Effective date: 2026-09-03
This Data Processing Addendum (“DPA”) supplements the Sleev Terms of Service, EULA, Enterprise Agreement, or other written master agreement (the “Agreement”) entered into by and between Sleev Labs Inc. (“Sleev,” “Processor,” or “Service Provider”) and the customer entity agreeing to these terms (“Customer” or “Controller”).
This DPA applies to the extent that Sleev processes Customer Personal Data (as defined below) in the course of providing hosted control-plane services, account administration, organization management, and licensing services under the Agreement.
1. Architectural Context & Scope of Processing
1.1 Local-First Architecture. Customer acknowledges that Sleev software is designed around a local gateway running on Customer’s workstations or self-hosted servers. Prompt content, source code, file contents, context transformations, session history, and model responses are processed locally on Customer’s infrastructure and routed directly to Customer’s chosen third-party AI model providers using Customer’s own credentials.
1.2 Processor vs. Licensor Role.
-
For local software execution, Sleev acts solely as software licensor; prompt and code payloads do not traverse or reside on Sleev servers and do not constitute Customer Personal Data processed by Sleev.
-
For hosted services (including the Sleev control plane, account authentication, team organization management, license verification, billing attribution, and optional diagnostic uploads), Sleev acts as a Data Processor (or Service Provider) processing Customer Personal Data on behalf of Customer as Data Controller (or Business).
1.3 Precedence. If there is any conflict between this DPA and the Agreement, this DPA shall govern with respect to data protection and personal data processing obligations.
2. Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement or under Applicable Data Protection Law:
- “Applicable Data Protection Law” means all worldwide privacy and data protection laws applicable to the processing of Customer Personal Data under the Agreement, including the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK Data Protection Act 2018 and UK GDPR (“UK GDPR”), the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (“CCPA/CPRA”).
- “Customer Personal Data” means any personal data or personal information provided by or on behalf of Customer to Sleev’s hosted services in connection with the performance of the Agreement.
- “Data Subject”, “Controller”, “Processor”, and “Processing” (and their grammatical equivalents) have the meanings given in the GDPR or equivalent concepts under Applicable Data Protection Law.
- “Security Incident” or “Personal Data Breach” means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed by Sleev.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries.
- “Subprocessor” means any third party appointed by or on behalf of Sleev to process Customer Personal Data in connection with the Agreement.
3. Processing Obligations & Instructions
3.1 Documented Instructions. Sleev shall process Customer Personal Data only on behalf of Customer and in accordance with Customer’s documented lawful instructions, including with respect to transfers of personal data outside the European Economic Area (“EEA”), United Kingdom, or Switzerland, unless required to do so by applicable law to which Sleev is subject. The Agreement and this DPA constitute Customer’s complete instructions to Sleev.
3.2 No Sale or Commercial Use. Sleev shall not:
-
“Sell” or “share” Customer Personal Data (as those terms are defined under the CCPA/CPRA);
-
Retain, use, or disclose Customer Personal Data for any purpose other than for the specific business purposes of performing the services specified in the Agreement;
-
Retain, use, or disclose Customer Personal Data outside of the direct business relationship between Sleev and Customer; or
-
Combine Customer Personal Data with personal data received from or on behalf of other third parties, except as permitted under Applicable Data Protection Law.
3.3 No AI Model Training. Sleev certifies that it does not use Customer Personal Data, prompt contents, source code, or operational telemetry to train, retrain, fine-tune, or improve foundational machine learning or artificial intelligence models without Customer’s explicit written consent.
4. Confidentiality & Personnel
4.1 Confidentiality. Sleev shall ensure that all employees, contractors, and agents who have access to Customer Personal Data are bound by strict contractual or statutory obligations of confidentiality.
4.2 Reliability & Access Control. Sleev shall take reasonable steps to ensure the reliability of any personnel who process Customer Personal Data and ensure that access is limited strictly to those individuals who require access to perform their obligations under the Agreement.
5. Security of Processing (TOMs)
5.1 Technical and Organizational Measures. Sleev shall implement and maintain appropriate administrative, technical, and organizational security measures designed to protect Customer Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure, as detailed in Schedule 2 of this DPA.
5.2 Security Review & Updates. Sleev regularly monitors and evaluates the effectiveness of its security measures and may update them from time to time, provided that such updates do not degrade the overall security posture or protection of Customer Personal Data.
6. Subprocessors
6.1 Authorized Subprocessors. Customer provides general written authorization for Sleev to engage Subprocessors to assist in delivering the hosted services. Sleev’s current list of approved Subprocessors is published at https://sleev.ai/subprocessors.
6.2 Subprocessor Obligations. Sleev shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those imposed on Sleev under this DPA. Sleev remains fully liable to Customer for the performance of each Subprocessor’s obligations.
6.3 Notice of Subprocessor Changes. Sleev shall provide Customer with at least thirty (30) days’ advance notice before engaging any new Subprocessor, which may be provided by updating the Subprocessors Directory or via electronic notification to registered organization administrators.
6.4 Objection Rights. Customer may object in writing to the appointment of a new Subprocessor on reasonable grounds relating to data protection within thirty (30) days of receiving notice. In the event of an objection, Sleev and Customer shall work in good faith to resolve the concern. If a mutually agreeable resolution cannot be reached within thirty (30) days of Customer’s objection, Customer may terminate the affected hosted services without penalty upon written notice.
6.5 Direct Upstream Model Providers. For the avoidance of doubt, any third-party AI model providers, custom base URLs, internal proxies, or self-hosted endpoints (including, but not limited to, Anthropic, OpenAI, Google, OpenRouter, or any other provider or local server) configured by Customer to receive local gateway completions via Customer API credentials or custom routing are direct vendors chosen and engaged directly by Customer, and are not Subprocessors of Sleev.
7. Security Incident Management & Breach Notification
7.1 Breach Notification SLA. Sleev shall notify Customer in writing without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Personal Data Breach impacting Customer Personal Data.
7.2 Incident Details. To the extent known, the notification shall describe:
-
The nature and circumstances of the Personal Data Breach, including the categories and approximate number of Data Subjects and records affected;
-
The name and contact details of Sleev’s data protection or security contact;
-
The likely consequences of the Personal Data Breach; and
-
The measures taken or proposed to be taken by Sleev to mitigate and address the breach.
7.3 Cooperation & Remediation. Sleev shall take immediate, commercially reasonable steps to contain, mitigate, and remediate the effects of any Personal Data Breach, and shall provide reasonable cooperation to assist Customer in fulfilling its statutory breach reporting and Data Subject notification obligations.
8. Data Subject Requests & Regulatory Assistance
8.1 Assistance with DSRs. To the extent Customer cannot access or modify the relevant Customer Personal Data through the self-service capabilities of the hosted services or local gateway, Sleev shall provide reasonable assistance to Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law (such as rights of access, rectification, erasure, restriction, or data portability).
8.2 Direct Inquiries. If a Data Subject submits a request directly to Sleev regarding Customer Personal Data, Sleev shall promptly advise the Data Subject to submit their request to Customer and notify Customer of the inquiry.
8.3 DPIAs and Prior Consultation. Taking into account the nature of the processing and the information available to Sleev, Sleev shall provide reasonable assistance to Customer in conducting data protection impact assessments (“DPIAs”) and participating in prior consultations with supervisory authorities where required by Applicable Data Protection Law.
9. Audits & Compliance Verification
9.1 Compliance Documentation. Sleev shall make available to Customer, upon reasonable written request, information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA and Applicable Data Protection Law.
9.2 Audit Rights. If Customer reasonably determines that the documentation provided is insufficient to verify compliance, or where mandated by a competent supervisory authority, Customer (or an independent third-party auditor subject to customary confidentiality obligations and not a competitor of Sleev) may conduct a remote or on-site audit of Sleev’s data processing procedures. Any such audit shall:
- Occur no more than once per twelve (12) month period during normal business hours;
- Be requested with at least thirty (30) days’ advance written notice;
- Avoid unreasonable disruption to Sleev’s business operations; and
- Be conducted at Customer’s sole expense.
10. Return & Deletion of Customer Personal Data
10.1 Deletion upon Termination. Upon termination or expiration of the Agreement, or upon Customer’s written request, Sleev shall delete or return all Customer Personal Data stored within Sleev’s hosted services within thirty (30) days, except to the extent that retention is required by applicable law, statutory retention obligations, or standard immutable disaster recovery backups (which are securely isolated and deleted in accordance with Sleev’s standard backup lifecycle).
10.2 Local Data Retention. Data stored locally on Customer’s machines (including local SQLite gateway databases, session transcripts, and locally generated keys) remains under Customer’s sole control and is not subject to server-side deletion.
11. Cross-Border International Transfers
11.1 Transfer Mechanisms. To the extent Customer Personal Data originating in the EEA, Switzerland, or the UK is transferred to countries that do not ensure an adequate level of data protection under Applicable Data Protection Law, the parties agree to abide by the following transfer mechanisms:
11.2 EU Standard Contractual Clauses (EU SCCs):
-
The EU SCCs (Module Two: Controller-to-Processor, and Module Three: Processor-to-Processor, as applicable) are hereby incorporated into this DPA by reference;
-
For the purposes of Clause 9(a), Option 2 (General written authorization) applies, and the notice period is thirty (30) days as set forth in Section 6.3;
-
For Clause 11, the optional language is omitted;
-
For Clause 17, the EU SCCs shall be governed by the laws of Ireland;
-
For Clause 18(b), disputes shall be resolved before the courts of Ireland;
-
The Annexes of the EU SCCs are deemed completed with the information set out in Schedule 1 and Schedule 2 of this DPA.
11.3 UK International Data Transfer Addendum (UK Addendum):
-
The UK Addendum issued by the Information Commissioner’s Office under s.119A(1) of the Data Protection Act 2018 is incorporated into this DPA by reference and applies to transfers of Customer Personal Data subject to the UK GDPR.
-
Table 1, 2, and 3 are completed with the information in this DPA and the Agreement.
11.4 Swiss Transfers:
-
For transfers subject to the Swiss FADP, the EU SCCs apply with amendments necessary under Swiss law, including references to the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) as competent supervisory authority.
Schedule 1: Details of Processing
A. Parties & Roles
- Data Exporter (Customer): Customer using Sleev’s hosted services.
- Data Importer (Sleev Labs Inc.): Provider of local gateway optimization software, team license administration, and cloud control-plane services.
- Role: Customer acts as Data Controller; Sleev Labs Inc. acts as Data Processor.
B. Categories of Data Subjects
- Customer’s authorized users, employees, contractors, developers, and team administrators.
C. Types of Personal Data
- Identity & Contact Data: Names, business email addresses, profile pictures, user identifiers.
- Account & Organization Metadata: Organization names, assigned roles, team memberships, license key identifiers.
- Usage & Telemetry Data: Provider and model identifiers, token consumption counts, estimated optimization savings, client software versions, IP addresses, and operational timestamps.
- Diagnostic Data: Optional, voluntary diagnostic log bundles submitted for debugging (with prompt and code content redacted client-side prior to upload).
- Excluded Data: Customer source code, repository files, developer prompts, and AI model generation completions are processed locally on Customer infrastructure and are explicitly excluded from data transmitted to or stored by Sleev’s hosted control plane.
D. Special Categories of Data
- No special categories of sensitive personal data (e.g., biometric, health, political, religious) are requested, required, or intentionally processed by Sleev hosted services.
E. Purpose and Nature of Processing
- Authentication and access control for Sleev services;
- Organization management, seat allocation, and license serving;
- Usage accounting, quota enforcement, and billing attribution;
- Security monitoring, abuse prevention, and technical support;
- Service reliability and feature enhancement.
F. Retention Period
- Personal data is retained for the duration of the Agreement and deleted within 30 days following termination, except for diagnostic log bundles (retained for a maximum of 7 days) or where retention is required by statutory legal requirements.
Schedule 2: Technical and Organizational Measures (TOMs)
Sleev maintains the following technical and organizational security measures:
-
Local-First Architectural Isolation:
- The Sleev gateway runs strictly on the local loopback interface (
127.0.0.1:17321) by default. - User prompts, repository files, and AI completions remain within the local execution environment and are sent directly to Customer-configured upstream endpoints.
- No prompt payloads or code repositories are mirrored, ingested, or processed on Sleev cloud infrastructure.
- The Sleev gateway runs strictly on the local loopback interface (
-
Data Encryption:
- In Transit: All external communications between local clients, the web application, and the Sleev control plane are encrypted using TLS 1.3 (with fallback to TLS 1.2).
- At Rest: Cloud databases (PostgreSQL on Google Cloud SQL) and storage buckets are encrypted using industry-standard AES-256 encryption.
-
Identity, Authentication & Access Control:
- Centralized Single Sign-On (SSO) supporting SAML 2.0 and OIDC via enterprise identity providers.
- Administrative and operational access to production infrastructure restricted to authorized personnel under least-privilege principles.
- Role-Based Access Control (RBAC) governing access to cloud resources and control-plane services.
-
Vulnerability & Incident Management:
- Automated dependency vulnerability scanning and regular software updates.
- Dedicated security triage contact maintaining active response monitoring at
support@sleev.ai. - Incident response procedures with documented 72-hour customer notification processes for confirmed security breaches.
-
Operational & Physical Safeguards:
- Control plane infrastructure hosted in ISO 27001, SOC 2 Type II, and PCI-DSS certified data centers provided by Google Cloud Platform.
- Personnel subject to confidentiality agreements and security awareness practices.
- Ephemeral diagnostic retention policy ensuring debug logs are automatically purged after 7 days.
Contact Information
For inquiries regarding this Data Processing Addendum, please contact:
Sleev Labs Inc.
Attention: Privacy & Compliance Team
Email: support@sleev.ai