Data Processing Addendum

Data Processing Addendum

Pure Grace AI, LLC — AI Privacy Center

Version: 1.0 · Effective Date: July 1, 2026

This Data Processing Addendum is available at https://puregraceai.com/legal/dpa

This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms of Service or other written agreement (the “Agreement”) between Pure Grace AI, LLC (“Company,” “Processor”) and the customer identified in the Agreement (“Customer,” “Controller”). In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA controls. All limitations of liability, caps, and the California Civil Code Section 1668 savings clause in the Agreement apply to this DPA, subject to Section 13 below.

1. Definitions

“Applicable Data Protection Law” means all privacy and data protection laws applicable to a party’s Processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and U.S. state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).

“Customer Personal Data” means Personal Data contained within Customer Data that Company Processes solely on behalf of and under the documented instructions of Customer in providing the Services.

“Personal Data,” “Processing,” “Controller,” “Processor,” “Service Provider,” “Contractor,” “Business,” “Sale,” “Share,” “Consumer,” and “Data Subject” have the meanings given in Applicable Data Protection Law.

“Sensitive Personal Information” has the meaning given in the CCPA/CPRA, and “Special Categories of Personal Data” has the meaning given in Article 9 of the GDPR.

“PHI” (protected health information) has the meaning given in the HIPAA Privacy Rule (45 C.F.R. § 160.103).

“Sub-processor” means a third party engaged by Company to Process Customer Personal Data.

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Company.

“Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission for the transfer of Personal Data to third countries under Commission Implementing Decision (EU) 2021/914, Module Two (Controller-to-Processor), and, where applicable, as supplemented by the UK International Data Transfer Addendum and Swiss-law adaptations.

Capitalized terms not defined here have the meaning given in the Agreement.

2. Roles and Scope

For Customer Personal Data, Customer is the Controller (or Business), and Company is the Processor (or Service Provider or Contractor), Processing only on Customer’s documented instructions. The subject matter, duration, nature and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.

This DPA applies only to Company’s Processing of Customer Personal Data as a Processor. Company acts as an independent Controller for Personal Data it Processes for its own purposes (e.g., account administration, billing, website analytics, and marketing); that Processing is governed by Company’s Privacy Notice, not by this DPA.

3. Customer Instructions

Company will Process Customer Personal Data only on Customer’s documented instructions, including instructions set out in the Agreement and this DPA, instructions reflected in Customer’s configuration of the Services, instructions necessary to provide the Services, and instructions relating to transfers of Customer Personal Data to a third country or international organization, unless required to do otherwise by applicable law (in which case Company will, where legally permitted, inform Customer of that legal requirement before Processing). Company will inform Customer if, in Company’s opinion, an instruction infringes Applicable Data Protection Law. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it, and for having a lawful basis and any required notices/consents for the Processing.

No Model Training; No Independent Use. Processor will not use Customer Personal Data to train, fine-tune, improve, develop, or evaluate general-purpose AI models, foundation models, large language models, or models used to provide services to other customers, except to the extent expressly authorized by Controller in this DPA, an Order Form, or another written agreement and only where permitted by Applicable Data Protection Law. Processor will not sell Customer Personal Data, share Customer Personal Data for cross-context behavioral advertising, use Customer Personal Data outside the direct business relationship with Controller, or derive independent commercial value from Customer Personal Data except as expressly permitted by this DPA and Applicable Data Protection Law.

Processor will not create or use deidentified, aggregated, or derived datasets from Customer Personal Data for model training, benchmarking, analytics, product development, or services for other customers, except as expressly authorized in this DPA or a separate written agreement.

4. Confidentiality

Company will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and Process the data only as instructed.

5. Security Measures

Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing, Company will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex II. Customer is responsible for its own configuration of the Services and for securing its account credentials.

6. Sub-processors

Customer provides a general authorization for Company to engage Sub-processors to Process Customer Personal Data, subject to this Section. The current Sub-processors are listed in Annex III. Company will: (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written contract; (b) remain responsible for each Sub-processor’s performance of the data-protection obligations imposed under this DPA as required by Applicable Data Protection Law, subject only to liability limitations that are enforceable under such law and the Agreement; and (c) provide a mechanism for Customer to receive notice of intended additions or replacements of Sub-processors at least thirty (30) days before the new or replacement Sub-processor begins Processing Customer Personal Data — unless a shorter period is required to address an emergency, security risk, legal requirement, or service-continuity issue, in which case Company will provide notice as soon as reasonably practicable — with a reasonable opportunity to object on reasonable data-protection grounds. If Customer reasonably objects and the parties cannot resolve the objection, Customer’s remedy is to terminate the affected Services as provided in the Agreement.

7. Assistance to Customer

Taking into account the nature of the Processing and the information available to Company, Company will provide reasonable assistance to Customer without undue delay, at Customer’s expense where the law permits, with: (a) responding to Data Subject requests to exercise rights under Applicable Data Protection Law, including by providing the Services’ self-service functionality (e.g., the data-subject-request workflow); (b) the security of Processing; (c) Security Incident notification; and (d) data protection impact assessments and prior consultations with supervisory authorities. If Company receives a Data Subject request directed to Customer’s data, Company will, where legally permitted, promptly forward it to Customer and not respond directly except on Customer’s instruction.

8. Security Incident Notification

Company will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include, to the extent known and reasonably available at the time: the nature of the Security Incident; the categories and approximate number of affected Data Subjects and records; the likely consequences of the incident; the measures taken or proposed to address and mitigate it; and a contact point for follow-up. Company may provide this information in phases as it becomes available, and will provide further information reasonably available to Company to assist Customer in meeting its own notification obligations. Company’s notification is not an acknowledgment of fault or liability.

9. Return and Deletion

Upon termination or expiration of the Agreement, Company will, at Customer’s choice, delete or return Customer Personal Data, and delete existing copies, except to the extent retention is required by applicable law or permitted by the Agreement. For clarity, any billing, tax, security, fraud-prevention, legal-hold, and auto-renewal-consent records that Company retains after termination are retained in Company’s independent Controller capacity as account records, and are not a continued Processing of Customer Personal Data as Processor under this DPA. The mechanics and timing of return/deletion follow the Agreement.

10. Audits

Company will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer. To the extent available, Company may satisfy this obligation by providing its then-current third-party certifications and audit reports (e.g., SOC 2). Any on-site or direct audit is subject to the following: it may be conducted no more than once per twelve (12) months, except where required by a supervisory authority or following a verified Security Incident affecting Customer Personal Data; Customer will provide at least thirty (30) days’ prior written notice; the audit will be conducted by Customer or an independent auditor bound by confidentiality, during business hours, in a manner that does not disrupt Company’s operations and does not access any other customer’s data or Company confidential information beyond what is necessary; and Customer bears its own and Company’s reasonable costs of the audit unless the audit reveals material non-compliance by Company, in which case Company bears the reasonable costs of that audit.

11. International Transfers

Where Company Processes Customer Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland in a country that has not received an adequacy decision, the parties agree as follows:

  • EEA transfers. The SCCs (Commission Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor), are incorporated by reference and apply, completed by the information in the Annexes. For the purposes of the SCCs: the optional docking clause (Clause 7) applies; the option for general sub-processor authorization (Clause 9, Option 2) applies, with the notice period in §6; the competent supervisory authority is determined under Clause 13 as set out in Annex I; under Clause 17 (Option 1) the SCCs are governed by the laws of Ireland; and under Clause 18 the forum is the courts of Ireland — all as specified in Annex I, Section C.

  • UK transfers. For transfers of Customer Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (the “UK Addendum”) applies and is incorporated by reference. The EU SCCs as completed in this Section and the Annexes are the Approved SCCs to which the UK Addendum appends (Module Two; Clauses 7, 9 Option 2, 13, 17, and 18). For UK transfers: the Information Commissioner’s Office (ICO) is the competent supervisory authority; references in the SCCs to the EU, EU Member States, EU law, and EU supervisory authorities are read as references to the United Kingdom, the UK GDPR and Data Protection Act 2018, and the ICO, as applicable; and the UK Addendum’s Tables are completed by this Section and the Annexes. By operation of the UK Addendum’s Mandatory Clauses, for UK Restricted Transfers Clause 17 is amended so that these Clauses are governed by the laws of England and Wales, and Clause 18 is amended so that any dispute arising from these Clauses shall be resolved by the courts of England and Wales, provided that a data subject may also bring proceedings before the courts of any country in the United Kingdom; this substitution applies to UK Restricted Transfers only and does not affect the Ireland selections for Clauses 17 and 18 governing EEA transfers under the EU SCCs. In Table 4 of the UK Addendum, both the Importer and the Exporter may end the Addendum in the circumstances set out in Section 19 of its Mandatory Clauses.

  • Swiss transfers. For transfers of Customer Personal Data subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs apply with the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC): (a) the FDPIC is the competent supervisory authority for transfers governed exclusively by the FADP, and acts in parallel to the competent EU supervisory authority (the Irish Data Protection Commission) for transfers subject to both the FADP and the GDPR; (b) references to the GDPR are read as references to the FADP insofar as the transfer is subject to the FADP; (c) references to EU Member States and the courts of EU Member States do not prevent data subjects in Switzerland from bringing proceedings in their place of habitual residence in Switzerland; and (d) the SCCs protect Personal Data as defined under the FADP. The revised FADP (in force 1 September 2023) protects only natural persons; no legal-entity extension applies.

  • Transfer impact. Each party will cooperate in good faith to assess whether the transfer tools provide an adequate level of protection and to adopt supplementary measures where reasonably necessary, and Company will, to the extent legally permitted, notify Customer of any binding request by a public authority for Customer Personal Data.

12. CCPA / CPRA Service-Provider and Contractor Terms

To the extent Company Processes Personal Information of California consumers as a Service Provider or Contractor on Customer’s behalf, Company will Process such Personal Information only for the limited and specified business purposes described in Annex I and the Agreement, including providing consent management, privacy-policy and cookie-policy generation, data-subject-request intake and workflow support, sub-processor registry and DPA-generation functionality, site scanning, security, fraud prevention, debugging, service improvement, and other purposes expressly permitted by the CCPA/CPRA and its regulations. Company will not Sell or Share such Personal Information. Company will not retain, use, or disclose such Personal Information for any purpose other than the limited and specified business purposes, outside the direct business relationship with Customer, or for a commercial purpose other than providing the Services, except as expressly permitted by the CCPA/CPRA. Company will not combine such Personal Information with Personal Information received from or on behalf of another person, or collected from Company’s own interaction with the consumer, except as expressly permitted by the CCPA/CPRA. Company will comply with applicable CCPA/CPRA obligations and provide the same level of privacy protection required of businesses. Company certifies that it understands and will comply with these restrictions. Company will notify Customer if Company determines that it can no longer meet its obligations under the CCPA/CPRA. Customer may take reasonable and appropriate steps to help ensure that Company’s use of Personal Information is consistent with Customer’s obligations under the CCPA/CPRA and, upon notice, to stop and remediate unauthorized use. Company will reasonably assist Customer in responding to consumer requests and, where applicable, in cooperating with cybersecurity audits, risk assessments, and automated-decisionmaking-technology obligations. Company will require any subcontractor that Processes such Personal Information to enter into a written contract that complies with the CCPA/CPRA.

13. Liability

Subject to the remainder of this Section, each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including the caps and the California Civil Code Section 1668 savings clause. Nothing in this DPA or the Agreement limits or excludes liability to the extent such limitation or exclusion is prohibited by Applicable Data Protection Law, California Civil Code Section 1668, or other applicable law — including liability for fraud, willful injury, intentional torts, statutory or regulatory penalties that cannot be contractually limited, or other non-limitable liability. This DPA does not increase a party’s aggregate liability beyond the caps in the Agreement except to the extent required by applicable law. If the SCCs apply, the liability provisions of the SCCs control to the extent required for the SCCs to remain valid and enforceable. For the avoidance of doubt, nothing in the Agreement’s liability caps limits or excludes any rights or remedies available to a data subject under the SCCs or Applicable Data Protection Law.

14. Term; Order of Precedence

This DPA is effective for as long as Company Processes Customer Personal Data under the Agreement. If any provision of this DPA conflicts with the Agreement, this DPA controls as to the Processing of Customer Personal Data. If the SCCs conflict with this DPA, the SCCs control.

Annex I — Details of Processing and SCC Transfer Description

A. List of Parties

Data exporter: Customer, as identified in the Agreement, Order Form, account registration, or other ordering document.

Address: Customer’s address as provided in the Agreement, Order Form, account registration, or other ordering document.

Contact: Customer’s account owner, privacy contact, DPO, or EU representative, as applicable and as provided by Customer.

Activities relevant to the transfer: Customer’s use of the Services to manage privacy-compliance workflows, including consent management, privacy/cookie policy generation, data-subject-request intake and workflow support, sub-processor registry and DPA-generation functionality, and site scanning.

Role: Controller.

Data importer: Pure Grace AI, LLC.

Address: 6285 E. Spring St, #457, Long Beach, CA 90808, United States.

Contact: privacy@puregraceai.com.

Activities relevant to the transfer: Provision, hosting, support, security, maintenance, and improvement of the Services in accordance with the Agreement and Customer’s documented instructions.

Role: Processor.

B. Description of Transfer

Categories of Data Subjects: Customer’s website visitors and end users; individuals who submit data-subject requests to Customer; Customer’s personnel and authorized users.

Categories of Personal Data: Website-visitor consent records, including pseudonymous visitor identifier, hashed IP address, user-agent, consent choices, and related timestamp/audit information; DSR requestor information, including name, email address, request details, and authorized-agent proof; Customer authorized-user account information, including name, email, and role; and scan output relating to cookies/trackers found on Customer sites, which may include identifiers in cookie values.

Sensitive Data / Special Categories: The Services are not designed to require Special Categories of Personal Data, Sensitive Personal Information, PHI, payment-card data, children’s data, or other regulated data unless expressly enabled in an Order Form or separate written agreement. Customer will not submit such data except where it has confirmed a lawful basis, provided all required notices/consents, and entered into any required additional agreement, including a HIPAA Business Associate Agreement where applicable. If such data is submitted incidentally through a DSR workflow, Company will Process it only on Customer’s documented instructions and subject to the safeguards in Annex II, including encryption, access controls, audit logging, and limited-purpose processing.

Frequency of Transfer: Continuous, for the duration of the Agreement.

Nature of Processing: Hosting, storage, retrieval, organization, structuring, transmission, analysis, scanning, display, deletion, and other processing necessary to provide the Services.

Purpose of Transfer and Further Processing: To provide the Services under the Agreement, including consent management, privacy/cookie policy generation, data-subject-request intake and workflow support, sub-processor registry and DPA-generation functionality, site scanning, security, debugging, fraud prevention, support, and service maintenance.

Retention Period: Customer Personal Data is retained for the term of the Agreement and deleted or returned in accordance with Section 9 of this DPA, unless retention is required by applicable law or permitted in Company’s independent Controller capacity for account, billing, tax, security, fraud-prevention, legal-hold, or compliance records.

Subject Matter, Nature, and Duration of Processing: The subject matter is Company’s provision of the Services to Customer. The nature of processing is described above. The duration is the term of the Agreement plus any legally required or permitted retention period.

C. SCC Governance (Clauses 13, 17, 18)

Competent supervisory authority (Clause 13): Determined under Clause 13 of the SCCs. Where Customer/data exporter is established in an EU Member State, the competent supervisory authority is the authority responsible for Customer’s GDPR compliance with respect to the relevant transfer. Where Customer/data exporter is not established in the EU but is subject to GDPR Article 3(2) and has appointed an EU representative under GDPR Article 27, the competent authority is that of the Member State where the representative is established. Where Customer/data exporter is not established in the EU but is subject to GDPR Article 3(2) and is not required to appoint an EU representative, the competent authority is that of one of the Member States in which the relevant Data Subjects are located.

Governing law (Clause 17): For purposes of Clause 17 of the SCCs, Option 1 applies and the SCCs are governed by the laws of Ireland.

Forum (Clause 18): For purposes of Clause 18 of the SCCs, disputes arising from the SCCs will be resolved by the courts of Ireland, without prejudice to a Data Subject’s right to bring legal proceedings before the courts of the Member State in which the Data Subject has habitual residence.

Annex II — Technical and Organizational Measures

The following measures describe technical and organizational measures currently implemented in the Services. This Annex is kept aligned with the then-current SOC 2 controls referenced in the Agreement. Controls still under development are tracked in Company’s internal security-planning documentation and are not represented here as presently enforced.

  • Encryption at rest. Sensitive stored data is encrypted using AES-256-GCM authenticated encryption with a unique random initialization vector and authentication tag per record. This covers CMS OAuth tokens and API credentials and data-subject-request requestor PII (name, email, request details, and authorized-agent information). The 256-bit key is supplied at runtime via a managed secret and is not stored in source code.

  • Encryption in transit. Data in transit is protected by TLS. The API sets HTTP security response headers, and session cookies are HttpOnly, Secure (in production), and SameSite=Strict.

  • Key management. Encryption keys are provisioned via managed secrets and segregated from the encrypted data; the key is supplied at runtime and is not stored in source code. A documented zero-downtime key-rotation procedure (decrypt-and-re-encrypt per record, executed within a per-row transaction) is maintained for use upon suspected key compromise or credential exposure.

  • Multi-tenant isolation. Tenant data is isolated at the database layer using PostgreSQL Row-Level Security. The application connects through a non-superuser role that cannot bypass RLS, and RLS is both enabled and forced on all tenant tables. Access is scoped on two independent dimensions (organization and client) via per-request session variables set inside a transaction, so a spoofed client scope is still blocked by the independent organization check. Multi-tenant isolation is exercised by automated tests in CI.

  • Tamper-evident audit logging. Consent records form a SHA-256 hash chain in which each record’s hash incorporates the prior record’s hash, serialized per website by a row-level chain-head lock, with a verification endpoint to detect post-hoc modification. Administrative audit logs are append-only — insert-only, with update and delete blocked by database policy.

  • Access control and authentication. Access uses short-lived JWT access tokens with refresh tokens stored in HttpOnly, Secure (in production), SameSite=Strict cookies, and role-based authorization (Owner / Admin / Member). Administrative and scheduled-job endpoints require a separate administrative API key.

  • Human-approval gate. Content is pushed to Customer Property only from policy versions that have been explicitly approved; the system refuses to push unapproved content. Sub-processor entries become public only after a human confirms the required legal fields.

  • Rate limiting and abuse controls. Public data-subject-request endpoints are rate-limited per website (5 per hour) and per IP globally (20 per day), backed by Redis where configured.

  • Scanning egress controls. The site-scanning subsystem runs against a self-hosted headless-browser service; in production the engine refuses to operate against public/third-party browser services, and network-layer egress filtering (blocking internal, loopback, link-local, and cloud-metadata ranges) is required at deployment.

  • Backups and restoration. Database backups and point-in-time recovery are managed by the database host (Neon) in accordance with the host’s then-current backup and retention configuration for Company’s deployment.

  • Secure development and testing. Changes pass automated type-checking and multi-tenant isolation tests in continuous integration before merge, and a coverage-audit gate verifies declared controls against code on every build.

  • Incident response. Security-incident notification to Customer is governed by Section 8 of this DPA.

Annex III — Sub-processors

Company’s direct Sub-processors for Customer Personal Data are listed below. Vendor legal entities, regions, and transfer mechanisms reflect each vendor’s then-current public terms.

Sub-processor Purpose Legal entity Country / Region Transfer mechanism
Anthropic LLM drafting of privacy policies / DSR response text Anthropic PBC United States Anthropic commercial DPA with SCCs; UK Addendum / Swiss adaptations as applicable. Do not rely on DPF unless counsel verifies current certification.
Neon PostgreSQL database hosting Neon, LLC (affiliate of Databricks, Inc.) United States; database/project processing region depends on Customer’s selected Neon/project configuration and Company’s actual deployment Databricks/Neon DPA; SCCs for restricted transfers.
Twilio SendGrid Transactional email Twilio Inc. United States; EU only if configured for supported EU data residency Twilio DPA; DPF where verified and/or EU SCCs / UK transfer terms. Twilio BCRs do not serve as a transfer mechanism for SendGrid Services.
Upstash Rate limiting Upstash, Inc. (Delaware corporation) United States; global as needed to provide the service Upstash DPA; DPF where verified; SCCs where DPF does not apply.
Stripe Billing / payment processing Stripe, LLC (effective Jan. 3, 2026; contracting entity varies by region) United States; other regions per account, product, and payment location Stripe DPA / Data Transfers Addendum; DPF first where verified, then EEA SCCs (Module 2) or UK Addendum as applicable.
Fly.io Application hosting/compute — storage and execution of the API and the headless-browser site-scanning runtime (self-hosted by Company on Fly.io; public browser services are blocked in production and network egress is restricted) Fly.io, Inc. United States (Fly.io region iad, US East / Ashburn, VA) Executed Fly.io DPA (Art. 28 flow-down terms); EU SCCs incorporated (Annex 2 of the Fly.io DPA) for restricted transfers, with UK coverage; DPF where verified. The Company-to-Fly.io onward leg is a US-to-US transfer (region iad).

Public sub-processor pages (for reference / vendor downstream lists):

  • Anthropic — trust.anthropic.com/subprocessors

  • Neon — neon.com/subprocessors

  • Twilio SendGrid — twilio.com/legal/sub-processors

  • Upstash — trust.upstash.com/subprocessors

  • Stripe — stripe.com/legal/service-providers

Customer-Authorized Integrations. Customer may choose to connect the Services to Customer-controlled third-party platforms, websites, CMS providers (e.g., WordPress, Webflow, Shopify, Squarespace), hosting providers, or other Customer Property. These Customer-authorized integrations are not Company Sub-processors unless Company separately engages the provider to Process Customer Personal Data on Company’s behalf. Customer is responsible for its own relationship, configuration, and legal terms with such providers.

The current sub-processor list is maintained in the public sub-processor registry at https://puregraceai.com/legal/subprocessors. Company will provide at least thirty (30) days’ advance notice before authorizing a new or replacement Sub-processor to Process Customer Personal Data, unless a shorter period is required to address an emergency, security risk, legal requirement, or service-continuity issue, in which case Company will provide notice as soon as reasonably practicable, consistent with §6.

Scroll to Top