PairRail Atlas
Privacy Security Subprocessors DPA
Back to home

Legal

Data Processing Terms

Last updated: September 25, 2026 · Operators of pairrail.com (“PairRail”)

These terms describe how PairRail processes Customer Content when you use Atlas. They supplement the Terms of Use and the Privacy Policy. They are not a substitute for an Enterprise order form. Counsel can request an executable DPA to sign once a contracting entity is on the paper.

1. Roles

You (the seller organization) are the controller of Customer Content you submit: catalogs, prices, evidence, workspace members, agent credentials metadata, and integration tokens. PairRail is the processor of that Customer Content. We process it only to provide Atlas, as you instruct through the product, or as required by law.

Account and billing data needed to run your PairRail subscription is processed as described in Privacy. Card numbers are handled by our payment partner, not stored by PairRail.

2. What we process

  • Workspace and catalog state (offers, versions, publication, policy).
  • Extraction inputs and model output when you run Gemini or agentic extract.
  • Protocol projections you choose to publish (UCP, MCP, A2A, ACP, UAP, and related feeds).
  • Quotes, access requests, deal-desk items, and audit events.
  • Optional connector tokens and the API payloads those connectors send or receive.
  • Operational telemetry and feedback as described in Privacy.

3. Instructions we will not take

We do not sell Customer Content. We do not use your price books to train a general public model. Extraction calls a configured provider for your workspace only. Published protocol endpoints expose what you publish. That is your instruction, not a PairRail listing.

4. Subprocessors

We use the providers on the Subprocessors page. Optional connectors you enable send data to your Stripe, Chargebee, HubSpot, merchant, or webhook endpoint.

5. Location and transfers

Default processing is in the United States on Google Cloud (us-central1), with Cloudflare at the edge, and other providers as listed. If you access Atlas from another country, Customer Content may be transferred to those locations. A different residency is an Enterprise contract term, not a self-serve toggle.

6. Security

We apply the administrative and technical measures described on the Security page. That page is a posture summary, not a SOC 2 report or a warranty.

7. Retention and deletion

  • Sandbox: about 14 days of activity history.
  • Pro: audit trail and catalog versions for 90 days, unless you still need them to run the live catalog.
  • Enterprise: retention can be extended under contract.

To offboard, email [email protected] from an owner seat and ask us to delete the workspace. We will take down published protocol surfaces for that seller, delete or anonymize Customer Content we no longer need to operate or defend the service, and confirm when the live copy is gone. Backups and security logs may remain for a limited period.

8. Assistance

We will help with reasonable requests that you need to answer your own data-subject or customer inquiries, to the extent the information sits in Atlas and you cannot pull it from the workspace yourself.

9. Executable Enterprise DPA

If you need a signed DPA (including SCCs or a UK addendum) on an order form, email [email protected]. We will issue it once the PairRail contracting entity is finalized, or attach these terms to your Enterprise paper in the meantime.

Formal legal entity name, registered address, and governing law will be added when finalized.

PairRail Atlas

Seller-side commercial truth and multi-protocol agent-readiness infrastructure.

© 2026 PairRail. All commercial responses are indicative and governed by seller policy.
Legal Terms of Use Privacy Policy Code of Conduct Acceptable Use Security Subprocessors DPA Cookie Notice
Support Support FAQ About Home