Data Processing Agreement
Last Updated: August 24, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between The Solo Software Group LLC (“TSSG,” “Processor,” “we”) and the customer agreeing to those Terms (“Customer,” “Controller,” “you”).
This DPA applies only where TSSG processes personal data on your behalf. That happens in exactly one circumstance: when you enable the Managed AI Service on the Sovereign tier. It takes effect automatically at that moment, with no signature required, and ceases to apply when you disable Managed AI.
If you have not enabled Managed AI, TSSG processes no personal data on your behalf and this DPA imposes no obligations. TSSG CRM Pro is self-hosted; your business data lives in your own database and never reaches us.
Where this DPA conflicts with the Terms of Service, this DPA governs as to the processing it covers.
1. Definitions
“Data Protection Law” means the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and any other privacy or data protection law applicable to the processing under this DPA.
“Customer Personal Data” means personal data contained in requests you transmit to the Managed AI Service and in the responses returned.
“Controller,” “Processor,” “Sub-processor,” “Data Subject,” “Personal Data,” “Processing,” and “Personal Data Breach” have the meanings given in the GDPR. Where the CCPA applies, TSSG is a “Service Provider” and you are a “Business.”
“Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor).
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s119A of the Data Protection Act 2018.
2. Roles
You are the Controller of Customer Personal Data. TSSG is the Processor. Each party complies with the Data Protection Law applicable to it in that role.
You determine the purposes and means of the processing. You are responsible for establishing a lawful basis, for providing any notice your data subjects are entitled to, and for ensuring you are permitted to disclose Customer Personal Data to us for the purpose described here. In particular, you acknowledge that enabling Managed AI adds a processor to your chain and that your own privacy notice needs to reflect it.
3. Scope of Processing (GDPR Article 28(3))
Subject matter. Provision of the Managed AI Service: transmitting your AI requests to a model provider and returning the responses.
Duration. For as long as Managed AI is enabled on your installation, plus the retention periods in Section 8.
Nature and purpose. Transmission, temporary handling in memory, routing, rate limiting, usage metering, and return of AI-generated responses. TSSG does not store request or response content at rest, does not analyse it for any purpose of its own, and does not use it to train any model.
Concretely: the request body is read into memory, checked against a fixed allowlist of providers, endpoints, models, and size limits, forwarded byte-for-byte to the provider with TSSG’s key substituted for yours, and the response returned to you unchanged. The only record kept is a metering row, described in Section 8.
Types of Personal Data. Whatever a given request causes the Plugin to retrieve from your CRM and include, which may comprise: names, business names, postal addresses, email addresses, telephone numbers, job and project descriptions, appointment details, invoice and payment amounts, proposal terms, consent records, notes, and free text you or your staff have entered. Also: the text your operator types, and technical metadata (licence identifier, timestamps, token counts).
You control the scope. The assistant retrieves records in response to specific requests; it holds no standing access. It is your responsibility not to place special-category data, payment card numbers, government identifiers, or protected health information into CRM fields, as the Terms of Service require.
Categories of Data Subject. Your clients and their contacts; your staff who use the CRM; any individual named in a record a request retrieves.
Special categories. Not processed by design. You must not submit them.
4. Processor Obligations
TSSG shall:
(a) Process on documented instructions only. Process Customer Personal Data solely to provide the Managed AI Service in accordance with this DPA, the Terms, and your use of the Plugin, which together constitute your documented instructions. If we are required by law to process otherwise, we will inform you first unless that law forbids it. We will tell you if we believe an instruction infringes Data Protection Law.
(b) Not sell or share. Not sell Customer Personal Data, not share it for cross-context behavioural advertising, not retain, use, or disclose it for any purpose other than performing this service, and not combine it with data from other sources except as the CCPA permits a Service Provider to do.
(c) Not train on it. Not use Customer Personal Data to train, fine-tune, or improve any machine learning model of TSSG or of any third party, and contract with sub-processors on terms consistent with that commitment.
(d) Ensure confidentiality. Ensure that anyone authorized to process Customer Personal Data is bound by a duty of confidentiality and processes it only as instructed.
(e) Implement security measures. Implement and maintain the technical and organizational measures set out in Annex A.
(f) Assist you. Taking into account the nature of the processing, provide reasonable assistance with data subject requests (Section 6), with data protection impact assessments, with prior consultation of a supervisory authority, and with your obligations under GDPR Articles 32 to 36.
(g) Delete or return. On termination of the Managed AI Service, delete Customer Personal Data as described in Section 8. Because we do not retain request content at rest, this is ordinarily satisfied immediately.
(h) Demonstrate compliance. Make available the information reasonably necessary to demonstrate compliance with Article 28 and permit audits as described in Section 9.
5. Sub-processors
You give general written authorization for TSSG to engage sub-processors, subject to this section.
The current sub-processors are listed on our Sub-processors page, which is maintained with a change history and is incorporated here by reference.
TSSG shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to you for each sub-processor’s performance.
Notice and objection. TSSG will publish any intended addition or replacement of a sub-processor on that page, and notify Managed AI customers by email, at least 30 days before the sub-processor begins processing. You may object on reasonable data protection grounds within those 30 days. We will work in good faith to provide an alternative. If we cannot, you may disable Managed AI and continue on own-key mode, or terminate the Sovereign subscription and receive a prorated refund of the unused remainder of your term, as your sole remedies.
6. Data Subject Rights
TSSG does not have a durable store of Customer Personal Data and therefore cannot locate an individual’s records on request. The records themselves live in your database, where you can access, correct, export, and erase them directly using the Plugin’s own tooling.
Where a data subject nonetheless contacts TSSG about processing under this DPA, we will not respond substantively, will direct them to you where we can identify you, and will notify you promptly. We will provide reasonable assistance, at your cost where the effort is more than trivial, in responding to any request that concerns processing we performed.
7. Personal Data Breach
TSSG shall notify you without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information is not all available at once, we will provide it in phases without undue further delay.
TSSG will take reasonable steps to mitigate and remediate, and will cooperate with you in meeting your own notification obligations. Notification is not an acknowledgement of fault or liability.
8. Retention and Deletion
Request and response content. Not stored at rest by TSSG. Content exists only in memory for the duration of the request and is discarded once the response is returned.
Usage metering. One row per request, holding a timestamp, licence identifier, provider name, model name, input, cached, and output token counts, computed cost, HTTP status, and round-trip duration. Nothing else. Retained for up to 24 months for billing, capacity planning, and abuse investigation.
Sub-processor retention. Governed by the terms stated on the Sub-processors page for each sub-processor.
On termination of Managed AI or of the Terms, TSSG shall delete remaining Customer Personal Data within 30 days, except where storage is required by law, in which case it shall be isolated and protected from further processing.
Because your business data never leaves your server, there is nothing for TSSG to return to you.
9. Audit
TSSG shall make available, on written request and no more than once in any twelve-month period unless a Personal Data Breach or a regulator’s requirement makes more frequent enquiry necessary, the information reasonably necessary to demonstrate compliance with this DPA, including a description of measures in place and the relevant sub-processor terms.
Where that information is insufficient for a Controller subject to GDPR Article 28(3)(h), TSSG shall permit and contribute to an audit conducted by you or an independent auditor you mandate, on at least 30 days’ written notice, during business hours, subject to confidentiality obligations, and without unreasonable disruption. You bear the cost of any such audit unless it establishes material non-compliance by TSSG.
10. International Transfers
TSSG processes Customer Personal Data in the United States and in the other locations stated on the Sub-processors page. No data residency guarantee is offered for the Managed AI Service. Our model provider’s standard API processes requests across its global infrastructure and does not pin machine learning processing to a chosen region.
Where you transfer Customer Personal Data subject to the GDPR, the UK GDPR, or Swiss law to TSSG in a country without an adequacy decision, the SCCs (Module Two, Controller to Processor) are incorporated into this DPA by reference and apply, with:
- Clause 7 (docking clause): included.
- Clause 9 (sub-processors): Option 2, general written authorization, with a 30-day notice period, as in Section 5.
- Clause 11 (redress): the optional independent dispute resolution body is not included.
- Clause 17 (governing law): the law of Ireland.
- Clause 18 (forum and jurisdiction): the courts of Ireland.
- Annex I.A (parties): you as data exporter and Controller; TSSG as data importer and Processor. Contact details are those in the Terms and in Section 12.
- Annex I.B (description of transfer): as set out in Section 3. Frequency: continuous, on demand. Transfer is for the duration of the Managed AI Service.
- Annex I.C (supervisory authority): that of the Member State in which you are established, or your EU representative.
- Annex II (technical and organizational measures): Annex A of this DPA.
- Annex III (sub-processors): the Sub-processors page.
For UK transfers, the UK Addendum applies to the SCCs above, with Table 4 completed as “neither party” able to end the Addendum on changes to the Approved Addendum. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, the competent authority is the Swiss FDPIC, and “Member State” is read so as not to deprive data subjects in Switzerland of their right to sue in Switzerland.
If a transfer mechanism is invalidated, the parties shall in good faith adopt a valid alternative.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by Data Protection Law. Nothing in this DPA limits any liability that cannot lawfully be limited, including a data subject’s rights under the SCCs.
12. Contact
Data protection enquiries under this DPA: [email protected], marked “Data Protection.”
Annex A: Technical and Organizational Measures
Encryption in transit. All traffic between your WordPress site, TSSG infrastructure, and sub-processors uses TLS 1.2 or above.
No content at rest. Request and response content is not written to persistent storage by TSSG. This is the primary control: data that is not stored cannot be breached, exfiltrated, or over-retained.
Encryption at rest. Credentials, secrets, and metering records held by TSSG are encrypted at rest. Secrets stored in the Plugin on your own server are encrypted using libsodium.
Access control. Administrative access to TSSG infrastructure is limited to personnel who require it, protected by multi-factor authentication, and granted on a least-privilege basis.
Authentication and isolation. Every Managed AI request is authenticated against a valid licence before any provider is contacted. Licence keys are never used as storage identifiers; they are hashed with SHA-256 first. Rate limiting, concurrency limits, daily call caps, and monthly spend accounting are enforced per licence in an isolated object, so one customer’s activity cannot consume or observe another’s.
Endpoint and payload restriction. The proxy forwards only to a fixed allowlist of provider hosts, endpoint paths, and model names. Request size and maximum output length are capped and a request omitting an output cap is rejected. Streaming is refused. Anything outside the allowlist is rejected before a provider key is ever attached, so a TSSG key cannot be relayed to an arbitrary endpoint.
Availability controls. A global spend circuit breaker and per-licence rate limits protect the service from runaway cost and abuse.
Segregation of duties. Your business data resides on your infrastructure. TSSG holds no copy, which structurally limits the blast radius of any incident on our side.
Logging and monitoring. Operational events are logged and alerted on. Logs record metadata, not request or response content.
Vendor management. Sub-processors are contracted on terms no less protective than this DPA, and their terms are published on the Sub-processors page.
Incident response. Documented procedure covering detection, containment, assessment, notification within the timeframe in Section 7, and post-incident review.
Personnel. All personnel with access are bound by confidentiality obligations.
Review. These measures are reviewed at least annually and on any material change to the architecture. TSSG may update them provided the level of security is not reduced.
