Legal and Security
  • Standard Agreement
  • Privacy Policy
  • Data Processing Agreement
  • Data Retention and Deletion
  • Security and Protection

Solcoro Terms of Service Agreement

Effective Date: October 2025

Last Updated: July 2026

  1. Using this Standard Agreement
    1. Standard Agreement. This Standard End User Agreement (Version 1.0) (“Standard Agreement”) sets forth the terms and conditions under which Solcoro, LLC (“Provider”) makes available Subscriptions to its Cloud Service or Provider Software (each, a “Product”) offered through a Listing on the Marketplace. Provider may (i) make additions to or modifications of this Standard Agreement (“Additional Terms”) or (ii) add Attachments by stating as such in its Listing. Any Additional Terms and any Attachments are collectively referred to as “Provider-Specific Terms.” Capitalized terms are defined in context or in Section 20 (Definitions).
    2. Entering the Agreement. Customer and Provider agree to this Standard Agreement and any Provider-Specific Terms (collectively, the “Agreement”) upon Customer’s first entry into an Order (“Effective Date”).
    3. Orders. As specified in the Marketplace, an Order may be between Customer and the Marketplace provider (or other reseller or agent of Provider) or directly with Provider. Each Order creates a separate Agreement between Provider and Customer but Orders do not become part of the Agreement
    4. Order of Precedence. In the event of a conflict between the elements of the terms and conditions making up the Agreement, the order of precedence is:
      1. any Amendment,
      2. Provider-Specific Terms and
      3. this Standard Agreement.
  2. Products
    1. Cloud Service. Subject to this Agreement, Customer may use the Cloud Service for its own business purposes in accordance with the Permitted Use.
    2. Users. Customer may permit Users to use the Product on its behalf. Customer is responsible for provisioning and managing its User accounts, for its Users’ actions through the Product, and for their compliance with this Agreement. Customer will ensure that Users keep their login credentials confidential and will promptly notify Provider upon learning of any compromise of User accounts or credentials.
  3. Customer Data
    1. Use of Customer Data. Subject to this Agreement, Provider will access and use Customer Data solely to provide and maintain the Cloud Service and under this Agreement (“Use of Customer Data”). Use of Customer Data includes sharing Customer Data as Customer directs through the Cloud Service, but Provider will not otherwise disclose Customer Data to third parties except as permitted in this Agreement.
    2. Security. Provider will implement and maintain the Security Measures, if any, identified in the Provider-Specific Terms. If no Security Measures are identified, Provider will use appropriate technical and organizational measures designed to prevent unauthorized access, use, alteration or disclosure of Customer Data.
    3. DPA. The parties will adhere to the Data Processing Agreement (DPA)
    4. Usage Data. Provider may collect Usage Data and use it to operate, improve and support the Product and for other lawful business purposes, including benchmarking and reports. However, Provider will not disclose Usage Data externally unless it is (a) de-identified so that it does not identify Customer, its Users or any other person and (b) aggregated with data across other customers.
  4. Mutual Compliance with Laws
    1. Each party will comply with all Laws that apply to its performance under this Agreement.
  5. Support and SLA
    1. Support. Provider will provide Support for the Product Monday through Friday, excluding Bank Holidays for the Province of Quebec, Canada, 8am through 5pm Eastern Standard Time.
  6. Warranties
    1. Mutual Warranties. Each party represents and warrants that:
      1. it has the legal power and authority to enter into this Agreement, and
      2. it will use industry-standard measures to avoid introducing Viruses and/or Malware into the Cloud Service.
    2. Performance Warranty
      1. Scope. Provider warrants that the Product will perform materially as described in the Documentation and that Provider will not materially decrease the overall functionality of the Cloud Service during the Subscription Term (the “Performance Warranty”).
      2. Claim Report. Customer must report a breach of warranty in reasonable detail (“Claim”) within 30 days after discovering the issue in the Product (“Claim Period”).
      3. Remedy. Within 30 days of receiving a verified Claim during the Claim Period (“Fix Period”), Provider will use reasonable efforts to correct or provide a reasonable workaround (“Fix”) for the Claim. If Provider fails to provide a Fix during the Fix Period, either party may on notice to the other terminate the Subscription as it relates to the nonconforming Product and Provider will refund to Customer any prepaid, unused fees for the terminated portion of the Subscription Term.
      4. Exclusive Remedy. The procedures set forth in this Section 6.2 are Customer's exclusive remedies and Provider's sole liability for breach of the Performance Warranty.
    3. Disclaimers. Except as expressly set out in this Agreement, each party disclaims all warranties, whether express, implied, statutory or otherwise, including warranties of merchantability, fitness for a particular purpose, title and non-infringement. Provider’s warranties in this Section 6 do not apply to issues arising from Third-Party Platforms or misuse or unauthorized modifications of the Product. These disclaimers apply to the full extent permitted by Law.
  7. Usage Rules
    1. Compliance. Customer (a) will comply with any Acceptable Use Policy (AUP) identified in the Provider-Specific Terms and (b) represents and warrants that it has all rights necessary to use Customer Data with the Cloud Service and grant Provider the rights to Customer Data specified in this Agreement, without violating third-party intellectual property, privacy or other rights. Between the parties, Customer is responsible for the content and accuracy of Customer Data.
    2. High-Risk Activities and Sensitive Data. Customer:
      1. will not use the Product for High-Risk Activities,
      2. will not submit Sensitive Data to the Cloud Service, and
      3. acknowledges that the Product is not designed for (and Provider has no liability for) use prohibited in this Section 7.2.
    3. Restrictions. Customer will not and will not permit anyone else to:
      1. sell, sublicense, distribute or rent the Product (in whole or part), grant non-Users access to the Product or use the Product to provide a hosted or managed service to others,
      2. reverse engineer, decompile or seek to access the source code of the Product, except to the extent these restrictions are prohibited by Laws and then only upon advance notice to Provider,
      3. copy, modify, create derivative works of or remove proprietary notices from the Product,
      4. conduct security or vulnerability tests of the Cloud Service or interfere with its operation,
      5. circumvent access restrictions to any Product or
      6. use the Product to develop a product or service that competes with the Product.
  8. Third-Party Platforms
    1. To the extent offered by Provider, Customer may choose to enable integrations or exchange Customer Data with Third-Party Platforms. Customer's use of a Third-Party Platform is governed by its agreement with the relevant provider, not this Agreement, and Provider is not responsible for Third-Party Platforms or how their providers use Customer Data.
  9. Fees
    1. Fees will be as stated in the Order and payment terms are as set forth in the Order or terms of the Marketplace.
  10. Suspension
    1. Provider may suspend Customer's access to the Cloud Service and related services due to a Suspension Event, but where practicable will give Customer prior notice so that Customer may seek to resolve the issue and avoid suspension. Provider is not required to give prior notice in exigent circumstances or for a suspension made to avoid material harm or violation of Law. Once the Suspension Event is resolved, Provider will promptly restore Customer's access to the Cloud Service in accordance with this Agreement. “Suspension Event” means:
      1. Customer's account is 30 days or more overdue,
      2. Customer is in breach of Section 7 (Usage Rules)
      3. Customer's use of the Cloud Service risks material harm to the Cloud Service or others.
  11. Term and Termination
    1. Subscription Terms. Each Subscription Term will be either monthly or annual, as specified in the Order. Monthly Subscription Terms automatically renew each month, and annual Subscription Terms automatically renew each 12-month period, in each case unless either party provides written notice of non-renewal prior to the end of the then-current Subscription Term.
    2. Term of Agreement. This Agreement starts on the Effective Date and continues until the end of all Subscription Terms, unless sooner terminated in accordance with its terms. If no Subscription is in effect, either party may terminate this Agreement for any or no reason with notice to the other party.
    3. Termination. Provider reserves the right to suspend or terminate your access to the Platform at its sole discretion if these Terms are violated. Upon termination, all rights granted to you under these Terms will immediately cease, and you must discontinue all use of the Platform. Provider will refund unused credits, if any, to the Customer within 30 days of termination.
    4. Data Export and Deletion
      1. During a Subscription Term, Customer may export Customer Data from the Cloud Service as described in the Documentation.
      2. After termination or expiration of this Agreement, Provider will delete Customer Data in accordance to the Provider’s Data Retention and Deletion Policy. After termination or expiration of this Agreement Customer has no access to Data Export.
      3. Nonetheless, the recipient may retain Customer Data or Confidential Information in accordance with its standard backup or record retention policies or as required by Law, subject to Section 3.2 (Security), Section 15 (Confidentiality) and any DPA or Data Retention Policy of the Provider.
    5. Effect of Termination
      1. Customer’s right to use the Product, Support and Professional Services will cease upon any termination or expiration of this Agreement, subject to this Section 11.
      2. The following Sections will survive termination or expiration of this Agreement: 3.4 (Usage Data), 6.3 (Disclaimers), 7 (Usage Rules), 11.4 (Data Export and Deletion), 11.5 (Effect of Termination), 12 (Intellectual Property), 13 (Limitations of Liability), 14 (Indemnification), 15 (Confidentiality), 18 (General Terms) and 19 (Definitions).
      3. Except where an exclusive remedy is provided, exercising a remedy under this Agreement, including termination, does not limit other remedies a party may have.
  12. Intellectual Property
    1. Reserved Rights. Neither party grants the other any rights or licenses not expressly set out in this Agreement. Except for Provider’s express rights in this Agreement, as between the parties, Customer retains all intellectual property and other rights in Customer Data and Customer Materials provided to Provider. Except for Customer's express rights in this Agreement, as between the parties, Provider and its licensors retain all intellectual property and other rights in the Product, Professional Services deliverables and related Provider technology.
    2. Feedback. If Customer gives Provider feedback regarding improvement or operation of the Product, Support or Professional Services, Provider may use the feedback without restriction or obligation. All feedback is provided “AS IS” and Provider will not publicly identify Customer as the source of feedback without Customer's permission.
  13. Limitations of Liability
    1. General Cap. Each party’s entire liability arising out of or related to this Agreement will not exceed the General Cap.
    2. Consequential Damages Waiver. Neither party will have any liability arising out of or related to this Agreement for indirect, special, incidental, reliance or consequential damages or damages for loss of use, lost profits or interruption of business, even if informed of their possibility in advance.
    3. Nature of Claims. The waivers and limitations in this Section 13 apply regardless of the form of action, whether in contract, tort (including negligence), strict liability or otherwise and will survive and apply even if any limited remedy in this Agreement fails of its essential purpose.
    4. Liability Definitions
      1. “General Cap” means amounts paid or payable by Customer to Provider under this Agreement in the 12 months immediately preceding the first incident giving rise to liability.
      2. “Uncapped Claims” means:
        1. the indemnifying party’s obligations under Section 15 (Indemnification),
        2. either party’s infringement or misappropriation of the other party’s intellectual property rights,
        3. any breach of Section 16 (Confidentiality), excluding breaches related to Customer Data and
        4. liabilities that cannot be limited by Law.
  14. Indemnification
    1. Indemnification by Provider. Provider, at its own cost, will defend Customer from and against any Provider-Covered Claims and will indemnify and hold harmless Customer from and against any damages or costs awarded against Customer (including reasonable attorneys’ fees) or agreed in settlement by Provider resulting from the Provider-Covered Claims.
    2. Indemnification by Customer. Customer, at its own cost, will defend Provider from and against any Customer-Covered Claims and will indemnify and hold harmless Provider from and against any damages or costs awarded against Provider (including reasonable attorneys’ fees) or agreed in settlement by Customer resulting from the Customer-Covered Claims.
    3. Indemnification Definitions
      1. “Customer-Covered Claim” means a third-party claim arising from Customer’s breach or alleged breach of Section 7.1 (Compliance) or 7.2 (High-Risk Activities and Sensitive Data).
      2. “Provider-Covered Claim” means a third-party claim that the Product, when used by Customer as authorized in this Agreement, infringes or misappropriates a third party’s intellectual property rights.
    4. Procedures. The indemnifying party’s obligations in this Section 14 are subject to receiving from the indemnified party:
      1. prompt notice of the claim (but delayed notice will only reduce the indemnifying party’s obligations to the extent it is prejudiced by the delay),
      2. the exclusive right to control the claim’s investigation, defense and settlement and
      3. reasonable cooperation at the indemnifying party’s expense. The indemnifying party may not settle a claim without the indemnified party’s prior approval if settlement would require the indemnified party to admit fault or take or refrain from taking any action (except regarding use or nonuse of the Product when Provider is the indemnifying party). The indemnified party may participate in a claim with its own counsel at its own expense.
    5. Mitigation. In response to an infringement or misappropriation claim, if required by settlement or injunction or as Provider determines necessary to avoid material liability, Provider may:
      1. procure rights for Customer’s continued use of the Product,
      2. replace or modify the allegedly infringing portion of the Product to avoid infringement, without reducing the Product’s overall functionality or
      3. terminate the affected Subscription and refund to Customer any prepaid, unused fees for the terminated portion of the Subscription Term.
    6. Exceptions. Provider’s obligations in this Section 14 do not apply to claims resulting from:
      1. modification or unauthorized use of the Product
      2. use of the Product in combination with items not provided by Provider, including Third-Party Platforms or
      3. Provider Software other than the most recent release, if Provider made available (at no additional charge) a newer release that would avoid infringement.
    7. Exclusive Remedy. This Section 14 sets out the indemnified party’s exclusive remedy and the indemnifying party’s sole liability regarding third-party claims of intellectual property infringement or misappropriation covered by this Section 14.
  15. Confidentiality
    1. Use and Protection. As recipient, each party will:
      1. use Confidential Information only to fulfill its obligations and exercise its rights under this Agreement,
      2. not disclose Confidential Information to third parties without the discloser’s prior approval, except as permitted in this Agreement and
      3. protect Confidential Information using at least the same precautions recipient uses for its own similar information and no less than a reasonable standard of care.
    2. Permitted Disclosures
      1. Personnel. The recipient may disclose Confidential Information to its employees, agents, contractors and other representatives having a legitimate need to know (including, for Provider, the subcontractors referenced in Section 19.9), provided it remains responsible for their compliance with this Section 15 and they are bound to confidentiality obligations no less protective than this Section 15.
      2. Required by Law. The recipient may disclose Confidential Information (including Customer Data) to the extent required by Law. If permitted by Law, the recipient will give the discloser reasonable advance notice of the required disclosure and reasonably cooperate, at the discloser’s expense, to obtain confidential treatment for the Confidential Information.
    3. Exclusions. These confidentiality obligations do not apply to information that the recipient can document:
      1. is or becomes public knowledge through no fault of the recipient
      2. it rightfully knew or possessed, without confidentiality restrictions, prior to receipt from the discloser
      3. it rightfully received from a third party without confidentiality restrictions or
      4. it independently developed without using or referencing Confidential Information.
    4. Remedies. Breach of this Section 15 may cause substantial harm for which monetary damages are an insufficient remedy. Upon a breach of this Section 15, the discloser is entitled to seek appropriate equitable relief, including an injunction, in addition to other remedies.
  16. Publicity
    1. By using the Platform, you grant Solcoro permission to list your company name and logo as a customer reference on Solcoro's website and marketing materials. You may opt out of this visibility at any time by submitting a written request, and Solcoro will remove the reference within thirty (30) days. This permission survives termination of the subscription agreement for thirty (30) days, after which Solcoro will remove the reference upon request.
  17. Trials and Betas
    1. Use of Trials and Betas is permitted only for Customer’s internal evaluation during the period designated in the Order (or if not designated, 30 days). Either party may terminate Customer’s use of Trials and Betas at any time for any reason. Trials and Betas may be inoperable, incomplete or include features never released. Notwithstanding anything else in this Agreement, Provider offers no warranty, indemnity, SLA or Support for Trials and Betas and has no liability for Betas and Trials.
  18. General Terms
    1. Assignment. Neither party may assign this Agreement without the prior consent of the other party, except that either party may assign this Agreement, with notice to the other party, in connection with the assigning party’s merger, reorganization, acquisition or other transfer of all or substantially all of its assets or voting securities. Any non-permitted assignment is void. This Agreement will bind and inure to the benefit of each party’s permitted successors and assigns.
    2. Governing Law and Courts
      1. These Terms are governed by the laws of the State of Florida, United States, without regard to its conflict of law principles. Any disputes related to these Terms will be subject to the jurisdiction of the appropriate courts in Florida.
    3. Notices
      1. Except as set out in this Agreement, notices, requests and approvals under this Agreement must be in writing to the addresses specified by Provider and Customer and will be deemed given:
        1. upon receipt if by personal delivery,
        2. upon receipt if by certified or registered U.S. mail (return receipt requested),
        3. one day after dispatch if by a commercial overnight delivery service or
        4. upon delivery if by email.
      2. Provider will specify its notice address through the Listing or Product and Customer will specify its notice address through the Order or other method designated by Provider. Either party may update its notice address with notice to the other. Provider may also send operational notices through the Product.
    4. Entire Agreement. This Agreement is the parties’ entire agreement regarding its subject matter and supersedes any prior or contemporaneous agreements regarding its subject matter. In this Agreement, headings are for convenience only and “including” and similar terms are to be construed without limitation. Terms in purchase orders used by Customer will not amend or modify this Agreement; any such documents are for administrative purposes only. This Agreement may be executed in counterparts (including electronic copies and PDFs), each of which is deemed an original and which together form one and the same agreement.
    5. Amendments
      1. Solcoro may update this Agreement from time to time in its sole discretion. Material changes shall be reflected by an updated "Last Updated" date above. Continued use of the Platform following any such amendment shall constitute acceptance of the amended Policy.
      2. Orders may contain Use Restrictions but do not amend or modify any part of this Agreement.
    6. Operational Changes. With notice to Customer, Provider may modify the AUP, Security Measures, SLA or Support Policy to reflect new features or changing practices, but the modifications may not be retroactive or materially decrease Provider’s overall obligations during a Subscription Term. Such changes do not require Amendment as per 18.5 and are at sole discretion of the Provider.
    7. Waivers and Severability. Waivers must be signed by the waiving party’s authorized representative and cannot be implied from conduct. If any provision of this Agreement is held invalid, illegal or unenforceable, it will be limited to the minimum extent necessary so the rest of this Agreement remains in effect.
    8. Force Majeure. Neither party is liable for a delay or failure to perform this Agreement due to a Force Majeure. If a Force Majeure materially adversely affects the Product for 29 or more consecutive days, either party may terminate the affected Subscription upon notice to the other and Provider will refund to Customer any prepaid, unused fees for the terminated portion of the Subscription Term. However, this Section 18.8 does not limit Customer’s obligations to pay fees owed.
    9. Subcontractors. Provider may use subcontractors and permit them to exercise Provider’s rights and fulfill Provider’s obligations, but Provider remains responsible for each subcontractor’s compliance with this Agreement and for Provider’s overall performance under this Agreement. This does not limit any additional terms for sub-processors under a DPA.
    10. Independent Contractors. The parties are independent contractors, not agents, partners or joint venturers.
    11. No Third-Party Beneficiaries. There are no third-party beneficiaries to this Agreement.
    12. Open Source. Provider Software may include third-party open source software (“Open Source”) as listed in the Documentation or by Provider upon request. Customer acknowledges that its license to use any Open Source will be the Open Source license applicable to such code and not the license to Provider Software in Section 2.2 (Provider Software) above to the extent required by such Open Source license.
    13. Export. Each party (a) will comply with all export and import Laws in performing this Agreement and (b) represents and warrants that it is not listed on any U.S. government list of prohibited or restricted parties or located in (or a national of) a country subject to a U.S. government embargo or designated by the U.S. government as a “terrorist-supporting” country. Customer will not submit to the Cloud Service any data controlled under the U.S. International Traffic in Arms Regulations.
    14. Government Rights. To the extent applicable, the Product is “commercial computer software” or a “commercial item” for purposes of FAR 12.212 and DFARS 227.7202. Use, reproduction, release, modification, disclosure or transfer of the Product is governed solely by the terms of this Agreement, and all other use is prohibited.
  19. Definitions
    • “Acceptable Use Policy” or “AUP” is defined in Section 7.1 (Compliance).
    • “Additional Terms” is defined in Section 1.1 (Standard Agreement).
    • “Agreement” is defined in Section 1.2 (Entering the Agreement).
    • “Amendment” is defined in Section 18.5 (Amendments).
    • “Attachments” means any AUP, Security Measures, SLA, Support Policy or other policies specified in the Provider-Specific Terms.
    • “Cloud Service” means Provider’s proprietary software as a service (SaaS) or cloud service as identified in the applicable Listing.
    • “Confidential Information” means information disclosed by or on behalf of one party (as discloser) to the other party (as recipient) under this Agreement, in any form, which (a) the discloser identifies to recipient as “confidential” or “proprietary” or (b) should be reasonably understood as confidential or proprietary due to its nature and the circumstances of its disclosure. Provider’s Confidential Information includes technical or performance information about the Product, and Customer’s Confidential Information includes Customer Data.
    • “Courts” is defined in Section 18.2 (Governing Law and Courts).
    • “Customer” means the party placing the Order.
    • “Customer Data” means any data, content or materials that Customer (including its Users) submits to its Cloud Service accounts, including from Provider Software or Third-Party Platforms.
    • “Customer Materials” means materials and resources that Customer makes available to Provider in connection with Professional Services.
    • “Data Protection Addendum” or “DPA” is defined in Section 3.3 (DPA).
    • “Documentation” means Provider’s standard usage documentation for the Product. Documentation is included in the definition of “Product” unless otherwise specified.
    • “End User Licensing Agreement” is defined in Section 1.1 (End User Licensing Agreement).
    • “Force Majeure” means an unforeseen event beyond a party’s reasonable control, such as a strike, blockade, war, pandemic, act of terrorism, riot, third-party Internet or utility failure, refusal of government license or natural disaster, where the affected party takes reasonable and customary measures to avoid or mitigate such event’s effects.
    • “Governing Law” is defined in Section 18.2 (Governing Law and Courts).
    • “High-Risk Activities” means activities where use or failure of the Product could lead to death, personal injury or environmental damage, including life support systems, emergency services, nuclear facilities, autonomous vehicles or air traffic control.
    • “Laws” means all laws, regulations, rules, court orders or other binding requirements of a government authority that apply to a party.
    • “Listing” means Provider’s description of its Product (and any related Support) and Subscriptions in a listing on the Marketplace that designates use of this Standard Agreement.
    • “Marketplace” means the application marketplace or app store on which Provider has published a Listing and made available Subscriptions to their Product.
    • “Open Source” is defined in Section 18.12.
    • “Order” means an order by Customer for a Subscription that is entered into through the Marketplace.
    • “Permitted Use” means use of a Product in accordance with the applicable Subscription, any Use Restrictions and the Documentation.
    • “Product” is defined in Section 1.1 (Standard Agreement).
    • “Provider” means the party providing the Product.
    • “Provider Software” means Provider’s proprietary installed software or apps identified in the applicable Listing.
    • “Provider-Specific Terms” is defined in Section 1.1 (Standard Agreement).
    • “Security Measures” is defined in Section 3.2 (Security).
    • “Sensitive Data” means (a) patient, medical or other protected health information regulated by the Health Insurance Portability and Accountability Act (as amended and supplemented) (“HIPAA”), (b) credit, debit, bank account or other financial account numbers, (c) social security numbers, driver’s license numbers or other government ID numbers and (d) special categories of data enumerated in European Union Regulation 2016/679, Article 9(1) or any successor legislation.
    • “Statement of Work” means a statement of work for Professional Services that is signed by the parties and references this Agreement.
    • “Subscription” means the right for Customer to access the Product and any related Support as described in a Listing and the applicable Order.
    • “Subscription Term” means the term for a Subscription as identified in the Order.
    • “Support” means support for the Product as described in Section 5.1 (Support).
    • “Support Policy” is defined in Section 5.1 (Support).
    • “Suspension Event” is defined in Section 10 (Suspension).
    • “Third-Party Platform” means any product, add-on or platform not provided by Provider that Customer uses with the Cloud Service.
    • “Trials and Betas” mean access to the Product on a free or trial basis or to particular features designated by Provider as “beta” or “early access.”
    • “Usage Data” means Provider’s technical logs, data and learnings about Customer’s use of the Product, but excluding Customer Data.
    • “Use Restrictions” means user, seat, copy, installation, license or other scope of use restrictions for the Product as specified in a Listing or Order.
    • “User” means anyone that Customer allows to use its accounts for the Product, who may include (a) employees, advisors and contractors of Customer and (b) others if permitted in this Agreement, the Documentation or a Listing.
    • “Virus” means viruses, malicious code or similar harmful materials.

Solcoro Privacy Policy

Effective Date: October 2025

Last Updated: July 2026

This Privacy Policy describes how Solcoro, LLC. ("Solcoro," "we," "us," or "our") collects, uses, discloses, and protects information about you when you use our platform, marketing website, and related services (collectively, the "Platform"). By using the Platform, you agree to the practices described in this policy.
This policy applies to the Solcoro Platform, Marketing Website and any related services. It does not apply to third-party websites or services linked from the Platform.
  1. Information We Collect
    1. Collection. We collect information in the following categories:
      1. Information You Provide Directly
        1. Account and identity information, such as your name, email address, job title, and company details
        2. Communications you send us, including support requests, feedback, and correspondence
      2. Information Collected Automatically
        1. Usage and log data, including IP addresses, browser type, pages visited, timestamps, and session duration
        2. Metadata from connected Systems of Work applications and interactions within the Platform
        3. Device information, such as operating system and browser version
        4. Cookies and similar tracking technologies (see Section 6 for details)
    2. Aggregated and Anonymized Data. We generate aggregated, de-identified data across our customer base to produce market trend insights, performance benchmarks, and best-practice analysis. This data cannot reasonably be used to identify any individual or organization and is not considered personal information under applicable law.
  2. How We Use Your Information
    1. Usage. We use the information we collect for the following purposes:
      1. Service delivery: To operate, maintain, and provide the features and functionality of the Platform.
      2. Personalization: To tailor recommendations and experiences based on your environment and usage patterns.
      3. Analytics and improvement: To understand how the Platform is used and to improve its performance, reliability, and features.
      4. Communications: To send transactional messages (e.g., account notices, security alerts) and, where you have given consent or we have a legitimate interest, product updates and marketing communications.
      5. Market insights: To generate and share anonymized, aggregated industry benchmarks and trend reports.
      6. Legal and compliance: To comply with applicable laws, enforce our agreements, and respond to lawful requests.
      7. WE DO NOT SELL YOUR PERSONAL INFORMATION
  3. How We Share Your Information
    1. Sharing. We may share your information in the following circumstances:
      1. Service providers: We share information with vetted third-party vendors who perform services on our behalf, such as cloud hosting, analytics, customer support tooling, and payment processing. These parties are contractually obligated to use your data only as directed by us and to maintain appropriate security standards.
      2. Business transfers: If Solcoro is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.
      3. Legal obligations: We may disclose information when required by law, regulation, court order, or governmental authority, or when we believe disclosure is necessary to protect the rights, property, or safety of Solcoro, our users, or others.
      4. With your consent: We may share your information for other purposes with your explicit consent.
      5. Aggregated data: We may publicly share anonymized, aggregated data that does not identify any individual customer or end user.
  4. Data Security
    1. Protection Measures. Solcoro maintains administrative, technical, and physical safeguards designed to protect your information against unauthorized access, disclosure, alteration, and loss. These measures include encryption in transit and at rest, access controls, and periodic security assessments.
    2. Limitations. No method of transmission over the internet or electronic storage is completely secure. While we take reasonable precautions, we cannot guarantee the absolute security of your information. In the event of a data breach that affects your rights or interests, we will notify you in accordance with applicable law.
  5. Data Retention and Deletion
    1. Data Use. We retain personal information for as long as necessary to provide the Platform, fulfill the purposes described in this policy, and comply with our legal obligations. When personal information is no longer needed, we delete or anonymize it in accordance with our data retention schedule.
    2. Data Retention and Deletion. Data retention and deletion practices for Customer data are governed by the Solcoro Data Retention and Deletion Policy, incorporated herein by reference.
  6. Cookies and Tracking Technologies
    1. Tracking. We use cookies and similar technologies to operate the Platform, remember your preferences, and collect analytics data. You can control cookie preferences through your browser settings or our cookie consent tool. Note that disabling certain cookies may affect Platform functionality.
    2. Opt-Out. We do not currently respond to "Do Not Track" browser signals, but we support opt-out mechanisms described in Section 7.
  7. Your Privacy Rights and Choices
    1. Rights. Depending on your location and applicable law, you may have the right to:
      1. Access the personal information we hold about you
      2. Correct inaccurate or incomplete information about you
      3. Delete your personal information (subject to certain exceptions)
      4. Restrict or object to specific types of processing
      5. Data portability — receive a copy of your information in a structured, machine-readable format
      6. Withdraw consent at any time where processing is based on consent
      7. Opt out of marketing communications via the unsubscribe link in any email or by contacting us directly
    2. California Residents. California residents may have additional rights under the CCPA/CPRA, including the right to know what personal information is sold or disclosed and to opt out of its sale. We do not sell personal information.
    3. EEA, UK, and Swiss Residents. EEA, UK, and Swiss residents may also have the right to lodge a complaint with your local data protection authority.
    4. Exercising Your Rights. To exercise any of these rights, please contact us at info@solcoro.com. We will respond within the timeframe required by applicable law. Rights requests are handled in accordance with the Data Processing Agreement ("DPA") between you and Solcoro.
  8. International Data Transfers
    1. Application Hosting. Solcoro's Platform and all associated data are hosted on Amazon Web Services (AWS) infrastructure, with the primary datacenter located in the US-EAST-1 region (Northern Virginia, United States). All customer data is stored and processed within AWS's secure cloud environment.
    2. Information Transmission. If you access the Platform from outside the United States, your information will be transmitted to, and processed in, the United States. By using the Platform, you acknowledge that your information will be hosted in the United States, where data protection laws may differ from those in your country of residence.
    3. Legal Mechanisms. For users in the EEA, UK, or Switzerland, we ensure that transfers of personal information to the United States are conducted under appropriate legal mechanisms, including:
      1. Standard Contractual Clauses (SCCs) as approved by the European Commission
      2. Data processing agreements with AWS that incorporate applicable data protection requirements
      3. Reliance on AWS's compliance certifications, which include:
        1. ISO 27001, 27017, and 27018
        2. SOC 1, SOC 2, and SOC 3
        3. General Data Protection Regulation (GDPR) compliance under AWS's Data Processing Addendum
    4. AWS Compliance. AWS maintains its own comprehensive security and compliance program. Details of AWS's certifications, compliance controls, and regional data handling practices are available at aws.amazon.com/compliance.
    5. We do not replicate or store customer data outside of the AWS US-EAST-1 region except where required by law or explicitly requested by the customer.
  9. Children's Privacy
    1. Child Data Collection. The Platform is not directed to children under the age of 16, and we do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a child, please contact us and we will promptly delete it.
  10. Changes to This Policy
    1. Policy Updates. Solcoro reserves the right to amend, modify, or update this Policy from time to time in its sole discretion. Material changes shall be reflected by an updated "Last Updated" date above. Continued use of the Platform following any such amendment shall constitute acceptance of the amended Policy.
  11. Contact Us
  12. For questions, concerns, or to exercise your privacy rights, please contact:

    Solcoro LLC - info@solcoro.com

Solcoro Data Processing Agreement

Effective Date: October 2025

Last Updated: July 2026

  1. Purpose & Scope
    1. This Data Processing Agreement ("DPA") governs Solcoro's collection, use, and protection of Customer metadata in connection with the Solcoro SaaS platform (the "Platform"). It forms part of, and is incorporated into, the Subscription Terms Agreement between the Customer ("Controller") and Solcoro, LLC. ("Processor"). In the event of a conflict, this DPA takes precedence.
    2. The Platform provides metadata-driven optimization of systems-of-work ecosystems and enterprise software environments. To deliver insights, recommendations, and telemetry-based reporting, Solcoro processes limited Customer metadata strictly as defined herein.
  2. Definitions
    • "Customer Metadata" means workspace identifiers, usage telemetry, performance counters, and other indirect technical identifiers generated through Customer's use of the Platform. Excludes personally identifiable information (PII) unless explicitly agreed in writing.
    • "Data Protection Laws" means all applicable privacy and data protection legislation, including without limitation GDPR (EU 2016/679), UK GDPR, CCPA/CPRA, and equivalent regional requirements in jurisdictions where Customer operates.
    • "Controller" means the Customer, who determines the purposes and means of processing Customer Metadata within their organization.
    • "Processor" means Solcoro, LLC., acting on the Controller's instructions to process Customer Metadata solely to deliver the Platform's functionality.
    • "Sub-processor" means any third party engaged by Solcoro to assist in processing Customer Metadata on the Controller's behalf.
    • "Security Incident" means any confirmed unauthorized access, disclosure, alteration, or destruction of Customer Metadata.
    • "Agreement" means the Subscription Agreement and any agreement entered into between Customer and Solcoro.
  3. Roles & Responsibilities
    1. Processor. Solcoro acts solely as a data processor with respect to Customer Metadata. Solcoro shall:
      1. Process Customer Metadata only on documented instructions from the Customer, including those set out in this DPA.
      2. Refrain from selling, renting, or otherwise commercially exploiting Customer Metadata for any purpose beyond fulfilling the Platform's intended functionality.
      3. Ensure personnel authorized to process Customer Metadata are bound by appropriate confidentiality obligations.
      4. Notify the Customer without undue delay if, in Solcoro's reasonable opinion, an instruction violates applicable Data Protection Laws
    2. Controller. The Customer represents and warrants that:
      1. It has a lawful basis for providing Customer Metadata to Solcoro and for authorizing the processing activities described in this DPA.
      2. It has provided all required notices and obtained all required consents from data subjects where applicable.
      3. Its use of the Platform and instructions to Solcoro comply with Data Protection Laws.
  4. Data Processing Details
    1. Subject Matter. Technical optimization analytics for enterprise software environments and systems of work.
    2. Duration. For the term of the Agreement, plus any post-termination retention period set out in Section 6.
    3. Nature & Purpose. Collection, aggregation, analysis, and reporting of telemetry data to generate platform insights and recommendations.
    4. Categories of Data. Workspace identifiers, usage frequency metadata, integration event counts, performance and latency metrics. No special-category personal data is processed.
    5. Data Subjects. Customer's authorized end users of enterprise software tools connected to the Platform. No consumer data subjects are processed under normal operation.
  5. Data Minimization & Use Limitation
    1. Minimization. Solcoro applies the principle of data minimization across all processing activities. Specifically:
      1. Customer Metadata is collected only to the extent necessary to deliver the analytics, recommendations, and optimization features described in the Agreement.
      2. No profiling or automated decision-making with legal or similarly significant effects on data subjects is performed.
      3. Customer Metadata is not used to train or improve Solcoro's machine learning models without the Customer's prior written consent.
      4. Customer Metadata is processed in aggregated or pseudonymized form wherever technically feasible.
  6. Data Retention & Deletion
    1. Retention. Data retention and deletion practices for Customer Metadata are governed by the Solcoro Data Retention and Deletion Policy, incorporated herein by reference. In the event of a conflict between the Data Retention and Deletion Policy and this DPA, this DPA controls.
  7. Technical & Organizational Security Measures
    1. Security Measures. Solcoro implements and maintains security measures appropriate to the risk of the processing according the Solcoro Security and Protection Policy, incorporated herein by reference. In the event of a conflict between the Security and Protection Policy and this DPA, this DPA controls.
  8. Security Incident Notification & Response
    1. Incident Response. In the event of a confirmed or reasonably suspected Security Incident involving Customer Metadata, Solcoro will:
      1. Notify the Customer's designated security or privacy contact without undue delay, and in accordance with applicable law.
      2. Provide in the initial notification: the nature of the incident, categories and approximate volume of data affected, likely consequences, and measures taken or proposed.
      3. Cooperate with the Customer and relevant supervisory authorities in the investigation, containment, and remediation of the incident.
      4. Not make public disclosures regarding the incident that identify the Customer without the Customer's prior written consent, except as required by law.
  9. Sub-processors
    1. Sub-processor Engagement. Customer hereby grants Solcoro general authorization to engage Sub-processors to assist in delivering the Platform. Solcoro will:
      1. Maintain and make available upon request an up-to-date list of Sub-processors, including their name, location, and the nature of processing performed.
      2. Impose data protection obligations on each Sub-processor no less protective than those set out in this DPA.
      3. Remain liable to the Customer for the performance of Sub-processors to the same extent as if Solcoro were performing the processing directly.
      4. Provide at least 30 days' prior written notice of any intended addition or replacement of a Sub-processor. The Customer may object in writing within that period on reasonable data protection grounds; the parties will work in good faith to resolve such objection.
  10. Cross-Border Data Transfers
    1. Transfer Practices. Cross-border data transfer practices are governed by the International Data Transfers section of Solcoro's Privacy Policy, incorporated herein by reference. In the event of a conflict between the Privacy Policy and this DPA, this DPA controls.
  11. Audit Rights
    1. Compliance Auditing. The Customer may audit Solcoro's compliance with this DPA no more than once per calendar year, subject to:
      1. Providing at least thirty (30) days' prior written notice specifying the scope and proposed timing.
      2. Conducting (or commissioning) the audit during normal business hours with minimal disruption to Solcoro operations.
      3. Executing a confidentiality agreement reasonably acceptable to Solcoro before receiving audit findings.
    2. Substitution. In lieu of an on-site audit, Solcoro may satisfy Customer's audit right by providing the most recent third-party audit report (e.g., SOC 2 Type II, ISO 27001 certificate) covering the relevant period.
  12. Data Subject Rights Assistance
    1. Processing. Given that Solcoro processes Customer Metadata rather than directly identifiable personal data, data subject rights requests are primarily managed by the Customer as Controller. Solcoro will:
      1. Promptly forward to the Customer any data subject rights requests Solcoro receives that relate to Customer Metadata.
      2. Provide reasonable technical assistance to help the Customer fulfill access, rectification, erasure, portability, restriction, and objection requests within timeframes required by applicable Data Protection Laws.
      3. Not respond directly to data subjects on behalf of the Customer without prior written authorization.
  13. Term & Termination
    1. Effectiveness. This DPA is effective from the Customer's first use of the Platform (or the earlier execution of the Agreement) and continues until termination or expiry of the Agreement. Obligations that by their nature survive termination — including data deletion, confidentiality, audit rights for the relevant period, and security incident obligations — remain in effect until fully discharged.
  14. General Provisions
    1. Order of Precedence. In the event of a conflict between this DPA and the Agreement with respect to data protection matters, this DPA prevails. For all other matters, the Agreement controls.
    2. Amendments. Solcoro reserves the right to amend, modify, or update this DPA from time to time in its sole discretion. Material changes shall be reflected by an updated "Last Updated" date above. Continued use of the Platform following any such amendment shall constitute acceptance of the amended Policy.
    3. Governing Law. This DPA is governed by the laws of the State of Florida, United States, without regard to its conflict of law principles. Any disputes related to these Terms will be subject to the jurisdiction of the appropriate courts in Florida.
    4. Entire Agreement. This DPA, together with the Agreement and any exhibits or schedules thereto, constitutes the entire agreement between the parties with respect to data protection matters and supersedes all prior discussions, representations, or agreements relating thereto.

Solcoro Data Retention and Deletion Policy

Effective Date: October 2025

Last Updated: October 2025

We collect several types of information to deliver and improve our services. This includes information you provide directly—such as your name, email address, company details, and any feedback or communications related to your use of the Platform. We also collect certain data automatically, including metadata about your use of connected Systems of Work applications, log files, and interactions within the Platform. Cookies and similar tracking technologies are used to enhance your experience and support analytics. In addition, we collect anonymized and aggregated data across multiple customers to provide insight into market trends, performance benchmarks, and best practices. No personally identifiable information (PII) is ever included in these aggregated insights.
  1. Types of Deletions
    1. Active Deletion: A customer has an active Solcoro subscription, and a user or administrator deletes data, administrators delete a user, or has data deleted through a customer support request.
    2. Passive Deletion: A customer subscription ends due to cancellation, expiration, or non-conversion from trial.
  2. Data Categories and Retention
  3. Data Category Classification Description Examples Retention
    Metadata Scan & Configuration Data Machine-generated metadata pulled from customer systems that describes configuration, security posture, usage, and backup status Jira project counts, permission settings, MFA status, backup coverage, API scopes, configuration drift, Solcoro Scores

    Active Deletion: Up to 30 days

    Passive Deletion: Up to 90 days

    Custom Identifiers Workspace-Scoped Identifiers Data and metadata linking scan data to a specific organization or system. Workspace ID, organization name, integration IDs, site URLs

    Active Deletion: Up to 30 days

    Passive Deletion: Up to 90 days

    User Identifiers End-User Identifiable Information (EUII) Data that identifies or could identify a user of Solcoro Name, email, role, IP address

    Active Deletion: Up to 30 days

    Passive Deletion: Up to 90 days

    Platform Identifiers Anonymized System Identifiers Internal identifiers used to operate the Solcoro platform User IDs, session IDs, audit IDs

    Active Deletion: Up to 30 days

    Passive Deletion: Up to 90 days

    Aggregated Analytics De-identified Benchmark Data Aggregated, anonymized scan data used to generate market benchmarks and industry insights Industry percentiles, region-level averages, security posture trends, Scores

    May be retained indefinitely

  4. Subscription Retention Rules
    1. Active Subscription. While a Solcoro subscription is active, customers may:
      1. Access Scan History and Benchmarks
      2. Export Data
      3. Remove Integrations
      4. Delete Integrations
    2. Retention: Solcoro retains historical scan metadata for the duration of the active subscription to support:
      1. Trend Analysis
      2. Drift Detection
      3. Compliance Reporting
      4. Security Investigations
      5. Support and Billing Validation
  5. Subscription Termination
    1. Access. When a paid subscription or free trial expires, is terminated or is cancelled:
      1. Customer access to the Solcoro platform and all connected integrations is immediately disabled. Customers must download any reports, exports, or data prior to termination
      2. The workspace(s) enters a retention-only state for up to 90 days, during which:
        1. Solcoro retains customer data solely for billing reconciliation, dispute resolution, audit, and compliance purposes
        2. No customer access to the platform or data is provided
        3. Solcoro may, at its discretion, reinstate the workspace if the subscription is reactivated or a Trial is converted to a paid subscription.
      3. After the 90-day retention period expires, the workspace is permanently disabled
      4. No later than 90 days after termination, all customer-identifiable data is deleted from Solcoro production systems.
  6. Benchmarking & Market Intelligence
    1. Retention. After a subscription or trial is terminated, Solcoro may retain de-identified and aggregated scan data for:
      1. Market Benchmarking
      2. Industry Comparisons
      3. Product Development
      4. Security Research
    2. Limitations. De-identified and aggregated data retained for benchmarking and market intelligence purposes:
      1. Contains no workspace IDs, organization names, URLs, or PII
      2. Cannot be used to identify any unique customer information
      3. Product Development
      4. Cannot be reasonably reconstructed to reveal a specific organization
  7. Data Backups
    1. Usage. Customer data may persist in encrypted backups until those backups are rotated and overwritten under Solcoro’s standard backup retention schedule (typically 30–180 days). Backups are NOT used for production, analytics, or benchmarking.
    2. Recoverability. Backed Up Data is encrypted and rendered commercially unrecoverable through normal backup expiration and rotation.
  8. Amendments
    1. Amendments. Solcoro reserves the right to amend, modify, or update this Policy from time to time in its sole discretion. Material changes shall be reflected by an updated "Last Updated" date above. Continued use of the Platform following any such amendment shall constitute acceptance of the amended Policy.

Solcoro Security and Protection

Effective Date: October 2025

Last Updated: October 2025

This Security & Protection Policy (this "Policy") describes the technical, administrative, and organizational measures implemented by Solcoro ("Solcoro," "Company," "we," "us," or "our") to safeguard data processed in connection with the Solcoro platform (the "Platform"). This Policy is incorporated by reference into, and forms part of, the applicable agreement governing a customer's ("Customer," "you," or "your") use of the Platform. Capitalized terms not otherwise defined herein shall have the meanings ascribed to them in such agreement.
  1. Security Strategy; General Principles
    1. Data Value. Solcoro maintains that the value of data is contingent upon the adequacy of the security measures protecting it. Accordingly, security, privacy, and reliability constitute foundational design principles of the Platform, and not incidental or supplementary features thereof. Solcoro employs a defense-in-depth methodology, pursuant to which each layer of the Platform architecture is designed to limit exposure, enforce access controls, and enable early detection and remediation of potential issues.
    2. Minimization of Access. Solcoro shall collect and receive only such metadata as has been expressly authorized by the Customer, and only at such time as is reasonably necessary for the performance of the Platform's functions. All such metadata shall be transmitted via secure means. For the avoidance of doubt, Solcoro does not affirmatively retrieve or "pull" metadata absent Customer authorization.
    3. Secure Automation. All modifications to the Platform's infrastructure and codebase shall be defined, reviewed, and deployed exclusively through code-based mechanisms. All such changes shall be logged in their entirety and shall conform to prevailing AWS and version-control ("Git") industry best practices. No manual, undocumented, or unauthorized modifications shall be permitted.
    4. Continuous Monitoring. Solcoro shall maintain comprehensive observability across all Platform systems for the purpose of ensuring that anomalies and issues are identified at the earliest practicable opportunity and remediated prior to any material impact upon Customers.
  2. Data Protection and Infrastructure
    1. Data Protection Measures. Solcoro shall implement and maintain the following safeguards with respect to Customer data:
      1. All Customer data shall be encrypted in transit, utilizing Transport Layer Security ("TLS") version 1.2 or higher, and at rest, utilizing Advanced Encryption Standard 256-bit ("AES-256") encryption or such other industry-standard encryption methodology as may supersede it.
      2. Application secrets and credentials shall be managed through centralized, secure key management systems incorporating automated credential lifecycle management protocols.
      3. Access to production data shall be restricted to authorized systems and personnel only, in accordance with the principles of least-privilege access and just-in-time provisioning.
      4. For the avoidance of doubt, Solcoro does not collect, process, or store end-user content. Solcoro's analysis is limited to configuration metadata, thereby minimizing data exposure and supporting compliance with applicable law.
    2. Cloud Infrastructure.
      1. The Platform is hosted on Amazon Web Services ("AWS") infrastructure, utilizing containerized architecture engineered for scalability and operational resilience.
      2. All infrastructure provisioning is effected through Infrastructure as Code ("IaC") methodologies, such that every change is subject to peer review, is fully auditable, and is version-controlled.
      3. Solcoro's operating environments are segregated by function and purpose so as to preserve operational integrity and maintain appropriate data segregation.
  3. Data Retention and Deletion
    1. Metadata Only. Solcoro collects solely metadata originating from connected systems and, for the avoidance of doubt, does not collect application data, support tickets, documents, or messages of any kind.
    2. Retention and Deletion. For all terms governing data retention and deletion, refer to Solcoro's Data Retention and Deletion Policy, which is incorporated herein by reference.
  4. Authentication, Access Control, and Monitoring
    1. Authentication and Access Control.
      1. Solcoro exclusively supports federated authentication through major identity providers, utilizing OpenID Connect ("OIDC") and Security Assertion Markup Language ("SAML") protocols.
      2. The Platform implements granular, role-based permissioning such that each user's access is limited to that which such user is expressly authorized to view or utilize.
      3. All administrative access to Solcoro's systems is subject to multi-layered access control mechanisms.
    2. Monitoring and Incident Response.
      1. Solcoro maintains continuous collection of metrics, logs, and traces across its infrastructure and applications.
      2. Automated alerting mechanisms are configured to notify appropriate personnel of anomalous activity or threshold events.
      3. Solcoro maintains on-call engineering personnel and documented incident response playbooks to facilitate prompt investigation, containment, and remediation of security incidents.
  5. Data Protection and Infrastructure
    1. Compliance and Governance. Solcoro is in the process of pursuing SOC 2 Type II certification and operates in a manner consistent with the requirements of ISO/IEC 27001, the General Data Protection Regulation ("GDPR"), and the Digital Operational Resilience Act ("DORA"). Solcoro undertakes periodic review of its security controls and internal policies to ensure that such controls and policies continue to satisfy, or exceed, prevailing industry compliance standards.
    2. Responsible Disclosure. Solcoro encourages security researchers and third-party partners to responsibly report potential vulnerabilities. Any person who believes they have identified a security vulnerability affecting the Platform is invited to submit a report to support@solcoro.com. Solcoro treats all such reports with due seriousness and undertakes to respond in a timely manner. Submission of a report under this Section does not, by itself, confer any right, license, or authorization beyond that expressly granted by Solcoro in writing.
  6. Amendments
    1. Amendments. Solcoro reserves the right to amend, modify, or update this Policy from time to time in its sole discretion. Material changes shall be reflected by an updated "Last Updated" date above. Continued use of the Platform following any such amendment shall constitute acceptance of the amended Policy.

© 2026 Solcoro LLC. All rights reserved.
www.solcoro.com