1. Parties and contract documents
The supplier is Soroltech, a Finnish private trader, Business ID 3363620-8. The customer is the organization identified in the accepted final order (“Order”). The contract consists of the Order, this Business and Custom Agreement including its schedules, the Terms of Service, and the Privacy Policy. An inquiry or invoice request is not an Order.
The Order must identify its unique reference, customer and billing contact, package, features and limits, seats, price and taxes, billing and contract period, renewal and termination terms, start date, and any agreed support or service-level variation. If terms conflict, the data processing schedule controls processing of customer personal data, then the Order, this agreement, and the general Terms of Service in that order.
2. Service, fees, and customer responsibilities
Soroltech supplies only the features and capacity recorded in the Order and administrator-side package snapshot. Business may include owner-managed member accounts; Custom is an individually configured package without team rights unless the Order says otherwise. The customer must pay valid invoices, identify authorized contacts, manage members and credentials, keep encryption and widget keys secret, use lawful targets and content, and give all notices and instructions required for people whose data it controls.
Prices and payment dates are in the Order and invoice. Late payment may suspend access after reasonable notice, except where immediate action is necessary for security or law. Unless the Order provides a fixed term or renewal, the service continues month-to-month and either party may terminate it on 30 days’ written notice. Material breach may be terminated after a reasonable cure period; serious security, unlawful use, or non-payment may justify earlier suspension.
3. Standard support and service level
Support is provided through [email protected]. The standard target is an initial response within two Finnish business days. Security incidents and service-wide outages are handled as soon as reasonably practicable. Standard service has no 24/7 staffed help desk, guaranteed resolution time, service credit, or percentage uptime commitment. Any different response target, maintenance window, uptime objective, escalation route, or service credit must be stated expressly in the Order.
4. Data processing agreement
This section applies when the customer is controller and Soroltech processes personal data on its behalf. It is intended to meet GDPR Article 28. The subject is provision, security, support, maintenance, and deletion of the ordered Soroltech services for the contract duration and the deletion period below. Processing consists of receiving, storing, organizing, transmitting, retrieving, securing, troubleshooting, and deleting data as needed to provide the service.
Data subjects may include the customer’s employees, contractors, users, senders, recipients, monitored-site contacts, and people represented in customer content. Data may include account and team identifiers, contact details, authentication and audit records, public monitor targets and results, encrypted messages and files, file and link metadata, destinations, support communications, and other data submitted under documented instructions. Customers must not submit special-category or criminal-offence data unless the Order expressly authorizes it with additional safeguards.
- Soroltech processes customer personal data only on documented lawful instructions, including the Order and normal service controls, unless applicable law requires otherwise.
- Anyone authorized to process the data is bound by confidentiality. Soroltech currently operates as a one-person business.
- Soroltech maintains appropriate technical and organizational measures, assists reasonably with data-subject requests, security, breach duties, impact assessments, and regulator consultations, and notifies the customer without undue delay after becoming aware of a personal-data breach affecting customer data.
- Soroltech makes information reasonably necessary to demonstrate Article 28 compliance available and permits one reasonable audit per year on advance notice, plus a justified audit after a relevant breach. Audits must protect other customers, security, and confidentiality; customer-specific external audit costs are paid by the customer unless material non-compliance is found.
- Soroltech promptly tells the customer if an instruction appears to infringe applicable data-protection law and may pause that instruction while it is clarified.
5. Security schedule
- TLS protects network transport; network access and container privileges are restricted; production services have health monitoring, bounded logs, and authenticated administration.
- Passwords are stored as slow hashes. Sensitive link fields and authenticator secrets are encrypted at rest. One-time messages and file archives are encrypted in the browser; Soroltech does not receive the decryption key when the documented sharing flow is followed.
- Role, package, team, and per-user access controls are enforced server-side. Signed Paddle webhooks govern consumer entitlements; company packages require recorded signed-order evidence before activation.
- The customer remains responsible for endpoint security, lawful instructions, account provisioning, key delivery, backups of source files, and promptly reporting compromised credentials.
No system is completely secure. Soroltech may change controls to maintain or improve security without materially reducing the overall protection of customer data.
6. Retention, return, export, and deletion schedule
- Team membership, account configuration, monitors, managed links, and related records remain until the relevant item or account is deleted, subject to legal records.
- One-time encrypted messages remain until first retrieval or account deletion. Monitor history is capped at 2,000 results per monitor. Link analytics contain aggregate daily counts.
- Encrypted file drops use the Order/account retention limit and the sender’s selected period. They are deleted at expiry, download-limit completion, owner deletion, takedown, or account deletion. Incomplete uploads are removed after 24 hours.
- Authentication codes expire after 10 minutes. Login access expires after 12 hours; session and security records otherwise remain with the account. Size-bounded operational logs rotate according to traffic rather than a fixed number of days.
- On termination, the customer may request a reasonable machine-readable export of data Soroltech can technically associate with the account. The customer must request export before termination or within 30 days afterward and must retain its own decryption keys and source-file backups.
- After that 30-day return window, Soroltech deletes customer-controlled active-service data within 30 additional days, except records required for accounting, tax, security, disputes, or law. Residual copies in any protected backup are isolated from normal use and deleted or overwritten within 90 days unless law requires longer retention.
7. Authorized subprocessors
The customer gives general written authorization for the following subprocessors where they process customer personal data for the service:
- Hetzner Online GmbH — server hosting and storage; current workload location Helsinki, Finland.
- Cloudflare, Inc. — network tunnel, delivery, DNS, domain verification, and security; global network processing with applicable transfer safeguards.
- Brevo / Sendinblue SAS — transactional account, team, authentication, support, and invoice-request email; France/EEA with its documented subprocessors and transfer safeguards.
Paddle acts as Merchant of Record for separate individual purchases and is not used for Business package payment processing. Google analytics, when a site visitor separately consents, is processing for Soroltech’s own website purposes rather than processing customer content under this schedule.
Soroltech will give at least 30 days’ written notice before adding or replacing a subprocessor where reasonably possible. The customer may object on documented data-protection grounds during that period. The parties will seek a reasonable alternative; if none is available, either party may terminate the affected service. Urgent security or continuity changes may occur sooner with notice as soon as practicable. Soroltech remains responsible for each subprocessor’s relevant obligations.
8. International transfers
Processing is kept in the EEA where the stated service allows. If a subprocessor transfers personal data outside the EEA, Soroltech will require a lawful mechanism such as an adequacy decision, the EU Standard Contractual Clauses, and supplementary measures where required. The customer may request relevant transfer information.
9. Confidentiality, liability, and changes
Each party protects the other’s non-public business, security, and technical information and uses it only for this contract, subject to lawful disclosure. Liability limitations in the general Terms apply unless the Order says otherwise, but never exclude liability that mandatory law prohibits excluding. Changes to this public version do not replace the version incorporated into an accepted Order. A new version applies only through a new or amended Order.
10. Order checklist and signatures
Before activation, the final Order must contain the unique reference, both parties, authorized signers or equivalent acceptance evidence, acceptance date, agreement version, package specification and limits, fees and taxes, term and renewal, support/SLA selection, processing scope and any special-category-data decision, requested variations, and effective date. Soroltech records the reference, acceptance date, version, package limits, and activating administrator. Keep the accepted Order with the customer record.
Questions and notices: [email protected]. The European Commission publishes optional controller–processor standard contractual clauses.