privacy policy·v1.0.1

Privacy Policy

Last updated: 2026-06-26

This Privacy Policy explains how SlashHub Limited ("we", "us") collects, uses, discloses, processes, stores, and safeguards your Personal Data when you access or use our Services, including the SlashAI agent platform, the cross-product Single Sign-On (SSO) system, and the product-specific addenda. It is designed to comply with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), the EU General Data Protection Regulation (GDPR) (where applicable), and other applicable data-protection laws.

Effective
2026-07-01
Last Updated
2026-06-26
Governing Law
The laws of the Hong Kong Special Administrative Region (PDPO Cap. 486) and, for EU/UK data subjects, the EU GDPR
Contact
privacy@slashhub.hk

1. Controller, DPO & Contact

The data controller for your Personal Data is SlashHub Limited, a private company limited by shares incorporated in Hong Kong (Business Registration BR-XXXXXXX), with registered office at [Registered Office Address, Hong Kong].

Our Data Protection Officer can be contacted at: SlashHub Data Protection Officer, dpo@slashhub.hk, [DPO Address, Hong Kong].

For EU/UK data subjects, our EU representative under GDPR Article 27 is: [EU Representative — appoint before EU expansion], eu-rep@slashhub.hk, [EU Representative Address].

For specific requests, use the contact form in your account dashboard, or email the address above. We respond to all valid requests within the timeframes required by applicable law (PDPO: 40 days; GDPR: 30 days).

2. Definitions & Interpretation

"Personal Data" has the meaning given in the PDPO (Cap. 486) and, for data subjects in the European Economic Area or the United Kingdom, the meaning given in the GDPR. In short, it is any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or erasure. "Processor" means a third party who processes Personal Data on our behalf under a written contract. "Anonymised Data" means data that has been irreversibly stripped of personally identifying information and cannot reasonably be linked back to you. "AI Training" means the process of using data to train, develop, calibrate, validate, and improve machine-learning models, algorithms, and recommendation engines. "Services" means all websites, applications, platforms, APIs, AI agents, and services offered by us, including but not limited to SlashOne, FreelanceHub, SlashBooks, TimePlate, SlashStudio, and SlashAI.

Capitalised terms not defined here have the meaning given in our Terms of Service.

3. Data We Collect

We collect the following categories of Personal Data:

(a) Account Data — your name, email, password (hashed with scrypt), phone number (optional), avatar URL, locale, currency, timezone, business name (if applicable), and the unique identifiers we assign to your Account (Firebase UID, internal UUID, Stripe customer ID, etc.).

(b) Authentication Data — Firebase Auth tokens, SSO tokens (stored as SHA-256 hashes), session cookies, refresh tokens (stored as SHA-256 hashes), IP address, user agent, device fingerprint, and device labels. We do not store passwords in plaintext; passwords are hashed with scrypt and never recoverable.

(c) Product Data — content you create, upload, transmit, or otherwise make available through our products. This includes, for example, documents you write in SlashStudio, the bookkeeping records you create in SlashBooks, the shift schedules you set in TimePlate, the proposals and contracts you negotiate in FreelanceHub, the AI Memory entries and scheduled Jobs you create in SlashAI, and any other User Content.

(d) Usage Data — logs of your interactions with the Services (pages viewed, features used, AI agents invoked, tool calls, query and response payloads for AI features, response times, error codes), timestamps, IP address, user agent, and referrer. We retain these logs for 90 days for security, debugging, abuse-prevention, and product-improvement purposes.

(e) Device & Technical Data — browser type and version, operating system, screen size, language preference, time zone, hardware make/model (for mobile apps), and the device fingerprint for fraud detection.

(f) Cookies & Tracking — see our Cookie Policy for the full list of cookies, similar technologies, and their purposes.

(g) Payment Data — billing name, billing address, VAT/GST number (optional), last 4 digits of payment card, payment-card brand, and transaction history. Full card numbers are handled by our payment processors (currently Stripe and Airwallex) under their own Data Processing Agreements; they never touch our servers.

(h) Communication Data — when you contact our support, we collect the content of your message, the email address you use, and any attachments you send.

(i) Marketing Data — if you opt in to marketing communications, we collect your email, the products you use, and your interaction with our emails (opens, clicks). You may opt out at any time.

4. Lawful Basis for Processing (GDPR Article 6)

If you are in the European Economic Area or the United Kingdom, we process your Personal Data on the following lawful bases under GDPR Article 6:

(a) Performance of a Contract — to provide the Services, process payments, issue sessions, and provide customer support. (Legal basis: Article 6(1)(b).)

(b) Legitimate Interests — to secure the Services, prevent fraud and abuse, improve our products, and conduct analytics. (Legal basis: Article 6(1)(f).)

(c) Compliance with Legal Obligations — to comply with tax, accounting, AML, and other legal requirements. (Legal basis: Article 6(1)(c).)

(d) Consent — for marketing communications, non-essential cookies, and any other processing that requires your explicit consent. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. (Legal basis: Article 6(1)(a).)

If you are in Hong Kong or another non-GDPR jurisdiction, the PDPO's Data Protection Principles apply, and we process your Personal Data for the same purposes, on the equivalent legal bases (e.g. "all reasonably practicable steps" to protect the data, "prescribed purpose", etc.).

5. How We Use Your Data

We process your Personal Data for the following purposes:

(a) To provide and operate the Services, including authenticating you, issuing sessions and SSO tokens, syncing your identity across our products, processing payments, providing customer support, and enforcing our Terms.

(b) To provide AI Features, including SlashAI — your queries and the product data you authorise SlashAI to access are sent to the underlying AI providers (currently MiniMax, DeepSeek, and others) to generate responses. AI providers are bound by our Data Processing Agreements and are contractually prohibited from training their models on your data.

(c) To improve the Services — we analyse aggregated and anonymised Usage Data to understand how the Services are used, fix bugs, and develop new features.

(d) To communicate with you — to send you service-related notices (security alerts, billing receipts, terms updates, system status), and with your consent, marketing communications. You may opt out of marketing at any time from your account dashboard or by clicking "unsubscribe" in any marketing email.

(e) To comply with legal obligations — to respond to lawful requests from public authorities, detect and prevent fraud or abuse, enforce our Terms, and meet our record-keeping obligations.

(f) To protect the vital interests of any person — in rare cases where we have reason to believe that disclosure is necessary to prevent imminent harm to a person.

We do NOT use your Personal Data for automated profiling that produces legal or similarly significant effects on you (see §13 for the narrow cases where we do use automated decision-making).

6. Cross-Product Data Sharing & Unified Identity

SlashHub operates a unified identity layer. When you sign in to one product (e.g. FreelanceHub) and then visit another (e.g. SlashBooks), the products share limited information via the Single Sign-On (SSO) cookie to recognise that you are the same person. The shared data includes your Account UUID, display name, email, and avatar URL.

We do NOT share product-specific Content (e.g. your FreelanceHub contracts, your SlashBooks bookkeeping records, your TimePlate shift schedules, or your SlashStudio documents) across products by default. Such sharing occurs only when (a) you explicitly initiate a cross-product tool call via SlashAI, (b) you explicitly link accounts, or (c) you explicitly enable cross-product recommendations.

You may explicitly link your Account to pre-existing accounts on FreelanceHub, SlashBooks, TimePlate, or SlashStudio. Linked accounts are recorded in our PostgreSQL database. You may unlink any account at any time from the Connections page; unlinking is a soft delete (the row is marked as unlinked but retained for audit purposes for 7 years).

If you delete your Account, all product_accounts links are removed; product-specific data is deleted or anonymised in accordance with our retention schedule (see §8).

7. AI & Machine-Learning Data Processing

When you use AI Features, including SlashAI, your queries, the product data you authorise SlashAI to access, and the AI-generated responses are:

(a) Sent to the underlying AI provider (e.g. MiniMax, DeepSeek) over encrypted channels (TLS 1.3) to generate the response. The provider returns the response, which is then streamed back to you and stored in your session history.

(b) NOT used to train any AI model. We contractually prohibit our AI providers from training on your data. The "Zero-Retention" setting available in some product tiers enforces this at the API level (no prompt or response is logged by the provider).

(c) Stored in your account history for the duration of your account plus 30 days after deletion, to allow you to retrieve past conversations and to comply with legal obligations.

(d) Subject to memory — you may instruct SlashAI to remember specific facts (Memory entries) and to perform scheduled tasks (scheduled Jobs). Memory entries and Jobs are visible and editable in your account dashboard at any time.

SlashAI may invoke third-party tools (e.g. Google Workspace, Stripe, WhatsApp) on your behalf. Each tool invocation is logged in your account activity log and can be reviewed or revoked at any time. We are not responsible for the actions of any third-party service in response to a tool call.

8. Data Retention

We retain Personal Data for as long as necessary to provide the Services and comply with our legal obligations. Specifically:

(a) Account Data — retained while your Account is active. Upon Account deletion, your email is replaced with a tombstone (`deleted+<id>@erased.local`) and your name, avatar, and other identifiers are cleared. Soft-deleted data is purged after 30 days. Backups are purged after 90 days.

(b) Product Data (e.g. documents, invoices, schedules) — retained while your Account is active. You may delete individual items at any time; the deletion is permanent and propagated to all backup systems within 30 days.

(c) Billing Records — retained for 7 years as required by Hong Kong tax law (Inland Revenue Ordinance Cap. 112) and applicable anti-money-laundering law (Cap. 615).

(d) Audit Logs — retained for 7 years for security, fraud detection, and regulatory compliance.

(e) AI Session History — retained while your Account is active plus 30 days after deletion, to allow you to retrieve past conversations.

(f) Cookies — see Cookie Policy for cookie-specific retention periods.

(g) Anonymised Data — may be retained indefinitely for analytics and product improvement.

(h) Backups — encrypted backups are retained for 90 days, after which they are securely destroyed.

9. Data Subject Rights (PDPO + GDPR)

Under the PDPO (Cap. 486), you have the right to: (a) check whether we hold Personal Data about you (Data Access Request); (b) require us to correct any data that is inaccurate; (c) ascertain our general policies and practices in relation to Personal Data; and (d) opt out of direct marketing.

Under the GDPR (if you are in the EEA or the UK), you additionally have the right to: (e) request erasure ("right to be forgotten"); (f) request restriction of processing; (g) data portability in a structured, commonly used, machine-readable format (JSON or CSV); (h) object to processing based on legitimate interests or for direct marketing; (i) withdraw consent at any time (where processing is based on consent) without affecting the lawfulness of processing carried out before withdrawal; and (j) lodge a complaint with your local data-protection authority.

To exercise any of these rights, submit a request to privacy@slashhub.hk from the email associated with your Account. We will respond within 30 days (PDPO allows up to 40 days for complex requests) or 30 days (GDPR Article 12), free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse, with reasons).

If you are in the EEA/UK, you also have the right to lodge a complaint with your local data-protection authority. A list of EU DPAs is available at edpb.europa.eu; the UK ICO is at ico.org.uk. If you are in Hong Kong, you may complain to the Office of the Privacy Commissioner for Personal Data at pcpd.org.hk.

10. Cookies & Tracking

We use cookies and similar technologies (localStorage, sessionStorage, IndexedDB) to provide and improve the Services. The categories are: (a) Strictly Necessary — required for authentication, security, and load balancing; (b) Functional — remember your preferences (theme, language, last-used workspace); (c) Analytics — anonymised usage statistics; (d) Marketing — only with your consent.

See our Cookie Policy for the full list of cookies, their purposes, and retention periods. You can manage cookie preferences from the cookie banner shown on your first visit, from your account settings, or from your browser settings.

We respect the Global Privacy Control (GPC) signal. When your browser sends the GPC header, we treat it as a valid opt-out of sale/sharing for California residents and as a valid withdrawal of consent for non-essential cookies for all users.

11. Security Measures

We employ industry-standard security measures to protect your Personal Data, including: (a) TLS 1.3 for all data in transit; (b) AES-256 encryption at rest; (c) scrypt password hashing; (d) SHA-256 hashing of all authentication tokens at rest; (e) short-lived JWT access tokens (15 min) with rotating refresh tokens (30 days); (f) HttpOnly Secure cookies with SameSite=Lax; (g) CSRF protection on all state-changing endpoints; (h) rate limiting (per-IP and per-Account); (i) audit logging of all data access; (j) per-Account row-level security in our PostgreSQL database; (k) encrypted backups stored in geographically separate regions; (l) regular third-party penetration tests (at least annually); (m) a documented incident-response plan; and (n) employee security training.

Access to Personal Data is restricted to employees and contractors with a need to know, who are bound by confidentiality obligations and subject to background checks. We conduct quarterly access reviews.

Despite our efforts, no system is 100% secure. In the event of a personal-data breach, we will notify affected users and applicable supervisory authorities in accordance with §14 and applicable law.

12. International Data Transfers

We are headquartered in Hong Kong. Personal Data is primarily processed in Hong Kong, with backups stored in Singapore (encrypted) and Ireland (for EU/UK data subjects).

When we transfer Personal Data outside Hong Kong (for example, to a third-party processor in the United States), we rely on one of the following safeguards: (a) the EU Standard Contractual Clauses (Decision 2021/914); (b) the UK International Data Transfer Addendum; (c) the recipient's participation in a recognised cross-border privacy framework (e.g. EU-US Data Privacy Framework); (d) the recipient's binding corporate rules; or (e) your explicit consent.

AI providers (MiniMax, DeepSeek, and others) currently process data in their data centres, which may be located in the US, Europe, or Asia. Each provider is bound by a Data Processing Agreement that includes Standard Contractual Clauses and a prohibition on using your data to train their models.

A list of our subprocessors and their locations is maintained at slashhub.hk/subprocessors and is updated at least 30 days before any change.

13. Automated Decision-Making (GDPR Article 22)

We use automated decision-making only in narrow, well-defined cases: (a) fraud detection (blocking suspicious sign-ins or transactions); (b) abuse detection (suspending Accounts that violate the AUP); and (c) AI Features where you explicitly invoke an automated action (e.g. SlashAI generating a financial report).

In cases (a) and (b), you have the right to obtain human review of the decision. To request review, contact privacy@slashhub.hk. We will respond within 30 days.

We do NOT use automated decision-making that produces legal or similarly significant effects on you (e.g. automated denial of credit, automated termination of employment, automated assessment of personal reliability) without your explicit consent. If we propose to introduce such processing, we will provide at least 30 days' notice and an opt-out.

AI Features (SlashAI) are not a substitute for human review. You are responsible for reviewing AI-generated Content before relying on it for any consequential decision. See §11 (Disclaimers) of our Terms of Service for the full disclaimer.

14. Data Breach Notification

A "personal data breach" is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (a) notify the Office of the Privacy Commissioner for Personal Data (Hong Kong) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (PDPO Section 1(3)); (b) notify the lead supervisory authority (if applicable) within 72 hours (GDPR Article 33); and (c) notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects.

We maintain a documented incident-response plan and conduct tabletop exercises at least annually. Our security team is on-call 24/7/365 for breach response.

15. Children's Privacy

The Services are not directed to children under 13 (or under 16 in the EEA/UK, or as otherwise required by applicable law). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child in violation of applicable law, we will delete it as soon as possible.

If you believe a child has registered, contact privacy@slashhub.hk and we will delete the Account within 7 days. Parents or guardians who believe their child has provided Personal Data to us may request access, correction, or deletion of that data.

Some features (e.g. time tracking in TimePlate) may be used by minors (e.g. teenage part-time workers) under the supervision of a parent, guardian, or employer who is the Account holder. In such cases, the Account holder is responsible for obtaining any necessary consents and for ensuring compliance with applicable child-labour laws.

16. Changes to This Privacy Policy

We may modify this Privacy Policy from time to time. If we make a material change, we will notify you at least 30 days before the change takes effect by email and by a prominent notice in the Services. The notice will identify the material change and provide access to the previous version for comparison.

Your continued use after the effective date constitutes acceptance. If you do not agree, you may close your Account before the effective date and request deletion of your Personal Data in accordance with §9.

A version history with diffs is available at slashhub.hk/privacy/history.

17. Contact & DPO

For questions, data-subject requests, or complaints, contact our Data Protection Officer:

SlashHub Data Protection Officer

Email: dpo@slashhub.hk

Address: [DPO Address, Hong Kong]

For general privacy questions: privacy@slashhub.hk

For EU/UK data subjects, our EU representative is: [EU Representative — appoint before EU expansion] (eu-rep@slashhub.hk).

You may also lodge a complaint with: (a) the Office of the Privacy Commissioner for Personal Data (Hong Kong) at pcpd.org.hk; (b) your local data-protection authority if you are in the EEA/UK; or (c) any other competent supervisory authority in your jurisdiction.

Product-Specific Addendum — freelancehub

The following additional terms apply specifically to freelancehub and supplement the main document above.

F-1. FreelanceHub-Specific Terms (Escrow & Marketplace)

FreelanceHub operates an online marketplace connecting freelancers ("Talent") with clients ("Clients") and provides optional escrow services for the secure transfer of payment funds. By using FreelanceHub as Talent or Client, you agree to the additional terms in this Addendum.

**Escrow Service.** When a Client and Talent agree to use escrow, the Client's payment is held by SlashHub's regulated payment partner (currently Airwallex Hong Kong Limited, SVF licence issued by the Hong Kong Monetary Authority) until the work is delivered and approved, or until a dispute is resolved. SlashHub does not itself hold the funds; Airwallex holds them in a segregated client account.

**Service Fees.** SlashHub charges a service fee on each completed transaction. The fee is disclosed to both parties before the transaction is initiated. The fee is non-refundable except in cases of demonstrable platform error.

**Dispute Resolution.** If a Client and Talent cannot agree on whether work has been satisfactorily delivered, either party may initiate a dispute. Disputes are resolved by a SlashHub dispute resolution specialist within 14 days, with the option to escalate to binding arbitration under the HKIAC rules. During the dispute, the escrowed funds remain frozen.

**Talent Obligations.** Talent represents and warrants that (a) they have the right to perform the services and assign the deliverables; (b) the deliverables do not infringe any third-party rights; (c) they hold all necessary licences or registrations required in their jurisdiction; and (d) they will comply with applicable tax laws (SlashHub reports payments to tax authorities as required).

**Client Obligations.** Client represents and warrants that (a) the brief does not request illegal services; (b) the payment method is theirs or they are authorised to use it; and (c) the deliverables are not intended for unlawful purposes.

F-2. KYC & Anti-Money-Laundering

To comply with Hong Kong Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) and similar laws, SlashHub performs Know-Your-Customer (KYC) checks on all users. By using FreelanceHub, you consent to: (a) verification of your identity via third-party providers (e.g. Stripe Identity); (b) screening against sanctions lists; (c) reporting of suspicious transactions to the Joint Financial Intelligence Unit (JFIU).

Failure to complete KYC may result in suspension of your Account and forfeiture of pending escrow funds (which will be held until verification is complete).

This document is a template provided by SlashHub and must be reviewed by qualified legal counsel in your jurisdiction before publication. © SlashHub. All rights reserved.