Legal

Legal

The contract, the operating rules, the privacy notices, and the vendor list.

Last updated August 24, 2026

These documents together comprise the Humfrid legal and enterprise trust framework.

Security & Trust Center

For our comprehensive technical security architecture, zero AI model training guarantees, ephemeral container sandboxing, private VPC isolation, and SOC 2 alignment posture, visit our Security & Trust Center.

The legal agreements

  • Terms of Service. The commercial contract — unconditional Output ownership, zero AI model training commitment, agent authorization, fees, liability limits, and dispute resolution. Read →
  • Data Processing Addendum (DPA). Processor agreement under GDPR Article 28 — technical & organizational security measures, EU Standard Contractual Clauses (Module 2), UK IDTA, 72-hour breach notice, and 30-day hard deletion. Effective automatically with the Terms. Read →
  • Privacy Policy. Controller privacy notice — account registration, billing, platform telemetry, GDPR and CCPA/CPRA data subject rights, and data retention. Read →
  • Usage Policy. Operating rules & safety standards — EU AI Act compliance, prohibited data types (PHI, PCI, SSNs), prompt-injection risk management, and agent authorization scopes. Read →
  • Sub-processors. Authoritative vendor registry — detailing sub-processors, services, data categories, locations, and compliance certifications (SOC 2, ISO 27001, PCI DSS). Read →
  • Cookie Policy. Cookie inventory — detailing essential authentication cookies and privacy-respecting site analytics. Read →

Last updated

Last updated August 24, 2026. Living security posture is maintained on the Security page.

Contact

legal@humfrid.com — legal, privacy, security diligence, DPA execution, and sub-processor notices.