Legal
Legal
The contract, the operating rules, the privacy notices, and the vendor list.
Last updated August 24, 2026
These documents together comprise the Humfrid legal and enterprise trust framework.
Security & Trust Center
For our comprehensive technical security architecture, zero AI model training guarantees, ephemeral container sandboxing, private VPC isolation, and SOC 2 alignment posture, visit our Security & Trust Center.
The legal agreements
- Terms of Service. The commercial contract — unconditional Output ownership, zero AI model training commitment, agent authorization, fees, liability limits, and dispute resolution. Read →
- Data Processing Addendum (DPA). Processor agreement under GDPR Article 28 — technical & organizational security measures, EU Standard Contractual Clauses (Module 2), UK IDTA, 72-hour breach notice, and 30-day hard deletion. Effective automatically with the Terms. Read →
- Privacy Policy. Controller privacy notice — account registration, billing, platform telemetry, GDPR and CCPA/CPRA data subject rights, and data retention. Read →
- Usage Policy. Operating rules & safety standards — EU AI Act compliance, prohibited data types (PHI, PCI, SSNs), prompt-injection risk management, and agent authorization scopes. Read →
- Sub-processors. Authoritative vendor registry — detailing sub-processors, services, data categories, locations, and compliance certifications (SOC 2, ISO 27001, PCI DSS). Read →
- Cookie Policy. Cookie inventory — detailing essential authentication cookies and privacy-respecting site analytics. Read →
Last updated
Last updated August 24, 2026. Living security posture is maintained on the Security page.
Contact
legal@humfrid.com — legal, privacy, security diligence, DPA execution, and sub-processor notices.