Effective date: 1 June 2026 · Last updated: June 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between Sofro (“Processor”) and the customer (“Controller”) and governs the processing of personal data by Sofro on behalf of the customer in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”).
By using Sofro you agree to this DPA. If you are acting on behalf of a company or organisation, you represent that you have authority to bind that entity.
2. Definitions
Terms not defined here have the meanings given in the GDPR. “Services” means the Sofro platform accessible at sofro.ai. “Sub-processor” means any processor engaged by Sofro to process personal data.
3. Subject matter and nature of processing
Sofro processes personal data to provide the Services, including connecting to your Microsoft 365 account (email, calendar), generating AI-assisted drafts, and storing action logs and audit trails. Processing is carried out on documented instructions from the Controller — i.e. your use of the Services.
4. Categories of data subjects and personal data
| Category | Examples |
|---|---|
| Account holders | Name, email address, organisation name |
| Email correspondents | Names and email addresses appearing in connected inboxes |
| Calendar participants | Names, email addresses, event titles and times |
| Document content | Any personal data present in files uploaded to Sofro |
Sofro does not intentionally process special category data. The Controller is responsible for ensuring that any special category data in connected accounts or uploaded files is processed lawfully.
5. Processor obligations
Sofro will:
6. Sub-processors
The Controller grants general authorisation for Sofro to engage sub-processors. Sofro will inform the Controller of any intended changes and give the Controller the opportunity to object. Current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting and edge infrastructure | USA / EU (SCCs applied) |
| Neon Inc. | Primary database | EU (within EEA) |
| Clerk Inc. | Authentication and user management | USA (SCCs applied) |
| DataCrunch Oy (Verda) | AI model inference — Sofro runs its own model on Verda infrastructure | Finland, EU (within EEA) |
| Microsoft Corporation | Microsoft 365 API (Outlook and Calendar) | USA (SCCs applied) |
| Stripe Inc. | Payment processing and subscription management | USA (SCCs applied) |
| Sentry (Functional Software Inc.) | Error monitoring — request bodies and user identifiers stripped before transmission | USA (SCCs applied) |
| Amazon Web Services (AWS) | Immutable audit log storage (S3) and audit queue (SQS) for enterprise customers | USA (SCCs applied) · data stored in EU (Stockholm, eu-north-1) |
7. International transfers
Sofro hosts its infrastructure and AI inference within the EU. Where any sub-processor is located outside the EEA in a country that does not benefit from an adequacy decision, Sofro ensures an appropriate safeguard is in place, such as Standard Contractual Clauses adopted by the European Commission.
8. Security measures
Sofro maintains technical and organisational measures including: encryption at rest and in transit, access controls, tamper-evident audit logs, regular security reviews, and incident response procedures. Details are available at sofro.ai/security.
9. Data subject rights
The Controller is responsible for handling data subject rights requests. Sofro will assist the Controller by technical and organisational means where possible. Requests can be submitted via sofro.ai/privacy.
10. Data retention and deletion
Personal data is retained for as long as necessary to provide the Services and comply with legal obligations. Upon termination, the Controller may request deletion of personal data within 30 days by contacting privacy@sofro.ai.
11. Contact
Questions about this DPA or requests for a countersigned copy should be directed to privacy@sofro.ai.
Last reviewed: June 2026