Data Processing Addendum
Last updated: 2026-05-10
This Data Processing Addendum ("DPA") is incorporated into the SoloRiff Terms of Service and supplements the Privacy Policy. It governs the processing of Personal Data by SoloRiff acting as processor / "service provider" on behalf of the Customer acting as controller / "business".
This DPA is entered into between the Customer ("Controller") and SoloRiff ("Processor") (each a "Party" and together the "Parties") and forms part of the Terms of Service (the "Agreement"). For Customers established in or processing Personal Data of individuals in the European Economic Area, the United Kingdom or Switzerland, this DPA reflects Article 28 GDPR / UK GDPR. For Customers subject to California or other US state privacy laws, this DPA includes the contractual restrictions required to qualify SoloRiff as a "service provider" / "processor" under those laws.
1. Definitions
- Applicable Data Protection Law means, as relevant: (a) the EU GDPR (Regulation (EU) 2016/679) and its national implementations; (b) the UK GDPR and Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection (FADP); (d) the California Consumer Privacy Act (CCPA) as amended by the CPRA; and (e) other US state privacy laws applicable to the Parties (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA and others as enacted).
- Personal Data has the meaning given in the EU GDPR / UK GDPR; "Personal Information" has the meaning given in the CCPA. Both are referred to as "Personal Data" in this DPA.
- Data Subject, Processing, Processor, Controller have the meanings given in the GDPR. "Service Provider" and "Business" have the meanings given in the CCPA.
- Subprocessor means any third party engaged by SoloRiff to process Personal Data on behalf of the Customer.
- Standard Contractual Clauses ("SCCs") means the standard contractual clauses adopted by the European Commission in Decision 2021/914 of 4 June 2021 (Modules 2 and 3 as applicable).
- UK IDTA means the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office.
2. Scope & subject matter
This DPA applies to the processing of Personal Data by SoloRiff on behalf of the Customer in the course of providing the Service. The duration of processing is the term of the Agreement plus any post-termination data-retention period agreed in writing. The nature and purpose of processing is the operation of the Service: hosting, securing, transmitting and analysing Customer Data, running AI agents, delivering messages, generating analytics and routing leads. The types of Personal Data and categories of Data Subjects are set out in Annex I.
3. Roles of the Parties
The Customer is the Controller / Business. SoloRiff is the Processor / Service Provider. Each Party will comply with its obligations under Applicable Data Protection Law. The Customer is solely responsible for ensuring that it has a valid legal basis (under GDPR Art. 6 and, where relevant, Art. 9) and any consents required (e.g. ePrivacy) for the Personal Data submitted to the Service.
4. Customer instructions
SoloRiff will process Personal Data only on documented instructions from the Customer, including those reflected in the Agreement, the Studio configuration and this DPA. Where SoloRiff is required to process Personal Data otherwise (e.g. by EU/UK/US law), it will inform the Customer before processing unless that law prohibits it on important grounds of public interest.
5. Confidentiality & personnel
SoloRiff ensures that personnel authorised to process Personal Data are bound by confidentiality obligations and have received appropriate training. Access is granted on a need-to-know basis and revoked upon role change or termination.
6. Security measures (GDPR Art. 32)
SoloRiff implements and maintains appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure. These measures are described in Annex II and updated from time to time without materially diminishing the level of protection.
7. Subprocessing
The Customer authorises SoloRiff to engage Subprocessors to process Personal Data, subject to:
- SoloRiff entering into a written agreement with each Subprocessor imposing data-protection obligations no less protective than those in this DPA;
- SoloRiff remaining liable for the acts and omissions of its Subprocessors as if they were its own; and
- SoloRiff providing reasonable advance notice (by email or in-product banner) of new Subprocessors. The Customer may object to a new Subprocessor on legitimate, documented data-protection grounds within 30 days. If the objection cannot be resolved, the Customer may terminate the affected Service for convenience as its sole remedy.
The current list of Subprocessors is in Annex III.
8. International transfers
Where SoloRiff transfers Personal Data outside the EEA, the UK or Switzerland to a country not deemed adequate, the transfer is governed by:
- the SCCs (Module 2 for Controller-to-Processor; Module 3 for Processor-to-Processor) for transfers from the EEA;
- the UK IDTA (or, at the Customer's election, the SCCs as supplemented by the UK Addendum) for transfers from the UK; and
- where transfers from Switzerland are subject to FADP, the SCCs as adapted under FDPIC guidance.
The SCCs are deemed entered into between the Parties for any in-scope transfer, with the modules, optional clauses and Annexes populated as set out in Annex IV. SoloRiff has performed Transfer Impact Assessments where required and applies supplementary measures (encryption in transit and at rest, strict access controls, contractual challenge of unlawful authority requests).
9. Data Subject rights
Taking into account the nature of the processing, SoloRiff will provide reasonable assistance to the Customer in fulfilling Data Subject requests under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where SoloRiff receives a request directly from a Data Subject relating to Customer Data, SoloRiff will (where lawful) forward it to the Customer and not respond on the substantive matter without the Customer's instructions.
10. Personal-data breach notification
SoloRiff will notify the Customer without undue delay (and within 48 hours where reasonably practicable) after becoming aware of a personal-data breach affecting the Customer's Personal Data, providing the information required by GDPR Art. 33(3) to the extent then known. Notifications will be sent to the security contact on file. Notification is not an admission of fault or liability.
11. Audits
SoloRiff makes available to the Customer information necessary to demonstrate compliance with this DPA, including the latest available third-party security report (e.g. SOC 2 Type II if and when issued). On reasonable prior written notice, the Customer may, at its own expense, audit SoloRiff's processing of Personal Data once per calendar year, conducted in a manner that does not unreasonably disrupt operations or compromise other customers' confidentiality. The Customer agrees that third-party reports are sufficient evidence in the absence of specific cause.
12. Return or deletion of Personal Data
On termination or expiry of the Agreement, and at the Customer's choice, SoloRiff will return or delete Personal Data within 30 days, except where retention is required by law. Backup copies are deleted on the standard backup-rotation schedule (within 35 days). SoloRiff will provide written confirmation of deletion on request.
13. CCPA/CPRA service-provider terms
The Parties acknowledge that, with respect to Personal Information of California residents, SoloRiff is a "Service Provider" under §1798.140(ag) CCPA. SoloRiff:
- will process Personal Information only for the limited and specified business purpose of providing the Service;
- will not sell or share Personal Information (as those terms are defined under the CCPA/CPRA);
- will not retain, use or disclose Personal Information for any purpose other than the business purpose, including outside the direct business relationship;
- will not combine Personal Information received from the Business with personal information received from another source, except as permitted by §1798.140(ag)(1)(D);
- will comply with applicable obligations under the CCPA/CPRA and provide the same level of privacy protection as required of Businesses;
- will notify the Customer if it determines it can no longer meet its obligations and grants the Customer the right to take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Information; and
- will provide reasonable assistance to the Customer in responding to verifiable consumer requests.
Equivalent contractual restrictions apply for processors / processors-equivalent under Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA and other US state privacy laws as enacted.
14. Liability
The liability of each Party under or in connection with this DPA is subject to the limitations of liability set out in the Agreement. Where the SCCs apply, the Parties agree that any claim for damages arising from a breach of the SCCs shall, as between the Parties, be subject to the same liability cap, except where prohibited by mandatory law.
15. Order of precedence
If there is a conflict between the terms of this DPA, the SCCs (where they apply) and the Agreement, the order of precedence is: (1) the SCCs; (2) this DPA; (3) the Privacy Policy; (4) the Agreement; (5) any order form.
16. Term & survival
This DPA enters into force on the effective date of the Agreement and continues for as long as SoloRiff processes Personal Data on behalf of the Customer. Sections that by their nature should survive (security, breach notification, return/deletion, liability, governing law, Annexes) survive termination.
Annex I — Description of processing
Categories of Data Subjects
- The Customer's authorised users (administrators, team members) of the Service.
- The Customer's prospects and end users who interact with widgets the Customer has embedded.
- The Customer's contacts ingested into CRM-style records inside the Service.
- Senders and recipients of emails routed through configured mailboxes.
Categories of Personal Data
- Identifiers: name, email address, phone number, organisation, job title.
- Conversation content: chat messages, voice recordings (where enabled), AI agent outputs, transcripts.
- Behavioural data: timestamps, IP addresses, page URLs, device and session identifiers, lead score and routing tags.
- Knowledge sources submitted by the Customer (which may incidentally contain Personal Data).
- Free-text fields submitted by Data Subjects in capture forms (which may incidentally contain Personal Data).
Special categories of data
None by default. Customers must not submit special categories of personal data under GDPR Art. 9 or sensitive personal information under the CCPA/CPRA without a separately executed addendum.
Nature and purpose of processing
Hosting, transmitting, securing and analysing Customer Data; running AI agents (chat, voice and avatar) on behalf of the Customer; delivering outbound messages through Customer-configured channels; performing routing, scoring and basic enrichment; generating analytics and audit logs.
Duration of processing
The term of the Agreement, plus retention periods set out in the Privacy Policy and Section 12 of this DPA.
Annex II — Technical and organisational measures (GDPR Art. 32)
- Encryption. TLS 1.2+ in transit; AES-256 at rest at the database and object-storage layers; envelope encryption for integration credentials.
- Access control. Role-based access; least privilege; SSO + MFA for SoloRiff personnel; access reviews on role change and at least quarterly.
- Tenant isolation. Logical isolation enforced in every API path; tenant-scoped queries; audit log on cross-tenant access by SoloRiff personnel.
- Network security. Private network for production services; VPC peering between cloud and database tier; security-group rules reviewed periodically.
- Vulnerability management. Dependency scanning on every commit; weekly patching cadence; periodic penetration testing.
- Logging & monitoring. Centralised application logs; alerts on suspicious authentication, privilege escalation and abnormal data export.
- Backups. Encrypted automated backups; rotation within 35 days; restore tests at least annually.
- Incident response. Documented runbook; on-call rotation; post-incident reviews retained for at least 24 months.
- Personnel. Confidentiality obligations; security training at hire and annually thereafter; background checks where lawful.
- Vendor risk. Subprocessor due diligence and re-review at least annually.
Annex III — List of Subprocessors
The following Subprocessors are authorised at the date of this DPA. The list is updated as it changes; updates are notified by email or in-product banner.
| Subprocessor | Purpose | Country / region |
|---|---|---|
| Cloud infrastructure provider | Hosting compute, database and storage | EU regions where available; US regions where required |
| OpenAI | Large language, speech and image model inference (no-training endpoints) | USA |
| ElevenLabs | Voice synthesis (where Customers enable premium voice) | USA |
| Stripe | Payment processing for Customer billing | USA / EU |
| Email delivery providers (Brevo / Postmark / Mailgun / SendGrid / Customer-configured SMTP) | Outbound email | EU / USA depending on provider |
| Contact enrichment providers | Firmographic / contact data enrichment (where Customer opts in) | USA / EU depending on provider |
| Qdrant | Vector index for knowledge-base retrieval | Self-hosted by SoloRiff in cloud-provider regions |
| Sentry / observability provider | Error monitoring and performance metrics | EU / USA depending on plan |
Names and locations of specific subprocessors are confirmed at [email protected] on request. The Customer may subscribe to subprocessor change notifications by emailing the same address with the subject prefix [subprocessors].
Annex IV — Standard Contractual Clauses
- Module: Module 2 (Controller-to-Processor) for transfers where the Customer is controller and SoloRiff is processor; Module 3 (Processor-to-Processor) where applicable.
- Optional clauses: Clause 7 (Docking) — applies; Clause 11 (Independent dispute-resolution body) — does not apply; Clause 17, Option 1 (Governing law) — Ireland; Clause 18 (Choice of forum and jurisdiction) — Ireland.
- Data exporter / importer: the Customer is the data exporter; SoloRiff (and its in-scope Subprocessors) are data importers.
- Annex I.A (Parties): identifying details as in the Agreement / order form.
- Annex I.B (Description of transfer): as set out in Annex I above.
- Annex II (Technical and organisational measures): as set out in Annex II above.
- Annex III (Subprocessors): as set out in Annex III above.
- UK IDTA: the UK IDTA is incorporated and Tables 1–4 are populated by reference to the corresponding sections of the SCCs as configured above.
Contact
For DPA-related questions, signed counterparts and verifiable consumer or data-subject requests: [email protected] with the subject prefix [dpa].
Have a question about this document? Email [email protected].
See also: Terms of Service, Privacy Policy, Cookie Policy.