SoloryBack to home

Last updated: 16 July 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Controller") and Alex Földvári, trading as "Solory" (the "Processor"), and governs the Processor's processing of personal data on the Controller's behalf. It reflects the requirements of Art. 9 of the Swiss Data Protection Act (revDSG) and Art. 28 of the EU GDPR. Where this DPA and the Terms conflict on data protection, this DPA prevails.

1. Roles and scope

When you use the Service to process personal data about your own clients, contacts, leads and other third parties, you act as the Controller, deciding the purposes and means, and we act as your Processor, processing that personal data only on your behalf and on your instructions. This DPA governs that relationship. Processing of your own account data, where we are the controller, is governed by our Privacy Policy, not this DPA.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meaning given to them in the revDSG and the GDPR. "Customer Personal Data" means personal data within the content you process through the Service.

3. Subject-matter, duration, nature and purpose

  • Subject-matter: the provision of the Service as described in the Terms.
  • Duration: for as long as you use the Service, and thereafter until Customer Personal Data is deleted or returned in accordance with section 12.
  • Nature and purpose: hosting, storing, organising, transmitting and otherwise processing Customer Personal Data solely to provide, secure, maintain and support the features you use, including invoicing, client and lead management, document storage, email, and the AI features you invoke.

4. Categories of data and data subjects

The categories of personal data and of data subjects are determined by you through your use of the Service. They typically include:

  • Data subjects: your clients, prospects and leads, their staff and contact persons, your correspondents, and any individuals you record in your business data.
  • Categories of data: identification and contact details (name, address, email, phone), business and transaction data (quotes, invoices, payments, projects, time entries), contract and document content, email content, and other data you choose to enter.
  • You are responsible for not entering special categories of data or data unnecessary for your purposes; the Service is not designed to process sensitive personal data.

5. Instructions

We process Customer Personal Data only on your documented instructions, including as to transfers, unless required to act otherwise by applicable law; in that case we will inform you of that legal requirement before processing, unless the law prohibits it. Your use of the Service and its settings, together with the Terms and this DPA, constitute your complete and documented instructions. We will inform you if, in our opinion, an instruction infringes applicable data-protection law.

6. Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by confidentiality and are trained and instructed appropriately. Access is limited to those who need it to provide, secure or support the Service.

7. Technical and organisational measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Row-level security in the database, so each account can access only its own rows and one customer's data is isolated from another's;
  • Encryption of data in transit (TLS/HTTPS) across the Service and its subprocessors;
  • The primary database hosted in Switzerland (Zurich region), with private file storage accessible only through short-lived signed links;
  • Authentication controls including optional two-factor authentication, and least-privilege access with privileged operations restricted to narrowly scoped server-side roles;
  • Audit logging of security-relevant actions, and a self-service data export so you can maintain your own backups;
  • Ongoing maintenance, patching and review of the Service and its dependencies.

We may update these measures over time provided the level of security is not materially reduced.

8. Sub-processors

You give general authorisation for us to engage the sub-processors listed below to help provide the Service. Each sub-processor is bound by a written agreement imposing data-protection obligations substantially equivalent to those in this DPA, and we remain responsible to you for their performance.

Current sub-processors
Sub-processorPurposeLocation
SupabaseDatabase, authentication and file storageZurich, Switzerland (eu-central-2)
VercelApplication hosting, serverless compute and content delivery (CDN)EU / Switzerland region, with a global edge network
Resend (delivers via Amazon SES)Sending and receiving transactional and business emailEU / US
OpenAIAI assistant, drafting, summarisation and document-reading (OCR) features; API data not used to train modelsUS

We will inform you of any intended addition or replacement of a sub-processor, giving you a reasonable opportunity to object on reasonable data-protection grounds. If you object and we cannot offer a reasonable alternative, you may terminate the affected part of the Service. To be notified of changes, contact support@solory.ch.

9. International transfers

Customer Personal Data is stored primarily in Switzerland. Where a sub-processor processes data in the EU or the US (as shown above), any transfer abroad is protected by an adequacy recognition, or by the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, plus supplementary technical measures such as encryption in transit.

10. Assistance to the Controller

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, so far as possible, in fulfilling your obligations to respond to data-subject requests (access, rectification, erasure, portability, objection and restriction). The Service's built-in export, editing and deletion tools are the primary means of this assistance. We also assist you, on request and taking into account the information available to us, with your security, breach-notification and impact-assessment obligations.

11. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to us to help you meet your own notification duties to the competent authority (the FDPIC in Switzerland) and to affected data subjects. Notifications are sent to your account email address; keep it current. You can reach us about security matters at support@solory.ch.

12. Deletion or return on termination

You may export Customer Personal Data at any time using the in-app export. On termination of the Service, and at your choice, we will delete or return Customer Personal Data and delete existing copies, unless applicable law requires storage. Where you delete your account, deletion follows the 30-day grace period and anonymisation process described in our Privacy Policy, after which residual copies are removed from active systems and purged from backups on the ordinary backup cycle.

13. Audit

We make available to you the information reasonably necessary to demonstrate compliance with this DPA, including this document, our Privacy Policy and the description of our measures. Where you require further audit information, you may submit a reasonable written request no more than once per year; we may satisfy it through up-to-date documentation, questionnaire responses, or available third-party reports of our sub-processors, so as not to compromise the security or confidentiality of other customers' data. On-site audits, if agreed as necessary, take place during business hours, with reasonable notice, and at your cost.

14. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. In case of conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails; in case of conflict with any Standard Contractual Clauses entered into between the parties or with a sub-processor, those clauses prevail to the extent of the conflict.

15. Governing law

This DPA is governed by Swiss law, with exclusive jurisdiction in Zürich, Switzerland, subject to any mandatory statutory place of jurisdiction. Contact for data-protection matters: Alex Földvári, Wartauweg 19, 8049 Zürich, Switzerland, support@solory.ch.

Terms of ServicePrivacy PolicyLegal NoticeData Processing Agreement