Effective and last updated October 4, 2026
Data Processing Addendum
A framework for Pyramad’s processing of customer personal data on behalf of business customers.
Applies to: Business customers acting as data controllers
Roles and scope
This DPA applies when Pyramad processes personal data on a business customer’s behalf in providing the Services. The customer is controller or processor, as applicable, and Pyramad is its processor or subprocessor. The customer determines lawful instructions, purposes, data subjects, and data categories through use of the Services and any order or Project Agreement.
Processing obligations
Pyramad will process customer personal data only on documented instructions, including to provide and secure the Services, unless law requires otherwise; ensure authorized personnel are bound by confidentiality; and notify the customer if an instruction appears to violate applicable data-protection law, where required.
Security and incidents
Pyramad will maintain reasonable measures appropriate to risk and notify the customer without undue delay after confirming a personal-data breach affecting customer personal data, as required by law. Notice does not admit fault or liability.
Subprocessors and transfers
The customer authorizes use of subprocessors listed in the Subprocessors page. Pyramad will impose appropriate data-protection obligations and remain responsible as required by the applicable agreement and law. Required international transfer mechanisms will be incorporated once the parties and transfer routes are known.
Assistance, deletion, and audits
Taking into account the nature of processing, Pyramad will provide reasonable assistance with data-subject requests, security, impact assessments, and regulator consultations where legally required. On termination, Pyramad will delete or return customer personal data according to the Services and legal retention duties. Reasonable compliance information may be provided; intrusive audits require advance agreement, confidentiality, limited scope, and reimbursement unless law or a confirmed material breach requires otherwise.