Privacy Policy
Last updated: 2026-05-10
This Privacy Policy describes how SoloRiff ("SoloRiff", "we", "our", "us") collects, uses, discloses and safeguards information when you use our website, dashboard ("Studio"), APIs and embedded widgets (the "Service"). It applies both to people who sign up as SoloRiff customers ("Customers") and to end users who interact with widgets that Customers have embedded on their websites ("End Users"). Capitalised terms not defined here have the meaning given in the Terms of Service or the Data Processing Addendum.
1. Roles under data-protection law
For data Customers submit, configure or process through the Service (e.g. visitor conversations, knowledge sources, contact lists), the Customer is the data controller (or, in California terminology, the "business") and SoloRiff acts as processor (or "service provider") under Article 28 GDPR, Article 28 UK GDPR, the CCPA/CPRA, and analogous US state privacy laws.
For data we collect about Customers themselves (account, billing, support correspondence, marketing where permitted), SoloRiff acts as controller / "business".
2. Personal data we collect
- Account data: name, work email, hashed password, organisation, role, locale, MFA secrets where enabled.
- Billing data: plan, payment-method tokens (held by our payment processor), invoices, tax identifiers, billing address.
- Conversational data: messages exchanged through Customer widgets, transcripts, voice recordings (where enabled), and lead-capture form fields.
- Knowledge sources: documents, URLs and other content Customers ingest to train their agents.
- Contact records: emails and metadata Customers ingest into the CRM views inside SoloRiff.
- Usage & technical data: IP address, user agent, language, request and error logs, device and session identifiers.
- Cookies and similar storage: strictly necessary cookies for authentication and CSRF protection; functional storage for theme and consent (see our Cookie Policy).
3. Categories under California law
For California residents, we treat the following CCPA/CPRA categories as collected:
- Identifiers (name, email, IP).
- Customer records (account profile, billing).
- Commercial information (transactions, plan history).
- Internet or other electronic network activity (logs, widget interactions).
- Geolocation (approximate, derived from IP).
- Audio data (voice recordings, where Customers enable voice mode).
- Professional or employment-related information (role, organisation).
- Inferences (derived ICP fit, intent signals — only as part of Customer Data on behalf of Customers).
We do not "sell" Personal Information as defined under the CCPA, and we do not "share" Personal Information for cross-context behavioural advertising as defined under the CPRA. We do not process "sensitive personal information" beyond what is strictly necessary to provide the Service.
4. Sources of personal data
We collect personal data:
- directly from Customers when they sign up, configure agents and submit support requests;
- from End Users when they interact with widgets embedded by Customers;
- from a limited number of integration partners (e.g. enrichment providers, identity providers) where Customers explicitly enable them; and
- from Customers' authorised systems (CRMs, mailboxes) when Customers connect them to the Service.
5. Purposes & legal bases (GDPR Art. 6)
- Provide the Service — performance of contract: operate the platform, run agents, deliver messages, store transcripts, generate analytics.
- Billing & accounting — legal obligation, contract: invoice Customers and meet tax-law retention requirements.
- Security & abuse prevention — legitimate interest, legal obligation: rate limiting, fraud detection, audit logging, incident investigation.
- Service communications — contract, legitimate interest: operational notices, security alerts, in-product changes.
- Marketing — consent (or legitimate interest where permitted by law and the soft opt-in regime applies); you can unsubscribe at any time.
- Compliance with law — legal obligation: responding to lawful requests from competent authorities.
6. How we use Personal Information (US)
Under US state privacy laws, we use Personal Information for the "business purposes" listed in §1798.140(e) CCPA, including providing requested services, security and integrity, debugging, short-term transient use, performing services on behalf of the business, and internal R&D solely to improve the Service.
7. Disclosure & subprocessors
We share Personal Information with subprocessors strictly to deliver the Service. Categories include:
- cloud infrastructure (EU regions where available);
- payment processing;
- large language model providers (we use enterprise / no-training endpoints by default);
- speech and avatar providers;
- email delivery (Customer-configured or shared mailer);
- contact enrichment (where Customers opt in); and
- product analytics for the SoloRiff dashboard.
The current list of named subprocessors is published in the DPA.
8. International transfers
Some subprocessors are located outside the European Economic Area, the United Kingdom or Switzerland. Where personal data is transferred internationally, we rely on:
- European Commission Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Addendum (IDTA);
- Swiss FDPIC requirements where applicable; or
- an adequacy decision (e.g. EU–US Data Privacy Framework where the importer is certified).
We assess each transfer for additional safeguards as required by Schrems II and document the assessment in the DPA.
9. Retention
We retain personal data for as long as needed to provide the Service, comply with legal obligations and resolve disputes:
- Active Customer tenants: retained for the lifetime of the subscription.
- Cancelled tenants: data is purged within 30 days of cancellation.
- Billing records: retained up to 10 years to satisfy applicable tax laws.
- Security logs: retained up to 12 months for incident investigation.
- Backup snapshots: rotated within 35 days.
End Users may exercise rights through the Customer (controller) that originally collected the data.
10. Your rights
Under GDPR / UK GDPR, you may:
- access, rectify or erase your personal data;
- request restriction of, or object to, processing;
- request portability in a machine-readable format;
- withdraw consent at any time (without affecting prior lawful processing); and
- lodge a complaint with your supervisory authority (in the EU/EEA your national DPA; in the UK the ICO).
Under the CCPA/CPRA and other US state laws, California residents and equivalent residents (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others where the law applies to us) may:
- request disclosure of categories and specific pieces of Personal Information collected (right to know);
- request deletion (right to delete);
- request correction of inaccurate information;
- opt out of sale or sharing for cross-context behavioural advertising (we do not engage in either);
- limit the use of sensitive personal information;
- not be subject to discriminatory treatment for exercising these rights; and
- designate an authorised agent to exercise rights on your behalf with verifiable proof.
To exercise any of these rights, email [email protected] with the subject prefix [privacy]. We will verify your identity using information already in our possession (typically the email associated with your account). We will respond within 30 days (45 days if extended, with notice) for GDPR, and within 45 days for CCPA/CPRA (extendable once with notice).
11. Automated decision-making
We do not use Personal Information to make automated decisions producing legal or similarly significant effects on you. Where Customers configure their agents to take such decisions, the Customer is the controller and is responsible for providing the Article 22 GDPR safeguards (right to obtain human intervention, to express their point of view, and to contest the decision).
12. Security
Data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted at the database and object-storage layers. Integration credentials are encrypted at the application layer with envelope encryption. We enforce role-based access control, scoped tenant isolation, audit logging on privileged actions and regular backups. We will notify Customers of personal-data breaches affecting them without undue delay (within 72 hours of becoming aware where required by GDPR Art. 33).
13. Children
The Service is not directed to children. We do not knowingly collect Personal Information from children under 13 (US, COPPA) or, where applicable under national law, under 16 (EU). If you believe a child has provided personal data, please contact us so we can delete it.
14. Notice to California residents (CCPA "Shine the Light")
California Civil Code §1798.83 entitles California residents to request a notice describing categories of personal information we share with third parties for direct-marketing purposes. We do not share Personal Information with third parties for their direct-marketing purposes; therefore, no such disclosure is required.
15. Notice to Nevada and Washington residents
We do not sell covered information as defined under Nevada SB 220, and we do not collect "consumer health data" subject to the Washington My Health My Data Act through the Service.
16. Changes
We may update this Policy to reflect changes in the law, our subprocessors, or the Service. Material changes will be communicated by email or in-product notice with reasonable advance notice. The "Last updated" date at the top of this page reflects the current effective date.
17. Contact
For privacy questions, DSR/DSAR requests, or any matter under this Policy, write to [email protected] with the subject prefix [privacy]. We are the sole point of contact for privacy matters; if a postal address or appointment of an EU/UK Article 27 representative becomes necessary in your jurisdiction, we will provide it on request.
Have a question about this document? Email [email protected].
See also: Terms of Service, Cookie Policy, Data Processing Addendum.