Legal
The contract, the operating rules, the privacy notices, and the vendor list.
Last updated August 24, 2026
These documents together comprise the Humfrid legal and enterprise trust framework.
Security & Trust Center
For our comprehensive technical security architecture, zero AI model training guarantees, ephemeral container sandboxing, private VPC isolation, and SOC 2 alignment posture, visit our Security & Trust Center.
The legal agreements
- Terms of Service. The commercial contract — unconditional Output ownership, zero AI model training commitment, agent authorization, fees, liability limits, and dispute resolution. Read →
- Data Processing Addendum (DPA). Processor agreement under GDPR Article 28 — technical & organizational security measures, EU Standard Contractual Clauses (Module 2), UK IDTA, 72-hour breach notice, and 30-day hard deletion. Effective automatically with the Terms. Read →
- Privacy Policy. Controller privacy notice — account registration, billing, platform telemetry, GDPR and CCPA/CPRA data subject rights, and data retention. Read →
- Usage Policy. Operating rules & safety standards — EU AI Act compliance, prohibited data types (PHI, PCI, SSNs), prompt-injection risk management, and agent authorization scopes. Read →
- Sub-processors. Authoritative vendor registry — detailing sub-processors, services, data categories, locations, and compliance certifications (SOC 2, ISO 27001, PCI DSS). Read →
- Cookie Policy. Cookie inventory — detailing essential authentication cookies and privacy-respecting site analytics. Read →
Last updated
Last updated August 24, 2026. Living security posture is maintained on the Security page.
Contact
[email protected] — legal, privacy, security diligence, DPA execution, and sub-processor notices.