← Back to Terms of Service

Data Processing Agreement

Last updated: June 25, 2026

This Data Processing Agreement ("DPA") supplements the Terms of Serviceand governs Prufer's processing of Personal Data on your behalf.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed through the Service.
  • "Controller" means the entity that determines the purposes and means of processing Personal Data (you, the Customer).
  • "Processor" means the entity that processes Personal Data on behalf of the Controller (Prufer LLC).
  • "Data Protection Laws"means the General Data Protection Regulation (EU 2016/679) ("GDPR"), the California Consumer Privacy Act ("CCPA"), and any other applicable data protection legislation.
  • "Sub-processor" means a third-party processor engaged by Prufer to assist in fulfilling its obligations under this DPA.

2. Scope & Roles

This DPA applies when Prufer processes Personal Data on your behalf as a Processor. You are the Controller of any Personal Data submitted to the Service.

This DPA does not apply to data that Prufer processes as a Controller (e.g., your account registration information), which is governed by our Privacy Policy.

3. Data Processing Details

Subject MatterProvision of the Prufer AI governance platform
DurationFor the term of the agreement plus data retention period
Nature & PurposePolicy enforcement evaluation, governance auditing, compliance reporting
Categories of DataAgent action logs, policy evaluation inputs/outputs, user identifiers, escalation context
Data SubjectsEnd users of AI agents governed by the Service, Customer employees

4. Prufer's Obligations

Prufer shall:

  • Process Personal Data only on your documented instructions and solely for providing the Service.
  • Not process Personal Data for any other purpose, including training machine learning models, without explicit written consent.
  • Ensure that persons authorized to process Personal Data are bound by obligations of confidentiality.
  • Implement appropriate technical and organizational security measures (encryption, access controls, audit logging).
  • Assist you in responding to data subject requests (access, rectification, erasure, portability).
  • Notify you without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.
  • Delete or return all Personal Data at the end of the agreement, at your election.
  • Make available information necessary to demonstrate compliance and allow for audits (subject to reasonable notice and scope).

5. Sub-processors

Prufer currently uses the following sub-processors:

Sub-processorPurposeLocation
Stripe, Inc.Payment processingUnited States
MongoDB AtlasDatabase hostingUnited States
ResendTransactional emailUnited States

Prufer will notify you at least 30 days before engaging a new sub-processor. You may object to a new sub-processor by notifying us within 14 days. If we cannot reasonably accommodate your objection, either party may terminate the affected services.

6. International Transfers

If Personal Data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognized as providing adequate data protection, such transfers will be conducted under the European Commission's Standard Contractual Clauses (SCCs), as supplemented by additional technical and organizational measures. A copy of the applicable SCCs is available upon request.

7. Data Breach Notification

In the event of a Personal Data breach, Prufer will notify you within 72 hours and provide: (a) a description of the nature of the breach, (b) the categories and approximate number of data subjects and records affected, (c) the likely consequences, and (d) the measures taken or proposed to mitigate the breach. Prufer will cooperate with your breach investigation and regulatory notification obligations.

8. How to Execute This DPA

To execute this DPA:

  • Enterprise customers: A DPA is included as part of your Master Service Agreement. Contact [email protected].
  • Pro customers: To request a signed DPA, email [email protected] with your organization name and account email.