← Pallas

Data Processing Agreement

1. Parties and roles

Between you (“Customer”) and the operator of Pallas(“Processor”). For personal data you put into Pallas — your staff’s logins, and contact details belonging to your suppliers and customers — you are the controller and we are the processor. We act on your instructions and for no purpose of our own.

2. What is processed

ItemDetail
Subject matterProviding the Pallas service
DurationWhile your account is open, plus the retention periods below
Nature and purposeStoring, organising, retrieving, displaying, exporting and deleting your business records so you can run your business
Categories of data subjectYour personnel; contacts at your suppliers and customers
Categories of personal dataName, business email, business phone, business and delivery address, job role, login credentials (passwords stored hashed), and audit records of actions taken in the account
Special category dataNone. Pallas is not designed for it — do not put it in.

3. Our obligations

4. Your obligations

5. Sub-processors

You authorise these sub-processors. All are in the United States.

Sub-processorPurpose
Vercel Inc.Application hosting
Neon Inc.Database hosting
Anthropic PBCThe in-product assistant. Data is sent per request to answer it and is not used for model training.
Stripe, Inc.Payment processing (card data goes directly to Stripe)
Resend (Plus Five Five, Inc.)Sending email that Pallas sends on your behalf, and account notices

We will give you at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, you may end your subscription without penalty for the remainder of the paid period. We remain responsible to you for what our sub-processors do.

6. Security measures

7. Personal data breach

We will notify you without undue delay and in any event within 72 hours of confirming a personal data breach affecting your data, by email to your account contact. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, what we have done and are doing, and the information you need to meet your own notification duties. We will keep you updated as we learn more, and we will not delay notice to finish investigating.

8. Return and deletion

You can export your data at any time from within Pallas. On termination, your data remains available to export for 30 days and is then deleted, unless you ask us to delete it sooner — in which case we will. Residual copies may persist in encrypted backups for up to a further 30 days before ageing out. We will confirm deletion in writing if you ask.

9. Audits and information

On reasonable request, and no more than once a year unless a regulator requires otherwise, we will give you the information you reasonably need to satisfy yourself we are meeting this DPA, including our security measures and sub-processor list. Where an on-site audit is genuinely required, we will cooperate to arrange one that does not compromise other customers’ data.

10. International transfers

Data is processed in the United States. If you are transferring personal data from the UK, EEA or Switzerland, the EU Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum are incorporated into this DPA by reference, with you as data exporter and us as data importer, the sub-processor list in section 5 and the measures in section 6 as the relevant annexes, and the governing law and forum as set out in the Terms.

11. Precedence

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.

12. Contact

privacy@getpallas.com