Snapshot 74863
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Introduction Supersonik is dedicated to safeguarding personal information. This policy details how the company collects, uses, discloses, and protects data received through its websites, product demo platform, integrations (including the Supersonik Slack app), and job applications. The policy aligns with the EU General Data Protection Regulation (GDPR) and applicable data privacy laws. Key Definitions: "Supersonik" refers to Supersonik, Inc. and its affiliates/subsidiaries "Controller" means Supersonik under GDPR and related data protection laws "Personal Information" encompasses any data identifying an individual, including names, identification numbers, location data, IP addresses, and factors relating to physical, physiological, genetic, mental, economic, cultural, or social identity Core Principles 1. Limited Data Sharing Supersonik shares personal information only for: User requests Processing transactions authorized by the user Legal disclosure requirements Assistance from marketing, recruiting, and service companies Professional advisory services 2. Processing Purpose and Legal Basis Personal Information Purpose Legal Basis Website visitor data, contact details, IP address Website provision and request responses Contract performance or legitimate interests Transaction and communication records Processing authorized transactions Contract performance Contact information Periodic product/service updates User consent Server diagnostic data Website administration Legitimate interests Job application materials Recruitment administration Pre-contract steps or legitimate interests All data types Legal/regulatory compliance Legal obligation 3. Security Safeguards Supersonik restricts information access to employees requiring it for job duties. The company maintains physical, electronic, and procedural safeguards complying with industry standards. Information systems and websites undergo routine testing to prevent unauthorized access. 4. Data Retention Retention periods depend on: Query-related data: reasonable period after relationship concludes Contract/service data: duration of service delivery plus reasonable query period Claims-related data: applicable legal claim period Regulatory requirements: as mandated by law Job applications: limited talent pool retention 5. International Data Transfers Supersonik operates globally with services hosted in France. Personal information may transfer internationally to affiliate locations and service providers. Transfer Recipients: Category Countries Purpose Data Types Customer support Spain Service and technical support Contact details Cloud providers (AWS) France Storage and security Name, voice data, account details, user history Payment processors (Stripe) US Payment processing Name, credit card details, billing address Marketing analytics (Google Analytics) Europe & US User analytics IP address, device info, browsing history EEA, UK, Gibraltar, and Swiss Residents Supersonik transfers personal data from these regions to the US and other countries using: Adequacy Decisions per GDPR Article 45 Standard Contractual Clauses (SCCs) and UK Information Commissioner's Office International Data Transfer Addendum (IDTA) Data Privacy Framework Compliance: Supersonik certifies adherence to the EU-US DPF, UK Extension to EU-US DPF, and Swiss-US DPF frameworks The company performs transfer impact assessments and continuously monitors transfers to maintain equivalent protection levels. DPF Dispute Resolution: EU, UK, Gibraltar, and Swiss individuals with DPF inquiries should contact our privacy team at dpo@supersonik.ai. The company investigates complaints within 45 days. Third-Party Responsibility: Supersonik acknowledges responsibility for third-party processing of personal information covered by this policy and remains liable under DPF Principles unless demonstrating non-responsibility for damages. 6. B2B Commercial Level Services target B2B commercial use exclusively. Consumers or those seeking non-commercial use should not register or submit personal information. Mistaken personal data collection will be deleted upon contact. Supersonik Slack App This section covers data received and processed when you install, connect, or use Supersonik in a Slack workspace. The rights and safeguards in this policy also apply to that data. Data We Receive Workspace and account information: Slack workspace ID and name, Slack user ID, installation credentials (OAuth bot tokens), and the connection to your Supersonik user and organization. Sender details for demo links come from your connected Supersonik account. Commands and interactions: slash command payloads, including the command, workspace, user and channel identifiers, temporary response URLs, and interaction identifiers. Slack also sends App Home and uninstall events. Text typed after /demo is received but is not used to create a demo link; you provide those details in the form. Information you submit: your selected demo, recipient email address, and any prospect details, questions, or context you enter in the app's form. If you separately connect Slackbot to Supersonik through MCP, we also receive the tool requests and arguments it sends, which can include context from your conversation, and return the requested Supersonik data. Messages and delivery information: the content of messages the app sends, such as demo links, completion summaries, configured insights, and personalized notifications supplied by authorized workflows. We also process destination user and channel IDs, message timestamps, delivery status, and error information. The Supersonik Slack app does not request permission to read your workspace's channel or direct-message history. Its Messages tab is used for notifications, not for receiving conversational requests. The optional Slackbot connection is separate from the /demo form. How We Use Slack App Data We use this information to connect your accounts, check your Supersonik permissions, display available demos, create personalized demo links, tailor the demo using the context you submit, and send or update notifications for the connected user. Identifiers, delivery records, and diagnostic information also help us prevent duplicate notifications, investigate failures, and maintain security. Storage and Sharing Workspace connections, submitted demo context, and notification delivery records are stored in Supersonik's service databases. Temporary interaction data is held in caches, and operational logs may contain identifiers, timestamps, and error information. OAuth bot tokens are encrypted before storage, and communication with Slack uses HTTPS. Supersonik sends message content and the identifiers needed for delivery to Slack. Submitted demo context is processed by Supersonik and its service providers to deliver the personalized demo. When you connect Slackbot or use an authorized automation, the information needed for that request also passes through the connected service. These services process data under their own applicable terms and privacy policies. Retention and Your Choices Temporary demo-form sessions expire after one hour. The temporary callback used to deliver a private command reply is removed when consumed or after 30 minutes. Account-connection requests expire after 10 minutes; completed requests are removed when used and expired requests are periodically deleted. Workspace identifiers, account connections, delivery records, and saved demo context are service data retained for service delivery and the support, claims, and legal purposes described in “Data Retention” above. Saved demo context does not expire with the temporary form session. Disconnecting your Supersonik account removes its Slack account connection. When Slack notifies us that the app has been uninstalled, we disable the workspace connection and clear its stored bot token. Uninstalling does not by itself erase saved demo context or all connection and delivery records. Messages already delivered to Slack are subject to your workspace's Slack retention settings. To request access, correction, export, or deletion of Slack app data held by Supersonik, email dpo@supersonik.ai. You do not need a Slack or Supersonik account to make a request. Include the email address associated with your data, if known. If someone invited you to a demo, you can also provide the inviting company or approximate demo date, if known, to help us locate your records. If you have a connected account, you may include your Slack workspace name and Supersonik account email. These additional details are optional. Please do not include passwords or access tokens. We may need to verify your identity or coordinate with the organization that provided your data to process the request. User Rights and Additional Information Feedback and Complaints Contact: legal@supersonik.ai or written correspondence to Supersonik's address. Users may lodge complaints with their country's Data Protection Authority if they believe Supersonik violates data protection obligations. Policy Modifications Changes to this policy will be posted on the website with notification via contact email, including impact explanations. Users are encouraged to review updates periodically. Key Rights Data Provision Notice: Submitted personal information is necessary for service provision. Failure to provide data may prevent service access. Supersonik does not employ automatic decision-making or profiling. Individual Rights (as applicable by jurisdiction): Access to held personal information Correction of inaccurate data Processing restriction or objection Erasure when retention is unnecessary Data portability in machine-readable formats Automated decision-making objection Consent withdrawal Marketing Communications With consent, Supersonik retains names, addresses, and contact details for product/service awareness and industry updates. Recipients may object or revoke consent via unsubscribe options or by contacting the company. Security Statement Supersonik implements appropriate technical and organizational measures including pseudonymization, encryption, system confidentiality protection, incident recovery capability, and regular security testing. While email communications may lack security, the company maintains physical, electronic, and procedural safeguards. Only employees needing specific information access it, and all staff receive ongoing security training. Cookies and Analytics Supersonik uses cookies and analytics tools (detailed in the Cookie Policy). Depending on location, users may provide consent for non-essential cookies. Third-Party Websites The policy does not cover third-party websites linked from Supersonik platforms. Users bear responsibility for third-party data use and should review their privacy policies independently. Last Updated: October 8, 2026