Version 1.0 — Last updated: July 26, 2026
This Data Processing Addendum ("DPA") is incorporated by reference into the PGR Sonar Terms of Service (the "Terms") and applies between PGR Data Solutions Yaz. Tek. San. Dış Tic. Ltd. Şti. ("PGR", the data processor) and the organization that holds the PGR Sonar account ("Customer", the data controller). By registering for or using the PGR Sonar service (the "Service"), Customer accepts this DPA. If PGR and Customer have executed a separate written service agreement covering the processing of personal data, that agreement prevails over this DPA to the extent of any conflict.
PGR processes data from the Customer's Microsoft Power BI / Fabric tenant to provide governance, usage analytics, capacity monitoring and related insights. Processing consists of: scheduled synchronization of Power BI metadata (workspaces, reports, semantic models, apps, capacities, refresh and activity history), storage, aggregation, display in the Service, and — where enabled — generation of analytical insights and assistant responses using an AI subprocessor over metadata and aggregates.
For as long as Customer maintains an account. Upon account closure PGR hard-deletes synchronized tenant data and retains only minimal commercial records (subscription/billing history) as required by law.
PGR processes personal data only on documented instructions from Customer, including as configured by Customer in the Service (sync scope selection, retention window, AI enablement, AI person-level data opt-in), unless required otherwise by applicable law (in which case PGR informs Customer unless legally prohibited).
PGR ensures persons authorized to process personal data are bound by confidentiality obligations.
Customer provides general authorization for the subprocessors listed at docs.pgrdata.com/subprocessors (current list: Microsoft Azure, Anthropic PBC, Microsoft Graph). PGR will give 30 days' prior notice of additions or replacements; Customer may object on reasonable data-protection grounds, in which case the parties will seek a solution (including, for the AI subprocessor, disabling AI features for Customer's account).
Service data is hosted in the EU. Where the AI feature is enabled, metadata and aggregates are transferred to Anthropic PBC (USA) under a DPA incorporating the EU Standard Contractual Clauses; Anthropic does not use API data to train models and retains it for approximately 30 days. For Customers subject to Turkish law (KVKK), person-level data is transferred abroad only if Customer enables the person-level AI option, and the parties will execute the KVKK Board's Standard Contract before any such transfer begins.
Taking into account the nature of processing, PGR assists Customer with data-subject requests: per-user data can be located by identifier; account closure hard-deletes synchronized personal data; AI conversations (when the feature exists) are hard-deleted on user deletion request.
PGR notifies Customer without undue delay and within 48 hours of becoming aware of a personal data breach affecting Customer data, with the information reasonably required for Customer's own notification obligations.
PGR makes available information reasonably necessary to demonstrate compliance (this DPA, subprocessor terms, security summaries) and allows audits once per 12 months, on 30 days' notice, at Customer's cost, which may be satisfied by written responses and documentation where reasonable.
Upon termination, Customer may export available data via the Service; PGR then deletes personal data per Section 3 except where retention is legally required.
PGR may update this DPA from time to time (for example, to reflect a new subprocessor or improved security measures). Material changes are announced at least 30 days in advance via the Service or e-mail to account administrators; continued use of the Service after the effective date constitutes acceptance. The current version is always available at this page.
In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. If you have any questions about this DPA, please contact us at:
sonar@pgrdata.com
Annex I (parties, subject matter, processing details) is constituted by Sections 1–3 together with Customer's account records; Annex II (technical and organizational measures) is Section 6 above, expandable on request.