Legal
Data Processing Addendum
The terms under which Pinevon processes personal data on behalf of business customers who use its products.
Version 0.2-draft · No effective date set yet · All legal documents
Draft — pending legal review. This document is a complete working draft prepared by the Pinevon team. It has not yet been reviewed by a lawyer and no effective date has been set. It describes how the service is actually built and operated today; bracket-free wording is deliberate, but jurisdiction-specific terms must be confirmed by qualified counsel before it is relied on.
1. Background and scope
This Data Processing Addendum (“DPA”) forms part of the agreement between Pinevon (“Processor”) and the business customer (“Controller”) that uses a Pinevon product to process personal data of its own customers, staff and contacts (“Customer Personal Data”). It applies to the extent data-protection law applies to that processing.
Where Pinevon determines its own purposes (for example securing accounts or billing) it acts as an independent controller as described in the Privacy Policy.
2. Roles and instructions
- The customer is the controller and Pinevon is the processor.
- Pinevon processes Customer Personal Data only on the customer’s documented instructions — the agreement, this DPA, and use of the product’s features — unless law requires otherwise, in which case it informs the customer where permitted.
- Pinevon tells the customer if it believes an instruction infringes data-protection law.
- The subject matter, duration, nature, purpose, types of data and categories of data subjects are set out in Annex 1.
3. Confidentiality
Pinevon ensures people authorized to process Customer Personal Data are bound by confidentiality and access it only as needed to deliver and support the service.
4. Security
Pinevon implements appropriate technical and organizational measures described in Annex 2, and keeps them appropriate to the risk. Each customer’s data is logically separated from every other customer’s, with access enforced in the database.
5. Subprocessors
The customer gives general authorization for the subprocessors on the Subprocessors page. Pinevon binds each to data-protection obligations no less protective than this DPA and remains responsible for their performance.
Pinevon gives at least 14 days’ notice before adding or replacing a subprocessor. The customer may object on reasonable data-protection grounds within that period; if it cannot be resolved, the customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. International transfers
Where Customer Personal Data is transferred to a country without an adequacy decision, Pinevon ensures an appropriate safeguard applies, such as standard contractual clauses, and will make the relevant clauses available on request.
7. Assistance with data-subject requests
Taking into account the nature of the processing, Pinevon assists the customer, through product features and on request, in responding to requests to exercise data-subject rights. If Pinevon receives such a request directly it forwards it to the customer and does not respond except to acknowledge it, unless instructed.
8. Personal-data breaches
Pinevon notifies the customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data, with the information it then has: the nature of the breach, likely consequences, measures taken and a contact. Notices go to the customer’s account owner email; customers can add a security contact. Pinevon security contact: security@pinevon.com.
9. Assistance, audits and records
- Pinevon assists with data-protection impact assessments and prior consultation where reasonably needed and relevant to its processing.
- Pinevon makes available information reasonably needed to show compliance with this DPA, and allows audits by the customer or its auditor no more than once a year (or after a breach) on reasonable notice, subject to confidentiality and without disrupting other customers. Pinevon may satisfy this through written responses or third-party reports where available.
10. Deletion and return
On termination, and at the customer’s request, Pinevon deletes or returns Customer Personal Data within 30 days, except where law requires retention. Backups are overwritten on their normal cycle. Customers can export their own data through product features before deleting it.
11. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the main agreement. If this DPA conflicts with the agreement on the processing of personal data, this DPA prevails.
Annex 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the customer’s chosen Pinevon product (for example Anchor). |
| Duration | For the term of the agreement plus the deletion period in section 10. |
| Nature and purpose | Hosting, storing, retrieving, transmitting and displaying data; generating AI-assisted replies from the customer’s own knowledge; support; security and abuse prevention. |
| Types of personal data | Names, email, phone numbers and messaging handles, conversation content, order and quotation details, delivery addresses, staff account data, and other data the customer chooses to submit. |
| Data subjects | The customer’s end customers and prospects, staff members, and other individuals whose data the customer submits. |
| Special-category data | Not intended. The customer must not submit special-category data unless the product expressly supports it. |
Annex 2 — Security measures
- Encryption of data in transit (TLS) and at rest by our infrastructure providers.
- Authentication through a dedicated identity provider with email verification, optional second factor and passkeys, session management and revocation.
- Access control enforced by row-level security in the database per business, role-based staff access, least privilege, and step-up re-authentication for sensitive actions.
- Audit logging of sensitive actions; append-only records for financial and ownership events.
- Secrets kept server-side and out of client code; provider keys rotated on suspicion of exposure.
- Separation of production and development environments; reviewed changes; automated tests including negative authorization tests.
- Backups and a documented recovery approach; incident response procedure with severity classification and post-incident review.
- Vendor review of subprocessors before use.
Pinevon does not currently hold SOC 2 or ISO 27001 certification.