Legal
Data Processing Addendum (DPA)
Last updated: Draft
Draft for review. A plain-language starting point, not legal advice. Have it reviewed by counsel and fill in your company/entity name, address, and governing-law jurisdiction before you go live.
This DPA forms part of the Terms and applies where we process personal data on your behalf. You are the controller; Pragor is the processor.
1. Scope & roles
We process personal data only to provide the Service and on your documented instructions (these Terms being one such instruction).
2. Subject matter & duration
Processing lasts for the term of your account. Categories: your users and any personal data contained in your board content.
3. Confidentiality
Our personnel are bound by confidentiality.
4. Security
We maintain appropriate technical and organisational measures: tenant isolation, encryption of secrets at rest, access control, logging and audit, and tested backups.
5. Sub-processors
You authorise us to engage sub-processors (hosting, payments, email) under written terms with equivalent obligations. A current list is available on request; we notify of changes and you may object on reasonable grounds.
6. Data-subject requests
We assist you, taking into account the nature of processing, in responding to access, correction, deletion and portability requests.
7. Assistance
We help you with security, breach notification, and data-protection impact assessments as required by GDPR Art. 28.
8. Breach notice
We notify you without undue delay after becoming aware of a personal-data breach affecting your data.
9. International transfers
EU data residency is available; where transfers occur we rely on standard contractual clauses or equivalent safeguards.
10. Deletion/return
On termination we delete or return personal data, save where retention is legally required.
Business & Enterprise customers can request a countersigned DPA via the contact page.