This Data Processing Addendum (“DPA”) sets forth the privacy practices of Pronoa, Inc. (“Pronoa”, “Company”, “we”, “us” or other similar terms) in connection with Pronoa’s Platform and Services.
This DPA supplements, is incorporated into and forms a part of your Customer Agreement. The parties hereto acknowledge and agree that the parties’ acceptance of and/or execution of the Customer Agreement constitutes their written execution of this DPA, including, without limitation, if this DPA is incorporated by reference into a Customer Agreement.
Please note that this DPA applies to all processing of Personal Information that may be included in Customer Data, whether you are an individual customer or a business customer. In addition, this DPA applies to any Personal Information of Authorized Users if Customer is a business. If Customer is an individual, then our Privacy Policy (https://pronoa.io/privacy) may apply with respect to specific account and similar Personal Information as set forth in the Privacy Policy (https://pronoa.io/privacy) instead of this DPA (but as noted above this DPA applies to all processing of Personal Information that may be included in Customer Data even if the Customer is an individual).
Capitalized terms used in this DPA have the meaning set forth herein or have the respective meanings provided in your Customer Agreement. In the event of any direct conflicts between the terms of your Customer Agreement and the terms of the DPA, the terms of this DPA shall control but solely as applicable to the processing of Personal Information as set forth herein and the Customer Agreement shall control in all other respects. This DPA shall be effective contemporaneously with the effective date of your Customer Agreement and shall terminate automatically upon the expiration or termination of your Customer Agreement (subject to any survival provisions therein or herein).
Additionally, for background purposes please note that while our Services are not designed to collect significant levels of Personal Information, Pronoa does require certain Personal Information from Authorized Users (e.g. name, email address, etc.) in order to register those Authorized Users with the Services and to facilitate their ongoing use of the Services. This DPA applies to that Authorized User Personal Information that Pronoa accesses or receives during the course of performing the Services as well as any other Personal Information that a Customer elects to process in the Services. For example, Customer may elect to upload and process Customer Data in the Services and such Customer Data will typically identify individuals involved in a decision, such as decision makers, approvers, stakeholders and counterparties, together with their titles, roles and positions on the decision. Beyond Authorized User Personal Information and such decision-related Personal Information contained in Customer Data, please note that (i) Pronoa does not require or intentionally collect any other Personal Information during the course of providing the Services and Customer is hereby requested to include in Customer Data only the Personal Information that a decision reasonably requires, and no Sensitive Personal Information, and (ii) Customer exercises sole control and discretion with respect to any other Personal Information that it elects to provide and makes available for processing by the Services.
The Parties hereby agree as follows:
1.Definitions
For purposes of this DPA, the following terms shall have the following meanings:
a. “Authorized Users” means Customer’s employees, agents and representatives authorized to access the Services pursuant to the terms of the Customer Agreement.
b. “Customer”, “you”, “your” and other similar terms means the customer that is a signatory, is party to, or has otherwise contractually entered into and accepted, a Customer Agreement for Services.
c. “Customer Agreement” or “Agreement” means the Platform Agreement, Terms of Service, or another written contract or order form mutually agreed to between Pronoa and Customer governing Pronoa’s provision of, and Customer’s access to and use of, the Platform and Services.
d. “Data Protection Laws” means (i) the General Data Protection Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and any applicable laws and/or regulations that implement and/or exercise derogations under it and/or replace or supersede it (“EU GDPR”); (ii) all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the United Kingdom including the U.K. Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003 and the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (“UK GDPR” and, together with EU GDPR, “GDPR”); (iii) the EU e‑Privacy Directive (2002/58/EC); (iv) any national data protection laws made under or pursuant to (i), (ii) or (iii); and (v) the Swiss Federal Data Protection Act (“Swiss DPA”); (vi) all U.S. state data protection laws and their implementing regulations, as amended or superseded from time to time, that apply generally to the processing of Personal Information, including, but not limited to, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (California Civil Code §§ 1798.100 to 1798.199) (“CPRA”); and (vii) each of the aforementioned as amended, superseded or updated from time to time. In the event of a conflict in the meanings of defined terms in the Data Protection Laws, the meaning from the law applicable to the location of the relevant data subject/individual/household shall apply.
e. “European Economic Area" or “EEA” means the Member States of the European Union together with Iceland, Norway, and Liechtenstein.
f. “Personal Information” means any data or information that is considered “personal data”, “personal information” or other similar terms as defined by applicable Data Protection Laws and that is provided by Customer or its Authorized Users to Pronoa or otherwise received by Pronoa in connection with the Services. Personal Information includes the information and data described in Annex I attached hereto.
g. “Sensitive Personal Information” means personal data or personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data and/or biometric data (where used for the purpose of uniquely identifying a natural person), data concerning health or data concerning a natural person's sex life or sexual orientation, and other personal data and personal information that is typically considered “sensitive” under applicable Data Protection Laws.
h. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data from controllers to processors (module two) established in third countries approved by the European Commission from time to time, as may be amended, superseded or replaced by the European Commission from time to time. For reference purposes, a current copy of the SCCs is located at: Standard contractual clauses for international transfers (europa.eu).
i. “UK Addendum” means the UK’s International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0), and as may be amended, superseded or replaced from time to time. For reference purposes, a current copy of the IDTA is located at: https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.
j. The terms “business” “controller”, “data protection impact assessment”, “data subject”, “personal data”, “personal data breach”, “processor”, “processing”, “service provider” and “supervisory authority” shall be as defined under relevant Data Protection Laws.
2.Processing of Personal Information
a. General. Pronoa shall comply with its obligations under applicable Data Protection Laws when processing Personal Information subject to such Data Protection Laws. The subject-matter of such processing is providing and making available the Platform and related Services to Customer in accordance with Customer’s Customer Agreement and such processing will continue until Customer’s Customer Agreement terminates or expires. Annex I attached hereto sets out the nature and purpose of the processing, including the types of Personal Information we process and the data subjects whose Personal Information is processed. Pronoa may update the descriptions of processing set forth on Annex I from time to time to reflect new products, features or functionality comprised within the Services consistent with the requirements of Section 19 of this DPA. For clarity, this DPA and the processes and requirements set forth shall apply if and when any of the Data Protection Laws are applicable to the specific processing of applicable Personal Information subject to such Data Protection Laws.
b. Roles of the Parties. Pronoa and Customer acknowledge that the status of each Party is a question of fact determined under applicable Data Protection Laws. Without limiting the foregoing, the Parties acknowledge and agree that Customer is the controller or business, and that Pronoa is the processor or service provider acting on Customer’s behalf,and that Pronoa may engage Subprocessors pursuant to the requirements set forth in Section 9 (Subprocessors) below. For the avoidance of doubt, the Parties acknowledge and agree that, Customer is responsible for determining the processes and means by which the Personal Information is collected and processed and for ensuring that the instructions provided to Pronoa for the processing of such Personal Information comply with Data Protection Laws. As between the Parties, Customer shall have sole responsibility for (i) the accuracy, quality, and legality of Personal Information and the means by which Customer acquired such Personal Information, and (ii) providing to Authorized Users all applicable notices and obtaining all applicable consents required for the collection and processing of their Personal Information. Without limiting the foregoing, Customer acknowledges that Pronoa does not actively filter, review, or control the content of any Customer Data (including any Personal Information contained therein) and all such Customer Data is selected and controlled solely by Customer.
c. Data Processing, Transfers and Sales. Customer hereby instructs Pronoa to retain, use, disclose and otherwise process the Personal Information for the following purposes, and Customer shall provide the Personal Information to Pronoa only for the following purposes, and Pronoa shall only retain, use, disclose or otherwise process the Personal Information for the following purposes: (i) to provide the Services to the Customer and Customer’s Authorized Users in accordance with Customer’s Customer Agreement covering those Services; (ii) as otherwise set out in Customer’s Customer Agreement and this DPA; and/or (iii) as otherwise agreed upon in writing by Customer and Pronoa, all of which Pronoa and Customer acknowledge to be instructions for the purposes of this DPA, unless a different manner of processing is required pursuant to any other applicable law to which Pronoa is subject, in which case Pronoa shall, to the extent permitted by applicable law, inform Customer of that legal requirement before processing that particular Personal Information.
d. Final Agreement. Customer’s Customer Agreement and this DPA shall be and are the Customer’s complete and final instructions to in relation to the processing of the Personal Information that is subject to the Data Protection Laws covered by this DPA. Processing outside the scope of this DPA and the Customer Agreement will require prior written agreement between Customer and Pronoa on additional instructions for such processing. If we reasonably believe any instruction Customer has provided with respect to the processing of Personal Information violates applicable Data Protection Laws, we may notify Customer.
e. Limited Use. Pronoa shall not retain, use, disclose or otherwise process Personal Information for any purpose other than for the specific purposes identified above, in the Customer Agreement or as otherwise permitted or required by applicable Data Protection Laws or otherwise pre-approved by Customer in writing. Pronoa does not “sell” or “share” (as defined by applicable Data Protection Laws) Personal Information, which means that Pronoa does not and shall not rent, disclose, transfer, make available or otherwise communicate Personal Information of Customer to any third party for monetary or other valuable consideration; provided that Pronoa does transfer or make available Personal Information to its Subprocessors in connection with the provision of Services to Customer. In other words, neither Pronoa nor any of its nor any of its employees, agents, consultants or representatives shall have any right to process any of Customer’s Personal Information for their own independent commercial benefit in any form. Pronoa shall require its employees, agents, and service providers to comply in all material respects with the obligations and restrictions applicable to Pronoa under this DPA.
f. Non-Personal Information. This DPA does not apply to any data related to Customer’s use of the Services unless it is Personal Information (e.g. this DPA does not apply to Usage Data, Service analytics, activity logs, use patterns, anonymized data, etc.). Pronoa may collect, use, retain, access, share, transfer, sell, or disclose any information that is not Personal Information consistent with the terms of the Customer Agreement.
g. Certification. Pronoa hereby acknowledges, agrees and certifies that it understands its restrictions and obligations set forth in this DPA and will comply with them.
h. Additional United States Requirements. To the limited extent that Pronoa is processing any Personal Information of Customer or its Users that is subject to the Data Protection Laws of California, the California-specific terms specified in Annex IV attached hereto shall apply in addition to the other terms of this DPA. Pronoa may update and amend Annex IV from time to time to the extent necessary to account for or reflect new state privacy laws that have come into effect, and all such updates and amendments shall automatically take effect without the necessity of Pronoa obtaining Customer’s prior approval or consent.
3.Required Consents
As the data controller or business under applicable Data Protection Laws, Customer is and shall be responsible for obtaining all necessary consents, and giving all necessary notices, to its Authorized Users or any other data subject appearing in Customer Data or Outputs, including any consents or notices required by this DPA, Customer’s applicable Customer Agreement or applicable Data Protection Law. With this in mind, Customer hereby warrants and represents that: (a) it has provided all applicable notices to, and obtained all necessary authorizations from, its Authorized Users and other applicable individuals and data subjects required for the lawful processing of their Personal Information by Pronoa in accordance with the Customer Agreement, this DPA and applicable Data Protection Law; and (b) in respect of any Personal Information collected or processed by Pronoa on behalf of Customer, it has obtained all necessary consents, authorizations and rights for the lawful processing of that Personal Information by Pronoa in accordance with the Customer Agreement, this DPA and applicable Data Protection Law. Pronoa does not review Customer’s Customer Data and Pronoa does not determine whether notice or consent is legally required for use of the Services in connection with any particular Authorized User or data subject. Pronoa does not provide legal advice regarding privacy or consent laws.
4.Assistance
Where applicable, taking into account the nature of the processing, and to the extent required under applicable Data Protection Laws, Pronoa shall provide the Customer with any information or assistance reasonably requested or required by the Customer for the purpose of complying with any of the Customer’s obligations under applicable Data Protection Laws, including: (i) using reasonable efforts to assist the Customer by implementing appropriate technical and organizational measures, insofar as this is reasonably possible, for the fulfillment of Customer’s obligation to respond to requests by Authorized Users or data subjects to exercise rights provided by applicable Data Protection Laws, including providing reasonable documentation, product functionality and/or processes to assist Customer in retrieving, deleting or restricting Personal Information; and (ii) providing reasonable assistance to the Customer with any data protection impact assessments and responding to or assisting with any requests from or consultations to any governmental, regulatory or supervisory authorities relevant to Customer, in each case solely in relation to processing of the Personal Information and taking into account the information available to Pronoa. All such assistance shall be provided by Pronoa at Pronoa’s reasonable fees, agreed with Customer in advance, unless otherwise restricted by applicable Data Protection Laws.
5.Access Requests
If Pronoa receives a request submitted by an Authorized User or data subject to exercise a right it has under any Data Protection Laws in relation to that Authorized User’s or data subject’s Personal Information, it will provide a copy of the request to Customer. Customer will be responsible for handling and communicating with the data subject in relation to such requests and, to the extent permitted by applicable law, Pronoa shall not respond to the data subject.
6.Government Requests
Pronoa shall notify Customer of any request for the disclosure of Personal Information by a governmental or regulatory body or law enforcement authority (including any data protection supervisory authority) unless otherwise prohibited by law or a legally binding order of such body or agency.
7.Audits
Provided that Customer has or does enter into a non-disclosure agreement acceptable to Pronoa, Pronoa shall (i) allow Customer and its authorized representatives who are reasonably acceptable to Pronoa (who have also signed a non-disclosure agreement acceptable to Pronoa) to access and review any Pronoa documentation, certifications or other reports or files reasonably required to ensure compliance with the terms of this DPA; or (ii) where required by Data Protection Law or the Standard Contractual Clauses or UK Addendum (and in accordance with this Section), allow Customer and its authorized representatives who are reasonably acceptable to Pronoa (who have also signed a non-disclosure agreement acceptable to Pronoa) to conduct reasonable audits (including inspections) during the term of the Customer Agreement to ensure compliance with the terms of this DPA.
Notwithstanding the foregoing, any audit must be conducted during Pronoa’s regular business hours, with reasonable advance notice to us (at least 20 business days) and subject to reasonable confidentiality procedures. The scope of any audit shall not require us to disclose to Customer or its authorized representatives, or to allow Customer or its authorized representatives to access: (1) any data or information of any other Pronoa customer; (2) any Pronoa internal accounting or financial information; (3) any Pronoa trade secret; (4) any information that, in our reasonable opinion could: (a) compromise the security of our systems or premises; or (b) cause us to breach our obligations under Data Protection Law or our security, confidentiality and or privacy obligations to any other Pronoa customer or any third party; or (5) any information that Customer or its authorized representatives seek to access for any reason other than the good faith fulfillment of Customer’s obligations under the Data Protection Laws and our compliance with the terms of this DPA.
In addition, audits shall be limited to once per year, unless (x) we have experienced a security breach within the prior twelve (12) months which has impacted Customer’s Personal Information; or (y) an audit reveals a material noncompliance. If we decline or are unable to follow your instructions regarding audits permitted under this Section (or the Standard Contractual Clauses or UK Addendum, where applicable), Customer may terminate this DPA and the Customer Agreement for convenience provided that Customer must provide written notice of such termination and a reasonable period (of at least 20 business day) to cure such issue, unless otherwise required by applicable Data Protection Laws.
8.International Transfers
a. General. Any Personal Information we collect will be primarily collected and stored in the United States of America, although processing and storage in other jurisdictions may occur from time to time as performance issues (speed, etc.) sometimes warrant. For individual data subject that are citizen of the EU, EEA, Switzerland or UK, this means that their Personal Information may be stored in a jurisdiction that offers a level of protection that may, in certain instances, be less protective of their Personal Information than the jurisdiction the impacted individual is typically resident in; provided however that Pronoa adheres to the Standard Contractual Clauses. To the extent permitted by applicable law, as the Parties agree to the clarifications, identifications and amendments to the SCCs as set forth in this Section 8. It is not the intention of either Party to contradict or restrict any of the provisions set forth in the Standard Contractual Clauses and, accordingly, in the event of any conflict or inconsistency between the provisions of the Customer Agreement (including this DPA) and the Standard Contractual Clauses, the provisions of the Standard Contractual Clauses shall prevail to the extent of such conflict to the extent required to comply with Data Protection Laws. Notwithstanding the foregoing, the Parties agree that it is their mutual intent for the clarifications to the SCCs set forth below to apply.
b. SCC Clarifications. The Parties agree on the following preferences, clarifications and mutual agreements in relation to the SCCs:
- Module Two of the SCCs will apply when Customer is the controller of the Personal Information (e.g., when Customer has a direct relationship with the Authorized Users or data subjects).
- The audits described in Clause 8.9(c) and (d) of the SCCs shall be carried out in accordance with Section 7 of this DPA.
- Pursuant to Clause 9(a) of the SCCs, Option 2 will apply, and Customer acknowledges and expressly agrees that Pronoa will appoint and engage new Subprocessors in accordance with Section 9 of this DPA (including the notice time periods specified in Section 9 of this DPA).
- In Clause 11 of the SCCs, the optional language will not apply.
- The liability described in Clause 12 of the SCCs shall in no event exceed the limitations set forth in the Customer’s Customer Agreement, and under no circumstances and under no legal theory (whether in contract, tort, negligence or otherwise) will either Party to this DPA, or their affiliates, officers, directors, employees, agents, service providers, suppliers, or licensors be liable to the other Party or any third party for any lost profits, lost sales of business, lost data (being data lost in the course of transmission via Customer’s systems or over the Internet through no fault of Pronoa), business interruption, loss of goodwill, or for any type of indirect, incidental, special, exemplary, consequential or punitive loss or damages, regardless of whether such Party has been advised of the possibility of or could have foreseen such damages. For the avoidance of doubt, this section shall not be construed as limiting the liability of either Party with respect to claims brought by data subjects or regulatory authorities.
- The Data Protection Commission of Ireland shall be the competent Supervisory Authority pursuant to Clause 13 of the SCCs.
- The certification of deletion of Personal Information that is described in Clause 16(d) of the SCCs shall be provided by Pronoa to Customer only upon Customer’s request.
- In Clause 17 of the SCCs, Option 1 will apply, and the SCCs will be governed by Irish law.
- In Clause 18(b) of the SCCs, disputes will be resolved before the courts of Ireland.
- Annex I of the SCCs is deemed completed with the information set out in Annex I to this DPA.
- Subject to Section 11 of this DPA, Annex II of the SCCs is deemed completed with the information set out in Annex II to this DPA.
- Annex III of the SCCs is deemed completed with the information set out in Annex III to this DPA.
c. UK Addendum. In the case of cross-border transfers of Customer’s Personal Information subject to UK GDPR, the parties acknowledge and agree that the UK Addendum shall govern and apply and the SCCs shall be deemed amended as specified in the UK Addendum in respect of the transfer of such Personal Information. In such event, the tables attached to the UK Addendum shall be deemed automatically populated and completed with the applicable information set forth in Annexes I, II and III attached to this DPA. Additionally, the parties’ preferences, clarifications and agreements set forth in Section 8 of this DPA shall also apply to and be used for purposes of interpreting the UK Addendum. Without limiting the foregoing, the parties acknowledge and agree that: (i) In Table 2 of the UK Addendum, the Parties select the checkbox that reads: “Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum”, and the accompanying table shall be deemed to be completed according to the parties’ preferences outlined in this DPA; (ii) In Table 4 of the UK Addendum, the Parties agree that either Party may terminate the Addendum as set out in Section 19 of the UK Addendum; (iii) Any conflict between the terms of the SCCs attached hereto and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum; and (iv) the clarifications and preferences set forth in Section 8 of this DPA shall be interpreted as also applying to the UK Addendum.
d. Swiss DPA. In the case of cross-border transfers of Customer’s Personal Information protected by Swiss law, the SCCs shall apply subject to the following amendments: (i) references to “Regulation (EU) 2016/679” will be deemed to refer to the Swiss DPA; (ii) references to specific articles of “Regulation (EU) 2016/679” will be deemed replaced with the equivalent article or section of the Swiss DPA; (iii) references to “EU,” “Union,” and “Member State” will be deemed replaced with “Switzerland”; (iv) references to the “competent supervisory authority” are replaced with the “Swiss Federal Data Protection Information Commissioner”; and (v) in Clause 18(b), disputes shall be resolved before the competent courts of Switzerland.
9.Subprocessors
Pronoa may from time to time use certain subcontractors (i.e., subprocessors) in connection with providing the Services (“Subprocessors”). See Annex III for more information regarding the specific Subprocessors we use. For the avoidance of doubt, Customer hereby approves all applicable Subprocessors identified on Annex III to the extent applicable to the Services received by Customer. We may update Annex III from time to time and will use reasonable efforts to provide you with notice of such updates. We recommend for each Customer to periodically review Annex III and any email updates we provide. By continuing to use our Services after any changes or modifications are made to Annex III (or any Subprocessor Lists linked to or referenced on Annex III), Customer is deemed to have automatically accepted the updated Annex. If Customer (acting reasonably) does not approve of any new Subprocessor being added for any reasonable or legitimate reason, they should (i) contact us at privacy@pronoa.io so we can discuss the basis for the Customer’s disapproval and possible alternative Subprocessors, or (ii) object within forty-five (45) days by terminating the Customer Agreement for convenience.
Our Subprocessors may have access to Personal Information. Please know that Pronoa carefully selects its Subprocessors including based on their security practices and availability levels and we perform due diligence on the technical and organizational security measures of all Subprocessors. We have entered into agreements with each Subprocessor which impose in all material respects the same or substantially similar obligations on the Subprocessor with regard to their processing of Personal Information as are imposed on Pronoa under this DPA and any Customer Agreements and which, as applicable, otherwise comply with the requirements of the Data Protection Laws. Pronoa is responsible for the acts and omissions of Subprocessors in relation to Pronoa’s obligations under this DPA and applicable Customer Agreements.
With respect to all Subprocessors having access to Personal Information of Authorized Users and data subjects that are in the EU, EEA, Switzerland or UK: Customer acknowledges that in order for Pronoa to provide the Services it may be necessary for certain Subprocessors to access or otherwise process the Personal Information outside the EEA, Switzerland or United Kingdom. In those circumstances, Pronoa will only use Subprocessors that have and maintain certification under the EU-U.S. Data Privacy Framework (including, as applicable, its UK Extension and the Swiss-U.S. Data Privacy Framework, or any successor framework) or that comply with the Standard Contractual Clauses (as updated from time to time), UK Addendum or other applicable requirements of the Data Protection Laws.
10.Data Retention and Deletion
Except as otherwise required by Data Protection Laws, Pronoa will retain Personal Information for as long as needed to provide the Services, maintain Customer’s account, comply with legal obligations, resolve disputes, and enforce agreements. If Customer wishes to delete any Personal Information processed by the Services, the Customer should send a deletion request to privacy@pronoa.io. Pronoa will strive to respond to all such requests as soon as reasonably practical. If Customer ceases to subscribe to and use the Services and the Customer Agreement is terminated or expires, or Customer permanently discontinues or terminates a Customer’s access to the Services, Pronoa will handle all of that Customer’s Personal Information as follows:
i. Subject to subsections (ii) and (iii) below, Pronoa shall, to the greatest extent reasonably possible, within sixty (60) days of the date of termination of the Customer Agreement: (1) upon the written request of Customer, return a copy of all Personal Information by secure file transfer in such reasonable format as notified by Customer to Pronoa; and (2) delete and use reasonable efforts to procure the deletion of all other copies of Personal Information processed by Pronoa or any Subprocessors.
ii. Subject to subsection (iii) below, Customer may in its absolute discretion notify Pronoa in writing within thirty (30) days of the date of termination of the Customer Agreement to require Pronoa to delete and procure the deletion of all copies of the Personal Information processed by Pronoa. In such case, Pronoa shall, to the greatest extent reasonably possible, within sixty (60) days of the date of termination of the Customer Agreement: (1) comply with any such written request; and (2) use reasonable efforts to procure that its Subprocessors delete all Personal Information processed by such Subprocessors.
iii. Notwithstanding the foregoing, Customer acknowledges that it may be impossible to completely delete certain residual Personal Information, including residual copies persisting in encrypted backups and replicas until expired in the ordinary course. Additionally, Pronoa and Subprocessors may retain Personal Information (including technical, transactional, and payment or tax records, or security and operational logs) to the extent required by and only to the extent and for such period as required by applicable laws and always provided that Pronoa shall ensure the confidentiality of all such Personal Information and shall ensure that such Personal Information is only processed as necessary for the purpose(s) specified in the applicable laws requiring its storage and for no other purpose. For example, we may retain tax records or legal compliance logs to meet mandatory holding periods. To the extent permitted by applicable Data Protection Laws, Pronoa may de-identify/anonymize or aggregate the Personal Information and may continue to collect, use, retain, access, share, transfer, sell or disclose such de-identified/anonymized or aggregated information following the termination of the Customer Agreement consistent with the terms and conditions of applicable Data Protection Laws.
11.Data Security Measures
Pronoa shall utilize industry standard practices on information security management to safeguard Personal Information, including the measures set out in Annex II attached hereto. Our information security systems apply to people, processes and information technology systems on a risk management basis. Without limiting the foregoing, Pronoa shall ensure that any employees or other personnel have agreed in writing to protect the confidentiality and security of such Personal Information. Upon request by the Customer, but no more frequently than once per calendar year (or more frequently if circumstances reasonably require) and only upon ten business days prior written notice, Pronoa shall make available information reasonably necessary to demonstrate compliance with this DPA. Customer has assessed the security measures offered by Pronoa to meet the standards required by applicable Data Protection Laws as at the effective date hereof.
If Pronoa becomes aware of a security incident involving a Customer’s Personal Information, Pronoa will (a) notify Customer of the security incident within 72 hours, (b) investigate the security incident and provide such reasonable assistance to the Customer (and any law enforcement or regulatory official) as required to investigate the security incident, and (c) take steps to remedy any non-compliance with this DPA. Notwithstanding the foregoing, because no method of transmission over the Internet, or method of electronic storage, is 100% secure, Pronoa cannot guarantee that unauthorized parties will not gain access to Personal Information processed by the Services. To the extent permitted by applicable law, Pronoa expressly excludes any liability arising from any unauthorized access to Personal Information. For the avoidance of doubt, Customer hereby acknowledges and agrees that the measures set forth in Annex II are reasonable technical and physical security practices and procedures for purposes of applicable Data Protection Laws and are compliant with applicable Data Protection Laws
12.Affiliates
Depending on the terms of your Customer Agreement, we may in certain circumstances collect, receive or otherwise process Personal Information in connection with use of the Services by Customer’s affiliates. In such cases, Customer will act as a single point of contact for its affiliates with respect to compliance with applicable Data Protection Laws, such that if Pronoa gives notice to Customer, such information or notice will be deemed received by Customer’s affiliates. Customer shall be responsible for such affiliates’ compliance with this DPA and all acts and/or omissions by a Customer affiliate with respect to Customer’s obligations in this DPA shall be considered the acts and/or omissions of Customer. The Parties acknowledge and agree that any claims in connection with this DPA (or applicable Data Protection Laws) will be brought by Customer, whether acting for itself or on behalf of an affiliate.
13.Customer Agreements
Customer agrees that it: (i) will comply with its obligations under all applicable Data Protection Laws and related laws with respect to its provision of, processing, security and handling of Personal Information, and will not do or omit to do anything which causes Pronoa (or any Subprocessor) to breach any of its obligations under applicable Data Protection Laws; (ii) will determine the purposes and general means of Pronoa’s processing of Personal Information in accordance with the Customer Agreement; (iii) will make appropriate use of the Services to ensure a level of security appropriate to the particular content of the Customer Personal Information, such as pseudonymizing or backing-up Customer Personal Information; (iv) has obtained all consents, permissions and rights necessary under applicable Data Protection Laws and related laws for Pronoa to lawfully process Customer’s Personal Information for the purposes contemplated hereby, including, without limitation, all consents and approvals of the Authorized Users and data subjects required for the processing their Personal Information in connection with the Services, and (v) unless the Parties have agreed otherwise in writing (via an amendment to Customer’s Customer Agreement, an order or statement of work thereunder, or otherwise), Customer shall only provide, deliver or otherwise make available to Pronoa Personal Information to the extent required for the Customer and the Users to access and use the Services consistent with their intended purpose and shall not provide, deliver or otherwise make available to Pronoa any other Personal Information for any other purpose. Customer shall have sole responsibility for the accuracy, quality, and legality of all Customer Personal Information and the means by which Customer acquired the Personal Information. Customer specifically acknowledges that its use of the Services will not violate the rights of any data subject that has opted-out from sales or other disclosures of Personal Information, to the extent applicable under Data Protection Laws.
14.Limitation of Liability
Subject to the terms of the Standard Contractual Clauses and Section 8 of this DPA, Pronoa’s aggregate liability to a Customer arising from or related to this DPA is subject to the applicable terms and conditions of the Customer’s applicable Customer Agreement.
15.Indemnity
Customer agrees to indemnify Pronoa and its officers, directors, employees, agents, affiliates, successors and permitted assigns (each an "Indemnified Party", and collectively the "Indemnified Parties") against any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs, or expenses of whatever kind, including legal fees and court fees, that are incurred by the Indemnified Parties related to or arising out of (i) any instructions given by the Customer to Pronoa with respect to processing of Personal Information, (ii) any failure by Customer to obtain the consents or provide the notices required under Section 3, (iii) any other breach or violation by the Customer of any of its obligations under this DPA or any breach or violation of any Data Protection Laws, or (iv) any claims by, or disputes with, Authorized Users (or any other data subjects or individuals appearing in Customer Data or Outputs) related to Pronoa’s obligations under this DPA or the Customer Agreement.
16.Sensitive Personal Information
We do not intentionally collect Sensitive Personal Information and we hereby request for Customer not (and Customer hereby agrees not to) to share or permit any Auhtorized User or third party to share any Sensitive Personal Information with us. If Customer chooses to provide us with Sensitive Personal Information, or if we receive Sensitive Personal Information on behalf of Customer, Customer is responsible for complying with any regulatory controls and requirements of applicable Data Protection Laws regarding that Sensitive Personal Information, including obtaining all necessary Authorized User or data subject consents and directing us as necessary to comply with Data Protection Laws as necessary or required by such law. In such event, Customer hereby instructs Pronoa to access and use such Sensitive Personal Information as necessary to perform the Services, and Customer hereby consents to and approves of Pronoa’s processing of such Sensitive Personal Information in accordance with this DPA. Customer hereby acknowledges and agrees that the protections, restrictions and security and organizational measures set forth in this DPA are reasonable and appropriate for purposes of processing the Sensitive Personal Information.
17.Enforceability of this Addendum
Any provision of this DPA that is prohibited or unenforceable shall be ineffective to the extent of such prohibition or unenforceability without invalidating the remaining provisions hereof. The Parties will attempt to agree upon a valid and enforceable provision that is a reasonable substitute and shall then incorporate such substitute provision into the Customer Agreement.
18.Integrations
The Services may enable Customer to access, or include integrations with, third party services, applications, stores, platforms, products or technologies (“Third Party Products”). If Customer elects to enable, access or use any such Third Party Products, its access and use of such Third Party Products is governed solely by the terms and conditions and privacy policies of such Third Party Products, and Pronoa does not endorse, is not responsible or liable for, and makes no representations as to any aspect of such Third Party Products, including, without limitation, their content or the manner in which they handle personal information or personal data or any interaction between Customer and the provider of such Third Party Products. Without limiting the foregoing, please know that all Personal Information shared with or submitted to the Third Party Products by or on behalf of Customer will be entirely outside of Pronoa’s control and will not be subject to this DPA or any of Pronoa’s privacy policies. Pronoa is not liable for any damage or loss caused or alleged to be caused by or in connection with Customer’s enablement, access or use of any such Third Party Products, or Customer’s reliance on the privacy practices, data security processes or other policies of such Third Party Products. The service providers of Third Party Products shall not be deemed or treated as Subprocessors for any purpose under this DPA unless otherwise expressly identified as Subprocessors on Annex III (or any Subprocessor lists linked to on Annex III).
19.Amendment
Pronoa may from time to time update this DPA (including the Annexes attached hereto) to account for new technologies, industry practices, processing activities, regulatory and legal requirements or for any other purposes. Notice of changes or amendments may be by email to Customer at the last email address provided by Customer, by posting notice of such changes on the Pronoa website and Platform, or by other means, consistent with applicable law. The Customer’s continued use of the Services after (i) receipt of any email notice and/or (ii) the amended DPA is posted to Pronoa website (or notice is otherwise provided, or consent is otherwise obtained, to the extent required in the last sentence of this Section), shall and hereby does constitute the Customer’s agreement to, and acceptance of, the amended DPA. If and where required by applicable law or Customer’s applicable Customer Agreement, Pronoa will also obtain Customer’s consent to the update
Annex IDescription of Processing Activities / Transfer
A. List of Parties
| Data Importer | Data Exporter/Customer | |
|---|---|---|
| Name: | Pronoa, Inc. | As provided in Customer’s Customer Agreement |
| Address / Email Address: | 1500 N Grant St, Ste R, Denver, CO 80203, USA; privacy@pronoa.io | As provided in Customer’s Customer Agreement |
| Contact Person's Name, position, and contact details: | Scott Sellers, Chief Executive Officer; privacy@pronoa.io | As provided in Customer’s Customer Agreement |
| Activities relevant to the transfer: | See below | See below |
| Role: | Processor | Controller |
B. Description of the Processing and Transfer
Pronoa has been engaged to provide certain Services as more fully set forth in the Customer Agreement. When performing the Services pursuant to the Customer Agreement, Pronoa may from time to time have access to or may otherwise process the Personal Information that Customer (and its Authorized Users and data subjects) from time to time upload, transmit and submit to the Services, and/or that the Services may from time to time otherwise collect.
Set out below is the description of the processing and transfers of personal data and personal information in connection with the Services provided by Pronoa as contemplated as of the date of this DPA. Such description is subject to change or may be supplemented pursuant to Section 19 of the DPA.
| Services: | Access to and use of the Platform and related Services in accordance with Customer’s Customer Agreement |
|---|---|
| Categories of data subjects whose Personal Information is being transferred: | Customer’s Authorized Users and any data subjects that are included in an Customer Data |
| Categories of Personal Information transferred: | Any Personal Information provided to Pronoa via the Services, whether by (or at the direction of) Customer or its Authorized Users. Personal Information could include, without limitation:
|
| Sensitive Data Transferred? If yes, applicable restrictions and safeguards that will be taken: | None, unless Customer or Customer’s Authorized Users elect in their sole discretion to provide Sensitive Data to Pronoa via the Services. In such event, the extent and nature of the Sensitive Data is determined and controlled by Customer and Customer’s Authorized Users. See Annex II and Section 16 of the DPA for restrictions and safeguards that will be taken. |
| Frequency of the Transfer: | Continuous |
| Nature of the Processing: | Pronoa will process Personal Information for purposes of: (i) providing the Services to Customer in accordance with Customer’s Customer Agreement and this DPA; (ii) providing related technical support for the Services; (iii) generating analysis and outputs from Customer Data using Pronoa’s third-party AI model provider; and (iv) allowing and facilitating Customer’s Authorized Users’ use of the Services. |
| Purpose of the Transfer and Processing: | Personal Information is being transferred and processed for purposes of enabling Pronoa to provide the Services to Customer in accordance with Customer’s Customer Agreement and this DPA. |
| The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period | The term of Customer’s Customer Agreement plus the period from the end of that term until deletion of all Personal Information in accordance with Customer’s Customer Agreement and this DPA. |
| For transfers to subprocessors, the subject matter, nature and duration of the processing: | The subject matter, nature, and duration of the Processing of Personal Information by Subprocessors shall be as outlined above and in the DPA. |
| Competent supervisory authority | As specified in Section 8 of the DPA. |
Annex IISecurity Measures
Description of the technical and organisational measures implemented by the data importer to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons. All section references in this Annex shall refer to the sections of this Annex. For purposes of this Annex the following terms are applicable to Personal Information and security practices related to such Personal Information.
1. Pseudonymisation and encryption of personal data
- Encryption at rest. Customer data held in Pronoa’s database and file storage (Supabase, hosted on AWS in the us-west-2 region) is encrypted at rest using AES-256, including backups. Encryption keys are managed by the hosting provider. Pronoa does not offer customer-managed encryption keys.
- Encryption in transit. The Services are delivered over HTTPS. Communications between the application and its subprocessors’ services are made over encrypted connections.
- Pseudonymisation. Pronoa does not pseudonymise customer content within the Services; content is processed in the form the customer supplies it. Prompt and completion text is not recorded in LLM observability traces (see Section 12).
2. Ongoing confidentiality, integrity, availability and resilience of processing systems
- Tenant separation. Customer data is logically separated between customers. Principal decision tables use row-level security restricting access to the record’s owner. Organization records and the shared company profile are organization-scoped. Server-side access is checked by the application.
- File storage. Customer documents and briefs are stored in private buckets. Documents are read through authenticated access under row-level security; brief downloads use time-limited signed links. No bucket is publicly readable.
- Integrity of records. The application records automated correction and validation events, including the step, repair type and outcome. A full prior-and-revised text history of every edit is not kept.
- Availability. The Services run on managed infrastructure (Vercel for application hosting; Supabase for database, authentication and storage) with provider-managed redundancy.
3. Ability to restore availability and access to personal data after a physical or technical incident
- The production database has provider-managed daily encrypted backups with a seven-day rolling recovery window. Point-in-time recovery is not enabled. Backups cover the database, not uploaded file contents.
4. Regular testing, assessing and evaluating the effectiveness of technical and organisational measures
- Application errors and exceptions are monitored continuously through an error-monitoring service (Sentry) and reviewed by engineering.
- Changes are reviewed and validated in non-production before an authorized operator promotes them to production, and each production deployment is verified.
5. User identification and authorisation
- End-user authentication. Authorized Users sign in with an email address and password through the platform’s authentication service (Supabase Auth). Sessions are maintained with strictly necessary authentication cookies; the application sets no other cookies.
- Customer organizations. Self-registration creates an organization with the registering user as its owner. Pronoa adds users to a Customer organization at the Customer’s direction.
- Internal access. Production access is restricted to authorized personnel with a business need.
- Personnel. All personnel and contractors with access to Customer Data are bound by written confidentiality obligations.
6. Protection of data during transmission
- Data in transit is protected as described in Section 1.
- Card payments are taken on the payment processor’s hosted checkout page (Stripe), and Team plans are billed by invoice. Card numbers are entered on and transmitted to the payment processor directly and do not transit or reside on Pronoa systems.
7. Protection of data during storage
- Encryption at rest, private storage buckets and row-level security are described in Sections 1 and 2.
- Pronoa does not store payment card numbers; these are held by the payment processor.
- Provider-side AI assistant features that could read database content (Supabase Assistant) are disabled.
8. Physical security of processing locations
- Pronoa operates no data centres or on-premises servers. All processing occurs in facilities operated by its hosting subprocessors (AWS, via Supabase in us-west-2, and Vercel), which maintain physical and environmental controls covered by their own independent attestations.
9. Events logging
- Error monitoring. Application errors are logged to Sentry. A scrubbing filter removes strings longer than 80 characters from error extras, breadcrumbs and exception text; default personal-data collection is disabled regarding errors; and session replay is not used. Short fragments of text may remain in error records.
- Hosting logs. Request and runtime logs are retained by the application hosting provider (Vercel).
- Model telemetry. Model calls are traced through an LLM observability service (Langfuse). Traces record operational data such as timing, token counts and cost, are labeled by environment, and do not record prompt or completion text.
- Application records. The application maintains a correction log and a per-call log for each decision session as part of the Customer’s data.
10. System configuration, including default configuration
- Storage buckets are private by default. Browser-side database access is governed by row-level security. AI assistant features offered by Pronoa’s hosting providers (such as Supabase Assistant) that could access stored data are disabled. Sentry is configured not to collect default personal data and to scrub long strings, as described in Section 9.
11. Certification and assurance of processes and products
- Pronoa does not currently hold independent security certifications. It relies on the independent attestations maintained by its infrastructure subprocessors (see Section 8).
12. Data minimisation
- The Services are designed for business decision content and are not intended for sensitive or regulated personal data (protected health information, payment card data, government identifiers); customers are instructed not to submit it.
- Pronoa’s model provider (Anthropic) is configured for zero data retention and no training on customer content. This setting is enabled on Pronoa’s account.
- Prompt and completion text is not recorded in LLM observability traces, and error records are scrubbed as described in Section 9.
13. Data quality
- Customers control the content and data they submit and can revise it during a decision session. Automated corrections are logged as described in Section 2.
14. Limited data retention
- Customer decision records are retained for the term of the customer agreement. On termination, Pronoa deletes customer data in accordance with that agreement and on the timeline it specifies, except as required by law.
- Deleted records may persist in provider backups until those backups age out, approximately seven days.
- Error records are retained for 30 days. Model-telemetry traces, which contain operational data only, are retained for the period provided by the telemetry service’s plan. Hosting logs are retained for the period provided by the hosting plan.
- Account, billing, website-usage and support data are retained on the criteria stated in the Privacy Policy. Subprocessors may retain records they are legally required to keep (for example, payment records at the payment processor).
15. Accountability
- Pronoa’s list of subprocessors and their functions is set forth in Annex III. Pronoa engages each under terms requiring appropriate security and confidentiality.
- This Annex is reviewed whenever Pronoa’s processing or subprocessors materially change.
16. Data portability and erasure
- Personal Information is accessible, deleted/destroyed and otherwise handled in accordance with the terms of the applicable customer agreement, the DPA and/or the Privacy Policy, each as, and to the extent, applicable to Customer.
Annex IIISubprocessors
Pronoa has authorized the use of the following subprocessors:
| Subprocessor Name: | Nature of Processing: | Location: |
|---|---|---|
| Anthropic | AI model provider (Claude); generation of outputs. Zero-data-retention / no-training configuration | USA |
| Supabase | Database, authentication, and storage; encryption at rest and tenant isolation | USA |
| Vercel | Application hosting and delivery | USA |
| Stripe | Payment processing and billing | USA |
| Sentry | Application error monitoring | USA |
| Resend | Transactional email delivery | USA |
| Langfuse | Model telemetry and observability; operational metadata only, not customer decision content | USA |
| Netlify | Marketing website hosting and website form submissions (prospect contact details) | USA |
| Google / Google Workspace | Communications | USA |
Annex IVState Specific Requirements
California
A. If Pronoa is processing on behalf of Customer any Personal Information subject to the CPRA, then the following additional terms and conditions shall apply solely to the limited extent required by the CPRA and solely with respect to the Personal Information that is in the scope of the CPRA (and not with respect to any Personal Information that is covered by Data Protection Laws of other jurisdictions):
1. Pronoa is prohibited from selling or sharing Personal Information it collects pursuant to Customer’s Customer Agreement.
2. The specific business purpose for which Pronoa is processing the Personal Information pursuant to Customer’s Customer Agreement is to provide, manage and secure the Pronoa Services, and Customer is disclosing the Personal Information to Pronoa only for the limited and specified business purpose set forth in Customer’s Customer Agreement.
3. Pronoa is prohibited from retaining, using, or disclosing the Personal Information that it collected pursuant to Customer’s Customer Agreement for any purpose other than for the business purpose specified in the Customer’s Customer Agreement or as otherwise permitted by the CPRA.
4. Pronoa is prohibited from retaining, using, or disclosing the Personal Information that it collected pursuant to the Customer’s Customer Agreement for any commercial purpose (as that term is defined in the CPRA) other than the business purposes specified in such Customer Agreement, unless expressly permitted by the CPRA.
5. Pronoa is prohibited from retaining, using, or disclosing the Personal Information that it collected pursuant to the Customer’s Customer Agreement outside the direct business relationship between Pronoa and Customer, unless expressly permitted by the CPRA.
6. Pronoa is required to comply with all applicable sections of the CPRA with respect to Personal Information of Customer that is subject to the CPRA, including – with respect to the Personal information that Pronoa collected pursuant to the Customer’s Customer Agreement – providing the same level of privacy protection as required of businesses by the CPRA.
7. Pronoa grants Customer the right to take reasonable and appropriate steps to ensure that Pronoa uses the Personal Information that it collected pursuant to the Customer’s Customer Agreement in a manner consistent with Customer’s obligations under the CPRA.
8. Pronoa is required to notify Customer after it makes a determination that it can no longer meet its obligations under the CPRA.
9. Pronoa grants Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate Pronoa’s unauthorized use of Customer’s Personal Information.
10. Pronoa is required to enable Customer to comply with consumer requests made pursuant to the CPRA or Customer is required to inform Pronoa of any consumer request made pursuant to the CPRA that they must comply with and provide the necessary information for Pronoa to comply with the request.
11. If Pronoa subcontracts with another person in providing services to Customer, Pronoa shall have a contract with the subcontractor that complies with the CPRA.
B. To the extent that Section A above does not apply (i. e., Pronoa is not considered a “service provider” or “contractor” of Customer, but is instead considered a “third party”, each as defined by the CPRA), and either Party sells or shares with the other Party any Personal Information in the scope of the CPRA, then the following additional terms and conditions shall apply solely to the limited extent required by the CPRA and solely with respect to the Personal Information that is in the scope of the CPRA (and not with respect to any Personal Information that is covered by Data Protection Laws of other jurisdictions):
1. The purposes for which the Personal Information is made available to and by Pronoa is to provide, manage and secure the Pronoa Services under the Customer’s Customer Agreement subject to the applicable Party’s applicable privacy policy.
2. The Personal Information is made available to the receiving Party only for the limited and specified purposes set forth in the Customer’s Customer Agreement and is required to be used only for those limited and specified purposes.
3. The receiving Party is required to comply with applicable sections of the CPRA, including – with respect to the Personal Information that is made available to the receiving Party – providing the same level of privacy protection as required of businesses by the CPRA.
4. The disclosing Party is granted the right – with respect to the Personal Information that is made available – to take reasonable and appropriate steps to ensure that the receiving Party uses the Personal Information in a manner consistent with the disclosing Party’s obligations under the CPRA.
5. The disclosing Party is granted the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information made available to the receiving Party.
6. The receiving Party is required to notify the other Party after it makes a determination that it can no longer meet its obligations under the CPRA.
Previous version: 1 October 2026