Data processing
Data processing terms.
These terms govern how Pharos processes personal data on your behalf. They define the roles, instructions, security measures, subprocessors, and deletion commitments that apply.
Draft, pending legal review. This document was written from what the software verifiably does. Every point marked in colour needs a decision from counsel before publication, and the document as a whole should be reviewed rather than adopted as written.
Roles
For workspace data retrieved from your connected providers and for the records you upload, you are the controller and [NEEDS COUNSEL: registered entity name] is the processor. For account and billing data about your own relationship with Pharos, we are the controller, as described in the privacy policy.
The applicable data protection laws, and the standard contractual clauses or equivalent mechanism incorporated for transfers, are [NEEDS COUNSEL: applicable law and transfer mechanism].
Processing schedule
- Subject matter
- Provision of AI spend reporting and analysis from provider billing and usage records.
- Duration
- For the term of the customer's use of Pharos, plus the deletion window in the privacy policy.
- Nature and purpose
- Retrieval of billing and usage aggregates from connected providers, normalization into a single ledger, storage, deterministic analysis, forecasting, and display to authorized workspace members.
- Categories of data subject
- The customer's workspace members, and any individual identified by a provider's own usage attribution, such as a team member associated with an API key.
- Categories of personal data
- Names, business email addresses, and job roles of workspace members. Provider-supplied member identifiers and per-member usage and cost aggregates. No prompt or completion content.
- Special category data
- None. Pharos is not designed to receive it and it should not be uploaded.
Instructions
Pharos processes personal data only on your documented instructions, which are these terms plus your configuration of the product: which providers you connect, which records you upload, whom you invite, and whether you opt into peer benchmarks. We will tell you if an instruction appears to conflict with applicable law.
Confidentiality and security
Personnel with access to personal data are bound by confidentiality obligations. The technical measures in place are described in full and in specifics on the security page: encryption of credentials at rest with AES-256-GCM, tenant isolation enforced by database row-level security, read-only provider scope, and rate-limited authentication.
Independent attestation is not yet held; the security page states this plainly rather than implying otherwise. Audit and inspection rights afforded to you are [NEEDS COUNSEL: audit and inspection rights].
Subprocessors
The current subprocessors are listed on the security page. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds. The notice period and objection procedure are [NEEDS COUNSEL: subprocessor notice period and objection procedure].
Assistance
We will assist you, taking into account the nature of the processing, with responding to data subject requests, with data protection impact assessments, and with consultations with a supervisory authority. Where a data subject contacts us directly about your workspace, we will refer them to you rather than act on it ourselves.
Breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available at the time and updates as the investigation proceeds. The committed notification window is [NEEDS COUNSEL: breach notification window, commonly 72 hours or less].
Return and deletion
On termination you may export your records. After the deletion window stated in the privacy policy, we delete personal data from active systems and, on the backup cycle, from backups. Deleting a provider connection removes its stored credential immediately.
Signing this agreement
For a counter-signed copy, or to run a security review or vendor questionnaire first, contact [NEEDS COUNSEL: monitored legal or security contact address]. This document was last revised on [NEEDS COUNSEL: publication date, set at review].