Skip to main content
SoAI logo, light theme SoAI logo, dark theme

    Explore SoAI

      Privacy

      Privacy notice

      The SoAI software collects nothing about you. This notice covers the far smaller set of records created when you buy a license, run a licensing operation, or open a support case.

      In short

      The SoAI software does not collect anything about you. It has no analytics, no usage reporting, no crash telemetry, and no background phone-home, and it never sends your prompts, model inputs and outputs, files, credentials, or knowledge-base content to anyone. That content stays on the machine you run SoAI on unless you configure and use a third-party service, such as a remote inference, search, image, mail, calendar, messaging, model-registry, or browser target, and what you send through that feature then reaches the provider you chose and is handled under that provider's own terms. Free personal use of SoAI Core needs no account, product key, or activation.

      This notice covers the far smaller set of records that do reach Roberto Martini: what happens when you buy a license, run an explicit licensing operation, or open a support case. Nothing on this page describes collection from a running SoAI installation.

      Controller

      Roberto Martini is the controller for the SoAI licensing website and related direct support records. Telephone: +393500342078. Privacy requests: [email protected]. Paddle separately controls the payment and checkout processing described in its buyer privacy notice on the Paddle website.

      Data, purposes, lawful bases, and necessity

      Data Purpose and basis If not provided
      Purchaser or acceptor name, email, country, organization identity, registration or tax identifier, and authority attestation Contract formation and eligibility under Article 6(1)(b) GDPR; tax and accounting compliance under Article 6(1)(c); and the legitimate interests in preventing fraud and establishing or defending legal claims under Article 6(1)(f) A purchase, evaluation, organization entitlement, or invoice may be unavailable.
      Exact legal acceptance, product and license identifiers, opaque deployment public key and identifier, activation, allocation, conversion, deactivation, and recovery events Deliver, activate, recover, and administer the requested license under Article 6(1)(b); and the legitimate interests in proving capacity, preventing abuse, preserving record integrity, and defending claims under Article 6(1)(f) The requested entitlement or recovery cannot be issued or capacity cannot be proved safely.
      Paddle transaction, subscription, adjustment, and status references; transactional-email outbox status Payment reconciliation, delivery, renewal, and refund administration under Article 6(1)(b); accounting obligations under Article 6(1)(c); and the legitimate interests in detecting fraud and resolving disputed transactions under Article 6(1)(f) Paid delivery or a requested adjustment may be delayed or refused until independently verified.
      Support contacts, cases, diagnostic material, security and audit events, backup evidence, and minimized server logs Provide requested support under Article 6(1)(b); and the legitimate interests in securing and recovering the service, investigating abuse, and establishing or defending claims under Article 6(1)(f) Support or investigation may be limited.
      Consent record and optional first-party analytics events Measure public-site use only after affirmative consent under Article 6(1)(a) GDPR, and keep proof that the consent was given and may be withdrawn Optional analytics remains disabled with no loss of licensing functionality.

      Data minimization and local operation

      SoAI does not send customer prompts, model inputs, model outputs, local files, credentials, or business datasets merely to validate a license. After successful activation, the entitlement is validated locally. Network contact occurs for a user-initiated activation, deactivation, recovery, conversion, update, or another expressly requested licensing operation. Commercial operation is local through the signed term.

      Recipients, transfers, and security

      Paddle is a separate controller for checkout, payment, tax, and related buyer records as merchant of record. Purelymail is a processor for transactional licensing and support email. Cloudflare is a processor for public DNS, reverse-proxy, traffic-security, and delivery services when a request reaches the public website. The origin service is operator controlled. Professional advisers and public authorities receive data only when needed for a specific professional or legal duty.

      The current sub-processor for commercial support material is Purelymail, because support cases are opened by email. No other provider is authorized to receive support-case content unless this list is updated and the notice promised by the commercial terms is given. Paddle's and Cloudflare's own notices describe their processing locations and transfer safeguards. For a restricted transfer made by Roberto Martini, the applicable basis will be an adequacy decision or the European Commission's standard contractual clauses. A copy of the applicable safeguard may be requested at [email protected].

      Access separation, encryption where appropriate, scoped credentials, signed entitlement records, integrity checks, bounded logs, backups, restoration tests, and incident procedures protect records in proportion to risk. No system is described as absolutely secure.

      Retention and rights

      Order, tax, acceptance, entitlement, audit, and dispute evidence is retained for applicable statutory, contractual, security, and limitation periods. Failed claim material and operational logs are retained only for bounded recovery and security periods; backups age out under the documented retention cycle. For website abuse detection, encrypted source-IP captures are retained for 30 days. Separate keyed, pseudonymous request matching is retained for 90 days from each request; a new request does not extend older request history. Readable-IP expiry does not end matching within that window. Shared or changing IP addresses mean these records do not identify unique users. Installer and update counters measure requests rather than completed installations, and update checks include the client-reported installed version without an installation identifier or completion callback. Nonidentifying aggregate counts may be retained beyond these periods. In concrete terms: identifying web server and application logs, failed or unclaimed credential-delivery material, expired checkout intents, and unactivated evaluation reservations are deleted within 30 days, and routine backups containing them age out within 30 days on the same cycle. Diagnostic material attached to a support case is deleted 30 days after the case closes, unless it is subject to an open dispute, a security investigation, or a legal hold. Administrative access logs are kept for six months, the minimum retention Italian rules impose on system-administrator access records, and are deleted after it. Support time entries, which exist only to account for the included and prepaid balance, are kept for the paid term and afterwards with the accounting records. Order, invoice, payment-reference, and accounting evidence is kept for ten years from the last entry, as Italian accounting law requires. Licensing identity, acceptance records, entitlement history, and the signed audit chain are kept while the entitlement exists and for ten years afterwards, matching the ordinary Italian limitation period for contract claims. Analytics consent records are kept while consent stands and for 30 days after it is withdrawn. Where one record falls into several categories the longest applicable period governs, and anything under legal hold is kept until the hold ends.

      Depending on applicable law, people may request access, correction, erasure, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to a supervisory authority, including the Italian Garante per la protezione dei dati personali and the authority of the EU or EEA country where they live, work, or believe the issue arose. Some records must remain for accounting, legal claims, fraud prevention, or license integrity. Identity is verified proportionately before disclosure.

      Automation, children, cookies, and changes

      Deterministic rules may validate signatures, payment state, eligibility, and deployment capacity. They do not profile people for advertising. A person may request review of a disputed licensing outcome. SoAI is not directed to children, and a child must not purchase or provide account information without the lawful involvement required in the child’s country.

      Essential session and security storage supports requested website features. Optional first-party analytics is disabled until affirmative consent and can be withdrawn. Licensing machine routes do not use browser analytics. Paddle may use necessary checkout technology under the notice displayed for that checkout.

      Material privacy changes receive a new date and are communicated through this page and, where required, directly. Historical acceptance and transaction evidence remains attached to the notice and operative documents then in effect.

      Legal notice version 1.0 · effective 22 August 2026.

      Document record

      Operative documents are versioned by exact bytes. Review the version and SHA-256 fingerprint shown at checkout before accepting.

      • This page is a public notice, not an operative license.

      Use your browser’s print command for a print-ready copy.

      About SoAI

      • Bundled plugins
      • Plugin Store
      • How it works
      • SoAI Connect
      • SoAI Bench
      • GPU leaderboard
      • SoAI OS
      • Interface
      • Licensing

      Resources

      • Documentation
      • Installation guide
      • API reference
      • Plugin development
      • Quickstart
      • Install SoAI
      • Support

      Community

      • GitHub
      • Discord

      License

      • Licensing
      • Terms
      • Privacy
      • Refunds
      • Support terms
      • Legal notices

      © 2024–2024 SoAI - Smart Orchestrator for Artificial Intelligence