← Back to Pondral
Compliance
Built for regulated teams.
Compliance docs, data-processing details, and DPAs for teams running a procurement review.
Frameworks
- GDPR: DPA incorporating EU/UK Standard Contractual Clauses, published for review at /dpa
- CCPA / CPRA: opt-out workflows in your workspace
- Data residency: United States (us-east-1)
Data residency
Pondral processes data in the United States (AWS us-east-1) through our managed infrastructure providers, Supabase and Vercel. EU data residency is not available. There is no dated plan to offer it, so if it is a requirement for your procurement review, Pondral is not a fit today rather than something to wait for. Saying so here is cheaper for you than finding out at signature.
Documents
- Data Processing Addendum (DPA)
- Subprocessor list
- Trust report
- Security assessment status — a third-party penetration test has not yet been conducted. An internal security-audit summary is available on request.
For full vendor-review packages or procurement questions, email privacy@pondral.com.
Last updated August 2026Run a free audit →