Privacy Policy
Effective Date: September 2, 2026
SoulMen is not a registered company. It is an independent, freelance project offered as a service to subcontractors and vendors in the United Arab Emirates, built and operated jointly by Tanmay Patil and Parth Salunkhe (together, "we", "us", or "our"), based in India. This privacy policy describes how we collect, use, and store information when a subcontractor company ("Customer", "you") uses SoulMen — a UAE vendor-readiness and tender-document compliance tool — to check a tender submission pack for completeness before it goes to a client or portal.
We are committed to protecting your privacy and handling data in line with applicable data protection principles, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45/2021), India's Digital Personal Data Protection Act 2023 (as the jurisdiction we currently operate from), and the GDPR where it applies. Because SoulMen has no corporate legal entity, the commitments in this policy are undertaken personally and jointly by Tanmay Patil and Parth Salunkhe, not by a company — this will be revisited if SoulMen is formally incorporated in the future.
1. Who This Covers
This policy applies to all registered users, reviewers, company administrators, and platform administrators of subcontractor companies ("tenants") using SoulMen to analyze and verify tender submission packages.
2. What We Collect
To provide our service, we collect the following categories of information:
- Account and Identity Information: Name, business email address, and organization membership. Sign-in and session management is handled by our authentication provider, Clerk (see §4) — we do not store or process your password ourselves.
- Uploaded Documents: Trade licenses, VAT/tax certificates, chamber of commerce certificates, ISO certificates, HSE policy manuals, audited financial statements, bank letters, lease agreements, ICV certificates, insurance certificates, and similar corporate/compliance documents uploaded for readiness checking. These commonly contain sensitive fields such as corporate names, license and registration numbers, TRNs, IBANs and bank details, financial figures, signatures, and corporate stamps.
- Client Requirement Packs / Checklists: The buyer or portal document(s) you upload (or select from our seeded template library) that define what your submission needs to contain.
- System-Generated Metadata: Extracted field values (e.g., expiry dates, TRNs, license numbers), compliance findings, confidence scores, and an audit ledger recording which user reviewed, overrode, approved, or rejected each finding.
- Platform Usage Logs: Actions taken within the workspace, checklists used, upload timestamps, and system performance/error logs needed to operate and troubleshoot the pipeline.
- Billing Information: If you purchase a plan or per-audit credits, our payment processor Polar (see §4) handles and stores your payment card details directly — we never receive or store your full card number. We store only the resulting order/subscription record, credit balance, and a reference token to your saved payment method (not the underlying card data).
- Website Visitor / Checklist Request Information: If you request a free portal-checklist PDF from one of our buyer-portal pages (e.g. dewa, adnoc), we collect the email address you provide, which portal's checklist you requested, whether you opted in to marketing emails, and, for evidentiary purposes, the IP address and browser user-agent your browser sent at the time and which version of this consent copy you agreed to. See "Website Visitors and Checklist Requests" below for how this is used and retained.
We do not collect this information for any purpose beyond providing, maintaining, securing, and improving the readiness-checking service.
3. How We Use Your Information
We process your data strictly to perform our contract with you, specifically to:
- Route, classify, and extract metadata from uploaded documents.
- Check extracted details against the buyer/portal checklist you selected or uploaded.
- Compile a readiness report and highlight missing, expired, mismatched, or unsigned/unstamped documents, each cited back to a specific page in your own documents.
- Keep an audit ledger of reviewer decisions and approvals to meet your own internal compliance/sign-off needs.
- Send automated email alerts for upcoming document expiries, invites, approvals, and account verification, where applicable.
- Process billing and, if approval workflows are enabled for your organization, reserve/charge audit credits.
- Monitor pipeline performance and reliability to prevent and diagnose service disruption.
Every AI-assisted finding is produced for human review, not automated action. The Service surfaces findings; a qualified representative of your organization reviews, approves, or overrides each one before it informs any business decision. See our Terms of Service §5A for the corresponding contractual obligation.
We do not sell your personal or corporate data, and we do not use your uploaded documents or extracted content to train our own AI models — including documents retained under the opt-in accuracy-benchmarking program described in §5. Benchmarking measures how accurately the Service performs against a hand-verified answer set; it does not feed your documents into training, fine-tuning, or otherwise modifying any AI model, ours or a third party's. See §4 for how our AI extraction provider (Google) handles the data it receives.
4. Subprocessors and Third-Party Providers
To deliver the service, we rely on the following third-party providers (subprocessors), each of which only receives the data needed to perform its function:
| Subprocessor | Purpose | What it receives | Data Protection Notes |
|---|---|---|---|
| Clerk | Authentication, session management, and organization/team membership | Name, email address, session/device data, org role | Clerk manages your credentials directly under its own security and privacy practices — we never see or store your password. |
| Google Gemini API (default) | AI-assisted document classification and field extraction | The text or page images of documents you upload | Under standard Gemini API terms, your files/prompts are not used to train Google's models, but may be logged/cached in countries where Google or its processing agents operate. There is no dedicated Google Cloud DPA or data-residency guarantee in this default mode. |
| Google Cloud Vertex AI (optional, enterprise) | Same AI extraction, routed through Vertex AI instead of the public Gemini API | Same as above | Available on request for customers who need a signed Google Cloud DPA and regional data-residency guarantees. Not enabled by default. |
| Cloudflare (R2 Object Storage) | Encrypted storage of uploaded documents and generated export packages | Your uploaded files | Encrypted at rest (SSE); never served via a public URL — all access uses short-lived (15-minute) pre-signed URLs. |
| Supabase (PostgreSQL) | Storage of accounts, extracted metadata, findings, and audit trails | Extracted field values, findings, decisions, tenant/user records | Hosted in Supabase's Mumbai (ap-south-1) region with strict per-tenant isolation enforced on every query. |
| Resend | Delivery of transactional emails (invites, approval requests, expiry alerts, verification) | Recipient email address and the relevant email content | Standard transactional email delivery; emails are queued and rate-limited on our side before sending. |
| ClamAV (self-hosted malware scanner) | When configured for the deployment, scans every uploaded file for malware before it is processed | The raw bytes of each uploaded file, transiently, for scanning only | Runs on infrastructure we operate; files are streamed to it for scanning and are not retained by the scanner itself. See §7 for what runs when it isn't configured. |
| Polar | Payment processing and billing | Payment card details, billing contact info | Card data is captured and stored directly by Polar via its hosted, tokenized checkout/payment-method widget — it never touches our servers. We store only the resulting order and a reference to your saved payment method. |
| Heroku | Hosts the application and background processing worker | All of the above, as the runtime environment | Standard cloud application hosting; no additional data categories beyond what's listed above. |
| Sentry | Error monitoring and crash diagnostics | Error/exception details, which may include a tenant or review identifier for the request that failed | Used only to detect and fix bugs; not used for marketing or analytics. |
| Umami (Umami Cloud) | Privacy-oriented website analytics on our marketing pages | IP address and browser/user-agent, in aggregate | No advertising or cross-site tracking; see §8 for our cookie stance — Umami is cookie-less. |
| Papertrail | Application log aggregation | Structured application logs; personal identifiers (e.g. email addresses) are hashed before being logged, not stored in the clear | Used for operational troubleshooting; retained on Papertrail's own short (days-scale) retention window. |
For customers under strict data sovereignty or DPA requirements — particularly around AI extraction — contact us before onboarding; a Vertex AI or dedicated-deployment configuration can be discussed. A signable Data Processing Addendum is available for procurement.
5. Retention and Deletion Policy
Operational retention (automatic, 90 days, applies to everyone). Uploaded files, extracted metadata, findings, and reviewer decisions tied to a review are automatically and permanently deleted 90 days after that review completes or errors out (RETENTION_DAYS, configurable per deployment). Cached AI extraction results (used only to avoid re-analyzing an identical re-uploaded file) are separately pruned after 14 days of inactivity.
You can also delete any review, document, or associated data immediately from your account at any time. When a review is deleted, its files are removed from storage and all database references are pruned permanently — this is not a soft delete.
Monitoring record (automatic, indefinite, survives review deletion). Deleting a review does not delete everything tied to it. For each document type your organization has ever had verified (e.g. "trade license", "ISO certificate"), we keep one small record — its expiry date, the company name on it, and its license/registration number — so expiry alerts and the document vault keep working even after the review that produced it is deleted, either by the 90-day operational window above or by you deleting it yourself. No file, extracted evidence snippet, or finding is kept in this record — only those four facts. It is not covered by the benchmark opt-in below; it exists for every organization, opt-in or not. You can view and delete these records at any time from Company Admin → Monitoring records; deleting one stops alerts for that document type until it's verified again.
Benchmark retention (opt-in, off by default, indefinite until revoked). Separately from the operational window and the monitoring record above, your organization may opt in — in workspace settings, with its own consent text shown at the moment you opt in — to let us retain copies of your documents for the accuracy-benchmarking purpose described in §3 and in our Terms of Service §8. If you opt in:
- Retained copies are stored in a separate storage location and database table, excluded from the 90-day operational sweep described above.
- You can revoke this opt-in at any time; revocation deletes the retained copies.
- If you never opt in, or you opted in and later revoked, no copy of your documents survives past the standard 90-day (or 14-day cache) windows — the two retention mechanisms are entirely independent, and declining or revoking one never affects the other.
- Access to the benchmark store is limited to Tanmay Patil and Parth Salunkhe in their capacity as the individuals operating the Service.
5A. Website Visitors and Checklist Requests
If you request a free buyer-portal checklist PDF from our marketing site without otherwise being a registered SoulMen user, we use your email solely to send you the requested PDF and, if you separately checked the marketing opt-in box, occasional related updates. You can unsubscribe from marketing emails at any time via the link in those emails.
- If you did not opt in to marketing, we delete your submission (email, IP, user-agent, and request record) once the one-time download link we sent you expires — 30 days after your request.
- If you did opt in to marketing, we keep your submission until you unsubscribe, at which point the same deletion applies.
- This is a separate, shorter retention window from §5's 90-day operational review window — a checklist request never creates a review, account, or uploaded document, so none of §5's other provisions apply to it.
6. Data Breach Notification
If we become aware of a breach affecting your personal or corporate data, we will notify the affected organization's registered administrator by email at [email protected] (as sender) without undue delay, and in any case within 72 hours of confirming the breach, describing what happened, what data was affected, and what we are doing about it.
7. Security Measures
We implement administrative, technical, and physical safeguards proportionate to the sensitivity of corporate compliance documents:
- Data Encryption: Files are encrypted at rest (AES-256, via Cloudflare R2's server-side encryption) and in transit (TLS 1.3).
- Authenticated Access: Sign-in and session validation is handled by Clerk on every request — we do not implement or store credentials ourselves.
- Tenant Isolation: Every database query is scoped to a tenant ID resolved and verified from your authenticated session before it reaches application code; a request can never read or write another organization's data by supplying its own tenant identifier.
- Malware Screening: Every uploaded file is checked against its declared file type's expected signature and against known malware test signatures before it is processed. When a ClamAV scanning engine is configured for the deployment, every file is additionally streamed to it for a full antivirus scan, and in production an unreachable or misbehaving scanner causes the upload to be rejected rather than silently passed. If no ClamAV engine is configured for a deployment, only the signature/test-pattern checks run — contact us to confirm which mode is active for your engagement.
- Payment Data: We never receive, process, or store raw payment card numbers. All card capture happens directly with our payment processor, Polar.
8. Cookies
We do not use analytics, advertising, or tracking cookies. The only cookies set are session cookies from our authentication provider, Clerk, needed to keep you signed in. Full detail in our Cookie Policy.
9. Your Rights
Under the UAE PDPL and, where applicable, the GDPR, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Deletion: Request deletion of your personal data when it is no longer needed.
- Right to Restriction: Request restriction of processing under specific circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at [email protected].
10. Policy Updates
We may update this policy periodically to reflect operational, legal, or regulatory changes. We will notify you of material changes by posting the updated policy on our platform and, where feasible, by email or in-app notice.
11. Contact Us
If you have questions about this Privacy Policy or our data handling practices, contact us:
- Email: [email protected]
- Operated by: Tanmay Patil and Parth Salunkhe, jointly, as an independent project based in India. SoulMen is not a registered company and has no mailing address at this time — the email above is the current point of contact for all privacy-related requests.