SoloRiff
Back to home

Privacy Policy

Last updated: 2026-05-10

This Privacy Policy describes how SoloRiff ("SoloRiff", "we", "our", "us") collects, uses, discloses and safeguards information when you use our website, dashboard ("Studio"), APIs and embedded widgets (the "Service"). It applies both to people who sign up as SoloRiff customers ("Customers") and to end users who interact with widgets that Customers have embedded on their websites ("End Users"). Capitalised terms not defined here have the meaning given in the Terms of Service or the Data Processing Addendum.

1. Roles under data-protection law

For data Customers submit, configure or process through the Service (e.g. visitor conversations, knowledge sources, contact lists), the Customer is the data controller (or, in California terminology, the "business") and SoloRiff acts as processor (or "service provider") under Article 28 GDPR, Article 28 UK GDPR, the CCPA/CPRA, and analogous US state privacy laws.

For data we collect about Customers themselves (account, billing, support correspondence, marketing where permitted), SoloRiff acts as controller / "business".

2. Personal data we collect

3. Categories under California law

For California residents, we treat the following CCPA/CPRA categories as collected:

We do not "sell" Personal Information as defined under the CCPA, and we do not "share" Personal Information for cross-context behavioural advertising as defined under the CPRA. We do not process "sensitive personal information" beyond what is strictly necessary to provide the Service.

4. Sources of personal data

We collect personal data:

5. Purposes & legal bases (GDPR Art. 6)

6. How we use Personal Information (US)

Under US state privacy laws, we use Personal Information for the "business purposes" listed in §1798.140(e) CCPA, including providing requested services, security and integrity, debugging, short-term transient use, performing services on behalf of the business, and internal R&D solely to improve the Service.

7. Disclosure & subprocessors

We share Personal Information with subprocessors strictly to deliver the Service. Categories include:

The current list of named subprocessors is published in the DPA.

8. International transfers

Some subprocessors are located outside the European Economic Area, the United Kingdom or Switzerland. Where personal data is transferred internationally, we rely on:

We assess each transfer for additional safeguards as required by Schrems II and document the assessment in the DPA.

9. Retention

We retain personal data for as long as needed to provide the Service, comply with legal obligations and resolve disputes:

End Users may exercise rights through the Customer (controller) that originally collected the data.

10. Your rights

Under GDPR / UK GDPR, you may:

Under the CCPA/CPRA and other US state laws, California residents and equivalent residents (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others where the law applies to us) may:

To exercise any of these rights, email [email protected] with the subject prefix [privacy]. We will verify your identity using information already in our possession (typically the email associated with your account). We will respond within 30 days (45 days if extended, with notice) for GDPR, and within 45 days for CCPA/CPRA (extendable once with notice).

11. Automated decision-making

We do not use Personal Information to make automated decisions producing legal or similarly significant effects on you. Where Customers configure their agents to take such decisions, the Customer is the controller and is responsible for providing the Article 22 GDPR safeguards (right to obtain human intervention, to express their point of view, and to contest the decision).

12. Security

Data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted at the database and object-storage layers. Integration credentials are encrypted at the application layer with envelope encryption. We enforce role-based access control, scoped tenant isolation, audit logging on privileged actions and regular backups. We will notify Customers of personal-data breaches affecting them without undue delay (within 72 hours of becoming aware where required by GDPR Art. 33).

13. Children

The Service is not directed to children. We do not knowingly collect Personal Information from children under 13 (US, COPPA) or, where applicable under national law, under 16 (EU). If you believe a child has provided personal data, please contact us so we can delete it.

14. Notice to California residents (CCPA "Shine the Light")

California Civil Code §1798.83 entitles California residents to request a notice describing categories of personal information we share with third parties for direct-marketing purposes. We do not share Personal Information with third parties for their direct-marketing purposes; therefore, no such disclosure is required.

15. Notice to Nevada and Washington residents

We do not sell covered information as defined under Nevada SB 220, and we do not collect "consumer health data" subject to the Washington My Health My Data Act through the Service.

16. Changes

We may update this Policy to reflect changes in the law, our subprocessors, or the Service. Material changes will be communicated by email or in-product notice with reasonable advance notice. The "Last updated" date at the top of this page reflects the current effective date.

17. Contact

For privacy questions, DSR/DSAR requests, or any matter under this Policy, write to [email protected] with the subject prefix [privacy]. We are the sole point of contact for privacy matters; if a postal address or appointment of an EU/UK Article 27 representative becomes necessary in your jurisdiction, we will provide it on request.

Have a question about this document? Email [email protected].

See also: Terms of Service, Cookie Policy, Data Processing Addendum.