Subprocessors
PGR Data Solutions (“PGR”) uses the following subprocessors to provide the PGR Sonar service. We notify customers of changes to this list per the Data Processing Addendum before engaging a new subprocessor.
Last updated: 2026-07-26
| Subprocessor | Purpose | Data involved | Location / region | Safeguards |
|---|---|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd.) |
Hosting: application containers, PostgreSQL database, Redis, static sites, Key Vault | All service data, including Power BI metadata, usage telemetry, and account/user records | North Europe (Ireland, EU) | Microsoft Products and Services DPA; EU hosting |
| Anthropic PBC | AI-generated insights and (future) assistant responses | Power BI metadata and aggregates only: report/model/workspace names, counts, statuses. No user identifiers by default — person-level data is sent only if the customer explicitly enables it in account settings. Never: credentials, service-principal secrets, raw database contents | United States | DPA incl. SCCs; API data is not used for model training; ~30-day retention |
| Microsoft Graph (Microsoft 365) |
Transactional email delivery (activation, lifecycle notices) from sonar@pgrdata.com | Recipient email addresses, notification content | Microsoft 365 (EU tenant) | Microsoft DPA |
Notes
- GeoIP (MaxMind GeoLite2) is not a subprocessor: the geo database is downloaded at build time and IP lookups run inside our own infrastructure; no visitor data is sent to MaxMind. Our public-site analytics are cookieless and store no IP addresses.
- Customer Power BI credentials (service-principal secrets) are encrypted at rest (Fernet) and never leave our Azure environment; they are structurally unreachable by the AI tool layer.
Questions about this list? Email sonar@pgrdata.com.