Privacy Policy

What personal data Treica processes, why, where it is stored, and the rights available to individuals.

Last updated 2026-07-28

Awaiting counsel review.

This document is not legal advice and has not yet been reviewed by a qualified lawyer. Anything shown as "to be supplied" is a value the operating company has yet to provide, and is left visible rather than guessed. Statements about how the product behaves are drawn from the implementation and are accurate.

Who is responsible

Treica is operated by Sodasoft LLC, a limited liability company registered in the State of Wyoming, at Sodasoft LLC, 30 N Gould St, Sheridan, WY 82801, the United States (the "Provider", "we").

For personal data that a customer loads into their own workspace, the customer is the controller and we act as processor on their documented instructions. For data we collect to run the service itself (account records, sign-in events, billing correspondence), we are the controller.

Data protection contact: privacy@treica.com. Anything shown as "to be supplied" is a value the operating company must complete before this document is relied on.

What we process, and why

CategoryExamplesPurposeLawful basis
Account dataName, work email, role, home entityProvide access, enforce roles, attribute actions in the audit trailContract performance
Authentication dataSign-in link tokens, two-factor secret, session recordsVerify identity, protect the accountContract performance; legitimate interest in security
Customer register contentThird-party records, contracts, evidence documents, assessment answers, findingsDeliver the service the customer configuredProcessor acting on the customer's instructions
Contact data of third-party representativesNames and business contact details recorded against a provider or evidence requestOperate the customer's third-party governance programmeProcessor; the customer's legitimate interest as controller
Usage and audit recordsActions taken, records viewed, IP address, user agent, timestampsProduce the immutable audit trail the regulation expects, and detect abuseLegal obligation of the customer; our legitimate interest in security
Support correspondenceMessages you send usAnswer you and improve the serviceLegitimate interest

Where data is stored

The application database and the evidence store are both hosted in the European Union (Frankfurt, Germany). Uploaded evidence is held with private access only: it is readable through an authenticated request to this service, never from a public URL.

Application hosting and content delivery are provided by Vercel Inc.; transactional email is sent through Resend. Current sub-processors are listed at /legal/subprocessors.

The operating company, Sodasoft LLC, is established in the United States. Your register content and evidence are stored in the European Union and are not relocated; however, administering the service from the United States means personal data may be accessed from outside the EEA. Those transfers rely on the European Commission's standard contractual clauses, supplemented by the technical measures described under Security, and on a transfer impact assessment we will provide on request. Where the customer is the controller, we act only on that customer's documented instructions.

Representative in the Union (Article 27 GDPR): none is currently designated. Because Sodasoft LLC is established outside the Union and offers services to entities in it, Article 27 requires a representative in writing, and an EU sub-processor does not satisfy that obligation. A company inside the European Union is being established to contract with customers directly; on that entity taking over the agreements, Article 27 ceases to apply and this section will say so. Until then, this document states the gap rather than implying it is closed. Data-protection enquiries reach us at privacy@treica.com.

AI processing

Treica Assist is an optional add-on, available with the Governance and Group plans, and is switched OFF by default. No content is sent to a model provider unless the add-on is on the workspace's contract AND an owner has explicitly enabled it AND the subscription year's action allowance has not been spent. Any one of those being absent means no model call is made at all.

When enabled, only the material submitted for that specific action is transmitted: the contract document or text you supply, the questions and answers of the assessment you are reviewing, or the code and message of a single validation result. Your register is never transmitted.

Model access is provided through Vercel's AI Gateway to Anthropic models. Submitted content is not used to train models. Full detail, including the human-in-the-loop guarantee, is in the AI Use and Compliance notice.

Retention

Register content and evidence are retained while the workspace is active. On termination, or on a documented erasure request, erasure is scheduled 30 days out and the workspace stays fully usable and exportable until then, so nothing is lost to a mistake. On that date the register rows and the stored evidence bytes are deleted irreversibly - not marked deleted, removed. Audit records are kept for 5 years after the agreement ends, because a supervisor may ask about a filing made during the relationship; that period is bounded rather than indefinite, and the entries are reduced to what identifies the actor rather than a copy of the record.

Sign-in tokens expire shortly after issue and are single-use. Sessions expire after a period of inactivity.

Security

  • Passwordless sign-in; no password is stored. Optional time-based two-factor authentication.
  • Every workspace's data is isolated at the database level by row-level security enforced under an application role that cannot bypass it, in addition to application-level scoping.
  • Evidence files are hashed on upload so any later alteration is detectable, and are served only to authenticated, authorised users.
  • Transport is encrypted and strict transport security is enforced. Administrative surfaces are separated from the customer application.
  • Every create, update, delete, privileged action and record view is written to an append-only audit log.

Your rights

Individuals in the EEA and the UK may request access, rectification, erasure, restriction, portability, and may object to processing based on legitimate interest. Where we act as processor, we will forward your request to the relevant customer, who is the controller, and assist them in answering it.

Requests: privacy@treica.com. You may also complain to your own national supervisory authority. We are established outside the Union; our EU representative under Article 27 GDPR is to be supplied.

Cookies

Treica sets only the cookies required to operate: a session cookie, a cross-site request forgery token, and a cookie remembering which entity you are working in. There is no advertising or cross-site tracking, and no third-party analytics cookie is set without consent.

Changes

We will post any material change here and, where the change affects how personal data is processed, notify workspace owners by email before it takes effect.