ProgullProgull
Legal

Data Processing Addendum

Plain-English summary. The signed, controlling policy is available on request from your account team.

Our DPA covers roles (Progull is Processor), sub-processors, cross-border transfer mechanisms (SCCs / UK IDTA / DPF), breach notification (≤72h), and audit rights. Request the signed copy from your account team. Progull is committed to WCAG 2.2 AA conformance, GDPR, CCPA, DPDP Act readiness, SOC 2 Type II controls, ISO 27001 alignment, encryption in transit and at rest, least-privilege access, auditability, and region-aware processing. The signed controlling policy, audit evidence, and customer-specific exhibits are available on request.

Processing posture

  • Progull acts as processor for customer-controlled operational data and as controller for limited business-contact and site data.
  • Processing instructions are captured in the order form, DPA, security exhibit, and deployment runbook.

Security measures

  • Access control, encryption, audit logging, vulnerability management, incident response, backup controls, and personnel confidentiality are baseline obligations.
  • Breach notification commitments, sub-processor flow-downs, and cross-border transfer terms are documented in the signed DPA.

Audit and deletion

  • Qualified enterprise customers may request audit evidence under NDA.
  • Deletion and return workflows are handled at contract termination or on validated request, subject to legal retention obligations.
Questions? Email zeeshan.afzal@progull.com or see the Trust Center.