Privacy Policy

Learn how Threewords Technologies Pvt Ltd collects, uses, discloses, retains, and processes personal data.

Threewords Technologies Pvt Ltd("SliceFlo," "we," "us," or "our") provides this Privacy Policy to explain how we collect, use, disclose, retain, and otherwise process personal data when you access our website’s, create or use a SliceFlo account, interact with a SliceFlo workspace, communicate with us, or otherwise engage with our services (collectively, the "Services").

1

Scope and Applicability

This Privacy Policy applies to personal data we process as a data controller—that is, when we determine the purposes and means of processing. It covers information collected through our website, account registration, billing, support, and direct communications.

It does not apply to Customer Data (as defined in our Terms of Service) that we process on behalf of a workspace administrator; such processing is governed by our Terms of Service, any applicable Data Processing Addendum, and the instructions of the relevant customer.

Capitalized terms not defined herein have the meanings set forth in our Terms of Service.

2

Controller and Processor Roles

We process personal data in two capacities:

a

SliceFlo as a Data Controller / Data Fiduciary

When you visit our website, register an account, subscribe to a paid plan, contact support, or otherwise interact with us directly, we determine the purposes and means of processing your personal data. For these activities, we act as a data controller under the GDPR and UK GDPR, a data fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), and a business under applicable U.S. state privacy laws.

b

SliceFlo as a Data Processor

When a customer organization (the workspace administrator) uses the Services to store, manage, and process tasks, files, comments, and other project content ("Customer Data"), we process such data solely on the customer's documented instructions. In that context, the customer is the data controller (or data fiduciary), and we act as a data processor (or service provider).

Individuals with access to a workspace managed by an organization should direct inquiries about Customer Data to that organization's workspace administrator.
3

Personal Data We Collect

We collect the categories of personal data described below. The specific data elements depend on how you interact with the Services.

CategoryExamples
Account and Profile DataFull name, work email address, profile photograph (if provided), organization or team name, job title, role, industry, company size, and the purpose for which you intend to use SliceFlo.
Authentication and Security DataPassword hashes, single sign-on tokens (via Google OAuth or Microsoft OAuth), session identifiers, and security challenge responses.
Workspace and Customer DataTask descriptions, comments, @mentions, assignees, due dates, file attachments, project names, and any other content you create or upload within a workspace.
Usage, Device, and Log DataIP address, browser type and version, operating system, device identifiers, pages visited, features used, clickstream data, referring and exit URLs, timestamps, crash logs, and diagnostic data.
Support and Communications DataName, email address, content of support tickets, chat messages, feedback, survey responses, and related correspondence.
Billing and Transaction DataBilling contact name, billing address, plan details, transaction amounts, currency, invoice records, subscription identifiers, and limited payment-method information (such as card brand and last four digits) received from our payment processor. Full payment card numbers are not stored or accessible by SliceFlo.
Cookie and Tracking DataCookie identifiers, consent preferences, and analytics information collected as described in Section 12.

We do not intentionally collect special categories of personal data or similarly sensitive information (e.g., health data, biometric data, government-issued identifiers) unless you choose to include such data in your workspace content, in which case you are responsible for ensuring a lawful basis for doing so.

4

Sources of Personal Data

We obtain personal data from the following sources:

  • Directly from you: When you register an account, complete your profile, create or upload content, submit a support request, or make a payment.
  • From your organization or workspace administrator: When an administrator invites you to a workspace, assigns tasks, or configures account settings.
  • From authentication providers: When you sign in using Google OAuth or Microsoft OAuth, we receive your name and email address as authorized by your provider settings.
  • Automatically from your device and browser: Through cookies, server logs, and similar technologies when you use the Services.
  • From service providers and business partners: Including payment processors, analytics providers, and operational partners, consistent with their own privacy practices and applicable law.
5

Purposes and Legal Bases of Processing

We process personal data for the following purposes. Where the GDPR or UK GDPR applies, we rely on the legal bases indicated below.

PurposeDescriptionLegal Basis (EEA/UK)
Provision and administration of the ServicesCreating and maintaining accounts, authenticating users, hosting workspaces, enabling collaboration and file storage, processing payments, delivering support, and communicating service-related information.Contractual necessity; steps requested prior to entering into a contract.
Security and protectionDetecting and preventing fraud, abuse, and unauthorized access; maintaining audit logs; investigating security incidents; enforcing our Terms of Service; and protecting the rights, property, and safety of SliceFlo, our users, and the public.Legitimate interests; legal obligation; contract.
Billing and financial operationsProcessing subscription payments, generating invoices, maintaining financial records, and complying with tax obligations.Contract; legal obligation; legitimate interests.
CommunicationsSending transactional messages (account confirmations, security alerts, billing receipts), responding to inquiries, and delivering product-related updates. Marketing communications are sent only where permitted by applicable law and subject to your right to opt out.Contract; legitimate interests; consent (where required for marketing).
Service improvement and analyticsAnalyzing aggregated usage trends, measuring performance, troubleshooting, conducting internal research, and developing new features. Where reasonably possible, we use aggregated or de-identified data.Legitimate interests; consent (where required for non-essential analytics).
Legal and corporate purposesComplying with applicable laws, regulations, and legal process; responding to lawful requests from authorities; establishing, exercising, or defending legal claims; and supporting corporate transactions (e.g., merger, acquisition, financing).Legal obligation; legitimate interests.

Where we rely on legitimate interests, those interests include operating, securing, and improving a business-to-business SaaS service, understanding service usage, preventing misuse, and communicating with business users. We balance those interests against your fundamental rights and freedoms.

You may object to processing based on legitimate interests as described in Section 11.

6

Disclosure of Personal Data

We may disclose personal data to the following categories of recipients for the purposes described in this Policy:

Workspace administrators and authorized users

Content you submit to a workspace is visible to other workspace members according to the permissions set by the workspace administrator.

Service providers and sub-processors

Third-party vendors that perform functions on our behalf, cloud hosting, payment processing, etc. Contractually bound to process data only on our instructions.

Professional advisers & counterparties

Legal counsel, auditors, insurers, and prospective acquirers or investors, subject to confidentiality obligations.

Law enforcement and authorities

Where disclosure is required by applicable law, regulation, legal process, or an enforceable governmental request.

No selling: We do not sell personal data for monetary consideration.

No sharing:We do not "share" personal data for cross-context behavioral advertising as defined under California law, and we do not use Customer Data for any form of third-party advertising.

7

Service Providers and Sub-Processors

The table below identifies the categories of service providers we engage, along with the specific entities currently processing personal data on our behalf.

ServiceProviderPurpose
Cloud infrastructure and file storageDigitalOcean; Amazon Web Services (AWS S3)Hosting the application and storing user-uploaded files.
Database hostingMongoDB AtlasCloud database services.
Content delivery and securityCloudflarePerformance optimization and DDoS mitigation.
AuthenticationGoogle OAuth; Microsoft OAuthSingle sign-on authentication.
Transactional email and messagingAmazon Web Services (AWS SNS)Sending service-related emails (e.g., password resets, notifications).
Marketing emailMailerLiteSending newsletters and marketing communications (with opt-out).
Payment processingRazorpayProcessing subscription payments and providing limited transaction metadata.
Business operations, CRM, and supportZoho OneInternal customer relationship management, support ticketing, and communication.
An up-to-date list of sub-processors, including their processing locations, is available at sliceflo.com/sub-processors. We will update that list at least 14 days before engaging a new sub-processor, where feasible, and we will notify affected customers in accordance with our Terms of Service.
8

International Data Transfers

SliceFlo's primary production servers are located in the United States (US-East region). Threewords Technologies Pvt Ltd is based in India, and certain service providers may process personal data in other jurisdictions.

When personal data is transferred across borders, we ensure appropriate safeguards are in place. These may include the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement or UK Addendum to the SCCs, or other lawful transfer mechanisms.

You may request further information about the specific safeguards we rely upon by contacting us at [email protected]. We may redact confidential or commercially sensitive information from any documentation provided.

9

Data Retention

Personal data is retained only for as long as reasonably necessary to fulfill the purposes for which it was collected, to comply with legal, accounting, or reporting obligations, and to resolve disputes or enforce agreements. The applicable retention period varies by data category.

Data CategoryRetention Period
Account and profile dataFor the life of the account. Upon account deletion, data is disabled immediately and permanently deleted from active systems within 30 days for paid accounts, and immediately for free accounts.
Customer Data (workspace content)For the duration of the workspace subscription. Deleted in accordance with the account deletion timeline described above.
BackupsEncrypted backups (MongoDB Atlas, DigitalOcean snapshots, AWS S3 versioning) are retained for a maximum of 30 days and then automatically overwritten or purged. Backups are not restored to production except for disaster recovery.
Billing and financial recordsRetained for the period required by applicable tax, accounting, and corporate laws (typically up to 7 years).
Security and audit logsRetained for a period reasonably necessary to secure the Services and investigate incidents, not exceeding the applicable legal retention period.
Marketing dataRetained until you opt out or unsubscribe, at which point we may retain a limited suppression record to honor your preference.

Where data is deleted, it may not be immediately removed from all backup systems, but it will be purged in the ordinary course of the backup cycle and will not be restored to active use except as necessary for disaster recovery.

10

Security and Breach Notification

We implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal data against accidental, unauthorized, or unlawful access, disclosure, alteration, loss, or destruction.

These measures include encryption in transit (TLS/HTTPS), encryption at rest for sensitive data, access controls, secure development practices, regular vulnerability assessments, and incident response procedures.

If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected individuals and any relevant supervisory authority without undue delay, in accordance with applicable data protection law. Notifications will describe the nature of the breach, the categories of data concerned, and the measures taken or proposed to mitigate its effects.

⚠️ No security measure is absolute. You are responsible for maintaining the confidentiality of your account credentials and for securing the devices you use to access the Services.

Please notify us immediately at [email protected] if you suspect any unauthorized access to your account.

11

Your Data Protection Rights

Depending on your jurisdiction and our role in processing, you may exercise the following rights. We will respond to verifiable requests within the timeframes required by applicable law.

Standard Rights Available to Users

  • Access: Request confirmation of whether we process your personal data and obtain a copy.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of personal data, subject to legal retention requirements.
  • Restriction: Request limitation of our processing under certain circumstances.
  • Portability: Receive your personal data in a structured, commonly used, and machine-readable format.
  • Objection: Object to processing based on legitimate interests or direct marketing.

* Withdrawal of consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

12

Cookies and Tracking Technologies

We use cookies and similar technologies to ensure the functionality of the Services, enhance security, and analyze usage.

Strictly necessary cookies:

These are essential for authentication, session management, and security. They cannot be disabled through our consent tool and do not require consent under applicable law.

Analytics cookies:

We use Google Analytics to collect information about how visitors interact with our website and application, including IP address, browser details, and page interactions.

Where required by law, we will not deploy non-essential analytics cookies unless you have provided prior consent through our cookie consent banner. You may withdraw your consent or change your preferences at any time via the cookie settings link on our website. Google's own processing of analytics data is governed by its privacy policy.

Browser settings may also be configured to block or delete cookies; however, doing so may affect the functionality of the Services. We do not currently respond to "Do Not Track" browser signals.

13

Marketing Communications

We may send you promotional emails about product updates, features, and related content, provided we have a lawful basis to do so (such as your consent or our legitimate interest in marketing to business customers).

You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us at [email protected]. Unsubscribing will not affect service-related transactional emails necessary for the operation of your account.

14

Children's Privacy

The Services are intended for business and professional use and are not directed to individuals under the age of 16. We do not knowingly collect or solicit personal data from anyone under 16.

If we become aware that we have inadvertently collected personal data from an individual under the applicable age threshold, we will take steps to delete it promptly. If you believe a minor has provided us with personal data, please contact us at [email protected].

15

Third-Party Services

The Services may contain links to, or integrations with, third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to the privacy practices of those third parties.

When you enable an integration (such as Google or Microsoft for authentication), the data shared with that integration is governed by the third party's own privacy policy. We encourage you to review the privacy notices of any third-party services you choose to connect.

16

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law.

When we make material changes, we will post the revised policy on this page with a new effective date and provide notice through the Services or by email as required by law.

Your continued use of the Services after the effective date of the updated policy constitutes acceptance of the changes, except where a more explicit form of consent is required by applicable law.

17

Contact Information

For questions, concerns, or requests regarding this privacy policy or our privacy practices, contact us at:

Threewords Technologies Pvt Ltd

#502 Mahitas Green Meadows, Kondapur, Hyderabad, India – 500081

Email Support

[email protected]

Last updated: June 22, 2026