notice, at a mutually convenient time, and at Controller's expense, Processor will make available to Controller information necessary to demonstrate compliance with this DPA. Processor's then-current SOC 2 Type II report (when available) satisfies this obligation in lieu of an on-site audit.

13.PIPEDA-Specific Provisions (Canadian Customers)

13.1 · Comparable protection

Processor provides a level of protection for Personal Information comparable to that required under PIPEDA, including the ten fair-information principles.

13.2 · OPC notification

For Personal Data Breaches involving Canadian Data Subjects that pose a real risk of significant harm, Processor will cooperate with Controller in providing notification to the Office of the Privacy Commissioner of Canada (“OPC”) and affected Data Subjects, and in keeping the records required by PIPEDA.

13.3 · OPC investigations

Processor will reasonably cooperate with the OPC in any investigation or audit relating to Controller's Personal Information processed by Processor.

14.Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability in the MSA, except that the carveouts for breach of confidentiality (including pricing privacy under Section 6.4) and gross negligence in the MSA apply equally here.

15.General

This DPA is governed by the law specified in the MSA. Where Applicable Data Protection Laws impose stricter requirements than this DPA, those laws control. Capitalized terms not defined here have the meanings given in the MSA. This DPA may be executed in counterparts and via electronic signature.

Annex A · Technical and Organizational Measures

Processor implements the following measures, reviewed and updated regularly:

Encryption

Access controls

Logging and monitoring

Backup and recovery

Vulnerability management

Incident response

Personnel

Annex B · Approved Subprocessors

The following subprocessors are authorized to process Personal Information on Processor's behalf as of the effective date:

Customer Data scope: Each subprocessor receives the minimum data necessary for its function. AI providers receive only the specific prompt context required to fulfill an assistant request, scoped to Controller's tenant. Subprocessors do not receive Controller's pricing or commercial data unless strictly necessary to render the requested feature, and never for training their own models.
Signatures
SlabOS LLC (Processor)
Signature

Name: ____________________________
Title: Co-Founder
Date: _____________________________

Customer (Controller)
Authorized Signature

Name: ____________________________
Title: ___________________________
Company: _________________________
Date: _____________________________