Summary
-
100+ web pages assessed
-
10 binding documents identified for a standard use case
-
7 directly from Slack's website
-
3 incorporated from Salesforce's website
-
-
Scored against a 59-point in-house counsel playbook: 25 aligned, 31 flagged for review, 3 conflicts
-
151 clauses matched to playbook requirements, every one cited to its source section
-
7 playbook points graded on silence (see below)
Key Findings from Slack’s Terms
No AI/ML Training on Our Data
Playbook requirement: Vendor may not use our data, including our Personal Data and Confidential Information, to train or improve AI/ML models, except models used solely for us.
“SFDC may access Customer Data in Slack for the following reasons, and Customer instructs SFDC to process its Customer Data for such purposes: 1. to train models for use by the services and features that Customer has access to; 2. to improve services and features that Customer has access to; 3. to conduct research and development of products that Customer will have access to without additional cost...”
Source: Slack Supplemental Terms, "Slack Search, Learning and Artificial Intelligence"
Acceptance of the Slack Terms itself authorizes this processing. The models trained on Customer Data are deployed platform-wide, not solely for the contributing customer, and SFDC retains ownership of aggregated machine learning results. An opt-out for global model training exists, but the contractual default is authorization, the stronger generative AI opt-in protection lives in Documentation that the MSA's order of precedence makes subordinate to these terms, and workspace-level training continues even after opt-out.
Conflict
Publicity
Conflict
Playbook requirement: we must give consent for uses of our logo for marketing purposes.
“Customer grants SFDC the right to use Customer's company name and logo as a reference for marketing or promotional purposes on SFDC's websites and in other public or private communications with existing or potential Slack customers, subject to Customer's standard trademark usage guidelines as provided to SFDC from time-to-time.”
Source: Slack Supplemental Terms, "Publicity"
The license is granted automatically upon acceptance of the terms. The customer's only lever is trademark usage guidelines, which govern how the logo appears, not whether it may be used. No consent step and no opt-out mechanism exists in the clause.
Breach Notification Timeline
Playbook requirement: Vendor shall notify us without undue delay, and in any event within 72 hours, of (i) an actual or suspected Data Security Breach and (ii) any other actual or potential breach of the DPA.
“...shall notify Customer without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data...”
Source: Salesforce Data Processing Addendum, Customer Data Incident Management (echoed in the Security Privacy and Architecture documentation, Incident Management)
A real notification obligation exists in the incorporated Salesforce paper, but no document commits to a specific hour bound. "Without undue delay" leaves the 72-hour requirement, and the 24-hour ideal, unmet on paper. Notably, this obligation is invisible from Slack's own legal pages; it lives entirely in the incorporated Salesforce DPA.
Needs Review
Data Segregation
Aligned
Playbook requirement: Physical and/or logical separation of data received from different controllers
“The Covered Services are operated on a multitenant architecture at both the platform and infrastructure layers that is designed to segregate and restrict Customer Data access based on business needs. The architecture provides a logical data separation for each different customer via a unique ID.”
Source: Slack Security, Privacy and Architecture documentation, Platform Controls
The segregation commitment is real but lives in the incorporated security documentation rather than the click-through terms. A reader working only from Slack's legal pages would grade this item as silent.
The full analysis below covers all 59 playbook points with 151 cited clauses.
What Slack’s Terms Don’t Say
The terms were silent on 7 of the 59 playbook points:
-
Exclusivity: no restriction on using competing tools (silence is favorable here; graded aligned)
-
Non-solicitation: no restriction on recruiting (silence favorable; graded aligned)
-
Anti-virus solution: no contractual commitment found (flagged for review)
-
Password encryption: no explicit contractual commitment (flagged for review)
-
Cyber risk insurance and insurance generally: no coverage commitments anywhere in the document set (flagged for review)
-
Ownership of custom deliverables: no assignment of custom work product to the customer anywhere in the ten documents (graded conflict)
Several checks that appear silent from Slack's own legal pages are in fact answered in the Salesforce documents those pages incorporate by reference; this analysis followed and reviewed every such cross-reference.
How TermTrax Produced This Analysis
TermTrax assembles the vendor's complete binding document set (here, 10 documents found across 100+ pages), compares every clause against each requirement in your playbook, and drafts a graded first pass. Every finding cites the exact source clause. You review, edit, and decide.
Your policies at a glance

Every finding cites the exact clause

AI analyzes, you decide

-
Output quality confirmed by in-house legal counsel
-
No implementation, no migration. Paste a URL and go
-
Every finding cites the exact source clause
-
AI analyzes, you decide. All findings can be edited and overwritten
This Slack terms analysis was generated by TermTrax using a standard general-terms playbook in August 2026. It is not legal advice. Vendor terms may have been updated since this analysis. Your team's playbook will produce findings specific to your organization's policies and risk tolerances.