SoJen.AI
SoJen.AI
SoJen.AI is trust infrastructure for AI-mediated communication.
Home About Enterprise Podcast Blog Contact

Legal Documents

API Terms of Use Privacy Policy Cookie Policy Acceptable Use Policy Data Processing Agreement Service Level Agreement AI Transparency Statement
← Back to Portal
These documents are provided for informational purposes. SoJen.AI recommends that Enterprise customers seek independent legal counsel before executing binding agreements.

SoJen.AI Data Processing Agreement

Effective Date: July 1, 2026 Last Updated: July 1, 2026

This Data Processing Agreement ("DPA") forms part of the API Terms of Use between SoJen.AI ("Processor") and the Customer ("Controller") and governs the processing of personal data by SoJen.AI on behalf of the Customer in connection with the API. This DPA is required for Customers subject to the General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection laws, and is available to all Customers upon request.


1. Definitions

  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained within Input Content or Account Data.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Controller" means the Customer, who determines the purposes and means of processing.
  • "Processor" means SoJen.AI, who processes Personal Data on behalf of the Controller.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data.
  • "Processing" has the meaning given in the GDPR.

2. Roles and Responsibilities

2.1 Controller. The Customer is the Controller of any Personal Data contained within Input Content submitted to the API. The Customer is responsible for:

  • Having a lawful basis for submitting Personal Data to the API.
  • Providing required notices to Data Subjects about processing by SoJen.AI.
  • Ensuring COPPA compliance for any data relating to children under 13.
  • Complying with all applicable data protection laws with respect to the original collection of the data.

2.2 Processor. SoJen.AI processes Personal Data only to deliver the API service and as otherwise described in this DPA. SoJen.AI shall not process Personal Data for its own purposes outside the scope of the Terms of Use and this DPA.


3. Processing Instructions

3.1 SoJen.AI processes Personal Data solely on the documented instructions of the Controller, which are: deliver inference results for submitted text content; maintain service reliability; improve model quality using anonymized or aggregated data (subject to Section 6).

3.2 If SoJen.AI is required by applicable law to process Personal Data beyond these instructions, it will notify the Controller before such processing unless legally prohibited from doing so.

3.3 If SoJen.AI believes an instruction violates applicable data protection law, it will promptly notify the Controller.


4. Security Measures

SoJen.AI implements and maintains appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption in transit: TLS 1.2 or higher for all API communications.
  • Access controls: Principle of least privilege; employee access to Customer data is restricted to those with operational need.
  • API key security: Keys are stored in hashed form; plaintext keys are not retained after initial issuance.
  • Incident response: Procedures for detecting, reporting, and investigating personal data breaches.
  • Vendor security: Sub-processors are selected with appropriate security standards.

5. Sub-processors

5.1 SoJen.AI may engage sub-processors to assist in providing the API. Current sub-processors include:

Sub-processor Role Location
Railway (Railway Corp.) Cloud infrastructure / hosting United States

5.2 SoJen.AI will notify the Controller of any intended addition or replacement of sub-processors at least thirty (30) days in advance by email or portal notification. The Controller may object to a new sub-processor within fourteen (14) days; if the parties cannot resolve the objection, the Controller may terminate the API subscription with a pro-rated refund for the unused period.

5.3 SoJen.AI enters into written agreements with sub-processors that impose data protection obligations no less protective than those in this DPA.


6. Model Training and Anonymization

6.1 SoJen.AI retains Input Content and may use it to improve and retrain its machine learning models. Before using Input Content for training, SoJen.AI applies anonymization techniques designed to remove or obscure directly identifying information.

6.2 If the Controller requires that its Input Content be excluded from model training entirely, it must request a training exclusion by contacting legal@sojen.ai. Training exclusions are available on Growth and Enterprise tiers at no additional charge; availability on the Pilot tier is subject to written agreement.

6.3 Once data has been irreversibly anonymized and incorporated into aggregate training datasets, it may not be practicable to identify and remove it. This limitation applies to the irreversibly anonymized form only; raw Input Content subject to a deletion request under Section 9 will be deleted from identifiable storage.


7. Confidentiality

SoJen.AI ensures that personnel authorized to process Personal Data are bound by confidentiality obligations.


8. Assistance to the Controller

SoJen.AI will, taking into account the nature of the processing, provide reasonable assistance to the Controller in:

  • Responding to Data Subject rights requests (access, rectification, erasure, portability, restriction, objection).
  • Fulfilling obligations related to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

SoJen.AI may charge a reasonable fee for assistance that requires substantial effort, agreed in writing in advance.


9. Data Subject Rights and Deletion

9.1 If SoJen.AI receives a Data Subject rights request directly from a Data Subject relating to the Controller's data, SoJen.AI will promptly forward it to the Controller and will not respond independently unless required by law.

9.2 Upon the Controller's written request, SoJen.AI will delete or return Personal Data (excluding anonymized training data as described in Section 6.3) within thirty (30) days, and will confirm deletion in writing.

9.3 Upon termination of the API subscription, SoJen.AI will delete identifiable Input Content within ninety (90) days, unless a longer retention period is required by law.


10. Data Breach Notification

10.1 SoJen.AI will notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any confirmed personal data breach affecting Input Content or Account Data.

10.2 Notifications will include, to the extent then known: the nature of the breach; categories and approximate number of Data Subjects and records affected; likely consequences; and measures taken or proposed.


11. International Data Transfers

Where Personal Data is transferred from the EEA, UK, or Switzerland to the United States, such transfers are made pursuant to the Standard Contractual Clauses (Controller-to-Processor) adopted by the European Commission (Decision 2021/914, Module 2), which are incorporated herein by reference. Copies are available at legal@sojen.ai on request.


12. Audits

Upon thirty (30) days' prior written notice (or immediately in the event of a confirmed breach), the Controller may audit SoJen.AI's data processing activities to verify compliance with this DPA, no more than once per calendar year. Audits must be conducted during normal business hours, at the Controller's expense, and in a manner that minimizes disruption. SoJen.AI may satisfy audit rights by providing relevant third-party audit reports (e.g., SOC 2) where available.


13. Term

This DPA remains in effect for the duration of the API Terms of Use and survives termination to the extent necessary to fulfill post-termination deletion and return obligations.


14. Order of Precedence

In the event of any conflict between this DPA and the Terms of Use with respect to data protection matters, this DPA controls.


Contact: legal@sojen.ai | sojen.ai

SoJen.AI

SoJen.AI develops communication intelligence technologies designed to support healthier digital communication across organizations and future communication environments.

Navigate
  • About
  • Enterprise
  • Podcast
  • Blog
  • Contact
Focus Areas
  • Communication Intelligence
  • Digital Dialogue
  • Platform Design
  • Healthier Online Environments
Legal
  • API Terms of Use
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Service Level Agreement
  • AI Transparency Statement
Connect

Explore enterprise solutions, follow thought leadership, or contact SoJen.AI for inquiries and collaboration.

Contact SoJen.AI
© 2026 SoJen.AI. All rights reserved. Built for healthier digital communication.