Data Processing Agreement (DPA)
Effective Date: March 21, 2026 | Last Updated: June 2026 (P0 BAA disclosures)
This Data Processing Agreement ("DPA") applies to B2B customers and organizations using Pondral where personal data processing is subject to GDPR, UK GDPR, or other data protection laws. It outlines how Pondral, LLC ("Processor") handles personal data on behalf of the Controller. This DPA is provided for review and is not currently available for signature; a signable version is issued once Pondral's Sub-processor data-processing terms are finalized. Questions: hello@pondral.com.
Healthcare & financial-institution plans: For US plans that process protected health information or are subject to HIPAA, state medical-board rules, or Reg DD/UDAAP, a separate signed Business Associate Agreement (BAA) is required before any regulated data is processed. Regulated-tier onboarding (healthcare / financial institutions) is handled case by case and is not currently available for self-serve execution. Contact hello@pondral.com to discuss. The current sub-processor list is published at /sub-processors. These features are offered as pilot / early access and are not a substitute for your own compliance program or counsel. Last updated June 2026.
1. Definitions
Key Definitions:
- Controller - The entity determining purposes and means of processing (typically your organization)
- Processor - Pondral, LLC, processing data on your behalf
- Data Subject - Identified individuals whose data is processed
- Personal Data - Information relating to identified or identifiable natural persons
- Processing - Collection, storage, retrieval, use, or deletion of personal data
- Sub-processor - Third parties engaged to process personal data (e.g., Supabase, Stripe, Resend)
2. Scope and Purpose of Processing
Personal Data is processed solely for providing the Pondral service, a Software-as-a-Service platform for AI Visibility analysis.
Processing purposes include:
- Account creation and management
- Payment processing and billing
- Delivering analysis results and reports
- Customer support and technical assistance
- Service improvement and optimization
- Security and fraud prevention
- Legal compliance and regulatory requirements
3. Categories of Personal Data
The Processor handles the following categories of personal data:
- Account Information: Name, email, company, job title, phone, billing address, profile picture
- Submitted Content: URLs, keywords, tags, metadata provided for analysis
- Analysis Results: Citation metrics, scores, timestamps, trend data, reports
- Usage Data: IP address, geolocation, browser type, pages viewed, time spent, interactions
- Communications: Email content, support messages, chat history
- Technical Data: Cookies, session tokens, authentication data, analytics events
4. Categories of Data Subjects
Personal data relates to:
- End users and employees of the Controller
- Account administrators
- Support contacts
- Organizations themselves (company name, billing address)
5. Obligations of the Processor
The Processor commits to:
- Process data only on documented instructions from the Controller
- Ensure confidentiality of all personnel accessing data
- Implement data protection by design and by default
- Maintain comprehensive security measures (detailed below)
- Assist with Data Subject rights requests
- Assist with legal compliance and regulatory obligations
- Notify of data breaches without undue delay and within 72 hours of confirmation
- Not process data beyond the Controller's authorization
California (CCPA/CPRA): Where Pondral processes personal information of California residents, Pondral acts as a Service Provider under Cal. Civ. Code §1798.140(ag). Pondral will not sell or share such personal information; will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Service Agreement or as otherwise permitted by the CCPA; will not retain, use, or disclose it outside the direct business relationship; and will not combine it with personal information from other sources except as permitted by the CCPA.
6. Security Measures Implemented
Technical Security:
- HTTPS/TLS 1.2+ encryption in transit
- AES-256-GCM encryption at rest for sensitive data
- Role-based access controls and least privilege principles
- Supabase-managed authentication with optional multi-factor authentication (MFA) via authenticator app
- Network-layer protections (DDoS mitigation, TLS termination) provided by our infrastructure hosts (Vercel, Supabase)
- Row-level database security and parameterized queries
- Dependency and vulnerability monitoring
- Application and infrastructure access logging (via Vercel and Supabase)
Administrative Security:
- Confidentiality obligations for any party with access to Personal Data
- Incident response and breach notification procedures
- Secure credential management
- Device security practices
7. Sub-processors
The Processor uses the following Sub-processors:
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database hosting and authentication | United States (hosted on AWS us-east-1) |
| Vercel | Application hosting and CDN | United States (global CDN) |
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| PostHog | Product analytics | United States |
| Sentry | Error tracking and performance monitoring | United States |
| Anthropic (Claude) | AI visibility analysis engine | United States |
| OpenAI (ChatGPT) | AI visibility analysis engine | United States |
| Google (Gemini) | AI visibility analysis engine | United States |
| Perplexity | AI visibility analysis engine | United States |
| xAI (Grok) | AI visibility analysis engine | United States |
The Processor provides 30 days' notice before engaging new Sub-processors and allows the Controller to object on reasonable grounds.
8. International Data Transfers
Data Location: Personal data is primarily processed in the United States.
Transfer Safeguards:
- Standard Contractual Clauses (Module Two), governing Controller-to-Processor transfers, incorporated at Appendix A of this DPA
- Equivalent data-processing terms with each Sub-processor are being finalized; until they are in place, this DPA is not available for signature (see the status note above)
- Supplementary technical measures (encryption, access controls)
- Data minimization practices
- Periodic internal security reviews
The Controller acknowledges that data protection laws may differ in the United States.
9. Data Subject Rights
The Processor assists the Controller with:
- Right of Access: Providing personal data in machine-readable format within 10 business days
- Right to Rectification: Correcting inaccurate data
- Right to Erasure: Deleting data within 30 days (unless legally required to retain)
- Right to Restrict Processing: Limiting processing to storage only
- Right to Data Portability: Providing data in structured format for transfer to another controller
- Right to Object: Responding to objections including for direct marketing
- Rights Related to Automated Decision-Making: Notifying of any such processing
10. Data Breach Notification
The Processor shall notify the Controller of any confirmed or suspected data breach:
- Timing: Without undue delay, and in any case within 72 hours of confirmation
- Method: Email to the account email and hello@pondral.com
- Content: Nature, scope, categories and number of affected data subjects, likely consequences, remediation measures
- Cooperation: Full cooperation with Controller's investigation and notifications to authorities
11. Audit Rights
The Controller may:
- Request a security review (max once per year under normal circumstances) with 30 days' notice
- Request documentation of security measures
- Receive available security documentation, including internal security-review summaries, in lieu of on-site inspection
The Processor shall cooperate with:
- Supervisory authority audits and investigations
- Regulatory requests (with notice to Controller where legally permitted)
- Controllers' compliance with their own legal obligations
12. Return and Deletion of Data
Upon termination, the Controller may elect to:
- Delete: All personal data deleted within 30 days
- Return: Data provided in CSV, JSON, or similar format within 30 days
- Anonymize: Data anonymized so it cannot be attributed to individuals
Backup data will be deleted or anonymized within 90 days (180 days for archived backups). The Processor will provide a written certification of deletion or anonymization within 45 days.
Data may be retained only if required by law, under legal hold, or for legitimate business continuity purposes.
13. Duration and Termination
This DPA remains in effect during the Service Agreement and terminates upon:
- Automatic termination with the Service Agreement
- Written notice if either party materially breaches (with 30-day cure period)
- Required by law to cease processing
Confidentiality obligations and breach notification procedures survive termination indefinitely.
14. Liability
The Processor is liable for damages caused by breach of this DPA or data protection laws, subject to limitations in the Service Agreement.
Limitations:
- No liability for indirect, incidental, or consequential damages
- Total liability capped at fees paid in preceding 12 months
- No liability for breaches caused by Controller's failure to follow security instructions
- No liability for breaches caused by force majeure beyond Processor's control
15. Governing Law
This DPA is governed by Florida law. However, data protection substantive law shall be governed by the jurisdiction where the Data Subject is located (typically GDPR for EU/EEA residents).
16. Contact Information
For DPA and data protection inquiries:
Email: hello@pondral.com (Subject: "DPA Inquiry" or "Data Protection Request")
For technical support:
Email: hello@pondral.com
Mailing Address:
Pondral, LLC
Florida, USA
17. Appendices
Appendix A: Standard Contractual Clauses
The parties incorporate by reference the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), for EU/EEA to non-adequate jurisdiction transfers, together with the UK International Data Transfer Addendum and the Swiss FADP supplement where applicable.
Appendix B: Sub-processor List
A current list of Sub-processors is available at pondral.com/sub-processors and is updated as Sub-processors change.
This Data Processing Agreement is effective as of March 21, 2026.
By using Pondral, B2B customers and organizations subject to GDPR or other data protection laws requiring a DPA agree to these terms. Individual consumers are governed by the Privacy Policy and Terms of Service.