Slidesearch Data Processing Agreement
Last updated: June 5, 2026
This Data Processing Agreement ("DPA") applies when O8X B.V. processes personal data on behalf of a customer in connection with Slidesearch. It forms part of the Slidesearch Service Terms, unless the parties have agreed a separate written data processing agreement.
If this DPA conflicts with the Service Terms, this DPA prevails for personal data processing. The Service Terms continue to govern all other matters.
1. Roles And Scope
The customer is the controller of personal data contained in customer workspaces, repositories, presentations, connected Microsoft 365 environments, and related service configuration.
O8X B.V. acts as processor for that personal data and processes it only to provide, secure, support, and maintain Slidesearch.
2. Processing Details
The subject matter is the provision of Slidesearch.
The duration is the term of the customer's use of Slidesearch, plus any period needed for deletion, backups, legal holds, or operational records.
The nature and purpose of processing are hosting, indexing, searching, previewing, retrieving, securing, logging, supporting, and maintaining the service.
The personal data may include account data, authentication data, workspace data, usage and diagnostic data, support communications, customer content, repository metadata, search queries, prompts, logs, and service configuration.
Data subjects may include customer users, administrators, employees, contractors, clients, prospects, and other individuals whose data appears in customer content or connected repositories.
3. Customer Instructions
O8X B.V. will process personal data only on documented customer instructions, including instructions reflected in the Service Terms, product configuration, customer-managed integrations, and other written agreements.
If O8X B.V. believes an instruction violates applicable data protection law, it will inform the customer unless legally prohibited.
4. Processor Commitments
O8X B.V. will:
- keep personal data confidential and ensure personnel with access are subject to confidentiality obligations;
- implement reasonable technical and organizational measures designed to protect personal data;
- assist the customer with data subject requests and data protection obligations where required by law and reasonably possible;
- assist the customer with security, breach notification, data protection impact assessment, and prior consultation obligations where required by law and reasonably possible;
- notify the customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA;
- make available information reasonably necessary to demonstrate compliance with this DPA, including security documentation, audit reports, or certifications where available;
- support reasonable audits or inspections with advance notice, confidentiality protections, and limited disruption to the service; and
- delete or return personal data after termination or an authorized deletion request, subject to backups, legal holds, and operational requirements.
5. Subprocessors
The customer gives O8X B.V. general authorization to use subprocessors to provide Slidesearch.
The current list is available in Subprocessors. O8X B.V. will require subprocessors to protect personal data under terms consistent with this DPA.
O8X B.V. will give at least 30 days' notice of intended subprocessor additions or replacements where reasonably possible. The customer may object on reasonable data protection grounds before the change takes effect.
6. International Transfers
O8X B.V. will process and transfer personal data only as needed to provide Slidesearch and in accordance with applicable data protection law.
Where required for an international transfer, O8X B.V. will use an appropriate transfer mechanism, such as the EU Standard Contractual Clauses.
7. Annex 1: Security Measures
O8X B.V. uses technical and organizational measures appropriate to the service, including:
- encryption in transit using TLS;
- encryption at rest where supported by the relevant storage or infrastructure service;
- access controls designed to limit access to authorized personnel and service components;
- logging and monitoring for security, reliability, and operational events;
- logical separation of customer workspaces and service environments;
- backup, retention, and deletion processes designed to protect service continuity and data lifecycle requirements; and
- confidentiality obligations for personnel with access to personal data.
8. Contact
Questions about this DPA may be directed to: