Welcome to Slidis. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website slidis.ie (including joining our waitlist) or use the Slidis mobile application (collectively, the “Service”).
Please read this policy carefully to understand our practices regarding your personal data.
1. Data Controller and Contact
For the purpose of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, the data controller is:
- Entity: Slidis App (Ireland)
- Email: legal@slidis.com
- Web: slidis.ie/contact
2. Your Rights Under GDPR
As an EU resident, you possess the following statutory rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your personal data.
- Right to Restrict or Object to Processing: Request that we limit how we process your data.
- Right to Data Portability: Request transfer of your data to another service provider.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
2.1 Request Handling and Safeguards
To exercise any of these rights, please contact us at legal@slidis.com. To protect your privacy, we will apply the following statutory procedures:
- Identity Verification: We reserve the right to request proof of your identity (such as confirming access to the registered email account) before acting on any request. We will not process requests where identity cannot be verified.
- Standard Timeline: We aim to respond to all legitimate requests within 30 days (one month) free of charge.
- Extension for Complexity: If your request is particularly complex or if we receive a high volume of requests, we may extend this period by a further 60 days (up to 90 days total). We will notify you of such an extension and the reasons for it within the first 30-day window.
- Abusive and Excessive Requests: In accordance with Article 12(5) GDPR, if your requests are manifestly unfounded, repetitive, or excessive (e.g., systematic automated spam), we reserve the right to either charge a reasonable administrative fee or refuse to act on the request.
3. Right to Lodge a Complaint
If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with the lead supervisory authority in Ireland:
- Authority: Data Protection Commission (DPC)
- Website: dataprotection.ie
4. Location Tracking and GPS Telemetry
To map, analyze, and provide feedback on your practiced driving test routes, the Slidis mobile application requires precise location data.
4.1 Location Access (expo-location)
- Explicit Consent Required: The App will request your permission to access your device’s precise GPS location while you are using the App.
- Purpose-Driven Tracking: This data is captured only while you are actively recording a practice drive session. We do not track your location when the session is stopped or when the App is closed outside of active practice mode.
- Control: You can grant, modify, or completely revoke location access at any time through your device’s system settings. If you disable location permissions, you will not be able to record driving routes.
4.2 Anonymization of Telemetry for AI Processing (Planned / Upcoming)
To generate smart driving insights (such as speed limit compliance and driving line analysis), anonymized telemetry data is planned to be processed asynchronously using artificial intelligence models (such as Google Gemini via secure APIs).
- Zero-Retention Anonymization: Prior to sending any driving log to external AI services, we remove all direct identifiers. Your User ID, email, precise start/end coordinates (to prevent identification of your home or workplace), and metadata are completely stripped.
- No Training on Your Data: The external AI APIs process this data stateless-ly under strict zero-data-retention agreements and do not use your data to train their models.
5. What Personal Data We Collect and Why
5.1 Account Registration & Authentication (Web/App)
We collect personal data when you create an account, log in, or sign up for our waitlist:
- Direct Registration (Email): We collect your email address and a secure, salted hash of your password.
- Federated Authentication (Google SSO & Apple SSO): If you choose to log in or register using your Google or Apple accounts, we request and process the following profile data provided by the identity provider:
- Email Address: To identify, verify, and secure your account.
- First Name & Last Name: To personalize your in-app experience.
- Username / Display Name: For your in-app profile identifier.
- Avatar / Profile Picture URL: To display your user profile image within the App.
- Legal Basis:
- Consent (Art. 6(1)(a) GDPR) for joining the pre-launch waitlist.
- Performance of a Contract (Art. 6(1)(b) GDPR) to create your account, facilitate secure third-party login, build your profile, and manage your active sessions.
5.2 Device Storage & Session Data
- Data Collected: Authentication tokens, system preferences.
- Storage Methods: Secured local storage (expo-secure-store for JWT auth tokens, and standard device storage for non-sensitive local settings).
- Purpose: To keep you securely logged into your account without requiring credentials on every launch.
5.3 Crash Reporting and Analytics (Planned)
To ensure system stability and optimize the user interface, we plan to utilize:
- Sentry: For crash reporting and software bug tracking. This processes device diagnostic metadata and anonymized stack traces.
6. Where Your Data is Stored
- Network & Routing Layer: All network traffic, including website visits and API requests, is routed through and protected by Cloudflare, Inc. (acting as our DNS, Content Delivery Network, and Web Application Firewall provider). Cloudflare processes transient technical metadata (such as IP addresses and device headers) to ensure service security and speed.
- Waitlist Database: Stored securely in a Cloudflare D1 serverless database operated by Cloudflare, Inc.
- Backend Database (Planned): Managed in a production PostgreSQL database hosted on secure Virtual Private Cloud (VPC) nodes provided by Oracle Cloud Infrastructure (OCI).
- Strict EU Location: All databases, servers, and cloud resources are physically located within the European Union. Infrastructure routing layers utilize the Dublin, Ireland region, while the primary backend databases and processing servers operate securely within the Amsterdam, Netherlands region. No unanonymized personal data is transferred or stored outside of EU boundaries.
7. Data Retention
We retain your data only for as long as necessary to fulfill the purposes outlined in this policy:
- Waitlist Emails: Retained until the Slidis mobile application officially launches and you are invited, or until you request deletion. If the pre-launch project is discontinued, all waitlist data will be permanently purged.
- Active Accounts: Your email, profile details (first name, last name, display name, avatar URL), and account preferences are retained for the lifetime of your registered account.
- GPS Telemetry Logs: Retained in our database to build your personal route history. You may delete individual logs or purge your entire driving history at any time from the App settings.
8. Data Security
We implement robust technical and organizational measures to protect your data, including secure HTTPS transmission, end-to-end JWT token encryption, and strict database access controls. However, no electronic transmission over the internet or storage method is 100% secure; we cannot guarantee absolute security.
9. Changes to This Privacy Policy
We may update this Privacy Policy to reflect technical or operational changes.
- Material Updates: If we make changes that alter your rights or how we process your personal data, we will notify you at least 14 days in advance via email or a prominent notification inside the App.
- Non-Material Updates: Minor text adjustments, typo corrections, or formatting fixes become effective immediately upon being published on this page.
- Acceptance and Active Consent: For material updates, you will be required to actively review and accept the updated Privacy Policy inside the App (e.g., via a blocking consent prompt) to continue using your registered account. For non-material updates, continued use of the Service after the update constitutes your acknowledgment of the changes.
10. Account Deletion
You can delete your account and all associated data at any time.
- In-App Deletion (Self-Service): You can trigger immediate account deletion directly inside the Slidis mobile application by navigating to Settings > Account > Delete Account. This action permanently deletes your profile and email address. All saved driving route logs are completely anonymised and decoupled from your identity.
- Manual Request: Alternatively, you can request deletion by contacting us at legal@slidis.com.com from your registered email address. We will verify your identity and delete your credentials within 14 days. Your telemetry logs are permanently anonymised.
- Web-Based Form: For full instructions and direct options, visit our dedicated Account Deletion page.
Please note that account deletion is permanent and irreversible. Once completed, your personal route history and settings cannot be recovered or restored to your identity.