Last updated: July 13, 2026
This policy describes how Solace AGI ("Solace", "we") handles data. It is written to match how the product actually works. Because Solace operates a managed technology department, we do process your data on your behalf — this policy is honest about where it goes and how it is protected.
The Solace runtime that executes work routes all network activity through a single controlled egress at solaceagi.com. The runtime does not hold third-party API keys and does not reach external services on its own. This means:
Each customer runs in its own tenant scope. Cross-tenant access to your data is a prohibited state in the architecture, not a configuration setting. WorldData (public/licensed) is kept separate from the private customer records you provide.
To operate the service we use infrastructure and model providers (for example, cloud hosting and language-model providers) reached only through our controlled backend. We contract these providers to protect your data and to process it only to deliver the service. A current subprocessor list is available on request.
We retain your data for as long as needed to operate your service and to maintain the evidence trail you rely on. On termination you may export your data, and you may request deletion consistent with the Ownership Covenant and any legal retention obligations.
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data we process. For data we process as a processor on a customer's behalf, we act on that customer's instructions. Contact us to exercise these rights.
Security controls are described on the Trust page, where each control is labeled as implemented, a design goal, or a contractual option. We do not claim certifications we have not completed.
Where a customer business uses our messaging features, we process the mobile phone numbers their own end users provide — for example a parent enrolling a child at a tutoring centre — solely to deliver the messages that end user consented to receive.
No mobile information is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Mobile numbers and SMS consent are never shared with third parties for their own marketing.
Numbers are disclosed only to the telecommunications provider that carries the message on our behalf, strictly for delivery, and to no one else. Text messaging originator opt-in data and consent are not shared with any third party.
Consent is collected on the enrolment and booking forms where the number is entered, is affirmative (never pre-checked), and is recorded with a timestamp and the exact wording shown. Consent is never a condition of enrolment or purchase.
Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out at any time, or HELP for assistance. Opt-out is honoured immediately and enforced on every subsequent send. Full programme details are on our SMS Policy page.
We may update this policy; material changes will be notified. This page supersedes any earlier "Solace City" privacy statement. Questions: phuc@phuc.net.