ProgullProgull
Legal

Privacy Policy

Plain-English summary. The signed, controlling policy is available on request from your account team.

We collect only the minimum data needed to operate the service: work identifiers, telemetry, and product usage. We never sell data. Data is regionally isolated (US / EU / APAC) and encrypted at rest (AES-256) and in transit (TLS 1.3). Progull is committed to WCAG 2.2 AA conformance, GDPR, CCPA, DPDP Act readiness, SOC 2 Type II controls, ISO 27001 alignment, encryption in transit and at rest, least-privilege access, auditability, and region-aware processing. The signed controlling policy, audit evidence, and customer-specific exhibits are available on request.

Data we process

  • Mainframe telemetry required to diagnose abends, including job names, step metadata, SQLCODEs, spool references, timestamps, incident IDs, and operator notes.
  • Business content is minimized by default; sensitive fields are tokenized or redacted before reasoning workflows when customer policy requires it.
  • Product usage data is used to improve reliability, security, and support outcomes — never sold, brokered, or used for advertising profiles.

Controls

  • TLS 1.3 in transit, AES-256 at rest, tenant isolation, signed access paths, and role-scoped audit trails.
  • Retention windows are configurable by environment and can be aligned to customer record schedules.
  • Sub-processors are reviewed for security posture and listed through the Trust Center.

Rights and requests

  • Customers can request access, deletion, export, or correction through their account team or the founder contact channel.
  • Enterprise customers can contract for regional processing, data residency commitments, and dedicated tenant boundaries.
Questions? Email zeeshan.afzal@progull.com or see the Trust Center.