privacy policy·v1.0.1

Privacy Policy

Last updated: 2026-06-26

This Privacy Policy explains how SlashHub Limited ("we", "us") collects, uses, discloses, processes, stores, and safeguards your Personal Data when you access or use our Services, including the SlashAI agent platform, the cross-product Single Sign-On (SSO) system, and the product-specific addenda. It is designed to comply with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), the EU General Data Protection Regulation (GDPR) (where applicable), and other applicable data-protection laws.

Effective
2026-07-01
Last Updated
2026-06-26
Governing Law
The laws of the Hong Kong Special Administrative Region (PDPO Cap. 486) and, for EU/UK data subjects, the EU GDPR

1. Controller, DPO & Contact

The data controller for your Personal Data is SlashHub Limited, a private company limited by shares incorporated in Hong Kong (Business Registration BR-XXXXXXX), with registered office at [Registered Office Address, Hong Kong].

Our Data Protection Officer can be contacted at: SlashHub Data Protection Officer, dpo@slashhub.hk, [DPO Address, Hong Kong].

For EU/UK data subjects, our EU representative under GDPR Article 27 is: [EU Representative — appoint before EU expansion], eu-rep@slashhub.hk, [EU Representative Address].

For specific requests, use the contact form in your account dashboard, or email the address above. We respond to all valid requests within the timeframes required by applicable law (PDPO: 40 days; GDPR: 30 days).

2. Definitions & Interpretation

"Personal Data" has the meaning given in the PDPO (Cap. 486) and, for data subjects in the European Economic Area or the United Kingdom, the meaning given in the GDPR. In short, it is any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or erasure. "Processor" means a third party who processes Personal Data on our behalf under a written contract. "Anonymised Data" means data that has been irreversibly stripped of personally identifying information and cannot reasonably be linked back to you. "AI Training" means the process of using data to train, develop, calibrate, validate, and improve machine-learning models, algorithms, and recommendation engines. "Services" means all websites, applications, platforms, APIs, AI agents, and services offered by us, including but not limited to SlashOne, FreelanceHub, SlashBooks, TimePlate, SlashStudio, and SlashAI.

Capitalised terms not defined here have the meaning given in our Terms of Service.

3. Data We Collect

We collect the following categories of Personal Data:

(a) Account Data — your name, email, password (hashed with scrypt), phone number (optional), avatar URL, locale, currency, timezone, business name (if applicable), and the unique identifiers we assign to your Account (Firebase UID, internal UUID, Stripe customer ID, etc.).

(b) Authentication Data — Firebase Auth tokens, SSO tokens (stored as SHA-256 hashes), session cookies, refresh tokens (stored as SHA-256 hashes), IP address, user agent, device fingerprint, and device labels. We do not store passwords in plaintext; passwords are hashed with scrypt and never recoverable.

(c) Product Data — content you create, upload, transmit, or otherwise make available through our products. This includes, for example, documents you write in SlashStudio, the bookkeeping records you create in SlashBooks, the shift schedules you set in TimePlate, the proposals and contracts you negotiate in FreelanceHub, the AI Memory entries and scheduled Jobs you create in SlashAI, and any other User Content.

(d) Usage Data — logs of your interactions with the Services (pages viewed, features used, AI agents invoked, tool calls, query and response payloads for AI features, response times, error codes), timestamps, IP address, user agent, and referrer. We retain these logs for 90 days for security, debugging, abuse-prevention, and product-improvement purposes.

(e) Device & Technical Data — browser type and version, operating system, screen size, language preference, time zone, hardware make/model (for mobile apps), and the device fingerprint for fraud detection.

(f) Cookies & Tracking — see our Cookie Policy for the full list of cookies, similar technologies, and their purposes.

(g) Payment Data — billing name, billing address, VAT/GST number (optional), last 4 digits of payment card, payment-card brand, and transaction history. Full card numbers are handled by our payment processors (currently Stripe and Airwallex) under their own Data Processing Agreements; they never touch our servers.

(h) Communication Data — when you contact our support, we collect the content of your message, the email address you use, and any attachments you send.

(i) Marketing Data — if you opt in to marketing communications, we collect your email, the products you use, and your interaction with our emails (opens, clicks). You may opt out at any time.

4. Lawful Basis for Processing (GDPR Article 6)

If you are in the European Economic Area or the United Kingdom, we process your Personal Data on the following lawful bases under GDPR Article 6:

(a) Performance of a Contract — to provide the Services, process payments, issue sessions, and provide customer support. (Legal basis: Article 6(1)(b).)

(b) Legitimate Interests — to secure the Services, prevent fraud and abuse, improve our products, and conduct analytics. (Legal basis: Article 6(1)(f).)

(c) Compliance with Legal Obligations — to comply with tax, accounting, AML, and other legal requirements. (Legal basis: Article 6(1)(c).)

(d) Consent — for marketing communications, non-essential cookies, and any other processing that requires your explicit consent. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. (Legal basis: Article 6(1)(a).)

If you are in Hong Kong or another non-GDPR jurisdiction, the PDPO's Data Protection Principles apply, and we process your Personal Data for the same purposes, on the equivalent legal bases (e.g. "all reasonably practicable steps" to protect the data, "prescribed purpose", etc.).

5. How We Use Your Data

We process your Personal Data for the following purposes:

(a) To provide and operate the Services, including authenticating you, issuing sessions and SSO tokens, syncing your identity across our products, processing payments, providing customer support, and enforcing our Terms.

(b) To provide AI Features, including SlashAI — your queries and the product data you authorise SlashAI to access are sent to the underlying AI providers (currently MiniMax, DeepSeek, and others) to generate responses. AI providers are bound by our Data Processing Agreements and are contractually prohibited from training their models on your data.

(c) To improve the Services — we analyse aggregated and anonymised Usage Data to understand how the Services are used, fix bugs, and develop new features.

(d) To communicate with you — to send you service-related notices (security alerts, billing receipts, terms updates, system status), and with your consent, marketing communications. You may opt out of marketing at any time from your account dashboard or by clicking "unsubscribe" in any marketing email.

(e) To comply with legal obligations — to respond to lawful requests from public authorities, detect and prevent fraud or abuse, enforce our Terms, and meet our record-keeping obligations.

(f) To protect the vital interests of any person — in rare cases where we have reason to believe that disclosure is necessary to prevent imminent harm to a person.

We do NOT use your Personal Data for automated profiling that produces legal or similarly significant effects on you (see §13 for the narrow cases where we do use automated decision-making).

6. Cross-Product Data Sharing & Unified Identity

SlashHub operates a unified identity layer. When you sign in to one product (e.g. FreelanceHub) and then visit another (e.g. SlashBooks), the products share limited information via the Single Sign-On (SSO) cookie to recognise that you are the same person. The shared data includes your Account UUID, display name, email, and avatar URL.

We do NOT share product-specific Content (e.g. your FreelanceHub contracts, your SlashBooks bookkeeping records, your TimePlate shift schedules, or your SlashStudio documents) across products by default. Such sharing occurs only when (a) you explicitly initiate a cross-product tool call via SlashAI, (b) you explicitly link accounts, or (c) you explicitly enable cross-product recommendations.

You may explicitly link your Account to pre-existing accounts on FreelanceHub, SlashBooks, TimePlate, or SlashStudio. Linked accounts are recorded in our PostgreSQL database. You may unlink any account at any time from the Connections page; unlinking is a soft delete (the row is marked as unlinked but retained for audit purposes for 7 years).

If you delete your Account, all product_accounts links are removed; product-specific data is deleted or anonymised in accordance with our retention schedule (see §8).

7. AI & Machine-Learning Data Processing

When you use AI Features, including SlashAI, your queries, the product data you authorise SlashAI to access, and the AI-generated responses are:

(a) Sent to the underlying AI provider (e.g. MiniMax, DeepSeek) over encrypted channels (TLS 1.3) to generate the response. The provider returns the response, which is then streamed back to you and stored in your session history.

(b) NOT used to train any AI model. We contractually prohibit our AI providers from training on your data. The "Zero-Retention" setting available in some product tiers enforces this at the API level (no prompt or response is logged by the provider).

(c) Stored in your account history for the duration of your account plus 30 days after deletion, to allow you to retrieve past conversations and to comply with legal obligations.

(d) Subject to memory — you may instruct SlashAI to remember specific facts (Memory entries) and to perform scheduled tasks (scheduled Jobs). Memory entries and Jobs are visible and editable in your account dashboard at any time.

SlashAI may invoke third-party tools (e.g. Google Workspace, Stripe, WhatsApp) on your behalf. Each tool invocation is logged in your account activity log and can be reviewed or revoked at any time. We are not responsible for the actions of any third-party service in response to a tool call.

8. Data Retention

We retain Personal Data for as long as necessary to provide the Services and comply with our legal obligations. Specifically:

(a) Account Data — retained while your Account is active. Upon Account deletion, your email is replaced with a tombstone (`deleted+<id>@erased.local`) and your name, avatar, and other identifiers are cleared. Soft-deleted data is purged after 30 days. Backups are purged after 90 days.

(b) Product Data (e.g. documents, invoices, schedules) — retained while your Account is active. You may delete individual items at any time; the deletion is permanent and propagated to all backup systems within 30 days.

(c) Billing Records — retained for 7 years as required by Hong Kong tax law (Inland Revenue Ordinance Cap. 112) and applicable anti-money-laundering law (Cap. 615).

(d) Audit Logs — retained for 7 years for security, fraud detection, and regulatory compliance.

(e) AI Session History — retained while your Account is active plus 30 days after deletion, to allow you to retrieve past conversations.

(f) Cookies — see Cookie Policy for cookie-specific retention periods.

(g) Anonymised Data — may be retained indefinitely for analytics and product improvement.

(h) Backups — encrypted backups are retained for 90 days, after which they are securely destroyed.

9. Data Subject Rights (PDPO + GDPR)

Under the PDPO (Cap. 486), you have the right to: (a) check whether we hold Personal Data about you (Data Access Request); (b) require us to correct any data that is inaccurate; (c) ascertain our general policies and practices in relation to Personal Data; and (d) opt out of direct marketing.

Under the GDPR (if you are in the EEA or the UK), you additionally have the right to: (e) request erasure ("right to be forgotten"); (f) request restriction of processing; (g) data portability in a structured, commonly used, machine-readable format (JSON or CSV); (h) object to processing based on legitimate interests or for direct marketing; (i) withdraw consent at any time (where processing is based on consent) without affecting the lawfulness of processing carried out before withdrawal; and (j) lodge a complaint with your local data-protection authority.

To exercise any of these rights, submit a request to privacy@slashhub.hk from the email associated with your Account. We will respond within 30 days (PDPO allows up to 40 days for complex requests) or 30 days (GDPR Article 12), free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse, with reasons).

If you are in the EEA/UK, you also have the right to lodge a complaint with your local data-protection authority. A list of EU DPAs is available at edpb.europa.eu; the UK ICO is at ico.org.uk. If you are in Hong Kong, you may complain to the Office of the Privacy Commissioner for Personal Data at pcpd.org.hk.

10. Cookies & Tracking

We use cookies and similar technologies (localStorage, sessionStorage, IndexedDB) to provide and improve the Services. The categories are: (a) Strictly Necessary — required for authentication, security, and load balancing; (b) Functional — remember your preferences (theme, language, last-used workspace); (c) Analytics — anonymised usage statistics; (d) Marketing — only with your consent.

See our Cookie Policy for the full list of cookies, their purposes, and retention periods. You can manage cookie preferences from the cookie banner shown on your first visit, from your account settings, or from your browser settings.

We respect the Global Privacy Control (GPC) signal. When your browser sends the GPC header, we treat it as a valid opt-out of sale/sharing for California residents and as a valid withdrawal of consent for non-essential cookies for all users.

11. Security Measures

We employ industry-standard security measures to protect your Personal Data, including: (a) TLS 1.3 for all data in transit; (b) AES-256 encryption at rest; (c) scrypt password hashing; (d) SHA-256 hashing of all authentication tokens at rest; (e) short-lived JWT access tokens (15 min) with rotating refresh tokens (30 days); (f) HttpOnly Secure cookies with SameSite=Lax; (g) CSRF protection on all state-changing endpoints; (h) rate limiting (per-IP and per-Account); (i) audit logging of all data access; (j) per-Account row-level security in our PostgreSQL database; (k) encrypted backups stored in geographically separate regions; (l) regular third-party penetration tests (at least annually); (m) a documented incident-response plan; and (n) employee security training.

Access to Personal Data is restricted to employees and contractors with a need to know, who are bound by confidentiality obligations and subject to background checks. We conduct quarterly access reviews.

Despite our efforts, no system is 100% secure. In the event of a personal-data breach, we will notify affected users and applicable supervisory authorities in accordance with §14 and applicable law.

12. International Data Transfers

We are headquartered in Hong Kong. Personal Data is primarily processed in Hong Kong, with backups stored in Singapore (encrypted) and Ireland (for EU/UK data subjects).

When we transfer Personal Data outside Hong Kong (for example, to a third-party processor in the United States), we rely on one of the following safeguards: (a) the EU Standard Contractual Clauses (Decision 2021/914); (b) the UK International Data Transfer Addendum; (c) the recipient's participation in a recognised cross-border privacy framework (e.g. EU-US Data Privacy Framework); (d) the recipient's binding corporate rules; or (e) your explicit consent.

AI providers (MiniMax, DeepSeek, and others) currently process data in their data centres, which may be located in the US, Europe, or Asia. Each provider is bound by a Data Processing Agreement that includes Standard Contractual Clauses and a prohibition on using your data to train their models.

A list of our subprocessors and their locations is maintained at slashhub.hk/subprocessors and is updated at least 30 days before any change.

13. Automated Decision-Making (GDPR Article 22)

We use automated decision-making only in narrow, well-defined cases: (a) fraud detection (blocking suspicious sign-ins or transactions); (b) abuse detection (suspending Accounts that violate the AUP); and (c) AI Features where you explicitly invoke an automated action (e.g. SlashAI generating a financial report).

In cases (a) and (b), you have the right to obtain human review of the decision. To request review, contact privacy@slashhub.hk. We will respond within 30 days.

We do NOT use automated decision-making that produces legal or similarly significant effects on you (e.g. automated denial of credit, automated termination of employment, automated assessment of personal reliability) without your explicit consent. If we propose to introduce such processing, we will provide at least 30 days' notice and an opt-out.

AI Features (SlashAI) are not a substitute for human review. You are responsible for reviewing AI-generated Content before relying on it for any consequential decision. See §11 (Disclaimers) of our Terms of Service for the full disclaimer.

14. Data Breach Notification

A "personal data breach" is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (a) notify the Office of the Privacy Commissioner for Personal Data (Hong Kong) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (PDPO Section 1(3)); (b) notify the lead supervisory authority (if applicable) within 72 hours (GDPR Article 33); and (c) notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects.

We maintain a documented incident-response plan and conduct tabletop exercises at least annually. Our security team is on-call 24/7/365 for breach response.

15. Children's Privacy

The Services are not directed to children under 13 (or under 16 in the EEA/UK, or as otherwise required by applicable law). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child in violation of applicable law, we will delete it as soon as possible.

If you believe a child has registered, contact privacy@slashhub.hk and we will delete the Account within 7 days. Parents or guardians who believe their child has provided Personal Data to us may request access, correction, or deletion of that data.

Some features (e.g. time tracking in TimePlate) may be used by minors (e.g. teenage part-time workers) under the supervision of a parent, guardian, or employer who is the Account holder. In such cases, the Account holder is responsible for obtaining any necessary consents and for ensuring compliance with applicable child-labour laws.

16. Changes to This Privacy Policy

We may modify this Privacy Policy from time to time. If we make a material change, we will notify you at least 30 days before the change takes effect by email and by a prominent notice in the Services. The notice will identify the material change and provide access to the previous version for comparison.

Your continued use after the effective date constitutes acceptance. If you do not agree, you may close your Account before the effective date and request deletion of your Personal Data in accordance with §9.

A version history with diffs is available at slashhub.hk/privacy/history.

17. Contact & DPO

For questions, data-subject requests, or complaints, contact our Data Protection Officer:

SlashHub Data Protection Officer

Email: dpo@slashhub.hk

Address: [DPO Address, Hong Kong]

For general privacy questions: privacy@slashhub.hk

For EU/UK data subjects, our EU representative is: [EU Representative — appoint before EU expansion] (eu-rep@slashhub.hk).

You may also lodge a complaint with: (a) the Office of the Privacy Commissioner for Personal Data (Hong Kong) at pcpd.org.hk; (b) your local data-protection authority if you are in the EEA/UK; or (c) any other competent supervisory authority in your jurisdiction.

Product-Specific Addendum — slashone

The following additional terms apply specifically to slashone and supplement the main document above.

O-1. SlashOne-Specific Terms (Unified Account, Billing, AI Management)

SlashOne is the unified account, billing, and SlashAI management layer for the entire SlashHub ecosystem. By using SlashOne, you agree to the additional terms in this Addendum.

**Unified Account.** Your SlashOne account is the single source of truth for your identity across our products. You may sign in to any product with a single set of credentials (email + password, Google OAuth, or Apple OAuth). The credentials are stored in FreelanceHub's Firebase project (`freelancehub-1b0b6`) and are shared by SlashStudio and SlashOne; SlashBooks and TimePlate use separate Firebase projects but can be linked to your SlashOne account.

**Single Sign-On (SSO).** When you sign in to one product, an encrypted SSO token is set as a cookie scoped to the `.slashhub.hk` domain. The token is HttpOnly, Secure, and rotated on every cross-product exchange. You may revoke all SSO tokens from the Security settings page; this will sign you out of every product on every device.

**Account Linking.** You may link your SlashOne account to pre-existing accounts on FreelanceHub, SlashBooks, TimePlate, or SlashStudio. Account linking is reversible at any time from the Connections page. Linked accounts share your core profile (name, email, avatar) but do not share product-specific data (e.g. your SlashBooks records or your TimePlate shifts) without your explicit action.

**Consolidated Billing.** SlashOne consolidates your subscriptions and credit usage across products into a single billing relationship. You will receive one invoice per billing period covering all products. You may opt out of consolidated billing from the Billing settings page; opting out will require you to manage each product's subscription separately.

**SlashAI Management.** SlashOne provides a management interface for SlashAI: viewing your credit balance, scheduled jobs, memory entries, and session history; managing enabled tools and agents; and configuring cross-product permissions. Your management actions are logged in the audit trail for security and compliance purposes.

**Cross-Product Data Minimisation.** Although SlashOne is the unified identity layer, we strictly minimise cross-product data sharing. Your FreelanceHub profile data, SlashBooks records, TimePlate shifts, and SlashStudio documents are NOT shared with other products by default. Sharing occurs only when (a) you explicitly initiate a cross-product tool call via SlashAI, (b) you explicitly link accounts, or (c) you explicitly enable cross-product recommendations.