Skip to content
Soras Corp Tech
Products Enthyma Legal Contact us
Part of Soras Corp
Englishen Deutschde Españoles Françaisfr Italianoit 日本語ja Polskipl Português (Brasil)pt Русскийru Українськаuk
Contact us

Data Processing Addendum

Documents for Enthyma, operated by Soras Corporation LTD.

Drafts under legal review

These documents are working drafts prepared for review by counsel and are not yet in force. The English version governs.

On this page
  1. 1. Processing on instructions
  2. 2. Security
  3. 3. Sub-processors
  4. 4. Assistance
  5. 5. Personal data breaches
  6. 6. Deletion and return
  7. 7. Audits
  8. 8. International transfers
  9. 9. CCPA/CPRA
  10. 10. No training
  11. 11. Liability
  12. 12. Signed copies
  13. Annex I — Details of processing
  14. Annex II — Technical and organisational measures
All legal documents

This Data Processing Addendum ("DPA") is part of the Terms of Service between Soras Corporation LTD ("Processor", "we") and the Customer ("Controller", "you"). It applies when we process personal data contained in Customer Data on your behalf, under the EU GDPR, the UK GDPR, the Swiss FADP and, as a service provider, the CCPA/CPRA.

1. Processing on instructions

1.1 We process Customer Data only on your documented instructions, which are these Terms, this DPA and your use of the Service's features, unless the law requires otherwise (in which case we tell you first where allowed).

1.2 We tell you if we believe an instruction infringes data protection law.

1.3 Everyone we authorise to process Customer Data is bound by confidentiality.

2. Security

We implement the technical and organisational measures in Annex II and keep them appropriate to the risk.

3. Sub-processors

3.1 You give us general authorisation to engage sub-processors. The current list is at Sub-processors, with each provider's location, transfer mechanism and retention.

3.2 We give at least 30 days' notice by email and on that page before adding or replacing a sub-processor. You can object on reasonable data-protection grounds by writing to help@sorascorp.com within the notice period. If we cannot address the objection, you may terminate the affected Service and receive a pro rata refund of prepaid fees.

3.3 In an emergency (for example, a provider's sudden failure or a security incident) we may replace a sub-processor with less notice; we then notify you as soon as possible and your right to object remains.

3.4 We impose data protection obligations on each sub-processor that are at least as protective as this DPA, including the commitment not to train AI models on Customer Data, and we remain liable for their performance.

4. Assistance

We help you, taking into account the nature of the processing, to respond to data subject requests (the Service includes export and deletion tools), and with security, breach notification, data protection impact assessments and prior consultations.

5. Personal data breaches

We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information you need to meet your own obligations, and we keep you updated.

6. Deletion and return

You can export Customer Data at any time. At the end of the Service we delete Customer Data within 30 days, after the export window in the Terms, unless the law requires us to keep it. Backups roll off within a further 30 days.

7. Audits

We make available the information needed to demonstrate compliance with this DPA, starting with our documentation and answers to reasonable security questionnaires. If that is not enough, you may carry out an audit once a year, at your cost, with 30 days' notice, during business hours, subject to confidentiality and without access to other customers' data.

8. International transfers

8.1 Where Customer Data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission apply: Modules 2 (controller to processor) and 3 (processor to processor). The UK International Data Transfer Addendum and the amendments needed for Swiss law apply to UK and Swiss transfers.

8.2 The Clauses are incorporated by reference with these choices: Clause 7 (docking) applies; Clause 9 option 2 (general authorisation, with the notice period in section 3.2); Clause 11 optional language does not apply; Clauses 17 and 18: the law and courts of Ireland [counsel to confirm]. Annexes I and II of this DPA complete the Clauses' annexes.

9. CCPA/CPRA

As a service provider we do not sell or share personal information, do not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Service, and do not combine it with other data except as the CCPA allows. We certify that we understand and will comply with these restrictions.

10. No training

We do not use Customer Data to train or fine-tune AI models, and our sub-processors are bound to the same.

11. Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms. Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR or data subjects' rights as third-party beneficiaries under the Standard Contractual Clauses.

12. Signed copies

Customers who need a countersigned copy can request one at help@sorascorp.com. A signed copy is recorded against the account.

Annex I — Details of processing

ItemDetails
PartiesController: the Customer. Processor: Soras Corporation LTD, to be confirmed, help@sorascorp.com
Data subjectsThe Customer's audience (reviewers, commenters, interviewees, survey respondents, authors of public posts), and the Customer's personnel who use the Service
Categories of dataQuotes and text fragments, pseudonymised author handles, timestamps, URLs of sources, uploaded files and their contents, generated concepts and answers
Special categoriesNot intended. They may be incidentally present in public posts; whether Article 9(2)(e) applies is the Controller's analysis
Nature and purposeStoring, indexing, tagging, clustering, searching and generating text on the Controller's instructions to provide audience research and creative analytics
DurationThe term of the agreement plus the deletion periods in section 6
FrequencyContinuous

Annex II — Technical and organisational measures

  • Isolation: every workspace's data is separated by row-level security enforced in the database, with search indexes covered by the same rules.
  • Encryption: TLS in transit; connector credentials encrypted with AES-256-GCM; platform secrets sealed per consuming service; backups encrypted before they leave the server.
  • Access control: least-privilege database roles; passwords hashed with Argon2id; an administration console with mandatory multi-factor authentication, step-up confirmation for sensitive actions, an IP allowlist option, and no access to customer content.
  • Accountability: an append-only audit log, hash-chained for administrative actions.
  • Availability and recovery: continuous database archiving with point-in-time recovery (target recovery point of 5 minutes or less), nightly base backups and a weekly encrypted dump kept for 30 days in to be confirmed; restore drills with a measured recovery time.
  • Hosting: to be confirmed; public traffic reaches the servers only through an encrypted tunnel.
  • Search index: built on our own servers; no third-party embedding service receives Customer Data.
  • AI providers: only providers that commit not to train on the data; per-workspace strict mode limits processing to selected regions and providers.
Soras Corp Tech

The technology division of the international Soras Corp holding. We build AI products for business.

Products

Enthyma Enthyma pricing Open the Enthyma app

Company

About Careers Contact Soras Corp

Legal

Privacy policy Terms of service Data processing All documents
© 2026 Soras Corp Tech. All rights reserved. Part of the Soras Corp holding. sorascorp.com