Trust Center
Trust Center
Sleak is the AI Coach that develops your team's professional skills and knowledge through conversation. Managers define what their team needs to learn or improve — Sleak's Coach teaches it, trains it through realistic simulated conversations, and evaluates progress against your own standards of excellence.
Frequently asked questions
- Where is the Sleak app and database hosted?
- Sleak GmbH is headquartered in Munich, Germany. Our infrastructure is fully cloud-native, built on Microsoft Azure and Supabase, with data processed in the EU/EEA.
- Will any of my data be used to train AI models?
- Sleak does not use your data to train its own models. For the AI and voice providers we rely on, most have contractual no-training clauses already confirmed — a small number are still being finalized and verified; check the sub-processors page for the current status of each provider.
- What does Sleak do to be GDPR compliant?
- Sleak is based in the EU and falls under GDPR. We host our platform and process customer data in the EU/EEA; our Data Processing Agreement is available to every customer and passes our data protection obligations down to every sub-processor; our terms and DPA were drafted under German/EU law; and our ISO 27001:2022-certified information security management system includes 93 Annex A controls, including controls dedicated to privacy and protection of personal data. We also work with an external data protection function (Kertos GmbH) alongside our internal Information Security Officer.
- Will my data leave the EU?
- By default, Sleak processes and stores customer data within the EU/EEA. A small number of our AI sub-processors process certain requests in the United States under Standard Contractual Clauses or the EU-U.S. Data Privacy Framework as a backup transfer mechanism, even where processing is EU-based by default. See the sub-processors page for exact regions per vendor.
- Is Sleak compliant with the EU AI Act?
- Sleak has assessed its platform against the EU AI Act. Our default coaching experience — where individual results are shown only in pseudonymized form — is treated as our non-high-risk baseline configuration. We provide transparency to users that they are interacting with AI in line with Article 50, and we offer additional configuration options and governance for customers who choose higher-sensitivity use cases (e.g. recruiting-related use, or enabling named performance visibility for managers), which carry additional obligations under the Act.