Legal

Data Processing Addendum

Effective July 20, 2026 · Last updated July 21, 2026

This Data Processing Addendum applies where we process personal data on your behalf as your processor. It forms part of, and is governed by, our Terms of Use.

About This Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Use (the "Agreement") between the Customer ("you," acting as the Controller or Business) and Engrain AI, LLC, doing business as "Soaklysoft" ("Soaklysoft," acting as the Processor or Service Provider), and applies to the extent Soaklysoft processes Personal Data on your behalf in providing the Service.

If a signed data processing agreement or negotiated addendum exists between the parties, that document controls to the extent it conflicts with this DPA. In the event of a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA controls.

To request a countersigned copy of this DPA, contact logan@soaklysoft.com.

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

  • "Applicable Data Protection Laws" means all privacy and data-protection laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act as amended (the "CCPA"), other U.S. state privacy laws, and the EU General Data Protection Regulation and UK GDPR (together, the "GDPR").
  • "Personal Data" means any information within Customer Data that relates to an identified or identifiable natural person, or that is "personal information"/"personal data" under Applicable Data Protection Laws, and that Soaklysoft processes on your behalf.
  • "Processing," "Controller," "Processor," "Business," "Service Provider," "Data Subject," and "Personal Data Breach" have the meanings given under Applicable Data Protection Laws.
  • "Subprocessor" means a third party engaged by Soaklysoft to process Personal Data.
  • "Standard Contractual Clauses" ("SCCs") means the clauses approved for the transfer of personal data to third countries under the GDPR.

2. Roles and Scope

You are the Controller/Business and Soaklysoft is the Processor/Service Provider with respect to Personal Data processed under the Agreement. Each party will comply with its obligations under Applicable Data Protection Laws. This DPA applies to processing carried out by Soaklysoft on your behalf as described in Annex A.

You are responsible for the lawfulness of the Personal Data you provide and of your instructions, including having a valid legal basis and providing all required notices to, and obtaining all required consents from, Data Subjects.


3. Processing Instructions

Soaklysoft will process Personal Data only (a) to provide, secure, and support the Service in accordance with the Agreement; (b) as further instructed by you in your use and configuration of the Service; and (c) as required by applicable law, in which case Soaklysoft will inform you of that legal requirement before processing unless prohibited by law. Soaklysoft will promptly inform you if, in its opinion, an instruction infringes Applicable Data Protection Laws.


4. Confidentiality

Soaklysoft will ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and are informed of the confidential nature of the Personal Data.


5. Security

Soaklysoft will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A summary of those measures is set out in Annex B. You are responsible for your own use and configuration of the Service, including access controls, user management, and any security options the Service makes available to you.


6. Subprocessors

You provide general authorization for Soaklysoft to engage Subprocessors to process Personal Data in connection with the Service, including the cloud hosting, payment, messaging, and other infrastructure and service providers Soaklysoft uses to operate the Service. Soaklysoft will (a) impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and (b) remain responsible for each Subprocessor's performance. Soaklysoft will make available a current list of Subprocessors on request and will provide a mechanism to notify you of intended changes, giving you the opportunity to object on reasonable data-protection grounds.


7. Data Subject Requests

Taking into account the nature of the processing, Soaklysoft will provide reasonable assistance, including through appropriate technical and organizational measures and the self-service tools in the Service, to help you respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If Soaklysoft receives such a request directly, it will, unless legally required to act, refer the Data Subject to you.


8. Personal Data Breach

Soaklysoft will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data, and will provide information reasonably available to it to help you meet your notification obligations. Soaklysoft's notification is not an acknowledgment of fault or liability. As the Controller, you are solely responsible for determining whether, when, and how to notify supervisory authorities, Data Subjects, or any other party of a Personal Data Breach, and for the content of those notifications.


9. Data Protection Impact Assessments

Taking into account the nature of processing and the information available to it, Soaklysoft will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that you are required to carry out under Applicable Data Protection Laws.


10. Audits

Soaklysoft will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To the extent available, Soaklysoft may satisfy this obligation by providing third-party certifications, audit reports, or a written response to a reasonable security questionnaire. Audits will be conducted on reasonable prior notice, no more than once per year absent cause or a regulator's requirement, during business hours, subject to confidentiality, and in a manner that does not disrupt Soaklysoft's operations.


11. International Transfers

Where Personal Data protected by the GDPR is transferred to a country that has not received an adequacy decision, the parties agree that the applicable Standard Contractual Clauses are incorporated into this DPA by reference and completed by the details in Annex A, with Soaklysoft as "data importer" and you as "data exporter," and with the applicable module for controller-to-processor transfers applying. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies as required and is deemed completed by the details in Annex A; for transfers subject to Swiss law, the SCCs apply as adapted to satisfy the Swiss Federal Act on Data Protection.


12. CCPA Terms

To the extent Soaklysoft processes Personal Data that is "personal information" governed by the CCPA, Soaklysoft acts as a "service provider." Soaklysoft will not (a) sell or share such personal information; (b) retain, use, or disclose it for any purpose other than the specific purpose of performing the Service, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between the parties; or (d) combine it with personal information from other sources except as permitted by the CCPA. Soaklysoft certifies that it understands and will comply with these restrictions. Soaklysoft will notify you if it determines it can no longer meet its obligations under the CCPA, in which case you may take reasonable and appropriate steps to stop and remediate any unauthorized use of personal information. Soaklysoft will not attempt to re-identify de-identified or aggregated data, except as permitted by law to test the effectiveness of de-identification.


13. Return and Deletion

Upon expiration or termination of the Agreement, Soaklysoft will, at your choice, delete or return Personal Data as described in the Agreement, and delete existing copies except to the extent retention is required by applicable law or held in routine backups that are deleted in the ordinary course.


14. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.


15. Term

This DPA takes effect on the effective date of the Agreement and continues until Soaklysoft ceases to process Personal Data on your behalf. Provisions that by their nature should survive termination will survive.


Annex A — Details of Processing

  • Subject matter: Soaklysoft's provision of the Service to you under the Agreement.
  • Duration: the term of the Agreement, plus any period during which Personal Data is retained under the Agreement.
  • Nature and purpose: hosting, storage, and processing of Personal Data to provide business-management, point-of-sale, service-dispatch, inventory, CRM, marketing, communications, customer-portal, and related features of the Service, and to support, secure, and improve the Service.
  • Categories of Data Subjects: your customers, leads, and contacts; your employees and contractors who are Authorized Users; and other individuals whose information you choose to store in the Service.
  • Categories of Personal Data: identity and contact details (name, address, email, phone); account and login data; transaction, order, invoice, and payment-related data; service, appointment, and communication history; and any other Personal Data you choose to submit through the Service. You agree not to submit special categories of data except as permitted by the Agreement.
  • Frequency of transfer: continuous, for the duration of the Agreement.

Annex B — Technical and Organizational Measures

Soaklysoft maintains measures that may include, as appropriate to the Service:

  • access controls, role-based permissions, and authentication for the Service;
  • encryption of data in transit, and encryption of sensitive stored credentials where supported;
  • network and application security controls and monitoring;
  • regular backups and documented restore procedures;
  • separation of production data and least-privilege administrative access;
  • logging and audit trails for key actions within the Service;
  • personnel confidentiality obligations and security practices; and
  • vendor management for Subprocessors.

These measures may be updated over time provided the level of protection is not materially decreased.


Contact

Questions about this DPA, or requests for a countersigned copy or the Subprocessor list, may be sent to:

Engrain AI, LLC d/b/a Soaklysoft Email: logan@soaklysoft.com