Data Processing Agreement (DPA)
Effective Date: March 21, 2026 | Last Updated: July 24, 2026
This Data Processing Agreement ("DPA") applies to B2B customers and organizations using Pondral where personal data processing is subject to GDPR, UK GDPR, or other data protection laws. It outlines how Pondral, LLC ("Processor") handles personal data on behalf of the Controller. This DPA forms part of, and is incorporated by reference into, the Pondral Terms of Service; by accepting the Terms, a Controller whose processing is subject to GDPR, UK GDPR, or comparable law is bound by this DPA. A countersigned copy is available on request: privacy@pondral.com.
Healthcare & financial-institution plans: Pondral does not offer plans for processing protected health information, and does not offer plans for financial institutions subject to Reg DD/UDAAP or NCUA marketing rules — not as a pilot, not as early access, and not case by case. No Business Associate Agreement is available for signature, and no regulated data should be sent to the platform. This DPA does not cover PHI. The current sub-processor list is published at /sub-processors. Nothing here is a substitute for your own compliance program or counsel.
1. Definitions
Key Definitions:
- Controller - The entity determining purposes and means of processing (typically your organization)
- Processor - Pondral, LLC, processing data on your behalf
- Data Subject - Identified individuals whose data is processed
- Personal Data - Information relating to identified or identifiable natural persons
- Processing - Collection, storage, retrieval, use, or deletion of personal data
- Sub-processor - Third parties engaged to process personal data (e.g., Supabase, Stripe, Resend)
2. Scope and Purpose of Processing
Personal Data is processed solely for providing the Pondral service, a Software-as-a-Service platform for AI Visibility analysis.
Processing purposes include:
- Account creation and management
- Payment processing and billing
- Delivering analysis results and reports
- Customer support and technical assistance
- Service improvement and optimization
- Security and fraud prevention
- Legal compliance and regulatory requirements
3. Categories of Personal Data
The Processor handles the following categories of personal data:
- Account Information: Name, email, company, job title, phone, billing address, profile picture
- Submitted Content: URLs, keywords, tags, metadata provided for analysis
- Analysis Results: Citation metrics, scores, timestamps, trend data, reports
- Usage Data: IP address, geolocation, browser type, pages viewed, time spent, interactions
- Communications: Email content, support messages, chat history
- Technical Data: Cookies, session tokens, authentication data, analytics events
4. Categories of Data Subjects
Personal data relates to:
- End users and employees of the Controller
- Account administrators
- Support contacts
- Organizations themselves (company name, billing address)
5. Obligations of the Processor
The Processor commits to:
- Process data only on documented instructions from the Controller
- Ensure confidentiality of all personnel accessing data
- Implement data protection by design and by default
- Maintain comprehensive security measures (detailed below)
- Assist with Data Subject rights requests
- Assist with legal compliance and regulatory obligations
- Notify of data breaches without undue delay and within 72 hours of confirmation
- Not process data beyond the Controller's authorization
California (CCPA/CPRA): Where Pondral processes personal information of California residents, Pondral acts as a Service Provider under Cal. Civ. Code §1798.140(ag). Pondral will not sell or share such personal information; will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Service Agreement or as otherwise permitted by the CCPA; will not retain, use, or disclose it outside the direct business relationship; and will not combine it with personal information from other sources except as permitted by the CCPA.
6. Security Measures Implemented
Technical Security:
- HTTPS/TLS 1.2+ encryption in transit
- AES-256-GCM encryption at rest for sensitive data
- Role-based access controls and least privilege principles
- Supabase-managed authentication with optional multi-factor authentication (MFA) via authenticator app
- Network-layer protections (DDoS mitigation, TLS termination) provided by our infrastructure hosts (Vercel, Supabase)
- Row-level database security and parameterized queries
- Dependency and vulnerability monitoring
- Application and infrastructure access logging (via Vercel and Supabase)
Administrative Security:
- Confidentiality obligations for any party with access to Personal Data
- Incident response and breach notification procedures
- Secure credential management
- Device security practices
7. Sub-processors
The Processor uses the following Sub-processors:
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database hosting and authentication | United States (hosted on AWS us-east-1) |
| Vercel | Application hosting and CDN | United States (global CDN) |
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| PostHog | Product analytics | United States |
| Sentry | Error tracking and performance monitoring | United States |
| Anthropic (Claude) | AI visibility analysis engine | United States |
| OpenAI (ChatGPT) | AI visibility analysis engine | United States |
| Google (Gemini) | AI visibility analysis engine | United States |
| Perplexity | AI visibility analysis engine | United States |
| xAI (Grok) | AI visibility analysis engine | United States |
The Processor provides 30 days' notice before engaging new Sub-processors and allows the Controller to object on reasonable grounds.
Each Sub-processor is engaged under a written contract that imposes data-protection obligations substantially the same as, and no less protective than, those set out in this DPA, including the requirement to implement appropriate technical and organisational measures under Article 32 GDPR. Where a Sub-processor fails to fulfil those obligations, the Processor remains fully liable to the Controller for that Sub-processor's performance.
8. International Data Transfers
Data Location: Personal data is processed in the United States (AWS us-east-1) through the Processor's managed infrastructure providers, Supabase and Vercel. EU data residency is not available, and there is no dated plan to offer it.
Transfer Safeguards:
- Standard Contractual Clauses (Module Two), governing Controller-to-Processor transfers, incorporated at Appendix A of this DPA
- Each Sub-processor is engaged under a written data-processing agreement that incorporates the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914) where the engagement involves transfers from the EU/EEA, and imposes data-protection obligations equivalent to those in this DPA
- Supplementary technical measures (encryption, access controls)
- Data minimization practices
- Periodic internal security reviews
The Controller acknowledges that data protection laws may differ in the United States.
9. Data Subject Rights
The Processor assists the Controller with:
- Right of Access: Providing personal data in machine-readable format within 10 business days
- Right to Rectification: Correcting inaccurate data
- Right to Erasure: Deleting data within 30 days (unless legally required to retain)
- Right to Restrict Processing: Limiting processing to storage only
- Right to Data Portability: Providing data in structured format for transfer to another controller
- Right to Object: Responding to objections including for direct marketing
- Rights Related to Automated Decision-Making: Notifying of any such processing
10. Data Breach Notification
The Processor shall notify the Controller of any confirmed or suspected data breach:
- Timing: Without undue delay, and in any case within 72 hours of confirmation
- Method: Email to the account email and privacy@pondral.com
- Content: Nature, scope, categories and number of affected data subjects, likely consequences, remediation measures
- Cooperation: Full cooperation with Controller's investigation and notifications to authorities
11. Audit Rights
The Controller may:
- Request a security review (max once per year under normal circumstances) with 30 days' notice
- Request documentation of security measures
- Receive available security documentation, including internal security-review summaries, in lieu of on-site inspection
The Processor shall cooperate with:
- Supervisory authority audits and investigations
- Regulatory requests (with notice to Controller where legally permitted)
- Controllers' compliance with their own legal obligations
12. Return and Deletion of Data
Upon termination, the Controller may elect to:
- Delete: All personal data deleted within 30 days
- Return: Data provided in CSV, JSON, or similar format within 30 days
- Anonymize: Data anonymized so it cannot be attributed to individuals
Backup data will be deleted or anonymized within 90 days (180 days for archived backups). The Processor will provide a written certification of deletion or anonymization within 45 days.
Data may be retained only if required by law, under legal hold, or for legitimate business continuity purposes.
13. Duration and Termination
This DPA remains in effect during the Service Agreement and terminates upon:
- Automatic termination with the Service Agreement
- Written notice if either party materially breaches (with 30-day cure period)
- Required by law to cease processing
Confidentiality obligations and breach notification procedures survive termination indefinitely.
14. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to, and counts toward, the exclusions and the aggregate limitation of liability set out in the Service Agreement (Terms of Service). This DPA does not create any separate or additional cap on, or expand, either party's liability beyond what the Service Agreement provides.
Nothing in this DPA limits liability that cannot be limited under applicable data-protection law. Where required by Article 82 GDPR (or UK GDPR), each party remains liable to data subjects as provided by law; as between the parties, liability is allocated per this Section and the Service Agreement.
15. Governing Law
This DPA is governed by Florida law. However, data protection substantive law shall be governed by the jurisdiction where the Data Subject is located (typically GDPR for EU/EEA residents).
16. Contact Information
For DPA and data protection inquiries:
Email: privacy@pondral.com (Subject: "DPA Inquiry" or "Data Protection Request")
For technical support:
Email: hello@pondral.com
Mailing Address:
Pondral, LLC
Florida, USA
17. Appendices
Appendix A: Standard Contractual Clauses
The parties incorporate by reference the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), for EU/EEA to non-adequate jurisdiction transfers, together with the UK International Data Transfer Addendum and the Swiss FADP supplement where applicable.
Appendix B: Sub-processor List
A current list of Sub-processors is available at pondral.com/sub-processors and is updated as Sub-processors change.
This Data Processing Agreement is effective as of March 21, 2026.
By using Pondral, B2B customers and organizations subject to GDPR or other data protection laws requiring a DPA agree to these terms. Individual consumers are governed by the Privacy Policy and Terms of Service.