Published document · PortalSix-approved for release
How it applies
The DPA for the organization’s use of Slash Social.
The complete DPA and its processing, security, and transfer schedules follow below. PortalSix has approved this exact version for release; this summary is not a substitute for the schedules or an executed copy.
Published and owner-approved
PortalSix has approved this exact version for release. It is the version incorporated when PortalSix processes Customer Personal Data on the customer organization’s behalf under the applicable agreement.
Organization-level acceptance
A workspace administrator or other authorized signer accepts for the organization—not for each brand.
International mechanisms
The schedules include EEA SCC, UK Addendum, and Swiss selections without promising regional data residency.
Execution copies available
Request an execution copy tied to the current version and SHA-256 through support. The applicable agreement determines when it takes effect for an organization.
This Data Processing Addendum (DPA) is between PortalSix, LLC (PortalSix, we, us) and the customer organization that agrees to the Slash Social Terms or a written order (Customer). It forms part of the Terms or other agreement governing Customer's use of Slash Social (Agreement).
This DPA applies automatically whenever PortalSix processes Customer Personal Data on Customer's behalf. The person accepting the Agreement represents that the person has authority to bind Customer. Customer may request an execution copy through the support contact without changing the effectiveness of this DPA.
Definitions and scope
Customer Personal Data means personal data or personal information contained in data that Customer or its authorized users submit to, store in, or direct PortalSix to collect or process through Slash Social. Data Protection Law means privacy, data-protection, and data-security law applicable to that processing, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, CCPA, and implementing law as applicable.
Controller, processor, business, service provider, contractor, personal data, personal information, processing, sale, and sharing have the meanings given by applicable Data Protection Law. The processing subject matter, duration, nature, purpose, data subjects, and data categories are described in Schedule 1.
Roles and documented instructions
Customer is the controller or business for Customer Personal Data, and PortalSix is the processor, service provider, or contractor. If Customer is itself a processor, PortalSix acts as Customer's subprocessor. Customer determines the purposes and essential means of processing and is responsible for lawful instructions, notices, consents, and rights needed for the processing.
PortalSix will process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's configuration and authorized use of Slash Social, support instructions, and instructions required by applicable law. PortalSix will inform Customer if an instruction appears to violate applicable Data Protection Law unless law prohibits that notice.
PortalSix acts as an independent controller for limited account administration, direct business communications, billing and tax records, service security, fraud prevention, dispute management, and legal compliance. Those activities are governed by the Privacy Policy rather than by processor instructions in this DPA.
Confidentiality and personnel
PortalSix will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations, receive access only as needed for their responsibilities, and process the data consistently with this DPA. PortalSix remains responsible for their compliance within the scope of PortalSix's obligations.
Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing, PortalSix will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures are described in Schedule 2 and the Trust Center.
PortalSix may update security measures as technology and risk change, provided the overall protection of Customer Personal Data is not materially reduced during the service term.
Subprocessors
Customer gives PortalSix general written authorization to use subprocessors to process Customer Personal Data. PortalSix will impose written data-protection obligations on each subprocessor that are no less protective in material respects than the obligations applicable to that subprocessor's processing under this DPA. PortalSix remains responsible for each subprocessor's performance to the extent required by applicable Data Protection Law.
The current approved subprocessor schedule is published at Subprocessors. PortalSix will provide at least 30 days' advance notice before a new subprocessor begins processing Customer Personal Data, except when an emergency replacement is reasonably necessary and advance notice is not practicable. In that case PortalSix will provide notice without undue delay and document the necessity.
Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith toward a reasonable resolution. If they cannot resolve the objection, PortalSix may disable the affected feature or Customer may terminate the affected service without penalty for future periods. This section does not classify a customer-directed connected platform as a PortalSix subprocessor when the platform acts under Customer's direct instruction or as an independent controller.
Data-subject requests and customer assistance
Taking into account the nature of processing, PortalSix will provide reasonable assistance with data-subject requests through appropriate technical and organizational measures so Customer can respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data. PortalSix will promptly inform Customer of a request received directly about Customer Personal Data unless PortalSix is legally prohibited or is authorized to respond.
PortalSix's operational objective is to acknowledge a verified controller request within five business days and provide assistance within 15 business days when feasible. An earlier statutory or contractual deadline controls. These objectives do not replace Customer's legal response obligations.
Personal-data breaches
PortalSix will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. A Personal Data Breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. A security event that does not meet this definition is not a Personal Data Breach.
To the extent information is reasonably available, notice will describe the nature of the breach, affected data and persons, likely consequences, mitigation taken or proposed, and a contact for follow-up. PortalSix may provide information in phases and will reasonably assist Customer with required notifications and investigation. Notification is not an admission of fault or liability.
Assessments and regulator consultations
Taking into account the nature of processing and information available to PortalSix, PortalSix will provide reasonable assistance with Customer's data-protection impact assessments and prior consultations with supervisory authorities where the processing through Slash Social requires them.
Government requests
Unless prohibited by law, PortalSix will notify Customer of a legally binding government request for Customer Personal Data. PortalSix will review requests for facial validity, challenge unlawful or disproportionate requests where reasonably appropriate, and disclose only data legally required. Nothing requires PortalSix to violate law or disclose privileged information.
Audit and compliance information
PortalSix will first make available information reasonably necessary to demonstrate compliance, such as current policies, available certifications, questionnaires, architecture and security summaries, subprocessor information, and relevant evidence. Customer will review those materials before requesting an audit.
If those materials are insufficient for a reasonable legal requirement, Customer may request a confidential, reasonably scoped, non-disruptive remote audit generally no more than once in any 12-month period. The audit may not provide production access, expose another customer's information, compromise security, or require disclosure of privileged material. Customer bears its audit costs unless the audit identifies material noncompliance by PortalSix.
The frequency and cost limits do not restrict a competent regulator's authority or reasonable additional review after a confirmed Personal Data Breach or material noncompliance. The parties will agree in advance on scope, timing, personnel, confidentiality, and evidence handling.
Return, deletion, and retention
Customer may export supported Customer Personal Data during the service term. Service termination begins a 30-day export window unless Customer waives it or applicable law requires an earlier action. After that window, PortalSix will delete active Customer Personal Data within its control unless a documented legal hold or legal retention requirement applies.
Protected backups are not restored for ordinary use and age out through documented normal cycles. PortalSix may retain narrowly limited independent-controller records needed for billing, tax, security, fraud prevention, disputes, and compliance. Upon written request, PortalSix will provide available information reasonably demonstrating completion of required deletion.
California service-provider and contractor restrictions
To the extent the CCPA applies to Customer Personal Data, PortalSix acts as Customer's service provider or contractor. PortalSix will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship except to provide Slash Social or as otherwise permitted by the CCPA; or combine it with personal information received from another person or from PortalSix's own consumer interactions except as permitted by the CCPA.
PortalSix certifies that it understands and will comply with these restrictions and will provide the level of privacy protection required by the CCPA. Customer may take reasonable and appropriate steps to help ensure compliant use and to stop and remediate unauthorized use after notice. PortalSix will notify Customer if PortalSix determines it can no longer meet these obligations.
International transfers
When Customer Personal Data subject to EEA, UK, or Swiss transfer restrictions is transferred to a country without an applicable adequacy decision, the transfer mechanisms and selections in Schedule 3 apply. A transfer mechanism does not create a commitment to regional data residency.
PortalSix will provide information reasonably needed for transfer assessments and will implement supplementary measures when required by applicable Data Protection Law. If a selected mechanism is invalidated, the parties will use another lawful mechanism and cooperate on necessary amendments.
Sensitive-data restrictions
Customer will not intentionally submit or direct PortalSix to process protected health information requiring HIPAA compliance; payment-card, bank-account, or online-banking credentials; government identification numbers or identity documents; passwords, private keys, or authentication secrets other than supported OAuth or token flows; biometric or genetic identifiers used for unique identification; or children's personal data where parental or guardian consent requirements apply.
Incidental sensitive material remains subject to this DPA's security, request, export, retention, incident, and deletion protections. This restriction does not excuse PortalSix from responding to a breach or rights request involving such material.
Precedence, liability, and term
This DPA controls over conflicting provisions of the Agreement for data-protection matters. The Standard Contractual Clauses or mandatory Data Protection Law control over this DPA where they conflict. Otherwise, the Agreement's liability limits, exclusions, governing law, and dispute provisions apply to this DPA to the maximum extent permitted by law.
This DPA remains in effect while PortalSix processes Customer Personal Data. Provisions that by their nature concern retained data, confidentiality, audits, deletion, transfers, disputes, or legal compliance survive termination for as long as relevant processing continues.
Updates and execution copies
PortalSix may update this DPA to reflect changes in law, transfer mechanisms, product behavior, or operational controls. Material changes receive a new version and effective date and require notice or renewed acceptance when applicable. Historical acceptance records continue to identify the exact version and content hash accepted.
To request an execution copy or ask a data-protection question, use the support form or email support@slashsocial.app.
Schedule 1 — Processing details
Subject matter and purpose: providing, securing, supporting, maintaining, and improving the customer-configured Slash Social service, including Slack workflows, drafting, media, approvals, publishing, connected-account operations, inbox activity, analytics, support, privacy operations, and related administration. Nature of processing: collection, recording, organization, storage, retrieval, consultation, use, transformation, transmission, restriction, export, and deletion as directed through the service.
Duration: the service term plus the export, deletion, backup-aging, legal-hold, and legally required retention periods described in this DPA and the Agreement. Frequency depends on Customer's configuration and use.
Data subjects may include Customer personnel and workspace users; contractors, clients, approvers, and collaborators; social account administrators; social audiences and persons appearing in Customer content, messages, comments, or analytics; support and privacy requesters; and other persons whose data Customer directs PortalSix to process.
Data categories may include workspace identity, organization and authorization data; selected Slack messages, commands, files, and metadata; drafts, copy, media, approvals, audit history, publishing and scheduling records; connected-account identifiers, OAuth credentials or tokens, provider records, comments, inbox items, and analytics; support, privacy, incident, security, and billing-administration records; and configuration, usage, device, network, and diagnostic data.
Customer's obligations and rights are those of controller or business under applicable law, including deciding lawful purposes and instructions, providing notices, obtaining permissions, responding to data subjects, maintaining appropriate access, and exercising the audit, objection, return, deletion, and termination rights in this DPA.
Schedule 2 — Technical and organizational measures
Access and tenancy: organization- and brand-scoped authorization, workspace resolution by Slack team identifier, role and persona checks, least-privilege operator access, protected administration, and negative isolation testing. Authentication material and provider credentials are stored and accessed through controlled service paths rather than exposed in customer interfaces.
Transport and storage: TLS for supported network transmission; managed-provider encryption for production storage where provided; secret and environment separation; signed and expiring state for sensitive handoffs; input validation; and controls designed to prevent unauthorized customer-data egress.
Reliability and integrity: transactional writes where required, immutable audit and acceptance evidence, idempotency claims, outbox delivery, retryable queues, backup and recovery controls, deployment gates, logging, monitoring, incident tracking, and reconciliation of deletion and external communications.
Development and vendor governance: code review, automated tests, dependency and recipient inventory, fail-closed feature and egress gates, separation of environments, restricted production changes, subprocessor review and flow-down terms, and periodic evaluation of technical and organizational measures. PortalSix does not claim a certification unless the current Trust Center expressly identifies it.
Schedule 3 — International-transfer selections
EEA transfers: the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 are incorporated by reference. Module 2 applies when Customer is controller and PortalSix is processor; Module 3 applies when Customer is processor and PortalSix is subprocessor. Docking applies. Optional Clause 7 applies; Option 2 in Clause 9 applies with the 30-day notice period in this DPA; the optional language in Clause 11 does not apply. For Clauses 17 and 18, the law and courts of Ireland apply unless mandatory law requires another eligible selection.
For Annex I, Customer is the exporter and PortalSix is the importer; the parties' identity and contact information come from the Agreement and acceptance record; the transfer details are those in Schedule 1; and the competent supervisory authority is determined under Clause 13, with the Irish Data Protection Commission used where the clauses require an eligible fallback. Schedule 2 supplies Annex II measures. The approved Subprocessors page and recipient evidence supply Annex III as applicable.
UK transfers: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner's Office is incorporated by reference. The parties, selected modules, transfer details, security measures, and subprocessors are completed from this DPA and the Agreement. Both parties may end the Addendum as permitted by its approved changes provisions.
Swiss transfers: references in the Standard Contractual Clauses to the GDPR and Member State law include the Swiss Federal Act on Data Protection to the extent applicable; supervisory-authority references include the Swiss Federal Data Protection and Information Commissioner; Swiss data subjects may enforce applicable rights; and Switzerland is the relevant forum to the extent Swiss law requires. These adaptations do not alter the clauses beyond what Swiss law permits.