PurVago

PurVago — Data Processing Addendum (DPA)

Effective date: October 18, 2026 for accounts opened before September 18, 2026; on acceptance for accounts opened since · Last updated: September 23, 2026 · Previous versions

This Data Processing Addendum ("DPA") forms part of the Terms of Service (https://app.purvago.com/legal/terms) and applies where PurVago processes Customer Personal Data on behalf of the Customer in providing the Service and where such processing is subject to Data Protection Laws (U.S. state privacy laws such as the CCPA/CPRA and, to the extent they apply, other data-protection laws).

1. Definitions

Terms such as "controller," "processor," "data subject," "personal data," "processing," and "personal data breach" have the meanings in the applicable Data Protection Laws. "Customer Personal Data" means personal data within Customer Data. "Subprocessor" means a third party engaged by PurVago to process Customer Personal Data. "De-identified data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual.

2. Roles

The Customer is the controller (or a processor acting for a third-party controller) of Customer Personal Data, and PurVago is the processor (or subprocessor). For CCPA/CPRA, PurVago acts as a service provider. Each party will comply with its obligations under Data Protection Laws.

3. Scope & instructions

3.1 PurVago will process Customer Personal Data only (a) to provide, secure, and support the Service; (b) per the Customer's documented lawful instructions (including the Terms, this DPA, and configuration of the Service); and (c) as required by law (in which case PurVago will inform the Customer unless legally prohibited). 3.2 PurVago will notify the Customer if it believes an instruction violates Data Protection Laws (without obligation to provide legal advice). 3.3 The Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having a valid legal basis and required notices/consents. 3.4 Support access. The Customer instructs PurVago that authorized PurVago personnel may access the Customer's workspace, including by operating it with administrator permissions, where reasonably necessary to provide support the Customer has requested (for example, loading data the Customer has sent for import), to investigate and resolve a problem, or to respond to a security or abuse concern. Such access is limited to the purpose, is restricted to personnel bound by confidentiality obligations, and is recorded in an audit log available to the Customer's administrators. The Customer may narrow this instruction in writing, subject to PurVago's ability to provide the affected support and security services.

4. Confidentiality

PurVago ensures that personnel authorized to process Customer Personal Data are bound by confidentiality and process it only as needed.

5. Security

PurVago will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art and the risk. These measures are summarized in Annex II and include role-based access control, database row-level security enforcing tenant isolation, field-level restrictions on sensitive data, encryption of data at rest and in transit, authenticated APIs, logging/audit trails, and access minimization.

6. Subprocessors

6.1 The Customer provides general authorization for PurVago to engage Subprocessors to process Customer Personal Data. The current list is in Annex III, the Subprocessors list at https://app.purvago.com/legal/subprocessors. 6.2 PurVago will impose data-protection obligations on each Subprocessor that are substantially the same as those in this DPA and remains responsible for its Subprocessors' performance. 6.3 PurVago will give notice of intended additions or replacements of Subprocessors by email to the Customer's admin address and by a dated entry in the change log on the Subprocessors list at least 30 days before the change, and the Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve the objection; if unresolved, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees for it.

7. Data-subject requests

Taking into account the nature of processing, PurVago will provide reasonable assistance (including appropriate technical and organizational measures, and self-service tools in the Service) to help the Customer respond to data-subject requests. If PurVago receives a request directly, it will (unless legally required to act) refer the data subject to the Customer.

8. Assistance

PurVago will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations under Data Protection Laws, taking into account the information available to PurVago and the nature of processing.

9. Personal data breach

PurVago will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations. Notification is not an acknowledgment of fault.

10. Deletion & return

On termination or expiry of the Service, and at the Customer's choice, PurVago will delete or return Customer Personal Data (and delete existing copies) within 30 days after the later of termination or restoration of the Customer's export access, except to the extent retention is required by law or for permitted backup cycles, during which the data remains protected by this DPA. If the Customer's only owner deletes their own account in the Service, that is the Customer's instruction to delete all Customer Personal Data and uploaded files at once, without an export period; PurVago deletes them immediately, subject to the same legal-retention and backup-cycle exceptions.

11. Audits

PurVago will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, security, frequency, and cost conditions; PurVago may satisfy audit requests by providing third-party certifications or reports where available.

12. Location of processing

The Service is offered to businesses in the United States and Customer Personal Data is processed in the United States, except as noted on the Subprocessors list. PurVago does not intend to process personal data subject to the EU or UK GDPR. If the parties agree in writing to processing that requires a cross-border transfer mechanism under those laws, they will execute the appropriate standard contractual clauses before that processing begins.

13. CCPA/CPRA (service-provider terms)

PurVago will process personal information only to perform the Service under the Terms (the "business purpose"), and will not (a) sell or share it, (b) retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purpose, or (c) combine it with other personal information except as permitted by CCPA/CPRA. PurVago may create and use De-identified data as CCPA/CPRA permits; PurVago will not attempt to re-identify such data, will maintain it in de-identified form, and will contractually obligate any recipient to the same. PurVago certifies it understands and will comply with these restrictions.

14. Liability & precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In a conflict between this DPA and the Terms regarding personal-data processing, this DPA controls.


Annex I — Processing details

Annex II — Technical & organizational security measures (summary)

Access control and least-privilege roles; row-level security enforcing per-tenant isolation; field-level read/write restrictions on sensitive fields (e.g., property access codes and integration secrets); server-side re-verification of tenant ownership in privileged operations; authenticated APIs and webhook signature verification for payment events; encryption of data at rest and in transit; audit logging of security-relevant actions, including personnel support access to a Customer workspace; environment secret management; daily backups and recovery; personnel confidentiality; and vulnerability management.

Annex III — Subprocessors

The Subprocessors list at https://app.purvago.com/legal/subprocessors is incorporated into this DPA.