Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", the controller) and Pandora Technologies LLC ("Pandora", the processor) and applies where Pandora processes personal data contained in Customer Data on Customer's behalf. Where this DPA conflicts with the Terms on data protection, this DPA controls.
1. Definitions
"Personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law (including the GDPR/UK GDPR and U.S. state privacy laws, as applicable). "Customer Data" has the meaning given in the Terms. "Subprocessor" means a third party engaged by Pandora to process personal data.
2. Roles and scope
Customer is the controller and Pandora is the processor of the personal data within Customer Data. Pandora processes it only to provide the Service and on Customer's documented instructions (the Terms, this DPA, and Customer's use of the Service being such instructions), except where law requires otherwise — in which case Pandora will inform Customer unless prohibited.
3. Nature and purpose of processing
| Subject matter | Provision of the Pandora Modules platform. |
|---|---|
| Duration | The term of the Terms, plus the post-termination export/deletion window. |
| Nature & purpose | Hosting, storage, transmission, backup, display, and processing of Customer Data to operate the modules Customer subscribes to. |
| Types of data | Determined by Customer; may include names, contact details, employment data, customer/CRM records, support communications, financial records, and documents Customer chooses to store. |
| Data subjects | Determined by Customer; may include Customer's employees, customers, contacts, and end users. |
4. Pandora's obligations
- Process personal data only on Customer's documented instructions.
- Ensure persons authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 6).
- Assist Customer, taking into account the nature of processing, with data-subject requests and with security, breach notification, and data-protection-impact-assessment obligations.
- Not sell personal data and not use it for any purpose other than providing the Service; not use Customer Data to train AI models.
5. Subprocessors
Customer authorizes Pandora to engage subprocessors to provide the Service. Pandora imposes data protection obligations on each subprocessor substantially similar to those in this DPA and remains responsible for their performance. The current subprocessors are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Anthropic | AI model API (only data the Customer exposes to AI features; not used for training) | USA |
| Email delivery provider (transactional email/SMTP) | Sending account, notification, and support email | USA |
| Payment processor | Billing and payment handling for paid plans | USA |
| Hosting / infrastructure | Servers, network, and storage for the Service | USA |
Pandora will give Customer advance notice (by email or in-product) of any new or replacement subprocessor and a reasonable opportunity to object on legitimate data-protection grounds; if the objection cannot be resolved, Customer may terminate the affected Service.
6. Security
Pandora maintains technical and organizational measures appropriate to the risk, including: database-enforced tenant isolation (fail-closed row-level security with a non-bypassing application role), encryption of traffic in transit and of stored credentials/secrets at rest, salted password hashing, role-based access control, audit logging of privileged and AI data access, independent pre-release security review, and validated, off-copied backups with tested restores. Further detail is on the Security page, which is incorporated by reference.
7. Personal data breach
Pandora will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to help Customer meet its notification obligations. Pandora will take reasonable steps to contain and remediate.
8. Data subject requests
Because Customer administers its own tenant, Customer can access, correct, export, and delete personal data within the Service directly. To the extent Customer cannot do so through the Service, Pandora will, on request, provide reasonable assistance with data-subject requests.
9. International transfers
Pandora processes data in the United States. Where Customer transfers EEA/UK personal data to Pandora, the parties agree the applicable Standard Contractual Clauses (and UK Addendum) are incorporated by reference, with Pandora as "data importer" and Customer as "data exporter", to the extent required by law.
10. Deletion and return
On termination, Pandora will, at Customer's choice, make Customer Data available for export for 30 days and then delete it from live systems; residual copies in encrypted backups age out on Pandora's standard rotation and are not restored to production except for recovery.
11. Audit
On reasonable written request (no more than annually, except after a breach or where required by a supervisory authority), Pandora will make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of the Security page, summaries, or responses to a security questionnaire.
12. General
This DPA is governed by the same law and venue as the Terms. If any provision is unenforceable, the remainder stays in effect. This DPA takes effect on the earlier of Customer's acceptance of the Terms or first use of the Service for processing personal data. Contact: pandoramodules.com/contact.