Data Processing Agreement
Last updated 7 August 2026
This DPA applies automatically to every customer as part of the Terms of Service — you do not need to sign or request it. If your procurement process needs a countersigned copy, email privacy@getpallas.com and we will sign yours.
1. Parties and roles
Between you (“Customer”) and the operator of Pallas(“Processor”). For personal data you put into Pallas — your staff’s logins, and contact details belonging to your suppliers and customers — you are the controller and we are the processor. We act on your instructions and for no purpose of our own.
2. What is processed
| Item | Detail |
|---|---|
| Subject matter | Providing the Pallas service |
| Duration | While your account is open, plus the retention periods below |
| Nature and purpose | Storing, organising, retrieving, displaying, exporting and deleting your business records so you can run your business |
| Categories of data subject | Your personnel; contacts at your suppliers and customers |
| Categories of personal data | Name, business email, business phone, business and delivery address, job role, login credentials (passwords stored hashed), and audit records of actions taken in the account |
| Special category data | None. Pallas is not designed for it — do not put it in. |
3. Our obligations
- Process personal data only on your documented instructions, which include your use of the product and any support request you make.
- Never use it for our own purposes, never sell it, and never use it to train AI models.
- Keep it confidential and ensure anyone with access is bound to do the same.
- Apply the security measures in section 6.
- Help you respond to a data subject’s request, and to a regulator, at no charge.
- Tell you promptly if we believe an instruction of yours would breach data protection law.
- Delete or return the data at the end of the agreement, as set out in section 8.
4. Your obligations
- Have a lawful basis for the personal data you put into Pallas.
- Give the people concerned whatever notice the law requires.
- Keep your own access under control — issue individual logins, and remove people who leave.
5. Sub-processors
You authorise these sub-processors. All are in the United States.
| Sub-processor | Purpose |
|---|---|
| Vercel Inc. | Application hosting |
| Neon Inc. | Database hosting |
| Anthropic PBC | The in-product assistant. Data is sent per request to answer it and is not used for model training. |
| Stripe, Inc. | Payment processing (card data goes directly to Stripe) |
| Resend (Plus Five Five, Inc.) | Sending email that Pallas sends on your behalf, and account notices |
We will give you at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, you may end your subscription without penalty for the remainder of the paid period. We remain responsible to you for what our sub-processors do.
6. Security measures
- Separation:each customer’s records live in their own database schema, not commingled in shared tables.
- Encryption: TLS in transit; encryption at rest on the database.
- Authentication: per-user accounts, passwords stored hashed, session cookies that are HTTP-only and expire.
- Auditability: an append-only record of changes to business records, showing who or what made each change, when, and the previous value. It cannot be edited or deleted from within the product.
- Least access: production access is limited to those who need it to operate the service, over authenticated connections.
- Backups: automated, encrypted, with point-in-time recovery, and restores are tested rather than assumed.
- Payment data: never touches our systems — card details go straight to Stripe.
7. Personal data breach
We will notify you without undue delay and in any event within 72 hours of confirming a personal data breach affecting your data, by email to your account contact. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, what we have done and are doing, and the information you need to meet your own notification duties. We will keep you updated as we learn more, and we will not delay notice to finish investigating.
8. Return and deletion
You can export your data at any time from within Pallas. On termination, your data remains available to export for 30 days and is then deleted, unless you ask us to delete it sooner — in which case we will. Residual copies may persist in encrypted backups for up to a further 30 days before ageing out. We will confirm deletion in writing if you ask.
9. Audits and information
On reasonable request, and no more than once a year unless a regulator requires otherwise, we will give you the information you reasonably need to satisfy yourself we are meeting this DPA, including our security measures and sub-processor list. Where an on-site audit is genuinely required, we will cooperate to arrange one that does not compromise other customers’ data.
10. International transfers
Data is processed in the United States. If you are transferring personal data from the UK, EEA or Switzerland, the EU Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum are incorporated into this DPA by reference, with you as data exporter and us as data importer, the sub-processor list in section 5 and the measures in section 6 as the relevant annexes, and the governing law and forum as set out in the Terms.
11. Precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.
12. Contact
See also the Terms of Service and the Privacy Policy.