Pursor
Legal · B2B

Data Processing Addendum

For business customers — defines Pursor's role as a service provider/processor for personal data of your customers, including subprocessors and security commitments.
Effective: May 12, 2026
Last updated: May 12, 2026
Version: 1.0

1. Scope and roles

This Data Processing Addendum ("DPA") is incorporated into the Terms of Service between you ("Customer") and Pursor, Inc. ("Pursor"). It governs Pursor's processing of "Personal Information" of your customers, contacts, or end users (collectively "Your Customers") through the Service.

For Personal Information of Your Customers:

  • Under CCPA/CPRA terminology, you are the "Business" and Pursor is a "Service Provider."
  • Under GDPR/UK GDPR terminology, you are the "Controller" and Pursor is the "Processor."
  • Under VCDPA/CPA/CTDPA/UCPA terminology, you are the "Controller" and Pursor is the "Processor."

2. Processing instructions

Pursor will process Personal Information only:

  • To provide and improve the Service as described in the Terms
  • To comply with your reasonable documented instructions
  • To comply with applicable law (in which case we will inform you unless legally prohibited)
  • For security, abuse prevention, and to enforce our agreements

Pursor will not sell or share Personal Information, will not use it for cross-context behavioral advertising, will not combine it with data from other sources for unrelated purposes, and will not use it to train general-purpose AI models.

3. Subprocessors

Pursor engages the following subprocessors to provide the Service. You consent to their use. We will notify you at least 14 days before adding a new subprocessor or changing the role of an existing one, and you may object to material changes by contacting legal@pursor.co.

Subprocessor Purpose Location
Anthropic, PBCAI model inferenceUSA
Twilio, Inc.SMS/MMS delivery, A2P 10DLCUSA
Amazon Web ServicesCloud hosting, database, storageUSA (us-east-1)
Stripe, Inc.Payment processingUSA
Resend (or equivalent ESP)Transactional email deliveryUSA
DeepgramVoice memo transcriptionUSA

An up-to-date list is maintained at pursor.co/subprocessors. All subprocessors are bound by data protection terms substantially equivalent to those in this DPA.

4. Security measures

Pursor implements and maintains appropriate technical and organizational measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Network segmentation and least-privilege access controls
  • Multi-factor authentication for all employee accounts
  • Centralized audit logging with tamper detection
  • Annual third-party penetration testing
  • Vendor risk reviews of all subprocessors
  • Documented incident response procedures

5. Your customers' rights

If one of Your Customers contacts Pursor directly to exercise their rights (access, deletion, correction, etc.), we will, unless legally required otherwise, route that request to you within 5 business days. You remain responsible for responding within the timelines required by applicable law. Pursor will assist you in fulfilling verified requests at no additional cost beyond ordinary support.

6. Security incidents

If Pursor becomes aware of a security incident involving Personal Information, we will notify you without undue delay and in any event within 72 hours of confirmation. The notification will include the nature of the incident, categories of data and individuals affected, likely consequences, and remediation steps. We will reasonably cooperate with your investigation and any regulatory reporting you are required to make.

7. Return & deletion of data

Upon termination of the Service, Pursor will, at your option and within 30 days of your request, return all Personal Information in a portable format or delete it. We may retain Personal Information beyond that window only where required by law (e.g., billing records, SMS consent logs) and only for the period required.

8. Audits and certifications

On reasonable written request and no more than once per year, Pursor will provide its current security documentation (SOC 2 Type II report, when available; ISO 27001 status; subprocessor list; security summary). Customers with elevated audit rights under applicable law may arrange an audit subject to reasonable confidentiality and scoping terms.

9. International transfers

If Personal Information transfers outside the European Economic Area, the United Kingdom, or other jurisdictions with cross-border restrictions, Pursor relies on the EU Standard Contractual Clauses (Module 2 or 3 as applicable) and the UK International Data Transfer Addendum. By executing the Service Agreement that incorporates this DPA, the parties are deemed to have signed the SCCs.

© 2026 Pursor, LLC. All rights reserved.
Terms of Service  ·  Privacy Policy