Legal

The contract, the operating rules, the privacy notices, and the vendor list.

Last updated August 24, 2026

These documents together comprise the Humfrid legal and enterprise trust framework.

Security & Trust Center

For our comprehensive technical security architecture, zero AI model training guarantees, ephemeral container sandboxing, private VPC isolation, and SOC 2 alignment posture, visit our Security & Trust Center.

The legal agreements

  • Terms of Service. The commercial contract — unconditional Output ownership, zero AI model training commitment, agent authorization, fees, liability limits, and dispute resolution. Read →
  • Data Processing Addendum (DPA). Processor agreement under GDPR Article 28 — technical & organizational security measures, EU Standard Contractual Clauses (Module 2), UK IDTA, 72-hour breach notice, and 30-day hard deletion. Effective automatically with the Terms. Read →
  • Privacy Policy. Controller privacy notice — account registration, billing, platform telemetry, GDPR and CCPA/CPRA data subject rights, and data retention. Read →
  • Usage Policy. Operating rules & safety standards — EU AI Act compliance, prohibited data types (PHI, PCI, SSNs), prompt-injection risk management, and agent authorization scopes. Read →
  • Sub-processors. Authoritative vendor registry — detailing sub-processors, services, data categories, locations, and compliance certifications (SOC 2, ISO 27001, PCI DSS). Read →
  • Cookie Policy. Cookie inventory — detailing essential authentication cookies and privacy-respecting site analytics. Read →

Last updated

Last updated August 24, 2026. Living security posture is maintained on the Security page.

Contact

[email protected] — legal, privacy, security diligence, DPA execution, and sub-processor notices.