This Data Processing Addendum ("DPA") is incorporated into the Terms of Service between you ("Customer") and Pursor, Inc. ("Pursor"). It governs Pursor's processing of "Personal Information" of your customers, contacts, or end users (collectively "Your Customers") through the Service.
For Personal Information of Your Customers:
Pursor will process Personal Information only:
Pursor will not sell or share Personal Information, will not use it for cross-context behavioral advertising, will not combine it with data from other sources for unrelated purposes, and will not use it to train general-purpose AI models.
Pursor engages the following subprocessors to provide the Service. You consent to their use. We will notify you at least 14 days before adding a new subprocessor or changing the role of an existing one, and you may object to material changes by contacting legal@pursor.co.
| Subprocessor | Purpose | Location |
|---|---|---|
| Anthropic, PBC | AI model inference | USA |
| Twilio, Inc. | SMS/MMS delivery, A2P 10DLC | USA |
| Amazon Web Services | Cloud hosting, database, storage | USA (us-east-1) |
| Stripe, Inc. | Payment processing | USA |
| Resend (or equivalent ESP) | Transactional email delivery | USA |
| Deepgram | Voice memo transcription | USA |
An up-to-date list is maintained at pursor.co/subprocessors. All subprocessors are bound by data protection terms substantially equivalent to those in this DPA.
Pursor implements and maintains appropriate technical and organizational measures including:
If one of Your Customers contacts Pursor directly to exercise their rights (access, deletion, correction, etc.), we will, unless legally required otherwise, route that request to you within 5 business days. You remain responsible for responding within the timelines required by applicable law. Pursor will assist you in fulfilling verified requests at no additional cost beyond ordinary support.
If Pursor becomes aware of a security incident involving Personal Information, we will notify you without undue delay and in any event within 72 hours of confirmation. The notification will include the nature of the incident, categories of data and individuals affected, likely consequences, and remediation steps. We will reasonably cooperate with your investigation and any regulatory reporting you are required to make.
Upon termination of the Service, Pursor will, at your option and within 30 days of your request, return all Personal Information in a portable format or delete it. We may retain Personal Information beyond that window only where required by law (e.g., billing records, SMS consent logs) and only for the period required.
On reasonable written request and no more than once per year, Pursor will provide its current security documentation (SOC 2 Type II report, when available; ISO 27001 status; subprocessor list; security summary). Customers with elevated audit rights under applicable law may arrange an audit subject to reasonable confidentiality and scoping terms.
If Personal Information transfers outside the European Economic Area, the United Kingdom, or other jurisdictions with cross-border restrictions, Pursor relies on the EU Standard Contractual Clauses (Module 2 or 3 as applicable) and the UK International Data Transfer Addendum. By executing the Service Agreement that incorporates this DPA, the parties are deemed to have signed the SCCs.