Privacy Policy

Last updated: 21 July 2026. This notice explains how Deckly collects, uses, shares, and protects personal information. It covers the EU General Data Protection Regulation (GDPR) and South Africa's Protection of Personal Information Act (POPIA), where they apply.

Who is responsible

The controller for presenter accounts, billing, and operation of the Deckly service is Deckly, Johannesburg, South Africa. Contact us at support@dodeckly.com.

A presenter or their organisation normally decides why participant names and answers are collected in a session and is the controller for that information. Deckly processes that session information on their instructions to provide the service. Participants should first contact the presenter or organisation that invited them; they may also contact us and we will help route the request.

Information we collect

  • Presenter account data: name, email address, optional organisation, authentication records, plan, and account timestamps.
  • Content: uploaded decks, extracted slide text and images, speaker notes, activities, and AI prompts derived from the slide text you choose to submit.
  • Session data: participant display names, responses, scores, join and activity timestamps, and aggregate reports.
  • Organization learning data: staff roles, participant enrolments, class or course membership, completion status, attendance, and account-linked learning journeys where an organization enables these features.
  • Payment records: PayFast transaction references, payment status, amount, currency, and plan. Deckly does not receive or store full payment-card details.
  • Technical and security data: IP address or derived rate-limit key, request metadata, device/browser information made available in normal web requests, and diagnostic or security events.

Purposes and legal bases

  • Contract: create and secure presenter accounts, host decks, run sessions, provide reports, process subscriptions, and respond to support requests.
  • Legitimate interests: prevent abuse, rate-limit requests, diagnose failures, protect users and the service, and keep proportionate operational records. We balance these interests against your rights and minimise the information used.
  • Legal obligation: retain records required for tax, accounting, fraud prevention, disputes, and lawful requests.
  • Presenter instructions: process participant data and uploaded content to deliver a session. The presenter must establish an appropriate lawful basis and provide any notice required to participants.

AI suggestions run only when a presenter asks for them. Deckly does not use participant answers for advertising and does not make decisions producing legal or similarly significant effects solely by automated means.

Service providers and international transfers

We disclose data only as needed to operate Deckly:

  • Supabase — authentication and database hosting.
  • Cloudflare R2 — uploaded deck and slide-image storage.
  • PayFast — subscription payment processing.
  • Alibaba Cloud / Qwen — optional AI generation from slide text submitted by a presenter.
  • Application hosting provider — application hosting, delivery, security, and platform logs for dodeckly.com.

These providers may process information outside your country, including outside the EEA. A transfer is permitted only where the controller has confirmed a valid mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, with supplementary measures where required. If no valid mechanism is available for a provider and location, we will not transfer EEA personal data there. Email us to request the current transfer details.

Children and learner data

Deckly accounts are intended for presenters, instructors, and trainers, not for children to create independently. Participants join with a session code and display name. A presenter using Deckly with minors must have authority to do so, provide an age-appropriate notice, and obtain school, guardian, or other authorisation where the applicable law requires it. Presenters should use anonymous mode or non-identifying nicknames whenever names are unnecessary.

Cookies and local device storage

Deckly uses authentication cookies required to sign users in and keep accounts secure. It also stores limited preferences and local deck-edit state in browser storage. We do not currently use advertising cookies or third-party behavioural analytics. If that changes, we will update this notice and request consent where required before setting non-essential cookies.

How long we keep data

  • Presenter profiles and deck content are kept while the account is active, unless deleted sooner.
  • Ended session history is automatically deleted after 90 days on Free accounts and 24 months on Pro or Organization accounts, based on the plan in effect when cleanup runs.
  • Organization participant and enrolment records are kept while the organization account is active, unless an authorized organization administrator removes them sooner or applicable law requires a different period.
  • Rate-limit records are kept for no more than 24 hours; application security and diagnostic events for up to 90 days; and AI usage totals for up to 395 days.
  • Billing records are retained for the period required by applicable tax, accounting, chargeback, and dispute laws, then deleted or anonymised.
  • Encrypted backups and provider logs may persist for their limited rotation periods and are not restored except for disaster recovery or security purposes.

Your rights and choices

Depending on where you live and the context, you may ask for access, correction, deletion, restriction, objection, or a portable copy of personal data, and may withdraw consent where consent is the legal basis. You may also complain to a supervisory authority. These rights can be limited where another person's rights or a legal retention duty applies.

  • Presenters can correct profile details, download a JSON data export, or delete their account from Settings.
  • For any other request, email support@dodeckly.com. Include the account email or session code and presenter name so we can locate the right controller without collecting unnecessary details.
  • We may verify identity before disclosing information. We aim to respond without undue delay and within one month where GDPR applies.

EEA residents may complain to the data protection authority where they live or work, or where the issue occurred. The European Data Protection Board publishes a directory of authorities at edpb.europa.eu. South African residents may complain to the Information Regulator at inforegulator.org.za.

Security and data incidents

We use access controls, encryption in transit, restricted server credentials, row-level database controls, request validation, and rate limiting. No service can guarantee absolute security. We investigate suspected incidents, document personal-data breaches, and notify regulators and affected people where applicable law requires it.

Changes to this notice

We will update the date above when this notice changes. We will provide a more prominent notice before a material change where required; using the service does not override rights that require a separate consent.