SoloRiff
Back to home

Data Processing Addendum

Last updated: 2026-05-10

This Data Processing Addendum ("DPA") is incorporated into the SoloRiff Terms of Service and supplements the Privacy Policy. It governs the processing of Personal Data by SoloRiff acting as processor / "service provider" on behalf of the Customer acting as controller / "business".

This DPA is entered into between the Customer ("Controller") and SoloRiff ("Processor") (each a "Party" and together the "Parties") and forms part of the Terms of Service (the "Agreement"). For Customers established in or processing Personal Data of individuals in the European Economic Area, the United Kingdom or Switzerland, this DPA reflects Article 28 GDPR / UK GDPR. For Customers subject to California or other US state privacy laws, this DPA includes the contractual restrictions required to qualify SoloRiff as a "service provider" / "processor" under those laws.

1. Definitions

2. Scope & subject matter

This DPA applies to the processing of Personal Data by SoloRiff on behalf of the Customer in the course of providing the Service. The duration of processing is the term of the Agreement plus any post-termination data-retention period agreed in writing. The nature and purpose of processing is the operation of the Service: hosting, securing, transmitting and analysing Customer Data, running AI agents, delivering messages, generating analytics and routing leads. The types of Personal Data and categories of Data Subjects are set out in Annex I.

3. Roles of the Parties

The Customer is the Controller / Business. SoloRiff is the Processor / Service Provider. Each Party will comply with its obligations under Applicable Data Protection Law. The Customer is solely responsible for ensuring that it has a valid legal basis (under GDPR Art. 6 and, where relevant, Art. 9) and any consents required (e.g. ePrivacy) for the Personal Data submitted to the Service.

4. Customer instructions

SoloRiff will process Personal Data only on documented instructions from the Customer, including those reflected in the Agreement, the Studio configuration and this DPA. Where SoloRiff is required to process Personal Data otherwise (e.g. by EU/UK/US law), it will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

5. Confidentiality & personnel

SoloRiff ensures that personnel authorised to process Personal Data are bound by confidentiality obligations and have received appropriate training. Access is granted on a need-to-know basis and revoked upon role change or termination.

6. Security measures (GDPR Art. 32)

SoloRiff implements and maintains appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure. These measures are described in Annex II and updated from time to time without materially diminishing the level of protection.

7. Subprocessing

The Customer authorises SoloRiff to engage Subprocessors to process Personal Data, subject to:

The current list of Subprocessors is in Annex III.

8. International transfers

Where SoloRiff transfers Personal Data outside the EEA, the UK or Switzerland to a country not deemed adequate, the transfer is governed by:

The SCCs are deemed entered into between the Parties for any in-scope transfer, with the modules, optional clauses and Annexes populated as set out in Annex IV. SoloRiff has performed Transfer Impact Assessments where required and applies supplementary measures (encryption in transit and at rest, strict access controls, contractual challenge of unlawful authority requests).

9. Data Subject rights

Taking into account the nature of the processing, SoloRiff will provide reasonable assistance to the Customer in fulfilling Data Subject requests under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where SoloRiff receives a request directly from a Data Subject relating to Customer Data, SoloRiff will (where lawful) forward it to the Customer and not respond on the substantive matter without the Customer's instructions.

10. Personal-data breach notification

SoloRiff will notify the Customer without undue delay (and within 48 hours where reasonably practicable) after becoming aware of a personal-data breach affecting the Customer's Personal Data, providing the information required by GDPR Art. 33(3) to the extent then known. Notifications will be sent to the security contact on file. Notification is not an admission of fault or liability.

11. Audits

SoloRiff makes available to the Customer information necessary to demonstrate compliance with this DPA, including the latest available third-party security report (e.g. SOC 2 Type II if and when issued). On reasonable prior written notice, the Customer may, at its own expense, audit SoloRiff's processing of Personal Data once per calendar year, conducted in a manner that does not unreasonably disrupt operations or compromise other customers' confidentiality. The Customer agrees that third-party reports are sufficient evidence in the absence of specific cause.

12. Return or deletion of Personal Data

On termination or expiry of the Agreement, and at the Customer's choice, SoloRiff will return or delete Personal Data within 30 days, except where retention is required by law. Backup copies are deleted on the standard backup-rotation schedule (within 35 days). SoloRiff will provide written confirmation of deletion on request.

13. CCPA/CPRA service-provider terms

The Parties acknowledge that, with respect to Personal Information of California residents, SoloRiff is a "Service Provider" under §1798.140(ag) CCPA. SoloRiff:

Equivalent contractual restrictions apply for processors / processors-equivalent under Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA and other US state privacy laws as enacted.

14. Liability

The liability of each Party under or in connection with this DPA is subject to the limitations of liability set out in the Agreement. Where the SCCs apply, the Parties agree that any claim for damages arising from a breach of the SCCs shall, as between the Parties, be subject to the same liability cap, except where prohibited by mandatory law.

15. Order of precedence

If there is a conflict between the terms of this DPA, the SCCs (where they apply) and the Agreement, the order of precedence is: (1) the SCCs; (2) this DPA; (3) the Privacy Policy; (4) the Agreement; (5) any order form.

16. Term & survival

This DPA enters into force on the effective date of the Agreement and continues for as long as SoloRiff processes Personal Data on behalf of the Customer. Sections that by their nature should survive (security, breach notification, return/deletion, liability, governing law, Annexes) survive termination.


Annex I — Description of processing

Categories of Data Subjects

Categories of Personal Data

Special categories of data

None by default. Customers must not submit special categories of personal data under GDPR Art. 9 or sensitive personal information under the CCPA/CPRA without a separately executed addendum.

Nature and purpose of processing

Hosting, transmitting, securing and analysing Customer Data; running AI agents (chat, voice and avatar) on behalf of the Customer; delivering outbound messages through Customer-configured channels; performing routing, scoring and basic enrichment; generating analytics and audit logs.

Duration of processing

The term of the Agreement, plus retention periods set out in the Privacy Policy and Section 12 of this DPA.


Annex II — Technical and organisational measures (GDPR Art. 32)


Annex III — List of Subprocessors

The following Subprocessors are authorised at the date of this DPA. The list is updated as it changes; updates are notified by email or in-product banner.

SubprocessorPurposeCountry / region
Cloud infrastructure providerHosting compute, database and storageEU regions where available; US regions where required
OpenAILarge language, speech and image model inference (no-training endpoints)USA
ElevenLabsVoice synthesis (where Customers enable premium voice)USA
StripePayment processing for Customer billingUSA / EU
Email delivery providers (Brevo / Postmark / Mailgun / SendGrid / Customer-configured SMTP)Outbound emailEU / USA depending on provider
Contact enrichment providersFirmographic / contact data enrichment (where Customer opts in)USA / EU depending on provider
QdrantVector index for knowledge-base retrievalSelf-hosted by SoloRiff in cloud-provider regions
Sentry / observability providerError monitoring and performance metricsEU / USA depending on plan

Names and locations of specific subprocessors are confirmed at [email protected] on request. The Customer may subscribe to subprocessor change notifications by emailing the same address with the subject prefix [subprocessors].


Annex IV — Standard Contractual Clauses

Contact

For DPA-related questions, signed counterparts and verifiable consumer or data-subject requests: [email protected] with the subject prefix [dpa].

Have a question about this document? Email [email protected].

See also: Terms of Service, Privacy Policy, Cookie Policy.