privacy policy·v2.0.0

Privacy Policy

Last updated: 2026-08-11

This Privacy Policy explains how SlashHub Limited ("we", "us") collects, uses, discloses, processes, stores, and safeguards your Personal Data when you access or use our Services, including the SlashAI agent platform, the cross-product Single Sign-On (SSO) system, and the product-specific addenda. It is designed to comply with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), the EU General Data Protection Regulation (GDPR) (where applicable), and other applicable data-protection laws.

Effective
2026-08-15
Last Updated
2026-08-11
Governing Law
The laws of the Hong Kong Special Administrative Region (PDPO Cap. 486) and, for EU/UK data subjects, the EU GDPR

1. Controller, DPO & Contact

The data controller for your Personal Data is SlashHub Limited, a private company limited by shares incorporated in Hong Kong (Business Registration BR-XXXXXXX), with registered office at [Registered Office Address, Hong Kong].

Our Data Protection Officer can be contacted at: SlashHub Data Protection Officer, dpo@slashhub.hk, [DPO Address, Hong Kong].

For EU/UK data subjects, our EU representative under GDPR Article 27 is: [EU Representative — appoint before EU expansion], eu-rep@slashhub.hk, [EU Representative Address].

For specific requests, use the contact form in your account dashboard, or email the address above. We respond to all valid requests within the timeframes required by applicable law (PDPO: 40 days; GDPR: 30 days).

2. Definitions & Interpretation

"Personal Data" has the meaning given in the PDPO (Cap. 486) and, for data subjects in the European Economic Area or the United Kingdom, the meaning given in the GDPR. In short, it is any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or erasure. "Processor" means a third party who processes Personal Data on our behalf under a written contract. "Anonymised Data" means data that has been irreversibly stripped of personally identifying information and cannot reasonably be linked back to you. "AI Training" means the process of using data to train, develop, calibrate, validate, and improve machine-learning models, algorithms, and recommendation engines. "Services" means all websites, applications, platforms, APIs, AI agents, and services offered by us, including but not limited to SlashOne, FreelanceHub, SlashBooks, TimePlate, SlashStudio, and SlashAI.

Capitalised terms not defined here have the meaning given in our Terms of Service.

3. Data We Collect

We collect the following categories of Personal Data:

(a) Account Data — your name, email, password (hashed with scrypt), phone number (optional), avatar URL, locale, currency, timezone, business name (if applicable), and the unique identifiers we assign to your Account (Firebase UID, internal UUID, Stripe customer ID, etc.).

(b) Authentication Data — Firebase Auth tokens, SSO tokens (stored as SHA-256 hashes), session cookies, refresh tokens (stored as SHA-256 hashes), IP address, user agent, device fingerprint, and device labels. We do not store passwords in plaintext; passwords are hashed with scrypt and never recoverable.

(c) Product Data — content you create, upload, transmit, or otherwise make available through our products. This includes, for example, documents you write in SlashStudio, the bookkeeping records you create in SlashBooks, the shift schedules you set in TimePlate, the proposals and contracts you negotiate in FreelanceHub, the AI Memory entries and scheduled Jobs you create in SlashAI, and any other User Content.

(d) Usage Data — logs of your interactions with the Services (pages viewed, features used, AI agents invoked, tool calls, query and response payloads for AI features, response times, error codes), timestamps, IP address, user agent, and referrer. We retain these logs for 90 days for security, debugging, abuse-prevention, and product-improvement purposes.

(e) Device & Technical Data — browser type and version, operating system, screen size, language preference, time zone, hardware make/model (for mobile apps), and the device fingerprint for fraud detection.

(f) Cookies & Tracking — see our Cookie Policy for the full list of cookies, similar technologies, and their purposes.

(g) Payment Data — billing name, billing address, VAT/GST number (optional), last 4 digits of payment card, payment-card brand, and transaction history. Full card numbers are handled by our payment processors (currently Airwallex, and Stripe for legacy accounts) under their own Data Processing Agreements; they never touch our servers.

(h) Communication Data — when you contact our support, we collect the content of your message, the email address you use, and any attachments you send.

(i) Marketing Data — if you opt in to marketing communications, we collect your email, the products you use, and your interaction with our emails (opens, clicks). You may opt out at any time.

4. Lawful Basis for Processing (GDPR Article 6)

If you are in the European Economic Area or the United Kingdom, we process your Personal Data on the following lawful bases under GDPR Article 6:

(a) Performance of a Contract — to provide the Services, process payments, issue sessions, and provide customer support. (Legal basis: Article 6(1)(b).)

(b) Legitimate Interests — to secure the Services, prevent fraud and abuse, improve our products, and conduct analytics. (Legal basis: Article 6(1)(f).)

(c) Compliance with Legal Obligations — to comply with tax, accounting, AML, and other legal requirements. (Legal basis: Article 6(1)(c).)

(d) Consent — for marketing communications, non-essential cookies, and any other processing that requires your explicit consent. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. (Legal basis: Article 6(1)(a).)

If you are in Hong Kong or another non-GDPR jurisdiction, the PDPO's Data Protection Principles apply, and we process your Personal Data for the same purposes, on the equivalent legal bases (e.g. "all reasonably practicable steps" to protect the data, "prescribed purpose", etc.).

5. How We Use Your Data

We process your Personal Data for the following purposes:

(a) To provide and operate the Services, including authenticating you, issuing sessions and SSO tokens, syncing your identity across our products, processing payments, providing customer support, and enforcing our Terms.

(b) To provide AI Features, including SlashAI — your queries and the product data you authorise SlashAI to access are sent to the underlying AI providers (currently MiniMax, DeepSeek, and others) to generate responses. AI providers are bound by our Data Processing Agreements and are contractually prohibited from training their models on your data.

(c) To improve the Services — we analyse aggregated and anonymised Usage Data to understand how the Services are used, fix bugs, and develop new features.

(d) To communicate with you — to send you service-related notices (security alerts, billing receipts, terms updates, system status), and with your consent, marketing communications. You may opt out of marketing at any time from your account dashboard or by clicking "unsubscribe" in any marketing email.

(e) To comply with legal obligations — to respond to lawful requests from public authorities, detect and prevent fraud or abuse, enforce our Terms, and meet our record-keeping obligations.

(f) To protect the vital interests of any person — in rare cases where we have reason to believe that disclosure is necessary to prevent imminent harm to a person.

We do NOT use your Personal Data for automated profiling that produces legal or similarly significant effects on you (see §13 for the narrow cases where we do use automated decision-making).

6. Cross-Product Data Sharing & Unified Identity

SlashHub operates a unified identity layer. When you sign in to one product (e.g. FreelanceHub) and then visit another (e.g. SlashBooks), the products share limited information via the Single Sign-On (SSO) cookie to recognise that you are the same person. The shared data includes your Account UUID, display name, email, and avatar URL.

We do NOT share product-specific Content (e.g. your FreelanceHub contracts, your SlashBooks bookkeeping records, your TimePlate shift schedules, or your SlashStudio documents) across products by default. Such sharing occurs only when (a) you explicitly initiate a cross-product tool call via SlashAI, (b) you explicitly link accounts, or (c) you explicitly enable cross-product recommendations.

You may explicitly link your Account to pre-existing accounts on FreelanceHub, SlashBooks, TimePlate, or SlashStudio. Linked accounts are recorded in our PostgreSQL database. You may unlink any account at any time from the Connections page; unlinking is a soft delete (the row is marked as unlinked but retained for audit purposes for 7 years).

If you delete your Account, all product_accounts links are removed; product-specific data is deleted or anonymised in accordance with our retention schedule (see §8).

7. AI & Machine-Learning Data Processing

When you use AI Features, including SlashAI, your queries, the product data you authorise SlashAI to access, and the AI-generated responses are:

(a) Sent to the underlying AI provider (e.g. MiniMax, DeepSeek) over encrypted channels (TLS 1.3) to generate the response. The provider returns the response, which is then streamed back to you and stored in your session history.

(b) NOT used to train any AI model. We contractually prohibit our AI providers from training on your data. The "Zero-Retention" setting available in some product tiers enforces this at the API level (no prompt or response is logged by the provider).

(c) Stored in your account history for the duration of your account plus 30 days after deletion, to allow you to retrieve past conversations and to comply with legal obligations.

(d) Subject to memory — you may instruct SlashAI to remember specific facts (Memory entries) and to perform scheduled tasks (scheduled Jobs). Memory entries and Jobs are visible and editable in your account dashboard at any time.

SlashAI may invoke third-party tools (e.g. Google Workspace, Stripe, WhatsApp) on your behalf. Each tool invocation is logged in your account activity log and can be reviewed or revoked at any time. We are not responsible for the actions of any third-party service in response to a tool call.

8. Data Retention

We retain Personal Data for as long as necessary to provide the Services and comply with our legal obligations. Specifically:

(a) Account Data — retained while your Account is active. Upon Account deletion, your email is replaced with a tombstone (`deleted+<id>@erased.local`) and your name, avatar, and other identifiers are cleared. Soft-deleted data is purged after 30 days. Backups are purged after 90 days.

(b) Product Data (e.g. documents, invoices, schedules) — retained while your Account is active. You may delete individual items at any time; the deletion is permanent and propagated to all backup systems within 30 days.

(c) Billing Records — retained for 7 years as required by Hong Kong tax law (Inland Revenue Ordinance Cap. 112) and applicable anti-money-laundering law (Cap. 615).

(d) Audit Logs — retained for 7 years for security, fraud detection, and regulatory compliance.

(e) AI Session History — retained while your Account is active plus 30 days after deletion, to allow you to retrieve past conversations.

(f) Cookies — see Cookie Policy for cookie-specific retention periods.

(g) Anonymised Data — may be retained indefinitely for analytics and product improvement.

(h) Backups — encrypted backups are retained for 90 days, after which they are securely destroyed.

9. Data Subject Rights (PDPO + GDPR)

Under the PDPO (Cap. 486), you have the right to: (a) check whether we hold Personal Data about you (Data Access Request); (b) require us to correct any data that is inaccurate; (c) ascertain our general policies and practices in relation to Personal Data; and (d) opt out of direct marketing.

Under the GDPR (if you are in the EEA or the UK), you additionally have the right to: (e) request erasure ("right to be forgotten"); (f) request restriction of processing; (g) data portability in a structured, commonly used, machine-readable format (JSON or CSV); (h) object to processing based on legitimate interests or for direct marketing; (i) withdraw consent at any time (where processing is based on consent) without affecting the lawfulness of processing carried out before withdrawal; and (j) lodge a complaint with your local data-protection authority.

To exercise any of these rights, submit a request to privacy@slashhub.hk from the email associated with your Account. We will respond within 30 days (PDPO allows up to 40 days for complex requests) or 30 days (GDPR Article 12), free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse, with reasons).

If you are in the EEA/UK, you also have the right to lodge a complaint with your local data-protection authority. A list of EU DPAs is available at edpb.europa.eu; the UK ICO is at ico.org.uk. If you are in Hong Kong, you may complain to the Office of the Privacy Commissioner for Personal Data at pcpd.org.hk.

10. Cookies & Tracking

We use cookies and similar technologies (localStorage, sessionStorage, IndexedDB) to provide and improve the Services. The categories are: (a) Strictly Necessary — required for authentication, security, and load balancing; (b) Functional — remember your preferences (theme, language, last-used workspace); (c) Analytics — anonymised usage statistics; (d) Marketing — only with your consent.

See our Cookie Policy for the full list of cookies, their purposes, and retention periods. You can manage cookie preferences from the cookie banner shown on your first visit, from your account settings, or from your browser settings.

We respect the Global Privacy Control (GPC) signal. When your browser sends the GPC header, we treat it as a valid opt-out of sale/sharing for California residents and as a valid withdrawal of consent for non-essential cookies for all users.

11. Security Measures

We employ industry-standard security measures to protect your Personal Data, including: (a) TLS 1.3 for all data in transit; (b) AES-256 encryption at rest; (c) scrypt password hashing; (d) SHA-256 hashing of all authentication tokens at rest; (e) short-lived JWT access tokens (15 min) with rotating refresh tokens (30 days); (f) HttpOnly Secure cookies with SameSite=Lax; (g) CSRF protection on all state-changing endpoints; (h) rate limiting (per-IP and per-Account); (i) audit logging of all data access; (j) per-Account row-level security in our PostgreSQL database; (k) encrypted backups stored in geographically separate regions; (l) regular third-party penetration tests (at least annually); (m) a documented incident-response plan; and (n) employee security training.

Access to Personal Data is restricted to employees and contractors with a need to know, who are bound by confidentiality obligations and subject to background checks. We conduct quarterly access reviews.

Despite our efforts, no system is 100% secure. In the event of a personal-data breach, we will notify affected users and applicable supervisory authorities in accordance with §14 and applicable law.

12. International Data Transfers

We are headquartered in Hong Kong. Personal Data is primarily processed in Hong Kong, with backups stored in Singapore (encrypted) and Ireland (for EU/UK data subjects).

When we transfer Personal Data outside Hong Kong (for example, to a third-party processor in the United States), we rely on one of the following safeguards: (a) the EU Standard Contractual Clauses (Decision 2021/914); (b) the UK International Data Transfer Addendum; (c) the recipient's participation in a recognised cross-border privacy framework (e.g. EU-US Data Privacy Framework); (d) the recipient's binding corporate rules; or (e) your explicit consent.

AI providers (MiniMax, DeepSeek, and others) currently process data in their data centres, which may be located in the US, Europe, or Asia. Each provider is bound by a Data Processing Agreement that includes Standard Contractual Clauses and a prohibition on using your data to train their models.

A list of our subprocessors and their locations is maintained at slashhub.hk/subprocessors and is updated at least 30 days before any change.

13. Automated Decision-Making (GDPR Article 22)

We use automated decision-making only in narrow, well-defined cases: (a) fraud detection (blocking suspicious sign-ins or transactions); (b) abuse detection (suspending Accounts that violate the AUP); and (c) AI Features where you explicitly invoke an automated action (e.g. SlashAI generating a financial report).

In cases (a) and (b), you have the right to obtain human review of the decision. To request review, contact privacy@slashhub.hk. We will respond within 30 days.

We do NOT use automated decision-making that produces legal or similarly significant effects on you (e.g. automated denial of credit, automated termination of employment, automated assessment of personal reliability) without your explicit consent. If we propose to introduce such processing, we will provide at least 30 days' notice and an opt-out.

AI Features (SlashAI) are not a substitute for human review. You are responsible for reviewing AI-generated Content before relying on it for any consequential decision. See §11 (Disclaimers) of our Terms of Service for the full disclaimer.

14. Data Breach Notification

A "personal data breach" is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (a) notify the Office of the Privacy Commissioner for Personal Data (Hong Kong) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (PDPO Section 1(3)); (b) notify the lead supervisory authority (if applicable) within 72 hours (GDPR Article 33); and (c) notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).

Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects.

We maintain a documented incident-response plan and conduct tabletop exercises at least annually. Our security team is on-call 24/7/365 for breach response.

15. Children's Privacy

The Services are not directed to children under 13 (or under 16 in the EEA/UK, or as otherwise required by applicable law). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child in violation of applicable law, we will delete it as soon as possible.

If you believe a child has registered, contact privacy@slashhub.hk and we will delete the Account within 7 days. Parents or guardians who believe their child has provided Personal Data to us may request access, correction, or deletion of that data.

Some features (e.g. time tracking in TimePlate) may be used by minors (e.g. teenage part-time workers) under the supervision of a parent, guardian, or employer who is the Account holder. In such cases, the Account holder is responsible for obtaining any necessary consents and for ensuring compliance with applicable child-labour laws.

16. Changes to This Privacy Policy

We may modify this Privacy Policy from time to time. If we make a material change, we will notify you at least 30 days before the change takes effect by email and by a prominent notice in the Services. The notice will identify the material change and provide access to the previous version for comparison.

Your continued use after the effective date constitutes acceptance. If you do not agree, you may close your Account before the effective date and request deletion of your Personal Data in accordance with §9.

A version history with diffs is available at slashhub.hk/privacy/history.

17. Contact & DPO

For questions, data-subject requests, or complaints, contact our Data Protection Officer:

SlashHub Data Protection Officer

Email: dpo@slashhub.hk

Address: [DPO Address, Hong Kong]

For general privacy questions: privacy@slashhub.hk

For EU/UK data subjects, our EU representative is: [EU Representative — appoint before EU expansion] (eu-rep@slashhub.hk).

You may also lodge a complaint with: (a) the Office of the Privacy Commissioner for Personal Data (Hong Kong) at pcpd.org.hk; (b) your local data-protection authority if you are in the EEA/UK; or (c) any other competent supervisory authority in your jurisdiction.

Product-Specific Addendum — timeplate

The following additional terms apply specifically to timeplate and supplement the main document above.

T-1. TimePlate-Specific Terms (Workforce Management for All Companies)

TimePlate is a workforce-management, attendance, payroll, and shift-scheduling platform designed for companies of all sizes and industries — including but not limited to retail, hospitality, restaurants, healthcare, manufacturing, professional services, construction, logistics, education, and the public sector. By using TimePlate, you agree to the additional terms in this Addendum.

**Industry Modes.** TimePlate provides industry-specific templates and rule packs to accommodate different workforce needs: (a) **Hospitality / Restaurants** — tip-out rules, Average Daily Wage (ADW), split-shifts, statutory-holiday pay under the Hong Kong Employment Ordinance (Cap. 57); (b) **Retail** — multi-site scheduling, seasonal rotas, commission tracking; (c) **Healthcare** — shift handovers, on-call rotas, professional-registration expiry tracking; (d) **Manufacturing** — production-line rosters, overtime caps, fatigue-management rules; (e) **Construction** — site-based attendance, weather-day rules, CIS (Construction Industry Scheme) compliance; (f) **Professional Services** — billable-hour tracking, project allocation, leave-management; (g) **Education** — academic-year calendars, term-time scheduling, substitute-teacher pools; (h) **Logistics & Warehousing** — shift bidding, fatigue rules, vehicle-assignment logs; (i) **General Office** — flexible working, remote/hybrid scheduling, core-hours compliance. You select an industry mode at sign-up and may switch modes at any time; switching does not erase your existing data but may require you to re-verify industry-specific settings.

**POS Integration (Hospitality & Retail only).** For hospitality and retail companies, TimePlate optionally integrates with third-party point-of-sale (POS) systems (e.g. Square, TouchBistro, Lightspeed). POS transactions are processed by the respective POS provider under their own terms. SlashHub is not a party to the POS transaction and is not liable for payment disputes, refunds, chargebacks, or POS outages.

**Tip Processing (Hospitality & Restaurants only).** Tips collected through TimePlate are distributed to employees in accordance with your company's tip policy. You are responsible for setting the tip policy and for complying with applicable employment and tax laws regarding tip reporting.

**Construction Industry Scheme (CIS) Support.** TimePlate supports Hong Kong's Construction Industry Council (CIC) reporting and the UK Construction Industry Scheme (CIS) for deductions at source. By using these features, you authorise SlashHub to share the relevant employee and payment data with the CIC or HMRC as required.

**Employee Data.** TimePlate processes the personal data of your employees (name, contact details, schedule, hours worked, pay rate, performance notes, training records). By using TimePlate, you represent and warrant that you have obtained all necessary consents from your employees to process their data, and that you will provide each employee with a copy of our Privacy Policy.

**Payroll Calculation.** Payroll calculations (including overtime, holiday pay, MPF contributions, 13th-month pay, discretionary bonuses, and statutory deductions) are computed based on the data you provide and the applicable employment and tax laws in the employee's jurisdiction. SlashHub is not liable for miscalculations arising from inaccurate input data or from your failure to configure jurisdiction-specific rules correctly.

**Multi-Site & Multi-Country.** TimePlate supports scheduling and payroll for companies operating in multiple sites, regions, or countries. Each site may have its own timezone, currency, and labour-law configuration. You are responsible for configuring each site correctly and for complying with the local employment, tax, and data-protection laws of each jurisdiction in which you operate.

**Attendance & Geolocation.** TimePlate may collect attendance data via clock-in/clock-out features, including optional GPS coordinates, IP address, device fingerprint, or biometric data (fingerprint, face recognition) where enabled. You must obtain your employees' explicit consent before enabling biometric or location-based attendance. You can disable these features from the Settings page at any time.

**AI Scheduling & Forecasting.** SlashAI may assist with shift scheduling, demand forecasting, and labour-cost optimisation. All AI suggestions are drafts; you must review and approve before publishing to your employees. SlashHub is not liable for misallocations arising from inaccurate historical data or from your failure to incorporate local labour laws into the constraints.

**Workforce Data Sharing.** Aggregated, anonymised workforce metrics (e.g. industry-wide turnover rates, average overtime hours) may be used to improve TimePlate's scheduling recommendations. Personally identifiable employee data is never shared or sold.

T-2. TimePlate Subscriptions, Plans & Billing

TimePlate offers a free tier and paid annual subscription plans (currently Starter, Plus, Pro, and Enterprise), each with its own store and employee limits and price, as described on our pricing page and in the TimePlate Subscription Terms. The Free plan is limited (currently 1 store and 10 employees) and is intended for evaluation.

Paid TimePlate plans are billed annually in advance, in Hong Kong Dollars, through our payment provider Airwallex. Subscriptions renew automatically for successive 12-month terms unless you cancel before the renewal date. By purchasing a paid plan, you authorise us to charge the payment method on file at each renewal.

New paid plans may include a trial period. If no payment is received by the end of a trial, the plan automatically reverts to the Free plan and its limits. Similarly, if a renewal payment fails or is not received, the plan becomes past due and, after a short grace period, automatically reverts to the Free plan. These automatic changes may occur even if our renewal or warning notices did not reach you.

Plan fees are non-refundable except as required by applicable law; there are no partial or pro-rated refunds for cancellation, downgrade, or non-use. Upgrades take effect immediately (pro-rated), and downgrades take effect at the next renewal. Exceeding your plan limits may restrict or block functions until you upgrade. Add-ons (e.g. training sessions, advanced analytics, white-label branding) are billed separately and are available only on eligible plans.

The TimePlate Subscription Terms set out the full terms of purchase, billing, renewal, cancellation, refunds, promotional and loyalty pricing, and the conclusive nature of our system and payment records. The TimePlate Subscription Terms form part of the Terms of Service. Notices (including renewal notices, invoices, receipts, and expiry warnings) are deemed delivered when sent to the contact details on your account; non-receipt of a notice does not delay a renewal charge, prevent an automatic downgrade, or excuse payment.

T-3. TimePlate Partner Programme (Sales Partners / 合作者)

The TimePlate Partner Programme allows approved individuals and entities (internal or external "Partners") to earn commission by referring paying customers through a unique invite code. Participation is governed by the TimePlate Partner Programme Agreement (the "Partner Agreement"), which is available at /partner-terms and forms part of these Terms. By applying to, being accepted into, or participating in the Programme, you agree to the Partner Agreement.

Commission is a ONE-TIME percentage (15%–25%, rising automatically with your cumulative attributed first-year revenue) of the Net First-Year Fee actually received and retained by SlashHub. THERE IS NO BASE SALARY and no guaranteed income. Renewals, subsequent years, add-ons, free plans, and any amount not ultimately retained (including refunds and chargebacks) do not earn commission. Attribution is first-write-wins, must be linked at sign-up or before the customer's first payment, is unavailable after payment, and self-referral is prohibited. SlashHub may suspend or rotate invite codes, and its records are conclusive.

Partners participate solely as independent contractors; no employment, agency, partnership, or fiduciary relationship is created and Partners have no authority to bind SlashHub. Commission is provisional, and SlashHub may reverse or recover it (clawback) and set it off against amounts owed where a payment is refunded, charged back, or not retained, or where commission was earned through fraud, error, or breach. NO PAYOUT IS MADE until a TimePlate administrator confirms the final payable amount. SlashHub may suspend, terminate, or prospectively modify the Programme at any time. The Partner Agreement contains its own disclaimers, limitation of liability, indemnity, tax, confidentiality, and governing-law clauses, which apply to the Programme and prevail over these Terms for Programme matters.