Privacy Policy

Effective Date: September 15, 2026 · Last Updated: September 15, 2026

1. Who We Are

Soviic is a workflow automation platform for small and medium-sized businesses, operated by CyberSentinel Services LLC, a Texas limited liability company.

  • Company: CyberSentinel Services LLC (DBA: Soviic)
  • Address: 3245 Main St Ste 235-609, Frisco, TX 75034
  • Email: hello@soviic.com
  • Website: soviic.com

This Privacy Policy applies to the Soviic website and web application (collectively, the "Service").

2. Information We Collect

2.1 Information You Provide Directly

  • Waitlist / early access signups: email address and optional first name.
  • Account registration: name, business name, email address, and password.
  • Profile information: industry, team size, and business type.
  • Payment information: processed by Stripe; we do not store full card numbers.
  • Communications: support tickets and feedback you send us.

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, and clicks.
  • Device and browser information.
  • IP address, used for fraud prevention and analytics.
  • Cookies (see Section 7).

2.3 Information From Third-Party Integrations

When you connect third-party services (such as Gmail, Slack, Stripe, or Google Calendar), we receive the access tokens and data necessary to perform those integrations on your behalf. We access only what you explicitly authorize.

3. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To process transactions and send billing confirmations.
  • To send product updates, security notices, and account notifications.
  • To respond to support requests.
  • To improve and develop features.
  • To send marketing communications, only with your consent and only from Soviic.
  • To detect, prevent, and investigate security incidents or fraud.
  • To comply with legal obligations.

We do not sell your personal information to third parties. We do not share your data with advertisers. We do not use your data to train AI models without your explicit consent.

4. How We Share Your Information

4.1 Service Providers (Subprocessors)

  • Supabase — database and authentication.
  • Cloudflare Workers — application hosting.
  • Stripe — payment processing and billing.
  • Mailchimp / Intuit — waitlist and email communications.
  • Google Workspace — business email operations.
  • Cloudflare — DNS, CDN, and DDoS protection.
  • Resend — transactional email delivery.
  • PostHog — product analytics.
  • Sentry — error tracking and monitoring.

4.2 Legal Requirements

We may disclose information if required by law or to protect rights and safety.

4.3 Business Transfers

If Soviic or CyberSentinel Services LLC is acquired or merged, information may transfer as part of that transaction. Affected users will be notified with an option to delete their data.

5. Data Retention

  • Active accounts: retained for the duration of the account relationship.
  • Waitlist data: until you unsubscribe or request deletion.
  • Workflow and integration data: while active, plus 30 days after account deletion.
  • Billing records: 7 years, as required by tax law.
  • Security and audit logs: 12 months.
  • Deleted account data: purged within 30 days, except where legal retention is required.

6. Your Rights and Choices

You have the right to:

  • Access your personal information.
  • Correct inaccurate information.
  • Request deletion, subject to legal retention requirements.
  • Request portability of your data.
  • Opt out of marketing communications.
  • Withdraw consent at any time.

To exercise any right, email hello@soviic.com. We respond within 30 days.

7. Cookies and Tracking

  • Essential cookies: required for the Service to function and cannot be disabled. Disabling essential cookies prevents login.
  • Analytics cookies: PostHog and Cloudflare Analytics collect anonymous usage data; you can opt out via your browser settings.
  • We do not use advertising cookies.

8. Data Security

  • Data encrypted in transit (TLS 1.2+).
  • Data encrypted at rest (AES-256 via Supabase).
  • Supabase Auth with JWT and secure sessions.
  • OAuth 2.0 for integrations.
  • API keys and credentials encrypted at rest and never exposed client-side.
  • Row-level security enforced in the database.
  • Rate limiting on authentication endpoints.
  • HTTPS enforced.
  • Audit logging for security-relevant actions.

No method of transmission or storage is 100% secure. Please report vulnerabilities responsibly to hello@soviic.com.

9. Children's Privacy

The Service is not directed at children under 13, and we do not knowingly collect data from children under 13. If you believe we have, please contact hello@soviic.com.

10. International Data Transfers

Soviic operates in the United States. Data from outside the US is transferred to and processed in the US. Our service providers offer adequate protection via standard contractual clauses or equivalent safeguards.

11. California Privacy Rights (CCPA)

California residents have the right to know, delete, and opt out of the sale of their personal information. We do not sell personal information. To exercise these rights, contact hello@soviic.com.

12. Changes to This Policy

We may update this policy from time to time. For material changes, we will update the "Last Updated" date and notify active users via email or in-app notification at least 30 days before the changes take effect.

13. Contact Us

  • Email: hello@soviic.com
  • Mail: CyberSentinel Services LLC (DBA: Soviic), 3245 Main St Ste 235-609, Frisco, TX 75034