PRIVACY POLICY
Pantera AI, Inc.
Effective Date: September 9, 2026
Last Updated: September 9, 2026
This version supersedes the Privacy Policy effective July 30, 2025.
This Privacy Policy explains how Pantera AI, Inc. ("Pantera", "we", "us") collects, uses, shares and safeguards personal information when you access Pantera-branded products or services, including the Pantera platform and related domains, applications, APIs and integrations (together, the "Service").
1. Roles and Contact
For personal information that our customers upload to or generate within the Service ("Customer Content"), the customer organization is the controller and Pantera acts as processor on that customer's documented instructions. For information we collect about visitors to our websites, prospective customers and account administrators, Pantera acts as controller.
Data protection contact: privacy@getpantera.com
Security contact: security@getpantera.com
Mailing address: Pantera AI, Inc., 1415 Coral Ridge Dr, Fort Lauderdale, FL 33304, United States
2. Information We Collect
Information you provide
· Account and profile information: name, business email, role, organization
· Authentication credentials and, where you choose to connect third-party systems, the credentials or tokens required for those integrations
· Billing and tax information
· Files, documents and other content you upload to the Service
Information collected automatically
· IP address, browser type, operating system, device identifiers and access timestamps
· Pages viewed, workflows executed, prompts submitted and outputs generated within the Service
· Cookies and similar technologies used for authentication, preferences, analytics and fraud prevention
Information from third parties
· Analytics providers, identity providers and the cloud platforms our customers authorize us to connect to
3. How We Use Information
· To operate the Service, authenticate users and provision access
· To execute the workflows and automations that customers configure
· To provide support, respond to requests and communicate about the Service
· To detect, investigate and prevent misuse, fraud and security incidents, and to enforce our Terms and Conditions
· To produce aggregated and de-identified analytics about how the Service performs
· To meet legal, accounting and tax obligations
4. AI Models and Training
Pantera does not train AI models. We do not use Customer Content to train, fine-tune or otherwise adapt any model, and we do not build models from customer data.
Where the Service relies on third-party model providers, we engage them on terms that prohibit the use of Customer Content to train, fine-tune or otherwise improve their models. We do not share Customer Content with any provider for training purposes.
Interaction data is used only to operate, secure and support the Service. Any such use is limited to the customer's own tenant unless the customer authorizes otherwise in writing.
Enterprise customers can request details of our model providers and the applicable contractual terms under a non-disclosure agreement, at privacy@getpantera.com.
5. How We Share Information
· Sub-processors. Vendors that process personal information on our behalf under written contract, limited to what is necessary to deliver the Service. Our current list of sub-processors is available on request at privacy@getpantera.com.
· Within the customer organization. Authorized users and administrators of the customer tenant.
· Legal and safety. Where required by law or legal process, or to protect the rights, property or safety of Pantera, our customers or the public.
· Business transfers. In connection with a merger, acquisition or sale of assets, subject to this Policy.
We do not sell personal information, and we do not allow third-party advertising networks to track users across our domains for their own advertising.
6. Where Data Is Hosted
The Service is hosted on Google Cloud Platform. Production data resides by default in the us-central1 region (Iowa, United States) and is replicated to the us-east1 region (South Carolina, United States) for redundancy and disaster recovery. Google Cloud data centers hold ISO/IEC 27001 certification.
7. Retention
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law.
· Account data: for the duration of the customer relationship and up to three years after the account is closed
· Customer Content: for the duration of the customer relationship plus 90 days, unless a longer period is required by contract or law
· Conversation and workflow logs: 24 months by default, configurable by tenant administrators
· Operational logs: 90 days on a rolling basis
· Security logs: 2 years
· Audit and compliance logs: 7 years
· Backups: daily retained 30 days, weekly 90 days, monthly 12 months and annual 7 years, in encrypted snapshots. Deletion requests are applied to production systems immediately and propagate to backups as those backups expire on the schedule above
· Aggregated and de-identified data: retained indefinitely, and not re-identified
8. Your Choices and Rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to receive a portable copy, and to withdraw consent. These rights apply under the GDPR (EEA and UK), the CCPA and CPRA (California), the LGPD (Brazil) and PIPEDA (Canada), among others.
· Account administrators can export data through the dashboard or the API
· You can unsubscribe from marketing communications at any time
· To exercise a right, or to appeal a decision on a request, write to privacy@getpantera.com. We respond within the period required by applicable law, and in any case within 30 days
If Customer Content is involved, we will refer the request to the customer organization that controls it and assist that customer in responding.
9. Security
· Encryption. TLS 1.2 minimum and TLS 1.3 preferred in transit. AES-256 at rest, with keys held in a managed key management service and rotated automatically every 90 days.
· Access control. Least privilege, multi-factor authentication for all production access, just-in-time provisioning for a limited duration, and quarterly access reviews.
· Tenant isolation. Customer data is logically segmented and access is enforced at both the application and database layers.
· Monitoring. Centralized audit logging and cloud security posture monitoring, with alerting on security-relevant events.
· Vulnerability management. Continuous vulnerability scanning and periodic security reviews. Independent third-party penetration testing is part of our security roadmap.
· Compliance program. Pantera operates a SOC 2 readiness program administered through Drata. No SOC 2 report has been issued as of the effective date of this Policy, and Pantera does not represent that it holds a SOC 2 certification.
10. Security Incidents and Breach Notification
Pantera maintains a documented incident response process. If we become aware of a personal data breach affecting Customer Content, we will notify the affected customer organization without undue delay and in any event within 72 hours of becoming aware, at the administrative contact on file.
The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed, and a point of contact. We will provide the information a customer reasonably needs to meet its own notification obligations, including under Article 33 of the GDPR and applicable state breach notification laws, and will cooperate with the customer's investigation.
Where Pantera is the controller, we notify the competent supervisory authority within 72 hours where required, and affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
11. International Transfers
Personal information is processed in the United States. For transfers from the EEA, the United Kingdom and Switzerland we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out transfer impact assessments where required. For transfers from Brazil we rely on the mechanisms permitted by the LGPD, and for Canada on PIPEDA.
12. Data Processing Agreement
Where the Service involves the processing of personal data on a customer's behalf, the parties execute Pantera's standard Data Processing Agreement, which governs the roles of the parties, the categories of data, the security measures, the sub-processors, the international transfer mechanisms and the assistance we provide with data subject requests. Requests at privacy@getpantera.com.
13. Children
The Service is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we delete it.
14. Changes to This Policy and Contact
We will post any change on this page and update the date above. For material changes we will give at least 15 days' advance notice by email to account administrators or by an in-product banner.
Questions, requests and complaints: privacy@getpantera.com
Pantera AI, Inc., 1415 Coral Ridge Dr, Fort Lauderdale, FL 33304, United States
You also have the right to lodge a complaint with your local supervisory authority.