Pondral

Data Processing Agreement (DPA)

Effective Date: March 21, 2026 | Last Updated: July 24, 2026

This Data Processing Agreement ("DPA") applies to B2B customers and organizations using Pondral where personal data processing is subject to GDPR, UK GDPR, or other data protection laws. It outlines how Pondral, LLC ("Processor") handles personal data on behalf of the Controller. This DPA forms part of, and is incorporated by reference into, the Pondral Terms of Service; by accepting the Terms, a Controller whose processing is subject to GDPR, UK GDPR, or comparable law is bound by this DPA. A countersigned copy is available on request: privacy@pondral.com.

Healthcare & financial-institution plans: Pondral does not offer plans for processing protected health information, and does not offer plans for financial institutions subject to Reg DD/UDAAP or NCUA marketing rules — not as a pilot, not as early access, and not case by case. No Business Associate Agreement is available for signature, and no regulated data should be sent to the platform. This DPA does not cover PHI. The current sub-processor list is published at /sub-processors. Nothing here is a substitute for your own compliance program or counsel.

1. Definitions

Key Definitions:

  • Controller - The entity determining purposes and means of processing (typically your organization)
  • Processor - Pondral, LLC, processing data on your behalf
  • Data Subject - Identified individuals whose data is processed
  • Personal Data - Information relating to identified or identifiable natural persons
  • Processing - Collection, storage, retrieval, use, or deletion of personal data
  • Sub-processor - Third parties engaged to process personal data (e.g., Supabase, Stripe, Resend)

2. Scope and Purpose of Processing

Personal Data is processed solely for providing the Pondral service, a Software-as-a-Service platform for AI Visibility analysis.

Processing purposes include:

  • Account creation and management
  • Payment processing and billing
  • Delivering analysis results and reports
  • Customer support and technical assistance
  • Service improvement and optimization
  • Security and fraud prevention
  • Legal compliance and regulatory requirements

3. Categories of Personal Data

The Processor handles the following categories of personal data:

  • Account Information: Name, email, company, job title, phone, billing address, profile picture
  • Submitted Content: URLs, keywords, tags, metadata provided for analysis
  • Analysis Results: Citation metrics, scores, timestamps, trend data, reports
  • Usage Data: IP address, geolocation, browser type, pages viewed, time spent, interactions
  • Communications: Email content, support messages, chat history
  • Technical Data: Cookies, session tokens, authentication data, analytics events

4. Categories of Data Subjects

Personal data relates to:

  • End users and employees of the Controller
  • Account administrators
  • Support contacts
  • Organizations themselves (company name, billing address)

5. Obligations of the Processor

The Processor commits to:

  • Process data only on documented instructions from the Controller
  • Ensure confidentiality of all personnel accessing data
  • Implement data protection by design and by default
  • Maintain comprehensive security measures (detailed below)
  • Assist with Data Subject rights requests
  • Assist with legal compliance and regulatory obligations
  • Notify of data breaches without undue delay and within 72 hours of confirmation
  • Not process data beyond the Controller's authorization

California (CCPA/CPRA): Where Pondral processes personal information of California residents, Pondral acts as a Service Provider under Cal. Civ. Code §1798.140(ag). Pondral will not sell or share such personal information; will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Service Agreement or as otherwise permitted by the CCPA; will not retain, use, or disclose it outside the direct business relationship; and will not combine it with personal information from other sources except as permitted by the CCPA.

6. Security Measures Implemented

Technical Security:

  • HTTPS/TLS 1.2+ encryption in transit
  • AES-256-GCM encryption at rest for sensitive data
  • Role-based access controls and least privilege principles
  • Supabase-managed authentication with optional multi-factor authentication (MFA) via authenticator app
  • Network-layer protections (DDoS mitigation, TLS termination) provided by our infrastructure hosts (Vercel, Supabase)
  • Row-level database security and parameterized queries
  • Dependency and vulnerability monitoring
  • Application and infrastructure access logging (via Vercel and Supabase)

Administrative Security:

  • Confidentiality obligations for any party with access to Personal Data
  • Incident response and breach notification procedures
  • Secure credential management
  • Device security practices

7. Sub-processors

The Processor uses the following Sub-processors:

Sub-processorFunctionLocation
SupabaseDatabase hosting and authenticationUnited States (hosted on AWS us-east-1)
VercelApplication hosting and CDNUnited States (global CDN)
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
PostHogProduct analyticsUnited States
SentryError tracking and performance monitoringUnited States
Anthropic (Claude)AI visibility analysis engineUnited States
OpenAI (ChatGPT)AI visibility analysis engineUnited States
Google (Gemini)AI visibility analysis engineUnited States
PerplexityAI visibility analysis engineUnited States
xAI (Grok)AI visibility analysis engineUnited States

The Processor provides 30 days' notice before engaging new Sub-processors and allows the Controller to object on reasonable grounds.

Each Sub-processor is engaged under a written contract that imposes data-protection obligations substantially the same as, and no less protective than, those set out in this DPA, including the requirement to implement appropriate technical and organisational measures under Article 32 GDPR. Where a Sub-processor fails to fulfil those obligations, the Processor remains fully liable to the Controller for that Sub-processor's performance.

8. International Data Transfers

Data Location: Personal data is processed in the United States (AWS us-east-1) through the Processor's managed infrastructure providers, Supabase and Vercel. EU data residency is not available, and there is no dated plan to offer it.

Transfer Safeguards:

  • Standard Contractual Clauses (Module Two), governing Controller-to-Processor transfers, incorporated at Appendix A of this DPA
  • Each Sub-processor is engaged under a written data-processing agreement that incorporates the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914) where the engagement involves transfers from the EU/EEA, and imposes data-protection obligations equivalent to those in this DPA
  • Supplementary technical measures (encryption, access controls)
  • Data minimization practices
  • Periodic internal security reviews

The Controller acknowledges that data protection laws may differ in the United States.

9. Data Subject Rights

The Processor assists the Controller with:

  • Right of Access: Providing personal data in machine-readable format within 10 business days
  • Right to Rectification: Correcting inaccurate data
  • Right to Erasure: Deleting data within 30 days (unless legally required to retain)
  • Right to Restrict Processing: Limiting processing to storage only
  • Right to Data Portability: Providing data in structured format for transfer to another controller
  • Right to Object: Responding to objections including for direct marketing
  • Rights Related to Automated Decision-Making: Notifying of any such processing

10. Data Breach Notification

The Processor shall notify the Controller of any confirmed or suspected data breach:

  • Timing: Without undue delay, and in any case within 72 hours of confirmation
  • Method: Email to the account email and privacy@pondral.com
  • Content: Nature, scope, categories and number of affected data subjects, likely consequences, remediation measures
  • Cooperation: Full cooperation with Controller's investigation and notifications to authorities

11. Audit Rights

The Controller may:

  • Request a security review (max once per year under normal circumstances) with 30 days' notice
  • Request documentation of security measures
  • Receive available security documentation, including internal security-review summaries, in lieu of on-site inspection

The Processor shall cooperate with:

  • Supervisory authority audits and investigations
  • Regulatory requests (with notice to Controller where legally permitted)
  • Controllers' compliance with their own legal obligations

12. Return and Deletion of Data

Upon termination, the Controller may elect to:

  • Delete: All personal data deleted within 30 days
  • Return: Data provided in CSV, JSON, or similar format within 30 days
  • Anonymize: Data anonymized so it cannot be attributed to individuals

Backup data will be deleted or anonymized within 90 days (180 days for archived backups). The Processor will provide a written certification of deletion or anonymization within 45 days.

Data may be retained only if required by law, under legal hold, or for legitimate business continuity purposes.

13. Duration and Termination

This DPA remains in effect during the Service Agreement and terminates upon:

  • Automatic termination with the Service Agreement
  • Written notice if either party materially breaches (with 30-day cure period)
  • Required by law to cease processing

Confidentiality obligations and breach notification procedures survive termination indefinitely.

14. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to, and counts toward, the exclusions and the aggregate limitation of liability set out in the Service Agreement (Terms of Service). This DPA does not create any separate or additional cap on, or expand, either party's liability beyond what the Service Agreement provides.

Nothing in this DPA limits liability that cannot be limited under applicable data-protection law. Where required by Article 82 GDPR (or UK GDPR), each party remains liable to data subjects as provided by law; as between the parties, liability is allocated per this Section and the Service Agreement.

15. Governing Law

This DPA is governed by Florida law. However, data protection substantive law shall be governed by the jurisdiction where the Data Subject is located (typically GDPR for EU/EEA residents).

16. Contact Information

For DPA and data protection inquiries:

Email: privacy@pondral.com (Subject: "DPA Inquiry" or "Data Protection Request")

For technical support:

Email: hello@pondral.com

Mailing Address:
Pondral, LLC
Florida, USA

17. Appendices

Appendix A: Standard Contractual Clauses

The parties incorporate by reference the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), for EU/EEA to non-adequate jurisdiction transfers, together with the UK International Data Transfer Addendum and the Swiss FADP supplement where applicable.

Appendix B: Sub-processor List

A current list of Sub-processors is available at pondral.com/sub-processors and is updated as Sub-processors change.

This Data Processing Agreement is effective as of March 21, 2026.

By using Pondral, B2B customers and organizations subject to GDPR or other data protection laws requiring a DPA agree to these terms. Individual consumers are governed by the Privacy Policy and Terms of Service.