Effective date: 2026-09-06
This Data Processing Addendum (“DPA”) describes the obligations of Sleev Labs Inc. (“Sleev”) when processing personal data on Customer’s behalf. It forms part of the agreement governing Customer’s use of Sleev (the “Agreement”) when that agreement incorporates this DPA or the parties otherwise agree in writing.
1. Scope & Roles
1.1 Services. The Sleev gateway runs on Customer-controlled infrastructure and connects to configured upstream endpoints. Sleev also provides hosted account, organization, licensing, and operational services. Details of processing covered by this DPA are set out in Schedule 1.
1.2 Roles. Sleev processes Customer Personal Data on Customer’s behalf and follows Customer’s instructions. Customer must be authorized to give those instructions. Where California privacy law applies, Sleev acts as a service provider or contractor.
1.3 Separate Controller Activities. Sleev acts as an independent controller where it determines the purposes and means of processing for its own customer relationship, invoicing, legal compliance, or protection against fraud and abuse, as described in the Privacy Policy. This distinction depends on the actual processing and does not authorize Sleev to repurpose Customer Personal Data contrary to this DPA.
1.4 Precedence. This DPA prevails over conflicting terms in the Agreement concerning Customer Personal Data. Applicable SCCs and the UK Addendum prevail over conflicting terms in this DPA or the Agreement in accordance with their own precedence provisions.
2. Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement or under Applicable Data Protection Law:
- “Applicable Data Protection Law” means privacy and data protection laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation (“GDPR”), UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection (“FADP”), and California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).
- “Customer Personal Data” means personal data or personal information processed by Sleev on behalf of Customer in providing the services, including data supplied by Customer or collected or generated for Customer through those services.
- “Data Subject”, “Controller”, “Processor”, and “Processing” have the meanings given in the GDPR or equivalent concepts under Applicable Data Protection Law.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed by Sleev.
- “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 for transfers of personal data to third countries.
- “Subprocessor” means a third party engaged by Sleev to process Customer Personal Data on Customer’s behalf.
3. Processing Obligations & Instructions
3.1 Documented Instructions. Sleev shall process Customer Personal Data only on Customer’s documented lawful instructions, including instructions concerning international transfers, unless required by law in a manner permitted by Applicable Data Protection Law. The Agreement, this DPA, and Customer’s use of the agreed service features set out those instructions. Customer may provide additional documented lawful instructions consistent with the agreed services. Sleev shall inform Customer before processing required by law unless that law prohibits notification, and shall immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3.2 Purpose Restrictions. Sleev shall not:
- “Sell” or “share” Customer Personal Data (as those terms are defined under the CCPA/CPRA);
- Retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes of performing the services specified in the Agreement;
- Retain, use, or disclose Customer Personal Data outside the direct business relationship between Sleev and Customer; or
- Combine Customer Personal Data with personal data received from other parties or collected from Sleev’s own interactions with individuals, except as permitted by Applicable Data Protection Law.
3.3 No AI Model Training. Sleev shall not use Customer Personal Data, prompt contents, source code, or operational telemetry to train, retrain, fine-tune, or improve machine learning or artificial intelligence models.
3.4 California Requirements. Where the CCPA/CPRA applies, Sleev shall comply with applicable obligations and provide the same level of privacy protection required by that law. Sleev shall notify Customer if it determines it can no longer meet those obligations. Customer may take reasonable and appropriate steps to verify compliant use of Customer Personal Data and, upon notice, to stop and remediate unauthorized use.
3.5 Customer Responsibilities. Customer is responsible for the lawfulness of its instructions and for providing required notices and obtaining any permissions necessary for the processing it instructs.
4. Confidentiality & Personnel
4.1 Confidentiality. Sleev shall ensure that employees, contractors, and agents authorized to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality.
4.2 Access Control. Sleev shall take reasonable steps to ensure the reliability of personnel who process Customer Personal Data and limit access to individuals who require it to perform their obligations under the Agreement.
5. Security of Processing
5.1 Security Measures. Sleev shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration, or disclosure, as detailed in Schedule 2.
5.2 Review & Updates. Sleev shall regularly assess the effectiveness of its security measures as appropriate to the processing risks. Updates shall not materially reduce the overall protection of Customer Personal Data.
6. Subprocessors
6.1 Authorization. Customer provides general written authorization for Sleev to engage Subprocessors to provide the agreed services. Subprocessors are identified in the Subprocessors Directory.
6.2 Subprocessor Obligations. Sleev shall engage only Subprocessors providing sufficient guarantees of appropriate data protection measures and shall impose the same applicable data protection obligations by written contract for the processing entrusted to them. Sleev remains fully liable to Customer for the performance of each Subprocessor’s obligations.
6.3 Change Notices. Sleev shall provide at least thirty (30) days’ advance notice before a new or replacement Subprocessor begins processing Customer Personal Data. Notice shall be published in the Subprocessors Directory and emailed to all registered users and organization administrators. No separate mailing-list subscription is required.
6.4 Objections. Customer may object in writing to a new Subprocessor on reasonable data protection grounds within thirty (30) days of receiving notice. The parties shall work in good faith to resolve the concern. If they cannot reach a mutually agreeable resolution within thirty (30) days of Customer’s objection, Customer may terminate the affected hosted services without penalty upon written notice.
6.5 Customer-Directed Providers. An upstream provider or endpoint engaged by Customer under Customer’s own account or agreement is not a Subprocessor merely because the local gateway connects to it. Where a provider instead processes Customer Personal Data on Sleev’s behalf, this Section 6 applies.
7. Personal Data Breaches
7.1 Notification. Sleev shall notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach. Notification shall not be delayed until the investigation is complete.
7.2 Details. To the extent known, the notification shall describe:
- The nature of the breach, including categories and approximate numbers of affected Data Subjects and records;
- A contact for further information;
- Likely consequences; and
- Measures taken or proposed to address the breach and mitigate its effects.
7.3 Cooperation & Remediation. Sleev shall take immediate, commercially reasonable steps to contain, mitigate, and remediate the breach and assist Customer with its statutory notification obligations. Information unavailable at the initial notification shall be provided in stages without undue further delay.
8. Data Subject Requests & Regulatory Assistance
8.1 Data Subject Requests. Taking into account the nature of the processing, Sleev shall assist Customer through appropriate technical and organizational measures, insofar as possible, in responding to Data Subjects exercising their rights under Applicable Data Protection Law.
8.2 Requests Received by Sleev. If an individual asks Sleev to exercise their privacy rights concerning Customer Personal Data, Sleev shall promptly notify Customer and respond only as Customer authorizes or the law requires.
8.3 Regulatory Assistance. Taking into account the nature of the processing and the information available to Sleev, Sleev shall assist Customer in meeting its obligations concerning security, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities.
9. Audits
9.1 Information. Sleev shall make available information reasonably necessary to demonstrate compliance with this DPA and applicable processor obligations under Applicable Data Protection Law.
9.2 Audit Rights. Sleev shall allow and contribute to audits and inspections by Customer or its appointed independent auditor, subject to appropriate confidentiality protections. The parties shall use available documentation where it adequately addresses the review. Routine customer audits shall:
- Occur no more than once per twelve (12) months during normal business hours;
- Be requested with at least thirty (30) days’ advance written notice;
- Avoid unreasonable disruption to Sleev’s operations; and
- Be conducted at Customer’s sole expense.
These routine conditions shall not prevent or delay audits required by law, a competent supervisory authority, or applicable SCCs, including where there are indications of non-compliance. In those circumstances, notice and scope shall be appropriate to the circumstances and mandatory requirements shall prevail.
10. Return & Deletion
When the Agreement ends or Customer requests in writing, Sleev shall, at Customer’s choice, return or delete Customer Personal Data held by Sleev or its Subprocessors and delete remaining copies within thirty (30) days, unless applicable law requires retention. Any legally required retention is limited to that purpose and lasts only as long as required. Diagnostic uploads remain subject to the shorter retention period in Schedule 1.
11. International Transfers
11.1 When This Applies. These provisions apply when European Economic Area (“EEA”), UK, or Swiss law requires safeguards for an international transfer of Customer Personal Data and no applicable adequacy decision covers it. Before the transfer, the parties shall complete the details in Schedule 1 and assess any additional safeguards required by Applicable Data Protection Law.
11.2 EU SCCs:
- The EU SCCs in Decision (EU) 2021/914 are incorporated by reference: Module Two where Customer is a controller, and Module Three where Customer is a processor. Customer is the data exporter and Sleev is the data importer.
- Options: Clause 7 does not apply. Clause 9(a), Option 2 applies with the thirty-day notice period in Section 6.3. The optional language in Clause 11 is omitted.
- Law & Courts: Irish law and courts apply under Clauses 17 and 18(b).
- Transfer Details: Annex I uses Schedule 1 and the Agreement or written transfer supplement. The supervisory authority is determined under Clause 13. Annex II uses Schedule 2 and any additional agreed security measures.
11.3 UK Addendum:
- For UK transfers covered by Section 11.1, the ICO UK Addendum applies to the SCCs in Section 11.2.
- Table 1 uses the parties, contacts, start date, and acceptance in the Agreement or transfer supplement. Tables 2 and 3 use the SCC selections and annex information in Section 11.2, respectively. Table 4 permits both parties to exercise the rights in Section 19 of the UK Addendum.
- The following is incorporated by reference: Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
11.4 Swiss Transfers. Where Swiss FADP applies, GDPR references include that law, and the Swiss Federal Data Protection and Information Commissioner supervises the Swiss-law aspects of the transfer. References to EU Member States include Switzerland for Data Subjects’ rights to bring claims where they habitually reside. Any separately applicable GDPR protections and supervisory authority remain unaffected.
Schedule 1: Details of Processing
A. Parties & Roles
- Customer: The entity identified in the Agreement, acting as controller or processor for the relevant data.
- Sleev Labs Inc.: Service provider acting as processor or subprocessor for Customer Personal Data.
- Transfer Details: Where Section 11 applies, the Agreement or a written transfer supplement shall identify both parties’ legal names, addresses, contact persons and contact details, relevant activities and roles, acceptance dates and signatures (which may be electronic), processing locations, and the competent supervisory authority determined under SCC Clause 13. These details shall be completed before the restricted transfer begins. Sleev’s privacy contact is
support@sleev.ai.
B. Categories of Data Subjects
- Customer’s authorized users, employees, contractors, developers, and team administrators.
- Individuals whose personal data is included in support communications or diagnostic material processed under this DPA.
C. Types of Personal Data
- Identity & Contact Data: Names, business email addresses, user identifiers.
- Account & Organization Data: Organization names, assigned roles, memberships, and installation or license identifiers.
- Usage & Operational Data: Account-linked usage, technical, and security data generated through the services.
- Support & Diagnostic Data: Personal data in support communications or diagnostic material voluntarily submitted by Customer’s users.
D. Special Categories of Data
The services do not require special-category data. Customer shall agree appropriate safeguards with Sleev before instructing such processing. If such data is incidentally included in submitted material, it remains protected under this DPA, with access and use limited to the agreed purpose.
E. Purpose, Nature & Frequency
- Collection, transmission, storage, retrieval, analysis, and deletion as needed to provide Customer’s account access, organization and license administration, usage accounting, service security, and technical support under the Agreement.
- Processing and transfers occur on an ongoing basis during use of the services; support and diagnostic submissions are voluntarily initiated by Customer’s users. Subprocessors process data for their listed service functions for as long as needed to provide them, subject to the retention limits below.
F. Retention
Customer Personal Data is retained as needed to provide the agreed services during the Agreement and is subject to deletion or return under Section 10. Diagnostic uploads are retained for no longer than seven (7) days.
Schedule 2: Technical & Organizational Measures
The following measures apply to the services. Additional customer-specific measures shall be recorded in the Agreement where applicable.
- Deployment Boundary: The gateway runs on Customer-controlled infrastructure and defaults to a loopback listen address. Customer manages its endpoint security, local storage protection, and any network-reachable deployment.
- Encryption: The hosted control-plane API uses HTTPS. Managed Google Cloud SQL databases and Google Cloud Storage use encryption at rest. Registered remote model-provider endpoints use HTTPS/WSS; transport and access protection for custom endpoints are Customer-managed.
- Service Access: Access to customer account and organization data requires authentication and authorization. Organization access is checked against membership and role permissions. Personnel access is subject to the confidentiality and access restrictions in Section 4.
- Software Checks: Development workflows include automated linting, type checking, and tests. Sleev shall assess and address security vulnerabilities in the services as appropriate to the risk.
- Incident Handling: Security reports may be sent to
support@sleev.ai. Sleev shall investigate Personal Data Breaches and provide notification and assistance under Sections 7 and 8. - Data Lifecycle: Diagnostic uploads are voluntarily initiated by users. Managed diagnostic logging includes content-redaction measures, and periodic automated cleanup is configured. The retention and deletion obligations in Schedule 1 and Section 10 apply.
Contact
Sleev Labs Inc.
Email: support@sleev.ai