Legal
Data Processing Addendum
The processor commitments that apply to every paid workspace. Enterprise customers can sign a customer-specific version.
Version 2026-09 · Last updated September 4, 2026
1.Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”) and pmmRush, Inc.(“pmmRush”). It applies whenever pmmRush processes personal data contained in Customer’s workspace content (“Customer Personal Data”) on Customer’s behalf.
For Customer Personal Data, Customer is the controller (or a processor acting for its own controller) and pmmRush is the processor. For account, billing, and usage data about Customer’s users, pmmRush is an independent controller, as described in the Privacy Policy.
Enterprise customers may sign a customer-specific DPA that replaces this page. Where the terms “controller”, “processor”, “personal data”, and “processing” are used, they have the meaning given in the GDPR, the UK GDPR, and the CCPA as applicable.
2.Details of processing
- Subject matter
- Provision of the pmmRush platform: ingesting Customer documents, maintaining the Customer's product portfolio graph, and generating marketing assets from it.
- Duration
- The term of the Terms of Service plus the deletion period in section 8.
- Nature and purpose
- Hosting, storage, extraction, embedding, search, drafting, display, and export, as instructed by Customer through the Service.
- Categories of data subjects
- Customer's employees and contractors who use the Service; individuals named in Customer's uploaded content (for example product managers, customers, or prospects referenced in a roadmap or deck).
- Categories of personal data
- Names, business contact details, job titles, and any other personal data Customer chooses to include in uploaded content. Customer should not upload special-category data; the Service is not designed for it.
3.Customer instructions
pmmRush processes Customer Personal Data only on Customer’s documented instructions, which are the Terms of Service, this DPA, and Customer’s use of the Service’s features. pmmRush will tell Customer if it believes an instruction breaks data-protection law. pmmRush will not use Customer Personal Data for its own purposes; structural interaction metadata retained under the Terms is anonymized and contains no raw Customer content.
4.Confidentiality and staff
pmmRush limits access to Customer Personal Data to personnel and consultants who need it to provide the Service and who are bound by confidentiality obligations. Consultants delivering a purchased engagement act on pmmRush’s instructions under a written agreement.
5.Security measures
pmmRush maintains technical and organizational measures appropriate to the risk, including:
- tenant isolation enforced at the database layer with row-level security on every customer table;
- encryption of data in transit (TLS) and at rest;
- role-based access inside each workspace (admin, editor, viewer) and least-privilege access to production for pmmRush staff, with logging;
- AI processing only through providers under Zero Data Retention terms, with no plaintext prompt logging;
- a decoupled telemetry store so usage analytics never share infrastructure with customer content;
- backups with defined rotation, and change control through code review and automated tests.
6.Sub-processors
Customer authorizes pmmRush to engage the sub-processors listed at /sub-processors. pmmRush imposes data-protection obligations on each sub-processor at least as protective as this DPA and remains responsible for their performance. pmmRush will give at least 30 days’ notice of a new sub-processor. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro rata refund of prepaid subscription fees.
7.International transfers
pmmRush and its sub-processors process data in the United States. Where Customer Personal Data originates in the EEA, the UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (Module 2, controller to processor, or Module 3 as applicable), incorporated by reference, together with the UK International Data Transfer Addendum. Executed copies are available on request.
8.Assistance, audits, and deletion
- Data-subject requests: pmmRush forwards requests it receives about Customer Personal Data to Customer and helps Customer respond, using the Service’s export and deletion tools.
- Breach notice: pmmRush notifies Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data.
- Impact assessments: pmmRush provides reasonable information to help Customer with data-protection impact assessments and consultations with authorities.
- Audits: pmmRush answers reasonable security questionnaires and provides available third-party reports. Where those are insufficient to show compliance, Customer may audit once a year on 30 days’ notice, during business hours, without disrupting the Service.
- Deletion: on termination, or within 30 days of Customer’s written request, pmmRush deletes Customer Personal Data from active systems and from backups as they rotate, unless the law requires retention.
9.California
Where the CCPA applies, pmmRush acts as Customer’s service provider. pmmRush does not sell or share Customer Personal Data, does not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Service, and will notify Customer if it can no longer meet these obligations.
10.General
If this DPA conflicts with the Terms of Service, this DPA controls for the processing of Customer Personal Data. Liability under this DPA is subject to the limitations in the Terms. Requests under this DPA go to privacy@pmmrush.com.