Legal

Data Processing Addendum

Last updated August 1, 2026.

This Data Processing Addendum (“DPA”) forms part of the ProGrid Terms of Service between ProGrid (a Sucrane Group product, “Processor”) and the customer (“Controller”) for personal data processed by ProGrid on the Controller’s behalf.

1. Scope

ProGrid processes personal data solely to provide the Services described in the Terms: AI job pricing, materials search, demand intel, client agreements, and communications.

2. Roles

Controller determines purposes and means. Processor acts only on documented instructions from Controller.

3. Sub-processors

Current sub-processors: Supabase (database, auth, storage), Cloudflare (hosting, CDN), Google Cloud (AI inference for scan classification), Home Depot / Lowe’s / Amazon APIs (product search), NOAA & US Census (public data), Resend or equivalent (transactional email). Updated list: privacy@progrid.online.

4. Security

See Security. Encryption in transit (TLS 1.2+) and at rest, Postgres row-level security, least-privilege access, audit logging.

5. International transfers

Where personal data is transferred outside the EEA/UK, the parties rely on the Standard Contractual Clauses (Module Two — Controller to Processor) which are incorporated by reference.

6. Data subject rights

Controller can export or delete customer data at any time from Settings, or by emailing us. Processor assists within 30 days.

7. Breach notification

Processor notifies Controller without undue delay (target < 72 hours) after becoming aware of a personal data breach.

8. Deletion

Upon termination, Processor deletes or returns personal data within 60 days, subject to legal retention requirements.

For a signed copy, email privacy@progrid.online.