Data Processing Addendum
Last Updated: August 14, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service and Privacy Policy between the Customer and Tanmay Patil and Parth Salunkhe, jointly (together, "we", "us"), the individuals operating SoulMen. SoulMen is not a registered company — this DPA is signed personally by Tanmay Patil and Parth Salunkhe, not by a corporate entity, consistent with the rest of our Terms of Service.
1. Parties and Roles
For the purposes of this DPA:
- Customer is the data controller for the personal data contained in the documents it uploads to the Service.
- We act as a data processor, processing that personal data solely to provide the Service as described in the Terms of Service, and as further detailed in this DPA.
2. Scope and Duration
This DPA applies for as long as we process Customer personal data under the Terms of Service, and survives termination for as long as any Customer personal data remains in our systems (see §6, Deletion and Return).
3. Subprocessors
We rely on the subprocessors listed in our Privacy Policy §4 (Clerk, Google Gemini API / Vertex AI, Cloudflare R2, Supabase, Resend, ClamAV, Polar, Heroku), each receiving only the data needed to perform its function. We will not add a new subprocessor that materially changes how Customer personal data is handled without updating that table and, where feasible, notifying the Customer in advance.
4. Security Measures
We implement the technical and organizational measures described in our Privacy Policy §7 (Security Measures): encryption at rest and in transit, tenant-isolated database access on every request, malware screening of uploaded files, and no storage of raw payment card data. See that section for current detail — it is incorporated here by reference so this DPA does not drift out of sync with what the Service actually does.
5. Breach Notification
We will notify the Customer's registered administrator of a personal data breach as described in our Privacy Policy §6 — without undue delay, and in any case within 72 hours of confirming the breach.
6. Deletion and Return on Termination
On termination of the Customer's use of the Service, or on request, we will delete Customer personal data in accordance with the retention schedule in our Privacy Policy §5 (90-day automatic operational retention, plus immediate on-demand deletion). If the Customer has separately opted in to benchmark retention (Privacy Policy §5, Terms of Service §8), that retained data is deleted on revocation of that opt-in or on request, independent of the operational retention schedule.
7. International Transfers
Customer personal data is processed in the jurisdictions listed in our Privacy Policy §4 — principally India (Supabase ap-south-1) and wherever Google's Gemini API or Vertex AI processes data for the deployment mode in use. Cross-border transfer under the UAE PDPL (Federal Decree-Law No. 45/2021, Arts 22–23) is made on the basis of contractual necessity to perform the Service the Customer has requested, and, where applicable, the Customer's consent recorded at Terms of Service acceptance.
8. Customer Obligations
The Customer represents that it has all necessary rights, consents, and legal basis to upload the personal data contained in the documents it submits to the Service, consistent with Terms of Service §4.
9. Contact
For DPA-related questions or to discuss execution of a signed copy, contact [email protected].