Pioneer Data Processing Agreement (DPA)
Last updated: August 25, 2026
This DPA is incorporated into the Pioneer Terms of Service and applies automatically to customers on whose behalf Pioneer processes Personal Data. Customers who require a countersigned copy may contact privacy@pioneerclimate.com.
This Data Processing Agreement ("DPA") forms part of the agreement between Mycorrxyz Inc. dba Pioneer ("Pioneer") and Customer for the Pioneer service (the "Agreement"), and applies where Pioneer processes Personal Data subject to Data Protection Laws on Customer's behalf.
1. Definitions
Terms defined in the Pioneer Terms of Service apply. "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the GDPR, UK GDPR, and CCPA/CPRA, in each case as applicable. "Controller," "Processor," "processing," and "data subject" have the meanings given in Data Protection Laws.
2. Roles and Scope
2.1 Pioneer as Processor. For Personal Data in Customer Data, including account data of Authorized Users, contacts imported by Customer, and the lead and prospect records maintained in Customer's Organization, Customer is the Controller (or a processor acting for another controller) and Pioneer is a Processor acting on Customer's instructions.
2.2 Pioneer as Independent Controller. Pioneer acts as an independent Controller for: (a) its collection of Public Information from publicly available and licensed sources and its initial processing to provide research results; (b) Usage Data and Service Data; and (c) Pioneer's own business records (billing, support). Pioneer's processing as a Controller is described in the Pioneer Privacy Policy, including transparency and rights mechanisms for data subjects who are not Pioneer users.
2.3 Instructions. Pioneer will process Customer Personal Data only per Customer's documented instructions (the Agreement, this DPA, and use of the Service's features), unless required by law, in which case Pioneer will notify Customer unless legally prohibited.
3. Details of Processing (Annex I)
- Subject matter & duration: provision of the Service for the term of the Agreement plus the deletion period.
- Nature & purpose: hosting, storage, retrieval, analysis, AI-assisted research and generation, email delivery, support.
- Categories of data subjects: Authorized Users; Customer's professional contacts; prospected individuals (business leads); recipients of shares/invitations.
- Categories of Personal Data: name, business contact details (email, role, company), professional background and public web presence, imported contact records, usage and diagnostic data. No special categories are intentionally processed; Customer must not submit them.
4. Pioneer Obligations
4.1 Confidentiality. Persons authorized to process Customer Personal Data are bound by confidentiality obligations.
4.2 Security. Pioneer implements the technical and organizational measures described in the TOMs (Annex II), including: hosting exclusively on SOC 2 Type 2 certified infrastructure; encryption in transit (TLS 1.2+) and at rest (AES-256); passwordless authentication with no password storage; organization-scoped data isolation; least-privilege internal access with database audit logging; immediate in-product account deletion; and a prohibition on any use of Customer Data for AI model training. Pioneer will not materially decrease the overall security of the Service during the term.
4.3 Assistance. Taking into account the nature of processing, Pioneer will reasonably assist Customer with data subject requests, security, breach notification, and (where required) data protection impact assessments, by providing available information and the mechanisms described in this DPA.
5. Subprocessors
5.1 Customer provides general authorization for Pioneer's use of subprocessors listed in the Subprocessor List (Annex III).
5.2 Pioneer will update the Subprocessor List before adding or replacing subprocessors; the published list is the notice mechanism. Customer may object to a new subprocessor on reasonable data-protection grounds within 15 days of the update; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro-rata refund of prepaid unused fees.
5.3 Pioneer imposes data-protection obligations on subprocessors consistent with this DPA and remains responsible for their performance.
6. Data Subject Requests
6.1 If Pioneer receives a request from Customer's data subject relating to Customer Personal Data, Pioneer will forward it to Customer without undue delay and will not respond except to direct the data subject to Customer, unless legally required.
6.2 Requests from other individuals. If a person not associated with Customer (for example, someone appearing in research results) contacts Pioneer about Pioneer's own collection of Public Information, Pioneer handles that request itself; Customer is not involved.
7. Security Incidents
Pioneer will notify Customer without undue delay, and in any event within three (3) business days of becoming aware of a Security Incident affecting Customer Personal Data, providing available details of its nature, scope, and remediation measures, and will keep Customer reasonably informed.
8. International Transfers
Pioneer processes Personal Data primarily in the United States. Where Customer transfers Personal Data subject to European Data Protection Laws to Pioneer, the parties incorporate by reference the EU Standard Contractual Clauses (Module Two: Controller-to-Processor, and Module Three where applicable), with Customer as data exporter and Pioneer as data importer; Annexes are populated by Sections 3 (Annex I), the TOMs (Annex II), and the Subprocessor List (Annex III). The UK Addendum applies to UK transfers.
9. CCPA/CPRA
Where the CCPA applies, Pioneer acts as a "service provider" for Customer Personal Data: Pioneer will not sell or share it, retain, use, or disclose it outside the direct business relationship, or combine it except as permitted for service providers, and will comply with applicable obligations of the CCPA.
10. Audits and Information
Upon reasonable written request (no more than once per year, absent a Security Incident or regulator requirement), Pioneer will provide: written responses to reasonable security questionnaires, the current TOMs, and available summaries of its infrastructure providers' audit reports (e.g., SOC 2 reports of Supabase and Vercel). This satisfies audit rights to the extent permitted by law; on-site audits are not offered at Pioneer's current scale.
11. Deletion and Return
Upon termination of the Agreement or Customer's verified request, Pioneer will delete Customer Personal Data within thirty (30) days, except for backups (deleted per backup rotation) and records Pioneer must retain by law (retained under continued protection of this DPA). Export features permit Customer to retrieve Customer Data before termination.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Agreement.
Annex I: Details of Processing: Section 3 above. Annex II: Technical & Organizational Measures: TOMs. Annex III: Subprocessors: Subprocessor List.