← sofro.ai

Data Processing Agreement

Effective date: 1 June 2026 · Last updated: June 2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the agreement between Sofro (“Processor”) and the customer (“Controller”) and governs the processing of personal data by Sofro on behalf of the customer in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”).

By using Sofro you agree to this DPA. If you are acting on behalf of a company or organisation, you represent that you have authority to bind that entity.

2. Definitions

Terms not defined here have the meanings given in the GDPR. “Services” means the Sofro platform accessible at sofro.ai. “Sub-processor” means any processor engaged by Sofro to process personal data.

3. Subject matter and nature of processing

Sofro processes personal data to provide the Services, including connecting to your Microsoft 365 account (email, calendar), generating AI-assisted drafts, and storing action logs and audit trails. Processing is carried out on documented instructions from the Controller — i.e. your use of the Services.

4. Categories of data subjects and personal data

CategoryExamples
Account holdersName, email address, organisation name
Email correspondentsNames and email addresses appearing in connected inboxes
Calendar participantsNames, email addresses, event titles and times
Document contentAny personal data present in files uploaded to Sofro

Sofro does not intentionally process special category data. The Controller is responsible for ensuring that any special category data in connected accounts or uploaded files is processed lawfully.

5. Processor obligations

Sofro will:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries.
  • Ensure that authorised persons are bound by appropriate confidentiality obligations.
  • Implement appropriate technical and organisational security measures (Article 32 GDPR).
  • Assist the Controller in responding to data subject rights requests.
  • Assist the Controller in meeting its Article 32–36 obligations.
  • Delete or return all personal data upon termination of the Services, at the Controller's choice.
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA.

6. Sub-processors

The Controller grants general authorisation for Sofro to engage sub-processors. Sofro will inform the Controller of any intended changes and give the Controller the opportunity to object. Current sub-processors include:

Sub-processorPurposeLocation
Vercel Inc.Hosting and edge infrastructureUSA / EU (SCCs applied)
Neon Inc.Primary databaseEU (within EEA)
Clerk Inc.Authentication and user managementUSA (SCCs applied)
DataCrunch Oy (Verda)AI model inference — Sofro runs its own model on Verda infrastructureFinland, EU (within EEA)
Microsoft CorporationMicrosoft 365 API (Outlook and Calendar)USA (SCCs applied)
Stripe Inc.Payment processing and subscription managementUSA (SCCs applied)
Sentry (Functional Software Inc.)Error monitoring — request bodies and user identifiers stripped before transmissionUSA (SCCs applied)
Amazon Web Services (AWS)Immutable audit log storage (S3) and audit queue (SQS) for enterprise customersUSA (SCCs applied) · data stored in EU (Stockholm, eu-north-1)

7. International transfers

Sofro hosts its infrastructure and AI inference within the EU. Where any sub-processor is located outside the EEA in a country that does not benefit from an adequacy decision, Sofro ensures an appropriate safeguard is in place, such as Standard Contractual Clauses adopted by the European Commission.

8. Security measures

Sofro maintains technical and organisational measures including: encryption at rest and in transit, access controls, tamper-evident audit logs, regular security reviews, and incident response procedures. Details are available at sofro.ai/security.

9. Data subject rights

The Controller is responsible for handling data subject rights requests. Sofro will assist the Controller by technical and organisational means where possible. Requests can be submitted via sofro.ai/privacy.

10. Data retention and deletion

Personal data is retained for as long as necessary to provide the Services and comply with legal obligations. Upon termination, the Controller may request deletion of personal data within 30 days by contacting privacy@sofro.ai.

11. Contact

Questions about this DPA or requests for a countersigned copy should be directed to privacy@sofro.ai.

Last reviewed: June 2026