The Soul Company, Inc.
See it livePricingBook a demo

Legal

Data Processing Agreement

Last updated July 2026
The Soul Company, Inc.

0. What this is

This agreement covers personal data that The Soul Company, Inc. (“Soul”) processes on behalf of a customer company (“Customer”) when Customer uses the Soul community service, and it forms part of the agreement between us.

It takes effect when both parties sign it. Nothing on this page is executed by reading it. To put it in place, email legal@soulverified.com and we will countersign, or send yours and we will review it.

1. Roles

Customer is the controller and decides why and how the personal data is processed. Soul is the processor and acts only on Customer’s documented instructions, of which this agreement and the service documentation are the whole set.

Where an end user connects their own account from another platform, that platform is an independent controller of the data it holds. Soul receives only what that user consented to release.

2. Subject matter and duration

Subject matter. Providing the Soul community service: reading coarse interest signals about Customer’s users, programming real-world gatherings for them, and recording who committed and who arrived.

Duration. For as long as Customer uses the service, plus the deletion window in section 11.

Nature and purpose. Storage, organisation, matching and retrieval, in order to show a user gatherings relevant to them and to report to Customer on their own community.

3. Annex I: categories of data

Data subjects: Customer’s end users who interact with the Soul surface inside Customer’s product.

Personal data processed:

  • A pseudonymous user identifier chosen by Customer, namespaced to Customer.
  • Coarse derived interest tags, for example early-riser, runner, techno.
  • City, where supplied.
  • Display name, only where Customer or the user supplies one.
  • Gathering activity: which gatherings a user committed to, whether they recorded an arrival, and whether that arrival was at the gathering.

Location, precisely. When a user taps that they have arrived, their device may offer a coordinate. It is used in the request to compare against where that gathering is and is then discarded. What is kept is a single true or false against the arrival. Soul stores one coordinate per gathering, rounded to roughly a hundred metres, which describes the park or the coffee shop rather than any person, and it is set by the first arrival rather than by tracking anyone. Sharing it is optional and refusing it still records the arrival.

Not processed. No location history, no movement trail, and no coordinate tied to a person is ever stored. Soul does not receive or store raw health records, heart rates, sleep records, workouts, or listening histories. Where a user connects an account, those records are reduced to coarse tags at the point of ingest and the underlying payload is not persisted.

Special category data. None is requested and none should be sent. Customer must not transmit special category data through the identify API.

4. Instructions and lawful basis

Soul processes personal data only on Customer’s documented instructions, including for international transfers, unless required otherwise by law, in which case Soul will tell Customer first unless that law forbids it.

Soul will tell Customer if, in its opinion, an instruction infringes applicable data protection law. Customer is responsible for having a lawful basis for the data it sends and for the notices it gives its own users.

No training. Customer personal data is not used to train models, and is not used to improve any product for anyone other than Customer.

5. Confidentiality

Access is limited to personnel who need it to run the service, each bound by confidentiality obligations that survive the end of their engagement.

6. Annex II: security measures

Technical and organisational measures actually in place:

  • Encryption in transit (TLS) for all traffic, including between the service and every sub-processor.
  • Encryption at rest for the database and object storage, provided by the infrastructure vendors in Annex III.
  • Data minimisation at ingest: raw records are reduced to coarse tags and discarded rather than stored.
  • Namespaced tenancy, so one customer’s users are separated from another’s and cannot be read across.
  • API keys scoped per customer, revocable, with optional origin allowlisting so a leaked publishable key cannot be used from another site.
  • Signed webhook deliveries (HMAC-SHA256, timestamped to prevent replay).
  • Rate limiting on every public endpoint.
  • Reported vulnerabilities triaged on receipt at security@soulverified.com.

What we do not have, stated plainly. Soul holds no SOC 2 report and no third-party penetration test on file. We would rather say so than imply a certification we do not hold. Customer may treat this as a condition to be satisfied before wider rollout, and we will say honestly where we are.

7. Annex III: sub-processors

Soul uses these sub-processors for the community service:

  • Railway, application hosting and the primary database (United States).
  • Cloudflare R2, object storage.
  • Anthropic, the model that writes gatherings and reduces signals to tags. Receives already-reduced tags and gathering titles, never raw records. No training on submitted data.
  • Resend, transactional email.
  • Stripe, payment processing. Handles Customer’s billing contact, not end-user data.
  • Twilio, SMS, only where a customer has enabled it.

Soul remains liable for its sub-processors’ acts and omissions as for its own, and each is bound by data protection terms no less protective than these.

8. Changes to sub-processors

Soul will give Customer at least 30 days’ notice before adding or replacing a sub-processor that processes Customer personal data. Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.

9. Data subject rights

Soul will assist Customer in responding to requests to access, correct, export, restrict, object to, or delete personal data, taking into account the nature of the processing.

A request can be satisfied directly through the service or by emailing privacy@soulverified.com. Deletion covers derived tags as well as the record itself. If a request reaches Soul directly, Soul will not respond substantively but will forward it to Customer without undue delay.

10. Personal data breach

Soul will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer’s data, with the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.

Where all the facts are not yet known, Soul will send what it has rather than wait for a complete picture, and follow up as the investigation proceeds.

11. Deletion and return

On termination, or on request, Soul will delete Customer personal data within 30 days, including derived tags, and will certify deletion in writing if asked. Customer may export its data before then.

Backups are purged on their ordinary rotation, within 90 days, and remain subject to this agreement until they are.

12. Audit

Soul will make available the information reasonably needed to demonstrate compliance with this agreement, and will respond to a security questionnaire once per year, or after a breach affecting Customer.

Customer may audit on 30 days’ written notice, no more than once a year except after a breach or where a supervisory authority requires it, during business hours and without unreasonable disruption.

13. International transfers

Soul processes data in the United States. Where Customer is in the EEA, the United Kingdom or Switzerland, transfers are made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated here by reference and prevail over this agreement if they conflict with it.

For those clauses: the categories in Annex I above serve as their Annex I, the measures in Annex II as their Annex II, and the list in Annex III as their Annex III. The supervisory authority is the one with jurisdiction over Customer.

14. Precedence and liability

If this agreement conflicts with the main services agreement, this one governs for matters of data protection. Liability is subject to the limitations in the main agreement, except where applicable law does not permit that.

If a term here is held unenforceable, the rest stands.

15. Signing it

Email legal@soulverified.com with the signing entity’s full legal name and address, and we will return a countersigned copy. If your own DPA is required instead, send it and we will review it rather than insisting on ours.

The Soul Company, Inc.

© 2026 The Soul Company, Inc.
PricingDocsPrivacyTermsDPABook a demo