← Back to SoulMen

Privacy Policy

Effective Date: September 2, 2026

SoulMen is not a registered company. It is an independent, freelance project offered as a service to subcontractors and vendors in the United Arab Emirates, built and operated jointly by Tanmay Patil and Parth Salunkhe (together, "we", "us", or "our"), based in India. This privacy policy describes how we collect, use, and store information when a subcontractor company ("Customer", "you") uses SoulMen — a UAE vendor-readiness and tender-document compliance tool — to check a tender submission pack for completeness before it goes to a client or portal.

We are committed to protecting your privacy and handling data in line with applicable data protection principles, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45/2021), India's Digital Personal Data Protection Act 2023 (as the jurisdiction we currently operate from), and the GDPR where it applies. Because SoulMen has no corporate legal entity, the commitments in this policy are undertaken personally and jointly by Tanmay Patil and Parth Salunkhe, not by a company — this will be revisited if SoulMen is formally incorporated in the future.

1. Who This Covers

This policy applies to all registered users, reviewers, company administrators, and platform administrators of subcontractor companies ("tenants") using SoulMen to analyze and verify tender submission packages.

2. What We Collect

To provide our service, we collect the following categories of information:

We do not collect this information for any purpose beyond providing, maintaining, securing, and improving the readiness-checking service.

3. How We Use Your Information

We process your data strictly to perform our contract with you, specifically to:

Every AI-assisted finding is produced for human review, not automated action. The Service surfaces findings; a qualified representative of your organization reviews, approves, or overrides each one before it informs any business decision. See our Terms of Service §5A for the corresponding contractual obligation.

We do not sell your personal or corporate data, and we do not use your uploaded documents or extracted content to train our own AI models — including documents retained under the opt-in accuracy-benchmarking program described in §5. Benchmarking measures how accurately the Service performs against a hand-verified answer set; it does not feed your documents into training, fine-tuning, or otherwise modifying any AI model, ours or a third party's. See §4 for how our AI extraction provider (Google) handles the data it receives.

4. Subprocessors and Third-Party Providers

To deliver the service, we rely on the following third-party providers (subprocessors), each of which only receives the data needed to perform its function:

SubprocessorPurposeWhat it receivesData Protection Notes
ClerkAuthentication, session management, and organization/team membershipName, email address, session/device data, org roleClerk manages your credentials directly under its own security and privacy practices — we never see or store your password.
Google Gemini API (default)AI-assisted document classification and field extractionThe text or page images of documents you uploadUnder standard Gemini API terms, your files/prompts are not used to train Google's models, but may be logged/cached in countries where Google or its processing agents operate. There is no dedicated Google Cloud DPA or data-residency guarantee in this default mode.
Google Cloud Vertex AI (optional, enterprise)Same AI extraction, routed through Vertex AI instead of the public Gemini APISame as aboveAvailable on request for customers who need a signed Google Cloud DPA and regional data-residency guarantees. Not enabled by default.
Cloudflare (R2 Object Storage)Encrypted storage of uploaded documents and generated export packagesYour uploaded filesEncrypted at rest (SSE); never served via a public URL — all access uses short-lived (15-minute) pre-signed URLs.
Supabase (PostgreSQL)Storage of accounts, extracted metadata, findings, and audit trailsExtracted field values, findings, decisions, tenant/user recordsHosted in Supabase's Mumbai (ap-south-1) region with strict per-tenant isolation enforced on every query.
ResendDelivery of transactional emails (invites, approval requests, expiry alerts, verification)Recipient email address and the relevant email contentStandard transactional email delivery; emails are queued and rate-limited on our side before sending.
ClamAV (self-hosted malware scanner)When configured for the deployment, scans every uploaded file for malware before it is processedThe raw bytes of each uploaded file, transiently, for scanning onlyRuns on infrastructure we operate; files are streamed to it for scanning and are not retained by the scanner itself. See §7 for what runs when it isn't configured.
PolarPayment processing and billingPayment card details, billing contact infoCard data is captured and stored directly by Polar via its hosted, tokenized checkout/payment-method widget — it never touches our servers. We store only the resulting order and a reference to your saved payment method.
HerokuHosts the application and background processing workerAll of the above, as the runtime environmentStandard cloud application hosting; no additional data categories beyond what's listed above.
SentryError monitoring and crash diagnosticsError/exception details, which may include a tenant or review identifier for the request that failedUsed only to detect and fix bugs; not used for marketing or analytics.
Umami (Umami Cloud)Privacy-oriented website analytics on our marketing pagesIP address and browser/user-agent, in aggregateNo advertising or cross-site tracking; see §8 for our cookie stance — Umami is cookie-less.
PapertrailApplication log aggregationStructured application logs; personal identifiers (e.g. email addresses) are hashed before being logged, not stored in the clearUsed for operational troubleshooting; retained on Papertrail's own short (days-scale) retention window.

For customers under strict data sovereignty or DPA requirements — particularly around AI extraction — contact us before onboarding; a Vertex AI or dedicated-deployment configuration can be discussed. A signable Data Processing Addendum is available for procurement.

5. Retention and Deletion Policy

Operational retention (automatic, 90 days, applies to everyone). Uploaded files, extracted metadata, findings, and reviewer decisions tied to a review are automatically and permanently deleted 90 days after that review completes or errors out (RETENTION_DAYS, configurable per deployment). Cached AI extraction results (used only to avoid re-analyzing an identical re-uploaded file) are separately pruned after 14 days of inactivity.

You can also delete any review, document, or associated data immediately from your account at any time. When a review is deleted, its files are removed from storage and all database references are pruned permanently — this is not a soft delete.

Monitoring record (automatic, indefinite, survives review deletion). Deleting a review does not delete everything tied to it. For each document type your organization has ever had verified (e.g. "trade license", "ISO certificate"), we keep one small record — its expiry date, the company name on it, and its license/registration number — so expiry alerts and the document vault keep working even after the review that produced it is deleted, either by the 90-day operational window above or by you deleting it yourself. No file, extracted evidence snippet, or finding is kept in this record — only those four facts. It is not covered by the benchmark opt-in below; it exists for every organization, opt-in or not. You can view and delete these records at any time from Company Admin → Monitoring records; deleting one stops alerts for that document type until it's verified again.

Benchmark retention (opt-in, off by default, indefinite until revoked). Separately from the operational window and the monitoring record above, your organization may opt in — in workspace settings, with its own consent text shown at the moment you opt in — to let us retain copies of your documents for the accuracy-benchmarking purpose described in §3 and in our Terms of Service §8. If you opt in:

5A. Website Visitors and Checklist Requests

If you request a free buyer-portal checklist PDF from our marketing site without otherwise being a registered SoulMen user, we use your email solely to send you the requested PDF and, if you separately checked the marketing opt-in box, occasional related updates. You can unsubscribe from marketing emails at any time via the link in those emails.

6. Data Breach Notification

If we become aware of a breach affecting your personal or corporate data, we will notify the affected organization's registered administrator by email at [email protected] (as sender) without undue delay, and in any case within 72 hours of confirming the breach, describing what happened, what data was affected, and what we are doing about it.

7. Security Measures

We implement administrative, technical, and physical safeguards proportionate to the sensitivity of corporate compliance documents:

8. Cookies

We do not use analytics, advertising, or tracking cookies. The only cookies set are session cookies from our authentication provider, Clerk, needed to keep you signed in. Full detail in our Cookie Policy.

9. Your Rights

Under the UAE PDPL and, where applicable, the GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at [email protected].

10. Policy Updates

We may update this policy periodically to reflect operational, legal, or regulatory changes. We will notify you of material changes by posting the updated policy on our platform and, where feasible, by email or in-app notice.

11. Contact Us

If you have questions about this Privacy Policy or our data handling practices, contact us: