We collect only the minimum data needed to operate the service: work identifiers, telemetry, and product usage. We never sell data. Data is regionally isolated (US / EU / APAC) and encrypted at rest (AES-256) and in transit (TLS 1.3). Progull is committed to WCAG 2.2 AA conformance, GDPR, CCPA, DPDP Act readiness, SOC 2 Type II controls, ISO 27001 alignment, encryption in transit and at rest, least-privilege access, auditability, and region-aware processing. The signed controlling policy, audit evidence, and customer-specific exhibits are available on request.
Data we process
- Mainframe telemetry required to diagnose abends, including job names, step metadata, SQLCODEs, spool references, timestamps, incident IDs, and operator notes.
- Business content is minimized by default; sensitive fields are tokenized or redacted before reasoning workflows when customer policy requires it.
- Product usage data is used to improve reliability, security, and support outcomes — never sold, brokered, or used for advertising profiles.
Controls
- TLS 1.3 in transit, AES-256 at rest, tenant isolation, signed access paths, and role-scoped audit trails.
- Retention windows are configurable by environment and can be aligned to customer record schedules.
- Sub-processors are reviewed for security posture and listed through the Trust Center.
Rights and requests
- Customers can request access, deletion, export, or correction through their account team or the founder contact channel.
- Enterprise customers can contract for regional processing, data residency commitments, and dedicated tenant boundaries.