Slashy procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ We conduct independent security testing and can share available documentation with prospective enterprise customers under NDA. Contact us at privacy@slashy.com to request the current materials.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Yes. We provide a DPA for enterprise customers that outlines our data handling obligations. It's available on our DPA page or by contacting privacy@slashy.com .” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ All customer data is stored on encrypted filesystems in PostgreSQL databases, which run on AWS cloud servers in the United States. Here is exactly what we store: Email and calendar data Email metadata (subject lines, sender and recipient, timestamps, labels), email content (message bodies and attachments), and calendar events are stored in our PostgreSQL database. This data remains encrypted until you disconnect your Google account, at which point it is deleted within the timeline below. Access is tightly controlled and used only to provide the services you have chosen.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Within 24 hours Hard delete from production systems (email and calendar data, AI memories, embeddings)” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Agent conversations We store your conversations with the Slashy AI agent to provide context and improve your experience. All conversations are encrypted.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We maintain backup and recovery procedures as part of our security program. Backup retention follows the timelines described in our Privacy Policy and contractual commitments. Enterprise customers can request current recovery documentation during security review.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Data required by law (billing records) may be retained longer. Request immediate deletion at privacy@slashy.com .” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Usage logs We maintain restricted logs for debugging and support. The information they contain is described in our Privacy Policy, and access is limited to team members who need it to provide support.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ You can delete all your data at any time. Upon account disconnection or deletion request, we follow this timeline: Immediate Account access revoked, OAuth tokens invalidated, sync stopped” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Memories The AI agent stores key facts it learns about you, your work patterns, and preferences to provide personalized assistance. All memories are encrypted and can be viewed or deleted at any time.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We use multiple AI providers to optimize for speed, accuracy, and cost. Our agreements require these providers not to retain or train on Slashy customer data:” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Slashy uses the following third party service providers that may process customer data. All subprocessors are bound by data processing agreements and are contractually obligated to maintain appropriate security measures.” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.