SSolvren
Data processing

Data-processing agreement

Effective 4 October 2026. This public DPA describes the standard processing commitments of Solvren, Inc., a Utah corporation, for customer-controlled personal data in the service. An executed order identifies the customer, any required transfer terms, and the applicable production region. Contact support@solvren.com for a signed copy.

Roles and instructions

The customer determines which customer and employee data it provides and acts as controller or equivalent decision-maker. Solvren processes that data as processor or service provider to deliver contract-margin analysis, authentication, reporting, support, security, billing, and deletion on the customer’s documented instructions in the service and agreement.

Data and duration

Processing may include work-email and account identifiers, customer and contract identifiers, cost and outcome metadata, report decisions, and support correspondence. The service does not require prompt bodies, response bodies, documents, or cardholder data. Processing lasts while the subscription or trial is active and through the documented retention and deletion period.

Security and personnel

Solvren uses role-based access, administrative MFA, tenant isolation, encrypted managed stores, HTTPS transport, restricted credentials, private file access, expiring export links, and access and change logs. Personnel access is limited to support diagnostics and approved, time-limited operational sessions. Solvren will notify the customer without undue delay after confirming a security incident affecting customer data, using the Owner’s account contact and the published incident process.

Subprocessors and assistance

The subprocessor list describes infrastructure, hosting, email, and payment providers. Solvren remains responsible for its subprocessors’ processing within the service and will update the public list when it changes. Solvren will reasonably assist with verified access, export, correction, deletion, and incident requests using the product controls and support process.

Return and deletion

An Owner can export organization data. After closure or canceled-access expiry, primary records and private files are scheduled for deletion within 29 days unless law or an agreed hold requires otherwise. Any infrastructure backup copies expire according to the provider’s retention schedule. Contact Support for a signed DPA or additional transfer terms required by your organization.