Compliance, security, and legal documentation for Pestle services
Last Updated: January 28, 2026
Pestle retains your data in accordance with our contractual obligations, legal requirements, and your instructions.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Information | Duration of account + 90 days | Contract |
| Compliance Data | Duration of account + 90 days | Contract |
| Evidence & Attachments | Duration of account + 90 days | Contract |
| Audit Logs | 7 years | Legal/Compliance |
| Billing Records | 7 years | Tax/Legal |
| Security Logs | 12 months | Security |
| Usage Analytics | 24 months | Legitimate Interest |
| Support Tickets | 3 years | Service Quality |
| Marketing Preferences | Until opt-out + 30 days | Consent |
Before account closure, you can export your data in standard formats (JSON, CSV, PDF) through the platform's export feature.
For customers who require a Data Processing Agreement (DPA) for GDPR or other regulatory compliance.
Enterprise customers can request a signed DPA by contacting sales@pestle.in. Our standard DPA is included in enterprise agreements.
Pestle implements comprehensive security measures to protect your data.
Annual security audit
Information security management
Compliant data processing
BAA available (Enterprise)
Background checks, security training, least privilege access
Regular scanning, penetration testing, bug bounty
Documented procedures, 24-hour breach notification
Disaster recovery, geographic redundancy
Pestle uses the following sub-processors to provide our Services:
| Sub-processor | Purpose | Location |
|---|---|---|
Amazon Web Services | Cloud infrastructure hosting | USA/EU |
Stripe | Payment processing | USA |
SendGrid | Transactional email | USA |
Sentry | Error monitoring | USA |
Intercom | Customer support | USA |
We notify customers of new sub-processors at least 30 days before engagement. Enterprise customers can subscribe to sub-processor update notifications.
You are the data controller; Pestle is the data processor.
Pestle is the data controller for account and billing information.
Processing necessary to provide the Services
Security, fraud prevention, service improvement
Tax records, audit logs
Marketing communications, optional analytics
EU residents can exercise their rights by contacting sales@pestle.in or through the platform's privacy settings.
For legal inquiries, DPA requests, or compliance questions: