Version 2026.08.06 ยท Effective 2026-08-06
Data Processing Addendum
1. Introduction
This Data Processing Addendum ("DPA") forms part of the agreement between Pamphlet Inc. ("Processor") and Customer ("Controller") for Services that involve Processor's processing of Personal Data on Controller's behalf. This DPA applies when Processor processes Personal Data in Pam Pods at Controller's direction.
2. Roles and scope
Controller determines the purposes and means of processing Personal Data in Pam Pods. Processor processes such Personal Data only on documented instructions from Controller through product configuration, API use, and support requests.
Processor acts as an independent controller for account registration, billing, website analytics where applicable, security logging, and compliance data necessary to operate Pamphlet as a service provider.
3. Processing details
Subject matter: provision of the Pamphlet platform.
Duration: term of the agreement plus retention periods in the Privacy Policy.
Nature and purpose: hosting, organizing, transmitting, analyzing, and displaying Customer Content; providing AI-assisted and automated features configured by Controller; delivering email and campaign functionality; and maintaining security and audit logs.
Categories of data subjects: Controller's employees, contractors, prospects, customers, and other individuals whose Personal Data Controller uploads or generates in Pam Pods.
Categories of Personal Data: contact details, communication content, employment or role information, commercial interaction data, and other data Controller chooses to store in the Services.
4. Controller obligations
Controller will:
- Provide lawful instructions and lawful bases for processing
- Implement appropriate notices and consents for data subjects
- Configure roles, retention, and approval gates appropriately
- Not submit special category data unless permitted by law and agreed in writing
- Ensure Authorized Users comply with applicable privacy law
5. Processor obligations
Processor will:
- Process Personal Data only on documented Controller instructions unless required by law
- Ensure personnel with access are bound by confidentiality obligations
- Implement appropriate technical and organizational measures per the Security Policy
- Assist Controller with data subject requests, security incidents, and impact assessments where required by law, subject to reasonable fees for extensive requests
- Delete or return Personal Data at termination per the Privacy Policy and Controller instructions, subject to legal retention requirements
6. Subprocessors
Controller authorizes Processor to engage subprocessors listed at /legal/subprocessors. Processor will impose data protection obligations on subprocessors substantially similar to this DPA.
Processor will notify Controller of material subprocessor changes by updating the Subprocessor List at least thirty (30) days before the change takes effect where practicable. Enterprise customers with different notice requirements in an Order Form receive notice as specified. Controller may object on reasonable grounds relating to data protection; parties will work in good faith to resolve objections.
7. Security measures
Processor maintains measures including:
- Authentication and organization-scoped access through Clerk
- Database row-level security and application-level Pam Pod isolation
- TLS encryption in transit and provider encryption at rest
- AES-256-GCM encryption for connector and model credentials
- SHA-256 hashing for API keys
- HMAC verification for webhooks
- Append-only audit events for security-sensitive actions
Details are published in the Security Policy and Trust Center.
8. Security incidents
Processor will notify Controller without undue delay after confirming a Personal Data breach affecting Controller's Pam Pod data, and will provide information reasonably available to assist Controller's regulatory and data subject notifications. Notifications are sent to the organization owner email and cs@pamphlet.io contact on file unless another contact is specified in an Order Form.
9. Audits
Upon reasonable request and subject to confidentiality, Processor will make available information necessary to demonstrate compliance with this DPA, including summaries of security controls and subprocessors. Enterprise customers may receive additional audit cooperation per the Enterprise Addendum or Order Form. Onsite audits require mutual scheduling and may be subject to fees and frequency limits.
10. International transfers
Where Personal Data is transferred to countries without an adequacy decision, parties will implement appropriate safeguards required by applicable law. Pamphlet makes standard contractual clauses or equivalent transfer mechanisms available upon request via cs@pamphlet.io or as attached to an enterprise Order Form.
11. Retention and deletion
Processor deletes or returns Personal Data within thirty (30) days after verified termination of the applicable Pam Pod or agreement, unless legal hold, enterprise Order Form terms, or applicable law require longer retention. Security logs and billing records follow the schedules in the Privacy Policy.
12. Precedence
If this DPA conflicts with the Terms of Service regarding processing of Personal Data in Pam Pods, this DPA controls. If an executed Order Form or enterprise agreement contains additional data protection terms, those terms control to the extent of conflict for that Customer.
13. Contact
Data protection inquiries: cs@pamphlet.io
