← Back to SoulMen

Data Processing Addendum

Last Updated: August 14, 2026

This Data Processing Addendum ("DPA") supplements the Terms of Service and Privacy Policy between the Customer and Tanmay Patil and Parth Salunkhe, jointly (together, "we", "us"), the individuals operating SoulMen. SoulMen is not a registered company — this DPA is signed personally by Tanmay Patil and Parth Salunkhe, not by a corporate entity, consistent with the rest of our Terms of Service.

1. Parties and Roles

For the purposes of this DPA:

2. Scope and Duration

This DPA applies for as long as we process Customer personal data under the Terms of Service, and survives termination for as long as any Customer personal data remains in our systems (see §6, Deletion and Return).

3. Subprocessors

We rely on the subprocessors listed in our Privacy Policy §4 (Clerk, Google Gemini API / Vertex AI, Cloudflare R2, Supabase, Resend, ClamAV, Polar, Heroku), each receiving only the data needed to perform its function. We will not add a new subprocessor that materially changes how Customer personal data is handled without updating that table and, where feasible, notifying the Customer in advance.

4. Security Measures

We implement the technical and organizational measures described in our Privacy Policy §7 (Security Measures): encryption at rest and in transit, tenant-isolated database access on every request, malware screening of uploaded files, and no storage of raw payment card data. See that section for current detail — it is incorporated here by reference so this DPA does not drift out of sync with what the Service actually does.

5. Breach Notification

We will notify the Customer's registered administrator of a personal data breach as described in our Privacy Policy §6 — without undue delay, and in any case within 72 hours of confirming the breach.

6. Deletion and Return on Termination

On termination of the Customer's use of the Service, or on request, we will delete Customer personal data in accordance with the retention schedule in our Privacy Policy §5 (90-day automatic operational retention, plus immediate on-demand deletion). If the Customer has separately opted in to benchmark retention (Privacy Policy §5, Terms of Service §8), that retained data is deleted on revocation of that opt-in or on request, independent of the operational retention schedule.

7. International Transfers

Customer personal data is processed in the jurisdictions listed in our Privacy Policy §4 — principally India (Supabase ap-south-1) and wherever Google's Gemini API or Vertex AI processes data for the deployment mode in use. Cross-border transfer under the UAE PDPL (Federal Decree-Law No. 45/2021, Arts 22–23) is made on the basis of contractual necessity to perform the Service the Customer has requested, and, where applicable, the Customer's consent recorded at Terms of Service acceptance.

8. Customer Obligations

The Customer represents that it has all necessary rights, consents, and legal basis to upload the personal data contained in the documents it submits to the Service, consistent with Terms of Service §4.

9. Contact

For DPA-related questions or to discuss execution of a signed copy, contact [email protected].