← Legal
04

Data Processing Addendum

For business customers subject to GDPR/UK-GDPR/CCPA: our processor commitments.

LAST UPDATED · August 18, 2026Aureum Growth Solutions LLC
This document is provided for transparency and does not constitute legal advice. Your use of Solipsis is governed by its full text. Questions? [email protected].

1. Scope and roles

This Data Processing Addendum ("DPA") supplements the Terms of Service between you ("Customer," the controller/business) and Aureum Growth Solutions LLC ("Solipsis," the processor/service provider) and applies where Solipsis processes personal data on Customer's behalf that is subject to data-protection laws including the EU/UK GDPR and the CCPA/CPRA. Where it conflicts with the Terms on data protection, this DPA controls.

For content (messages, files, calls), Solipsis processes only ciphertext it cannot decrypt. Solipsis's access as a processor is therefore limited to account data and metadata; it cannot access the plaintext of Customer content. The one exception is the Slack importer: where one of Customer's own users runs an import, the files they select pass through Solipsis's server memory in the clear for the duration of that single request and are never written to disk, database, or logs. See Section 2 of the Privacy Policy.

2. Details of processing

  • Subject matter: provision of the Solipsis Service.
  • Duration: the term of the Terms plus any legally required retention.
  • Nature and purpose: hosting, transmission, and administration of an end-to-end encrypted collaboration service.
  • Types of personal data: account identifiers (email, name), authentication public keys, billing metadata, technical/log data, and encrypted content (ciphertext) with routing metadata.
  • Categories of data subjects: Customer's authorized users and guests.

3. Processor obligations

  • Process personal data only on Customer's documented instructions (including as set out in the Terms and this DPA), unless required by law.
  • Ensure personnel with access are bound by confidentiality.
  • Implement appropriate technical and organizational security measures, including end-to-end encryption of content and row-level access controls.
  • Assist Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting security, breach-notification, and impact-assessment obligations.
  • Notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data.
  • Delete or return personal data at the end of the services, subject to legal retention; note that content deletion is performed by Customer using in-app tools and, once deleted, is unrecoverable.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality and security safeguards.

4. Subprocessors

Customer authorizes Solipsis to engage the subprocessors listed on our Subprocessors page, each bound by data-protection terms no less protective than this DPA. We will provide a mechanism to be notified of new subprocessors and a reasonable opportunity to object on legitimate data-protection grounds.

5. International transfers

For transfers of personal data from the EEA, UK, or Switzerland to the United States, the parties incorporate the European Commission's Standard Contractual Clauses (and the UK Addendum/Swiss amendments as applicable), which are deemed executed by acceptance of this DPA.

6. CCPA

To the extent the CCPA/CPRA applies, Solipsis acts as a "service provider." We will not sell or share Customer's personal information, retain, use, or disclose it except to provide the Service or as permitted by the CCPA, or combine it with data from other sources except as permitted.

7. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms. To request a countersigned copy of this DPA or the SCCs, contact [email protected].