What this covers
This agreement applies between Personade and you, the customer who subscribes to Personade for Slack. You are the controller of your employees' personal data. We are your processor.
Personade for Slack reads your Slack workspace so it can send your people a video from your leader on their first day, their birthday and their work anniversary. To do that, we handle personal data about your employees.
It forms part of our Terms of Service and applies automatically when you install Personade for Slack. There is nothing for you to sign. If your legal or privacy team needs a copy, this page is it, and you are welcome to send them the link.
This agreement covers Personade for Slack. Our credits product, where you record videos for your own leads, is covered by the Terms of Service and the Privacy Policy instead.
Words we use
- Personal data means information about a living person.
- Processing means anything done with it, including storing, sending and deleting.
- Controllermeans whoever decides why and how data is used. For your employees' data, that is you.
- Processormeans whoever does the work on the controller's instructions. That is us.
- Subprocessor means a company we use to help us do it.
- Data protection law means the UK GDPR, the EU GDPR, and any other privacy law that applies to you or to us.
Who is responsible for what
You are the controller.Your employees' data is yours. You are responsible for having a lawful reason to use it this way, and for telling your staff that Personade is in use. We cannot do either of those for you.
We are the processor.We use your employees' data only to run the service for you. We do not use it to train models, to build a product, to market to anyone, or for any purpose of our own. We do not sell personal data and we never will.
If we ever have to process your data for our own reasons, for example to comply with a law, we become a controller for that narrow purpose and we will tell you.
Your instructions
Installing the app, configuring it, and using it is your instruction to us. Annex 1 records what that instruction covers.
If we believe an instruction breaks data protection law, we will tell you, and we may pause rather than carry it out.
What we will not do
We will not remove or override an employee's opt-out because you asked us to. An opt-out belongs to the person, not to their employer. Once someone opts out it is permanent, and no administrator can put them back in.
We will not add someone back into a paid seat count after they have opted out. This is also in our Terms of Service and it is not negotiable.
Confidentiality
Only the people who need access in order to run the service have it, and each of them is authenticated individually. Everyone with access is under a duty of confidence that continues after they leave.
We do not disclose your data to anyone else except as set out in Annex 3, or where the law requires it. Where the law requires it we will tell you, unless we are forbidden from doing so.
Security
We keep appropriate technical and organisational measures in place, listed in Annex 2. Security changes over time, so we may improve those measures, but we will not reduce the overall level of protection.
Subprocessors
You agree that we may use the subprocessors described in Annex 3. Each one is under a written contract with data protection terms at least as strict as these. If a subprocessor fails, that is our responsibility to you, not theirs.
If we want to add or replace one, we will update Annex 3 and tell customers at least 30 days beforehand. If you reasonably object on data protection grounds within those 30 days, we will try to find a way around it. If we cannot, you may cancel the affected part of the service and we will refund the unused portion of what you have paid.
When an employee asks about their data
Your employees may ask to see their data, correct it, delete it, or object to it being used. Those requests belong to you, because you are the controller.
If one reaches us by mistake we will not answer it. We will pass it to you without undue delay and help you answer it.
There is one thing an employee can always do without going through you: opt out, themselves, in one click. That stops everything immediately and permanently.
If something goes wrong
If we discover a personal data breach affecting your data, we will tell you without undue delay and in any case within 48 hours of becoming aware of it.
We will tell you what happened, which categories of data and roughly how many people are affected, the likely consequences, and what we are doing about it. If we do not have all of that at first, we will send what we have and follow up.
We will not notify your regulator or your employees on your behalf. That decision is yours, and your own reporting deadline runs from when we tell you.
Deletion
When your subscription ends we delete your employees' personal data within 90 days, including from backups on their normal rotation.
If you ask us to delete it sooner, or to send it back to you first, we will do that within 30 days of the request. We keep only what a law requires us to keep, and only for as long as that law requires.
Records and audits
We keep records of what we process for you and will make them available on request.
If your regulator requires an audit, or you have a genuine reason to believe these terms are not being met, we will cooperate with a reasonable audit. Once a year unless the law or an incident requires more, at reasonable notice, during working hours, and without disrupting other customers. Each side covers its own costs.
Sending data outside the UK and EU
Some of our subprocessors are outside the UK and the EEA, including in the United States. Annex 3 says which categories that applies to.
Where we transfer your employees' data out of the UK or the EEA, we rely on the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum. Those clauses are incorporated into this agreement, with Personade acting as data exporter or importer as the case requires, and this agreement supplying the details their annexes call for.
Liability
Each side's liability under this agreement is subject to the limits in our Terms of Service.
How long this lasts
This agreement applies for as long as we process your employees' data. The obligations that should outlive it do, including confidentiality and deletion.
If documents disagree
If this agreement and our Terms of Service conflict on anything about personal data, this agreement wins.
Annex 1. What we process
Why: to create and deliver personalised celebration videos in your Slack workspace, on your instruction.
Whose data: the people in your Slack workspace, and the person who records the videos.
What we handle:
- Slack user ID, display name and first name
- Profile photo
- Timezone
- Start date from the standard Slack profile field, used for work anniversaries
- Date of birth, only where someone in your team enters it. Slack has no birthday field, so this is typed in or left blank.
- Whether the person is included, excluded by an administrator, or has opted out
- The video recording made by your leader, and the voice model built from it with their consent
- The rendered videos, each containing one person's spoken name
- Delivery records: what was sent, to whom, and when
What we do not handle: the contents of any Slack message, in any channel, public or private. The app holds no permission to read messages and does not request one.
Special category data:none is required. If your team chooses to enter a full date of birth, that is ordinary personal data. The voice model built from your leader's recording is their personal data, created with their consent, and is used only to speak names in their own videos. It is never used to identify anyone.
How long: for the life of your subscription, then as set out above under Deletion.
Annex 2. Security measures
- Encryption in transit using TLS on every connection.
- Encryption at rest for the database and for stored video.
- Access to production data is limited to the people who need it, and is authenticated individually.
- Slack tokens and other credentials are encrypted at rest and are never sent to a browser.
- We request the narrowest Slack permissions the product can work with, and none that read messages.
- Rendered videos are served from unguessable URLs and are deleted with the rest of your data.
- Changes to production are reviewed before release.
- Backups are encrypted and are covered by the deletion terms above.
- Everyone working on Personade is under written confidentiality obligations.
We do not currently hold SOC 2 or ISO 27001 certification. We would rather say so plainly than imply otherwise, and we will update this page if that changes.
Annex 3. Subprocessors
We use a small number of subprocessors to run the service, covering:
- the Slack workspace itself, which is the source of the roster
- application hosting
- database
- file and video storage
- voice model creation, which receives each recipient's first name in order to speak it
- video rendering, which receives the finished video containing that name
- transactional email and subscription billing, neither of which receives any employee data
Some of these are in the United States. No subprocessor receives more about an employee than is listed in Annex 1, and the two that handle the name and the video receive nothing else about the person: no surname, no email address, no dates.
The current named list, including each one's role and location, is available on request. Email privacy@personade.com and we will send it. We provide it to customers and to their data protection advisers, and we ask that it is not published.
Each subprocessor is under a written contract with data protection terms at least as strict as these. If we add or replace one, we will tell customers at least 30 days beforehand, and you have the right to object as set out above.
