Data Processing Agreement

Last updated: March 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Pyctura Inc. ("Processor") and the customer ("Controller") for the use of the Pyctura service. This DPA reflects the parties' agreement on the processing of personal data in accordance with GDPR and applicable data protection laws.

Definitions

Controller: the entity that determines the purposes and means of processing personal data. Processor: Pyctura Inc., which processes personal data on behalf of the Controller. Personal Data: any information relating to an identified or identifiable natural person. Processing: any operation performed on personal data.

Processing Details

Pyctura processes personal data solely to provide the service described in the Terms of Service. The nature of processing includes: storing account information; processing uploaded data files to generate reports; and logging usage data for service improvement.

Processor Obligations

Pyctura agrees to: process personal data only on documented instructions from the Controller; ensure persons authorized to process data are bound by confidentiality; implement appropriate technical and organizational security measures; assist the Controller in responding to data subject rights requests; delete or return all personal data upon termination; and make available all information necessary to demonstrate compliance.

Sub-Processors

Pyctura uses the following sub-processors: Supabase (database and storage), Vercel (hosting and CDN), Anthropic (AI analysis features). All sub-processors are bound by data processing agreements consistent with GDPR requirements.

Data Transfers

Personal data may be transferred to and processed in the United States and other countries where our sub-processors operate. Such transfers are conducted under appropriate safeguards including Standard Contractual Clauses where required.

Security Measures

Pyctura implements: TLS encryption for data in transit; encryption for data at rest; access controls and authentication; regular security reviews; and incident response procedures.

Data Breach Notification

Pyctura will notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Controller's data.

Termination

Upon termination of the agreement, Pyctura will delete all personal data belonging to the Controller within 30 days, unless retention is required by law.

Contact

DPA enquiries and data protection questions: hello@pyctura.ai