This agreement applies when you use SoloHum and it processes personal data on your behalf. It is part of the terms.
Roles
You are the controller of the data in the tools you connect. SoloHum is a processor: it reads that data only to provide the service to you, on your instructions, which are the settings and connections you make in the product.
What is processed
Described on the security page. SoloHum is designed so that end-customer personal data is not stored: identifiers are opaque, and names and email addresses are never written.
Obligations
- Process only on your instructions; never for SoloHum’s own purposes.
- Keep the data confidential; staff access is limited and logged.
- Protect it with the measures on the security page (encryption at rest and in transit, sealed credentials, row-level isolation).
- Help you answer requests from your own customers about their data.
- Tell you within 24 hours of confirming a breach that affects your data.
- Delete what was read from a source when you disconnect it, and everything under the account within 30 days of deletion.
- Use only the sub-processors below, and give notice before adding one.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, storage of everything SoloHum holds | AWS us-east-1, United States |
| Vercel, Inc. | Application hosting, serverless functions, scheduled jobs | United States (iad1) |
| Cloudflare, Inc. | DNS for solohum.com | Global |
| Resend, Inc. | Transactional email (sign-in links, briefs), once connected | United States |
Transfers
Data is stored in the United States. For data subject to EU/UK law, transfers rely on the providers’ standard contractual clauses.
Audit
On reasonable request SoloHum will provide the information needed to show compliance with this agreement.