Still loading…

This usually means a new version was just released. Reloading picks it up.

SlipperySign Back to sign-in

Data Processing Agreement

SlipperySign Mail · Version 1.0 · Effective 6 August 2026

These terms govern SlipperySign’s processing of personal data on your organisation’s behalf, as required by Article 28 of the GDPR and Article 9 of the Swiss FADP. They form part of the Terms of Service and apply automatically when your organisation uses the Service. No signature is required for them to bind us; if your procurement process needs a countersigned copy, write to [email protected].

1. Parties and roles

Processor. Yusuf Murad Disli, sole proprietor, trading as SlipperySign:

Rucholzstrasse 6
4103 Bottmingen
Switzerland

Controller. The organisation whose users hold accounts on the Service.

Your organisation is the controller of the campaign content and recipient data it processes through the Service. SlipperySign is your processor in respect of that data. SlipperySign is a separate controller in respect of account identifiers and service operation data, described in section 3(a) of the Privacy Policy; those are not covered by this agreement.

2. Subject matter, duration and purpose

Subject matterComposition, storage, approval and dispatch of internal email campaigns.
DurationFor as long as your organisation holds an account, plus any retention period your administrator has configured. See section 10.
Nature and purposeStoring and rendering campaign content; recording approval decisions; handing a finished message to your own mail provider for sending; counting opens and clicks in aggregate.
Types of personal dataBusiness email addresses of your users; the sender and reply-to addresses you configure; the distribution-list addresses you enter as recipients; any personal data your users choose to place in campaign content.
Categories of data subjectYour employees, contractors and other members of your organisation.
Special categoriesNone are required by the Service. If your users place special-category data in campaign content, that is your decision as controller and your lawful basis to establish.

What is deliberately not processed. The Service does not store individual recipient addresses against opens or clicks. Tracking is counted per campaign and per link, never per person, and there is no stored identifier that would allow a count to be attributed back to an individual. This is a property of how the data is stored, not a policy that could be reversed by configuration.

3. Processing on documented instructions

SlipperySign processes personal data only on your documented instructions, including as regards international transfers, unless required otherwise by Swiss or EU law. Your use of the Service, together with the Terms of Service and this agreement, constitutes those instructions.

If SlipperySign is required by law to process personal data beyond your instructions, you will be informed before processing unless the law prohibits it.

SlipperySign will tell you if, in its opinion, an instruction infringes the GDPR or the FADP.

4. Confidentiality

Access to your data is limited to the sole proprietor named in section 1. There are no employees or contractors with access. Should that change, any person granted access will be bound by a written confidentiality undertaking before access is given, and this section will be updated before rather than after.

Administrative access to a customer account for support purposes is possible through a “view as user” function. Every use of it is recorded in the audit log your administrators can read, and message sending is disabled while it is in use.

5. Security measures

The technical and organisational measures in place are:

  • Authentication. Sign-in is delegated entirely to Google Workspace. SlipperySign never receives, stores or verifies a password, and inherits whatever multi-factor policy your organisation enforces.
  • Mail dispatch. Messages are sent by your own mailbox through your own provider. The access token used to send is held in the browser for the duration of the send and is not stored on SlipperySign’s servers.
  • Tenant isolation. Every campaign, brand, asset and audit entry is stamped with a company identifier, and every query is scoped by it. Uploaded images are stored under a per-company key prefix, so one organisation’s storage cannot be enumerated from another’s session.
  • Encryption. Data is encrypted in transit (TLS) and at rest by the infrastructure provider named in section 6.
  • Content sanitisation. Campaign content is validated and sanitised on the server before storage, and link targets are restricted to schemes that cannot execute code.
  • Least privilege at the provider. The Service requests only the permission needed to send a message as the signed-in user. It does not request permission to read, search or modify mailboxes, and Google classifies the scope used as sensitive rather than restricted.
  • Retention controls. Your administrator sets how long sent campaigns and tracking detail are kept; a nightly job enforces it.
  • Audit logging. Sends, deletions, sharing, approval decisions, administrator changes and support access are recorded and readable by your own administrators.

What is not claimed. SlipperySign holds no SOC 2, ISO 27001 or equivalent certification, and does not operate a 24/7 security operations centre. It is a one-person operation. If your procurement policy requires a certified processor, it is better to establish that now than after a pilot.

6. Sub-processors

You give general authorisation for the following sub-processors:

Sub-processorFunctionLocation
Cloudflare, Inc.Application hosting, database, object storage, network securityEuropean Union, or United States where your organisation elects it

Cloudflare is the only sub-processor. Google appears in the Privacy Policy because it authenticates your users and because your own mailbox sends the mail, it acts under your own agreement with Google, not under a contract with SlipperySign, and is therefore not SlipperySign’s sub-processor.

SlipperySign will give at least 30 days’ notice before adding or replacing a sub-processor, by email to your registered administrators. You may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, you may terminate the affected part of the Service without penalty and receive a pro-rata refund.

Notifications. When a colleague asks you to approve a campaign or shares one with you, the Service records a notification you see when signed in. No third party is involved in that, and no email is sent. Should notification email be introduced, the delivery provider would be a sub-processor and would appear in the table above under the 30 days’ notice in the previous paragraph, before the first message was sent rather than after.

7. Assisting with data subject requests

Requests from your users are yours to answer. The Service is built so that you can answer them yourself rather than waiting on us: your administrators can, from the Compliance section of the admin area,

  • export everything held about a named address at your organisation - campaigns they own, access they hold or granted, saved recipient groups, files they uploaded, and audit entries naming them; and
  • erase that person, which removes their access grants, saved groups, upload attribution and any administrator rights, and transfers their campaigns to the administrator performing the erasure.

Campaigns are transferred rather than deleted because they are your organisation’s business records rather than the individual’s personal data. If you require the content itself to be destroyed, delete the campaigns before erasing the person.

One audit entry recording the erasure is retained, and it names the erased address, because it is the evidence that the request was honoured. It can be removed on written request.

An administrator may only act on addresses belonging to their own organisation. Where you cannot act yourself, SlipperySign will assist within 5 working days of a request to [email protected].

8. Breach notification

SlipperySign will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. Notification will go to your registered administrators and will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.

Where full information is not available within 48 hours, an initial notification will be sent within that period and updated as the investigation proceeds.

9. Assistance with impact assessments

SlipperySign will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of the processing and the information available. In practice this means answering questions about how the Service stores and processes data; the architecture is documented in the Privacy Policy and in this agreement, which together answer most of what an assessment asks.

10. Deletion and return of data

On termination, and at your choice, SlipperySign will delete or return all personal data processed on your behalf. Absent an instruction, data is deleted 30 days after termination.

During the term, your administrator controls retention: sent campaigns and tracking detail can be set to delete automatically after a chosen number of days, and unused uploaded images can be swept. The defaults keep data until you delete it, so nothing disappears unless you ask for it to.

Deletion covers backups on the infrastructure provider’s ordinary rotation schedule; data in backups is not individually addressable and is overwritten in the normal course.

11. Audit and information rights

SlipperySign will make available all information necessary to demonstrate compliance with Article 28, and will answer security questionnaires and written information requests within 15 working days.

Your administrators can read your organisation’s own audit log at any time from the admin area, without asking. That is the primary audit mechanism and it needs no notice.

On-site inspection is not offered. There is no site: the Service runs on Cloudflare’s infrastructure and is operated from a home office by one person. Cloudflare’s own certifications and audit reports cover the infrastructure layer and are available directly from them. If your policy requires a contractual on-site audit right, say so before signing rather than after.

12. International transfers

SlipperySign is established in Switzerland. The European Commission has determined that Switzerland provides an adequate level of protection for personal data, most recently in January 2024, so transfers from the EEA to SlipperySign require no Standard Contractual Clauses or additional safeguards.

Campaign content, account data and uploaded images are stored in the European Union by default. Your organisation may elect United States storage instead; that election is recorded against your organisation and applies only to your data. Where an election results in a transfer outside the EEA, it is made under the appropriate safeguards described in the Privacy Policy.

13. Liability

Liability under this agreement is subject to the limitations in section 12 of the Terms of Service. Nothing in this agreement limits either party’s liability to a data subject under Article 82 of the GDPR, or any liability that cannot be limited under applicable law.

14. Changes

Material changes to this agreement will be notified to your registered administrators at least 30 days before they take effect. If a change materially reduces the protections here, you may terminate the affected part of the Service without penalty during that period.

This agreement is governed by Swiss law, with the courts of Basel-Landschaft having exclusive jurisdiction, matching section 15 of the Terms of Service.