Last updated: March 6, 2026
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement ("Agreement") between ProcureLabs Pte. Ltd. ("Processor") and the entity subscribing to ProcureLabs services ("Controller"). Terms not defined herein shall have the meanings set forth in the Agreement or in Regulation (EU) 2016/679 ("GDPR").
The Processor shall process Personal Data solely for the purpose of providing the ProcureLabs procurement intelligence platform services as described in the Agreement. Categories of data subjects include Controller's employees, consultants, and authorized users. Categories of Personal Data include names, email addresses, job titles, organizational roles, IP addresses, and usage analytics.
The Controller grants general authorization for the Processor to engage sub-processors listed below. The Processor shall notify the Controller at least 30 days before adding or replacing sub-processors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | Singapore (AWS ap-southeast-1) |
| Supabase Inc. | Database and authentication | US |
| Stripe Inc. | Payment processing | US |
| Anthropic PBC | AI language model processing | US |
| OpenAI Inc. | AI language model processing | US |
| Sentry Inc. | Error monitoring | US |
| Resend Inc. | Transactional email delivery | US |
Current as of the date above. See /subprocessors for the live list.
Where Personal Data is transferred outside the European Economic Area, the Processor shall ensure adequate safeguards are in place, including: (a) EU Standard Contractual Clauses (Module 2: Controller to Processor) as approved by Commission Implementing Decision (EU) 2021/914; (b) binding corporate rules where applicable; or (c) transfers to countries with an adequacy decision by the European Commission.
The Processor shall notify the Controller without undue delay and in any event within 72 hours after becoming aware of a Personal Data breach. Notification shall include: (a) the nature of the breach including approximate number of data subjects affected; (b) the likely consequences of the breach; (c) measures taken or proposed to address the breach; (d) contact information for the Processor's data protection point of contact.
The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests within 30 calendar days. The platform provides self-service data export, account deletion (via offboarding workflow), and access review capabilities.
The Controller may audit the Processor's compliance with this DPA no more than once per calendar year, with 30 days' written notice. The Processor shall make available relevant compliance reports, certifications, and third-party audit summaries. Remote audits are preferred; on-site audits shall be conducted at the Controller's expense.
This DPA shall remain in effect for the duration of the Agreement. Upon termination, the Processor shall, at the Controller's election, return or delete all Personal Data within 30 days. Certification of deletion shall be provided upon request.
Enterprise customers can request a countersigned DPA by contacting support@procure-labs.com. We typically return signed DPAs within 2 business days.