Privacy Policy
Last updated: 1 May 2026This Privacy Policy explains how Slabr™ (“Slabr”, “we”, “us”) collects, uses, stores and protects personal information when you visit our website, use our software, or engage with our team. We comply with the Protection of Personal Information Act (POPIA) of South Africa and, where applicable, the EU General Data Protection Regulation (GDPR).
- 1. Who we are
- 2. What we collect
- 3. How we use your data
- 4. Legal bases (GDPR) / lawful processing (POPIA)
- 5. How we share your data
- 6. Sub-processors
- 7. Data retention
- 8. International transfers
- 9. Your rights
- 10. Cookies & tracking
- 11. Security
- 12. Children
- 13. Changes to this policy
- 14. Contact us
1. Who we are
Slabr is a software-as-a-service operating system for custom manufacturers. We are the data controller for personal data we collect about visitors and direct customers, and a data processor for personal data our customers submit through the platform.
2. What we collect
Information you provide
- Account data: name, email, role, company, phone number.
- Billing data: company name, billing address, VAT/registration numbers (handled by our payment processor).
- Communications: messages you send to support, sales, or our team.
- Workspace content: the quotes, jobs, clients, files and operational data your team puts into Slabr.
Information collected automatically
- Usage data: pages visited, features used, errors encountered (in-app analytics).
- Device data: browser, OS, IP address, approximate location.
- Cookies: see our Cookie Policy.
3. How we use your data
- To provide, maintain and improve the Slabr platform.
- To authenticate and secure your account.
- To process billing and respond to support requests.
- To send service-related notifications (you cannot opt out of these while using Slabr).
- To send product updates and marketing where you have opted in.
- To meet legal, regulatory and security obligations.
4. Legal bases (GDPR) / lawful processing (POPIA)
- Performance of a contract — to provide the services you have signed up for.
- Legitimate interest — to operate, secure and improve our platform.
- Consent — for marketing emails and non-essential cookies.
- Legal obligation — tax, accounting and law-enforcement requests where required.
5. How we share your data
We do not sell personal data. We share data only with:
- Sub-processors that help us run Slabr (cloud hosting, email delivery, analytics, support tooling).
- Integrations you choose to connect (Xero, Sage, Gmail, Paystack, etc.) — only the data needed for that integration.
- Authorities, where required by law.
- A successor entity in the event of a merger, acquisition or asset sale, under equivalent privacy commitments.
6. Sub-processors
Our current list of sub-processors and their purpose is available on request. Email privacy@slabr-os.app for the latest list.
7. Data retention
We keep account and workspace data for the duration of your subscription plus a reasonable wind-down period (typically 30 days). On request we will delete or export your data sooner. Some records (financial, legal) may be retained longer where required by law.
8. International transfers
Slabr is hosted in regions selected for low-latency access to our customer base. Where data crosses borders, we use standard contractual clauses or equivalent safeguards required under POPIA/GDPR.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time.
- Lodge a complaint with the Information Regulator (South Africa) or your local supervisory authority.
To exercise any right, email privacy@slabr-os.app. We respond within 30 days.
10. Cookies & tracking
See our full Cookie Policy. You can opt out of non-essential cookies at any time.
11. Security
See our Security page for full detail. Highlights: TLS 1.3, AES-256 at rest via our managed database, tenant isolation with row-level security, role and capability-based access, append-only audit logging on critical security, job and finance actions, and incident-response procedures with affected-customer notification aligned to applicable law.
12. Children
Slabr is a B2B product and is not directed at anyone under 18. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy as the platform evolves or laws change. Material changes will be communicated by email and in-app. Continued use of Slabr after changes take effect indicates acceptance.
14. Contact us
Privacy questions, data requests or complaints: privacy@slabr-os.app.