Skip to content
pr
  • CourseCourse
  • The workThe work
  • Race dayRace day
  • CrewCrew
  • RacesRaces
  • Log inLog in
  • Course
  • The work
  • Race day
  • Crew
  • Races
  • Log in

Legal

Data Processing Addendum

Effective August 31, 2026

On this page

  1. 1. Definitions
  2. 2. Scope, Duration, and Order of Precedence
  3. 3. Nature and Purpose of Processing
  4. 4. Categories of Personal Data
  5. 5. Categories of Data Subjects
  6. 6. Controller and Processor Roles
  7. 7. Processing Instructions
  8. 8. Confidentiality
  9. 9. Security Measures
  10. 10. Subprocessors
  11. 11. Data Subject Requests
  12. 12. Personal Data Breach Notification
  13. 13. Deletion and Return of Data
  14. 14. Audits and Compliance Information
  15. 15. International Transfers
  16. 16. Assistance with Compliance
  17. 17. Liability
  18. 18. Governing Law
  19. 19. Execution and Incorporation
  20. 20. Annex A: Processing Details
  21. 21. Annex B: Technical and Organizational Measures

This Data Processing Addendum governs PR Run’s processing of personal data on behalf of a business customer (a race organization, coach, or team) that submits athlete data, and is incorporated into our Terms of Service. Individual athletes who use the Service for themselves are described in the Privacy Policy.

Definitions

  • Customer means the entity that executes or accepts this Data Processing Addendum (“DPA”) and uses the Service, including a race organization, coach, or team that submits athlete data.
  • Personal Data means any information relating to an identified or identifiable natural person that PR Run processes on behalf of Customer through the Service.
  • Service means the PR Run website, any future application, APIs, emails, course notes, training guidance, race-morning materials, and related services described in the Terms of Service.
  • Subprocessor means any third party engaged by PR Run to process Personal Data on behalf of Customer.
  • Data Protection Laws means all applicable laws relating to privacy and data protection, including the GDPR, UK GDPR, CCPA/CPRA, and other U.S. state privacy laws, as applicable to the processing.

Scope, Duration, and Order of Precedence

This DPA applies when PR Run, a company organized and existing under the laws of the State of Montana (“PR Run,” “Processor,” “we,” “us,” or “our”), processes Personal Data on Customer’s behalf through the Service. The DPA is intended for business customers that submit athlete data. Individual athletes who use the Service on their own behalf are described in the Privacy Policy, under which PR Run generally acts as a controller.

This DPA is effective upon execution, acceptance through account settings or checkout where enabled, or incorporation into an order form, and remains in effect for the duration of the Service agreement.

In the event of conflict between this DPA and the Terms, this DPA governs with respect to the processing of Personal Data. In the event of conflict between this DPA and an executed order form or enterprise agreement, the order form or enterprise agreement governs.

Nature and Purpose of Processing

PR Run processes Personal Data to provide course-specific training guidance and related performance services, including storage and analysis of course, fitness, and race data submitted by Customer, generation of training and race-morning materials, support, and security monitoring as configured by Customer through the Service.

Categories of Personal Data

  • Account and contact information for authorized users (name, email, role).
  • Athlete identifiers and training context submitted by Customer, which may include name, email, race, fitness summary, and related files.
  • Course, kit, crew, and race-morning notes that contain personal data.
  • Usage, support, and operational logs related to the Service.

Categories of Data Subjects

  • Customer employees, contractors, coaches, agents, and authorized users.
  • Athletes, crew, and other individuals whose personal data Customer submits.

Controller and Processor Roles

Customer is the controller (or equivalent) of Personal Data it submits to the Service. PR Run acts as processor (or service provider) except where PR Run acts as controller for its own account administration, security monitoring, product improvement using aggregated or de-identified data, and compliance activities as described in the Privacy Policy.

Processing Instructions

PR Run shall process Personal Data only on documented instructions from Customer, including through Customer’s configuration and use of the Service, unless required by applicable law. If PR Run is required by law to process Personal Data contrary to Customer instructions, PR Run shall inform Customer of that requirement before processing unless prohibited by law.

Customer is responsible for ensuring that its instructions comply with Data Protection Laws and that it has established an appropriate legal basis for processing, including notices to and consents from athletes as required.

Confidentiality

PR Run ensures that personnel authorized to process Personal Data are bound by written confidentiality obligations and receive appropriate training on data protection. PR Run maintains access controls limiting personnel access to Personal Data on a need-to-know basis.

Security Measures

PR Run implements and maintains appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. A summary of security measures is available on our Security page and in Annex B below.

Customer is responsible for configuring appropriate access within the Service and for the devices its users employ.

Subprocessors

Customer provides general authorization for PR Run to engage Subprocessors listed at https://pr.run/subprocessors. PR Run shall:

  • Impose data protection obligations on Subprocessors substantially similar to those in this DPA.
  • Provide at least thirty (30) days’ advance notice of intended additions or replacements of Subprocessors that process Customer Personal Data, by updating the Subprocessor list and, where contact information is available, by email notification.
  • Allow Customer to object to a new Subprocessor on reasonable grounds relating to data protection by notifying hi@pr.run within fifteen (15) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected Service upon written notice as the sole remedy.

PR Run remains liable to Customer for the performance of Subprocessor obligations.

Data Subject Requests

PR Run shall, taking into account the nature of processing, provide reasonable assistance to Customer in responding to data subject requests under Data Protection Laws, using available account tools where practicable. Customer is responsible for responding to data subjects. PR Run shall promptly notify Customer if it receives a request directly from a data subject unless prohibited by law.

Personal Data Breach Notification

PR Run shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. Notification shall include, to the extent reasonably available:

  • A description of the nature of the breach.
  • Categories and approximate number of data subjects and records affected.
  • Likely consequences of the breach.
  • Measures taken or proposed to address the breach and mitigate harm.
  • Contact information for PR Run’s data protection contact.

PR Run shall cooperate with Customer’s investigation and provide additional information as it becomes available. PR Run’s notification obligations do not constitute acknowledgment of fault or liability.

Deletion and Return of Data

Upon termination of the Service or upon Customer’s written request, PR Run shall delete or return Customer Personal Data according to the Terms and deletion procedures, unless retention is required by applicable law. Backup copies may persist for a limited period in accordance with PR Run’s backup retention schedule before being overwritten in the ordinary course.

Audits and Compliance Information

Upon Customer’s written request no more than once per twelve (12) month period, PR Run shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may include:

  • Descriptions of technical and organizational measures then in place, and any third-party audit report if and when one is available.
  • Completed security questionnaires for enterprise customers upon request.
  • Responses to reasonable written inquiries regarding PR Run’s processing practices.

On-site audits may be conducted no more than once per twelve (12) month period upon thirty (30) days’ prior written notice, during normal business hours, subject to confidentiality obligations, and at Customer’s expense. Customer shall minimize disruption to PR Run operations. PR Run may satisfy audit requests through written materials in lieu of on-site inspection where such materials address the scope of the request.

International Transfers

Where PR Run transfers Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision, PR Run shall implement appropriate safeguards, including the Standard Contractual Clauses approved by European Commission Decision 2021/914:

  • Module Two (Controller to Processor) where Customer is controller and PR Run is processor.
  • Module Three (Processor to Processor) for onward transfers to Subprocessors where applicable.

For UK transfers, the UK International Data Transfer Addendum applies as incorporated into the applicable SCCs. A copy of applicable transfer mechanisms may be requested from hi@pr.run. Hosting presently occurs in the United States.

Assistance with Compliance

PR Run shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities where required by Data Protection Laws, taking into account the nature of processing and information available to PR Run. Additional assistance beyond reasonable scope may be subject to separate fees.

Liability

Liability arising under or in connection with this DPA is subject to the limitations and exclusions set forth in the Terms, except where prohibited by applicable Data Protection Laws. Nothing in this DPA limits either party’s liability for breaches of Data Protection Laws to the extent such limitation is prohibited by law.

Governing Law

This DPA is governed by the laws of the State of Montana, without regard to conflict-of-law principles, except where Data Protection Laws require otherwise with respect to the processing of Personal Data.

Execution and Incorporation

This DPA is incorporated into the Terms by reference and applies automatically where Customer processes Personal Data through the Service as a business customer. Customers may request a countersigned version by contacting hi@pr.run. For questions regarding this DPA, contact hi@pr.run.

Annex A: Processing Details

  • Subject matter: provision of course-specific training guidance and related athlete performance services for trail and ultrarunning.
  • Duration: term of the Service agreement plus any post-termination retention period described herein.
  • Nature of processing: storage, retrieval, analysis of course and athlete data, generation of training and race-morning materials, support, security logging, and deletion.
  • Purpose: to provide the Service as configured by Customer, including helping athletes prepare for a specific course.

Annex B: Technical and Organizational Measures

PR Run maintains measures including, without limitation:

  • Encryption of data in transit using TLS/HTTPS.
  • Encryption at rest as provided by the hosting infrastructure provider (presently Vercel, Inc.).
  • Access limited to personnel with a need to know.
  • Application security headers and input validation as implemented on the Service.
  • Incident response procedures and a security contact at security@pr.run.
  • Regular review and update of security measures.

This Annex describes practical measures. It is not a third-party certification.

TRAIN FOR THE COURSE, NOT JUST THE DISTANCE

Product

The CourseKnowledgeThe WorkKitRace MorningThe CrewRacesFirst Access

Start

The CoursesContact
Alex Daniels

Alex Daniels

Founder

Legal

TermsPrivacyAcceptable UseCookiesDPASubprocessorsSecurity
pr

Subscribe

No spam.

pr.run
© 2026 PR.RUN

For those who ♥ to adv.entu.re

PR YOUR NEXT RUN