← Back to Slayt AIPrivacy Policy
Last updated: 7 August 2026 · Slayt Intelligence Limited
Data Controller
Slayt Intelligence Limited
Registered address
66 Paul Street, London EC2A 4NA
ICO Registration
ZC107309
Data Protection Officer
Ms Jackline Nyaga · hello@slayt-ai.com
1. Who we are
Slayt Intelligence Limited ("Slayt AI", "we", "us", "our") is a company registered in England and Wales. We operate the platform at slayt-ai.com and are the data controller for personal data processed through our website and platform. We are registered with the Information Commissioner's Office (ICO) under registration number ZC107309. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What data we collect
When you create an account or use the Slayt AI platform, we collect your name and work email address, your role and organisation, your sector and the project data you enter into the platform, and payment information processed securely through Stripe (we do not store card details). We keep operational logs of platform errors, which may include your user identifier and the page or route that failed. We do not use website analytics, and we set no analytics or tracking cookies — see our
Cookie Policy.
3. Why we collect it and our legal basis
We process your personal data to provide and operate the Slayt AI platform under the legal basis of contract performance. We process usage data to improve the platform under legitimate interests. We process payment data to manage billing under contract performance. We send service communications — account updates, billing notices, security alerts — under contract performance. We may send product updates and relevant content under legitimate interests, with the right to opt out at any time.
4. How we use your data
We use your data to operate your account, process your subscription, provide platform intelligence, and communicate with you about your account. We never sell your data, share it with third parties for marketing purposes, or use it for any purpose other than those stated above. Your project data is yours — we do not use it to train AI models or share it with any third party.
5. Third parties who process your data
We appoint the following processors. Several appoint their own sub-processors in turn; where they do, we link their published list rather than reproduce it, because they maintain it and we would not know when it changed.
Vercel — application hosting and execution (see section 9 on where this happens). Supabase — database, stored in the UK London region (
sub-processors). Clerk — authentication, session management, and delivery of verification and sign-in email, which involves your email address (
sub-processors). Resend — delivery of our transactional email, which involves your name and email address. Stripe — payment processing (
service providers). Anthropic — the AI features described in section 9. Each acts as a data processor under appropriate data processing agreements.
6. How long we keep your data
We retain your account and project data for the duration of your subscription and for 90 days after cancellation, after which we delete it. Deletion is carried out by us rather than automatically, so if you want it done sooner — or want confirmation that it has been done — email
hello@slayt-ai.com and we will action it and confirm within 30 days. Operational error logs are kept for troubleshooting and are cleared periodically.
7. Your rights
Under UK GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. To exercise any right, email hello@slayt-ai.com. We will respond within 30 days.
8. Data security
Your data is stored in the UK — Supabase London region. Processing during a request may occur outside the UK; section 9 sets out where. The platform uses row-level security to isolate each organisation's data. All connections are encrypted via HTTPS. Access to production data is restricted to authorised personnel only.
9. International transfers
Your data is stored in the United Kingdom, but some processing takes place outside it. Our application code runs on Vercel's serverless infrastructure in the United States, so personal data is processed there in transit and in memory while a request is served. Clerk processes authentication data outside the UK, and all but two of the sub-processors on its published list are located in the United States. Anthropic processes the data described below in the United States.
What is sent to Anthropic, and when. Nothing is sent unless someone uses an AI feature. Three features do so. AI Insights and Escalation analysis send that project's context: its name, sector, phase, health and dates; milestone, risk, issue and decision titles with the names of their owners; recent progress updates including free-text summaries; budget figures including the budget holder; benefits and KPIs; and the project's active team list — each member's name, or their email address where no name is recorded, with their role. Document analysis sends up to 10,000 characters of text extracted from a document you upload, so its contents depend entirely on the file you choose. Anthropic does not use data submitted through its API to train its models. We do not send data to Anthropic for any other purpose, and no other feature transmits your data outside the platform.
How long Anthropic keeps it. Under Anthropic's commercial terms, API inputs and outputs are deleted within 30 days of receipt. Content flagged as violating their usage policies may be retained for up to two years, and trust-and-safety classification scores for up to seven years. Zero-data-retention processing is available from Anthropic as a per-organisation arrangement rather than a per-request setting; it is not currently in place for our account.
One further AI provider, through Clerk. Where we customise the wording of an authentication email — the verification and sign-in messages Clerk sends on our behalf — Clerk passes that template through OpenAI to check it for phishing and impersonation. What is scanned is the template text we write, and the scan happens when we edit a template rather than when you receive an email. We have customised two. OpenAI appears on Clerk's sub-processor list linked in section 5; we name it here because this section is about content sent to AI providers, and that is a different question from who hosts or delivers.
Where processing occurs outside the UK, we rely on appropriate safeguards including Standard Contractual Clauses in accordance with UK GDPR.
10. Complaints
If you have a concern about how we handle your data, contact us first at hello@slayt-ai.com. If you are not satisfied, you have the right to lodge a complaint with the ICO at ico.org.uk or 0303 123 1113.
© 2026 Slayt Intelligence Limited · 66 Paul Street, London EC2A 4NAICO ZC107309 · hello@slayt-ai.com