Pult Docs Pricing Get started

Data Processing Agreement

Last updated October 9, 2026

This agreement is part of the Terms of Service between Lantharos and the organization that uses Pult ("you"). It applies whenever personal data reaches Pult from your app or your team, and data protection law treats us as your processor. That law includes the EU and UK GDPR and the Swiss Federal Act on Data Protection. If you need a signed copy, write to legal@pult.sh.

Roles

You're the controller of the personal data your app sends to Pult and your team writes in it ("your personal data"). If you're processing it for someone else, you're a processor and we're your subprocessor. We're the processor, and we process your personal data only to provide Pult to you.

We're the controller for the account, session and billing information about the people in your organization. That's covered by our Privacy Policy, not by this agreement.

What we process

  • Purpose: running Pult for you. This means storing items, records and files, showing them to your team, triaging items, delivering requests to your app, sending notifications and keeping backups.
  • Whose data: your app's users, anyone else your app sends data about, and the people in your organization.
  • What data: whatever your definitions send. Typically this is identifiers, names, contact details, the content of messages and reports, account and usage details from your app, and uploaded files. Only send special categories of data, such as health data, when you have a lawful basis for it and actually need it.
  • For how long: while you use Pult, and until it's deleted as described below.

Your instructions

We process your personal data only on your documented instructions, unless the law requires otherwise, in which case we'll tell you first where we're allowed to. Your instructions are these terms, your definitions in code, your settings, and what your team does in the console and through the API. If we believe an instruction breaks data protection law, we'll tell you.

Confidentiality and security

Everyone at Lantharos who can access your personal data is bound to keep it confidential. We protect it with technical and organisational measures that fit the risk, including:

  • encryption in transit with TLS, and at rest in our databases and file storage;
  • a separate database for each environment, so one environment's data can't be read from another's;
  • signed requests between Pult and your app, so each side can verify the other;
  • roles that limit what each person and agent can see and do in each project;
  • sensitive values that stay hidden until revealed, with each reveal recorded;
  • an audit log of changes, approvals and reveals;
  • sign-in by passkey or by one-time email codes stored only as hashes, with no passwords;
  • rate limits on public endpoints;
  • continuous backups that can restore any point in the last 30 days.

Subprocessors

You authorise us to use these subprocessors:

Subprocessor What it does What it receives
Cloudflare, Inc. Hosts Pult, its databases and file storage, and delivers email All of your personal data in Pult
OpenRouter, Inc. Passes triage requests to the model Items from inboxes where you've turned on triage
TypeSafe Runs Jev, the model that answers triage questions Items from inboxes where you've turned on triage

Each subprocessor is bound by data protection terms at least as protective as this agreement, and we remain responsible for them. Before we add or replace one, we'll update this list and email your organization's admins at least 30 days ahead. If you object on reasonable data protection grounds and we can't resolve it together, you can cancel and we'll refund what you've paid for the remaining period.

International transfers

Your personal data may be processed outside the European Economic Area, including in the United States. Where data protection law requires it, transfers are made under the European Commission's Standard Contractual Clauses: module two between you as controller and us, and module three where you're a processor. The UK addendum and the Swiss amendments apply where needed. The clauses are part of this agreement. Where they conflict with it, the clauses take precedence.

Helping you

You can find, change and delete items in the console, and admins can delete them in bulk. Records stay in your own app, where you control them. If you need more help answering a request from a data subject, carrying out a data protection impact assessment, or talking to a supervisory authority, we'll help where we reasonably can. If a data subject contacts us directly about your personal data, we'll send them to you.

Breaches

If we become aware of a breach that affects your personal data, we'll tell your organization's admins without undue delay, and within 48 hours. We'll explain what happened, what data is affected, what we're doing about it, and how to reach us. We'll keep you updated as we learn more.

Deletion

Items and their timelines are deleted when your team deletes them, and timeline and audit history is deleted once it's older than your plan's history period. Files your app uploads are deleted within two days of the last item, occurrence or timeline entry that shows them going away, or of the last time anyone opened them if your app only shows them live. Deleting a project or an organization deletes everything in it straight away. If your organization stops using Pult without deleting it, we delete your personal data within 30 days of the end of your subscription or of your request. After that, it's gone from backups within a further 30 days. Before then, you can ask us for a copy.

Audits

We'll give you the information you reasonably need to show that we meet this agreement, including our subprocessors' security certifications and reports. If that isn't enough, or a supervisory authority asks, you can audit us once a year on 30 days' notice. The audit happens during business hours, under a confidentiality agreement and at your own cost.

Liability and term

The limits on liability in the Terms of Service apply to this agreement, except where data protection law doesn't allow them. This agreement lasts as long as we process your personal data for you.