Data Processing Agreement

Effective date: September 18, 2026
Looking for technical details about our security and architecture? See our Security & Architecture FAQ →

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service (“Principal Agreement”) between:

You (the “Company” or “Controller”) and Karvix Inc. (doing business as Slashy) (the “Processor”), together the “Parties”.

WHEREAS: (A) the Company acts as a Data Controller. (B) The Company wishes to use Services provided by the Processor, which involve the processing of personal data. (C) The Parties seek to implement a data processing agreement that complies with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable U.S. state privacy laws. It is agreed as follows.

1. Definitions

1.1 “Company Personal Data” means any Personal Data processed by Processor on behalf of Company pursuant to the Principal Agreement.

1.2 “Data Protection Laws” means the GDPR and, to the extent applicable, U.S. state privacy laws including the California Consumer Privacy Act.

1.3 “Subprocessor” means any third party appointed by Processor to process Personal Data on behalf of the Company.

1.4 The terms “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the same meaning as in the GDPR.

2. Processing of Company Personal Data

2.1 Processor shall:

(a) comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and

(b) not Process Company Personal Data other than on the Company's documented instructions, unless required by law.

2.2 The Company instructs Processor to process Company Personal Data to provide the Services, including email, calendar, and video meeting services, customer-enabled third-party integrations, and customer-configured external tools or MCP servers. The Company's configuration and use of a connection constitutes a documented instruction for Processor to access, retrieve, transmit, create, or modify data through that connection as requested or configured through the Services. This Agreement applies to Processor's processing for those connections without a separate Slashy data processing addendum for each connection.

2.3 Processor shall not sell or share Company Personal Data for advertising or marketing purposes.

2.4 The subject matter of the Processing is Company Personal Data made available through the Services and connections the Company enables. Processing lasts for the term of the Services and the deletion period in Section 9. Its nature and purpose are to access, store, retrieve, analyze, transmit, create, or modify data to provide requested features and configured workflows. The types of Personal Data depend on the Company's use of the Services and may include account and contact details, communications, calendar information, files, documents, records, metadata, and other content the Company makes available. Data Subjects may include the Company's users, employees, contacts, correspondents, and other individuals represented in that content.

3. Processor personnel

Processor shall ensure that persons authorized to process Company Personal Data are subject to confidentiality obligations and that access is limited to those who need it to perform the Services.

4. Security

4.1 Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

(a) encryption of Personal Data at rest and in transit;

(b) access controls and authentication measures; and

(c) regular testing and assessment of security measures.

4.2 Processor maintains SOC 2 Type II compliance.

5. Subprocessing

5.1 Company authorizes Processor to engage Subprocessors. A current list of Subprocessors is available on our Security page.

6. Data subject rights

6.1 Processor shall promptly notify Company if it receives a request from a Data Subject and shall not respond except as instructed by Company or required by law.

6.2 Processor shall assist Company in responding to Data Subject requests, taking into account the nature of the Processing.

7. Personal Data Breach

7.1 Processor shall notify Company without undue delay upon becoming aware of a Personal Data Breach affecting Company Personal Data.

7.2 Processor shall cooperate with Company and take reasonable steps to assist in the investigation and remediation of each such breach.

8. Data transfers

8.1 Company Personal Data may be transferred to and processed in the United States.

8.2 For transfers of Personal Data from the EEA, the Parties agree to rely on the EU Standard Contractual Clauses as the transfer mechanism.

9. Deletion of Company Personal Data

Upon termination of the Services, Processor shall delete all Company Personal Data within 24 hours, unless retention is required by law. Backup copies shall be deleted within 7 days (up to 14 days during active incident investigations).

10. General terms

10.1 This Agreement is governed by the laws of the State of Delaware, USA.

10.2 This Agreement shall remain in effect for as long as Processor processes Company Personal Data.

10.3 In the event of any conflict between this Agreement and the Principal Agreement with respect to data protection, this Agreement shall prevail.

Contact

For questions about this Agreement or to request security documentation, contact us at: