Pondral

Data Processing Agreement (DPA)

Effective Date: March 21, 2026 | Last Updated: June 2026 (P0 BAA disclosures)

This Data Processing Agreement ("DPA") applies to B2B customers and organizations using Pondral where personal data processing is subject to GDPR, UK GDPR, or other data protection laws. It outlines how Pondral, LLC ("Processor") handles personal data on behalf of the Controller. This DPA is provided for review and is not currently available for signature; a signable version is issued once Pondral's Sub-processor data-processing terms are finalized. Questions: hello@pondral.com.

Healthcare & financial-institution plans: For US plans that process protected health information or are subject to HIPAA, state medical-board rules, or Reg DD/UDAAP, a separate signed Business Associate Agreement (BAA) is required before any regulated data is processed. Regulated-tier onboarding (healthcare / financial institutions) is handled case by case and is not currently available for self-serve execution. Contact hello@pondral.com to discuss. The current sub-processor list is published at /sub-processors. These features are offered as pilot / early access and are not a substitute for your own compliance program or counsel. Last updated June 2026.

1. Definitions

Key Definitions:

  • Controller - The entity determining purposes and means of processing (typically your organization)
  • Processor - Pondral, LLC, processing data on your behalf
  • Data Subject - Identified individuals whose data is processed
  • Personal Data - Information relating to identified or identifiable natural persons
  • Processing - Collection, storage, retrieval, use, or deletion of personal data
  • Sub-processor - Third parties engaged to process personal data (e.g., Supabase, Stripe, Resend)

2. Scope and Purpose of Processing

Personal Data is processed solely for providing the Pondral service, a Software-as-a-Service platform for AI Visibility analysis.

Processing purposes include:

  • Account creation and management
  • Payment processing and billing
  • Delivering analysis results and reports
  • Customer support and technical assistance
  • Service improvement and optimization
  • Security and fraud prevention
  • Legal compliance and regulatory requirements

3. Categories of Personal Data

The Processor handles the following categories of personal data:

  • Account Information: Name, email, company, job title, phone, billing address, profile picture
  • Submitted Content: URLs, keywords, tags, metadata provided for analysis
  • Analysis Results: Citation metrics, scores, timestamps, trend data, reports
  • Usage Data: IP address, geolocation, browser type, pages viewed, time spent, interactions
  • Communications: Email content, support messages, chat history
  • Technical Data: Cookies, session tokens, authentication data, analytics events

4. Categories of Data Subjects

Personal data relates to:

  • End users and employees of the Controller
  • Account administrators
  • Support contacts
  • Organizations themselves (company name, billing address)

5. Obligations of the Processor

The Processor commits to:

  • Process data only on documented instructions from the Controller
  • Ensure confidentiality of all personnel accessing data
  • Implement data protection by design and by default
  • Maintain comprehensive security measures (detailed below)
  • Assist with Data Subject rights requests
  • Assist with legal compliance and regulatory obligations
  • Notify of data breaches without undue delay and within 72 hours of confirmation
  • Not process data beyond the Controller's authorization

California (CCPA/CPRA): Where Pondral processes personal information of California residents, Pondral acts as a Service Provider under Cal. Civ. Code §1798.140(ag). Pondral will not sell or share such personal information; will not retain, use, or disclose it for any purpose other than the business purposes specified in this DPA and the Service Agreement or as otherwise permitted by the CCPA; will not retain, use, or disclose it outside the direct business relationship; and will not combine it with personal information from other sources except as permitted by the CCPA.

6. Security Measures Implemented

Technical Security:

  • HTTPS/TLS 1.2+ encryption in transit
  • AES-256-GCM encryption at rest for sensitive data
  • Role-based access controls and least privilege principles
  • Supabase-managed authentication with optional multi-factor authentication (MFA) via authenticator app
  • Network-layer protections (DDoS mitigation, TLS termination) provided by our infrastructure hosts (Vercel, Supabase)
  • Row-level database security and parameterized queries
  • Dependency and vulnerability monitoring
  • Application and infrastructure access logging (via Vercel and Supabase)

Administrative Security:

  • Confidentiality obligations for any party with access to Personal Data
  • Incident response and breach notification procedures
  • Secure credential management
  • Device security practices

7. Sub-processors

The Processor uses the following Sub-processors:

Sub-processorFunctionLocation
SupabaseDatabase hosting and authenticationUnited States (hosted on AWS us-east-1)
VercelApplication hosting and CDNUnited States (global CDN)
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
PostHogProduct analyticsUnited States
SentryError tracking and performance monitoringUnited States
Anthropic (Claude)AI visibility analysis engineUnited States
OpenAI (ChatGPT)AI visibility analysis engineUnited States
Google (Gemini)AI visibility analysis engineUnited States
PerplexityAI visibility analysis engineUnited States
xAI (Grok)AI visibility analysis engineUnited States

The Processor provides 30 days' notice before engaging new Sub-processors and allows the Controller to object on reasonable grounds.

8. International Data Transfers

Data Location: Personal data is primarily processed in the United States.

Transfer Safeguards:

  • Standard Contractual Clauses (Module Two), governing Controller-to-Processor transfers, incorporated at Appendix A of this DPA
  • Equivalent data-processing terms with each Sub-processor are being finalized; until they are in place, this DPA is not available for signature (see the status note above)
  • Supplementary technical measures (encryption, access controls)
  • Data minimization practices
  • Periodic internal security reviews

The Controller acknowledges that data protection laws may differ in the United States.

9. Data Subject Rights

The Processor assists the Controller with:

  • Right of Access: Providing personal data in machine-readable format within 10 business days
  • Right to Rectification: Correcting inaccurate data
  • Right to Erasure: Deleting data within 30 days (unless legally required to retain)
  • Right to Restrict Processing: Limiting processing to storage only
  • Right to Data Portability: Providing data in structured format for transfer to another controller
  • Right to Object: Responding to objections including for direct marketing
  • Rights Related to Automated Decision-Making: Notifying of any such processing

10. Data Breach Notification

The Processor shall notify the Controller of any confirmed or suspected data breach:

  • Timing: Without undue delay, and in any case within 72 hours of confirmation
  • Method: Email to the account email and hello@pondral.com
  • Content: Nature, scope, categories and number of affected data subjects, likely consequences, remediation measures
  • Cooperation: Full cooperation with Controller's investigation and notifications to authorities

11. Audit Rights

The Controller may:

  • Request a security review (max once per year under normal circumstances) with 30 days' notice
  • Request documentation of security measures
  • Receive available security documentation, including internal security-review summaries, in lieu of on-site inspection

The Processor shall cooperate with:

  • Supervisory authority audits and investigations
  • Regulatory requests (with notice to Controller where legally permitted)
  • Controllers' compliance with their own legal obligations

12. Return and Deletion of Data

Upon termination, the Controller may elect to:

  • Delete: All personal data deleted within 30 days
  • Return: Data provided in CSV, JSON, or similar format within 30 days
  • Anonymize: Data anonymized so it cannot be attributed to individuals

Backup data will be deleted or anonymized within 90 days (180 days for archived backups). The Processor will provide a written certification of deletion or anonymization within 45 days.

Data may be retained only if required by law, under legal hold, or for legitimate business continuity purposes.

13. Duration and Termination

This DPA remains in effect during the Service Agreement and terminates upon:

  • Automatic termination with the Service Agreement
  • Written notice if either party materially breaches (with 30-day cure period)
  • Required by law to cease processing

Confidentiality obligations and breach notification procedures survive termination indefinitely.

14. Liability

The Processor is liable for damages caused by breach of this DPA or data protection laws, subject to limitations in the Service Agreement.

Limitations:

  • No liability for indirect, incidental, or consequential damages
  • Total liability capped at fees paid in preceding 12 months
  • No liability for breaches caused by Controller's failure to follow security instructions
  • No liability for breaches caused by force majeure beyond Processor's control

15. Governing Law

This DPA is governed by Florida law. However, data protection substantive law shall be governed by the jurisdiction where the Data Subject is located (typically GDPR for EU/EEA residents).

16. Contact Information

For DPA and data protection inquiries:

Email: hello@pondral.com (Subject: "DPA Inquiry" or "Data Protection Request")

For technical support:

Email: hello@pondral.com

Mailing Address:
Pondral, LLC
Florida, USA

17. Appendices

Appendix A: Standard Contractual Clauses

The parties incorporate by reference the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), for EU/EEA to non-adequate jurisdiction transfers, together with the UK International Data Transfer Addendum and the Swiss FADP supplement where applicable.

Appendix B: Sub-processor List

A current list of Sub-processors is available at pondral.com/sub-processors and is updated as Sub-processors change.

This Data Processing Agreement is effective as of March 21, 2026.

By using Pondral, B2B customers and organizations subject to GDPR or other data protection laws requiring a DPA agree to these terms. Individual consumers are governed by the Privacy Policy and Terms of Service.