Data Processing Agreement
Last updated: June 25, 2026
This Data Processing Agreement ("DPA") supplements the Terms of Serviceand governs Prufer's processing of Personal Data on your behalf.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed through the Service.
- "Controller" means the entity that determines the purposes and means of processing Personal Data (you, the Customer).
- "Processor" means the entity that processes Personal Data on behalf of the Controller (Prufer LLC).
- "Data Protection Laws"means the General Data Protection Regulation (EU 2016/679) ("GDPR"), the California Consumer Privacy Act ("CCPA"), and any other applicable data protection legislation.
- "Sub-processor" means a third-party processor engaged by Prufer to assist in fulfilling its obligations under this DPA.
2. Scope & Roles
This DPA applies when Prufer processes Personal Data on your behalf as a Processor. You are the Controller of any Personal Data submitted to the Service.
This DPA does not apply to data that Prufer processes as a Controller (e.g., your account registration information), which is governed by our Privacy Policy.
3. Data Processing Details
| Subject Matter | Provision of the Prufer AI governance platform |
| Duration | For the term of the agreement plus data retention period |
| Nature & Purpose | Policy enforcement evaluation, governance auditing, compliance reporting |
| Categories of Data | Agent action logs, policy evaluation inputs/outputs, user identifiers, escalation context |
| Data Subjects | End users of AI agents governed by the Service, Customer employees |
4. Prufer's Obligations
Prufer shall:
- Process Personal Data only on your documented instructions and solely for providing the Service.
- Not process Personal Data for any other purpose, including training machine learning models, without explicit written consent.
- Ensure that persons authorized to process Personal Data are bound by obligations of confidentiality.
- Implement appropriate technical and organizational security measures (encryption, access controls, audit logging).
- Assist you in responding to data subject requests (access, rectification, erasure, portability).
- Notify you without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.
- Delete or return all Personal Data at the end of the agreement, at your election.
- Make available information necessary to demonstrate compliance and allow for audits (subject to reasonable notice and scope).
5. Sub-processors
Prufer currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | United States |
| MongoDB Atlas | Database hosting | United States |
| Resend | Transactional email | United States |
Prufer will notify you at least 30 days before engaging a new sub-processor. You may object to a new sub-processor by notifying us within 14 days. If we cannot reasonably accommodate your objection, either party may terminate the affected services.
6. International Transfers
If Personal Data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognized as providing adequate data protection, such transfers will be conducted under the European Commission's Standard Contractual Clauses (SCCs), as supplemented by additional technical and organizational measures. A copy of the applicable SCCs is available upon request.
7. Data Breach Notification
In the event of a Personal Data breach, Prufer will notify you within 72 hours and provide: (a) a description of the nature of the breach, (b) the categories and approximate number of data subjects and records affected, (c) the likely consequences, and (d) the measures taken or proposed to mitigate the breach. Prufer will cooperate with your breach investigation and regulatory notification obligations.
8. How to Execute This DPA
To execute this DPA:
- Enterprise customers: A DPA is included as part of your Master Service Agreement. Contact [email protected].
- Pro customers: To request a signed DPA, email [email protected] with your organization name and account email.