Browse all articles (65)
Security & Data

Is Pangram GDPR compliant?

Pangram's approach to GDPR.

Last reviewed Jul 24, 2026

Yes. Pangram treats the data you submit as personal data under the GDPR (Article 4(1)) and is built to be fully compliant.

What that means in practice

Purpose limitation and data minimization: We collect data only to run AI detection and show you your results. We never use it for marketing or to train our models, and we collect only what the service needs.

Your rights are supported: You can request access to your data, correction, deletion, or that we stop processing it. Just email privacy@pangram.com, and we'll handle it through our formal Data Subject Access Request (DSAR) process.

Documented compliance: We've completed a Data Protection Impact Assessment (DPIA) and maintain a Record of Processing Activities (RoPA) documenting the personal data we handle.

Standard Contractual Clauses: Pangram will sign GDPR Standard Contractual Clauses (SCCs) when needed for data transfers.

Breach notification: In the event of an incident, we notify data controllers within GDPR timelines — within 24 hours of suspicion, with a detailed follow-up within 72 hours.

One thing to know about data location

Pangram stores all data in the United States and does not collect or store data in the EEA. Compliance for international transfers is handled through SCCs and our broader privacy program rather than EEA-based hosting. For organizations with stricter requirements, we can set up custom hosting arrangements tailored to how and where your data is handled.

Questions?

For privacy requests or GDPR questions, contact privacy@pangram.com. Our full privacy policy is available at https://www.pangram.com/privacy-policy.html.