Data Privacy & Security

Trust Matters: Pendo’s Commitment to You

At Pendo, performance, security and data privacy are first-order considerations, the north star for how we design our products and policies as an organization. We believe these principles need to be central to every decision we make, and everything we do as a company. That’s why we continue to make substantial investments in these areas to ensure that our solutions never negatively impact the integrity of your data, your users, or your application.

Meet Our DPO, Kate!

Kate Helin is Pendo’s data protection officer. A trained and licensed lawyer, Kate is responsible for defining and enforcing Pendo's privacy policies across the company. More about Kate here.

Certifications & Support

SOC 2

GDPR

Privacy Shield

Capabilities

Pendo has made extensive investments in data privacy and security, including:

Data Protection Officer

Data Protection Officer

Pendo has appointed a data privacy officer as the cross-functional company advocate for data privacy and security.

Privacy & Security Training

Privacy & Security Training

All Pendo employees are trained and certified on data privacy policies and best practices.

Vendor Audit & Approval Process

Vendor Audit & Approval Process

Pendo performs an extensive compliance review and approval process before licensing or using any third-party tools.

Data Encryption & Access Controls

Data Encryption & Access Controls

In transit and at rest, all customer data is encrypted using only industry-accepted tools, standards and best practices for data handling and security.

Role Based Permissions

Role Based Permissions

Pendo lets you set granular access controls to grant and restrict capabilities based on specific roles and authorities.

Audit Trails

Audit Trails

Pendo logs and stores every change, every action and every event, including the deletion of data, for easy auditing and root cause analysis.

Data Deletion Requests

Data Deletion Requests

Pendo supports data deletion requests for both the data we control and the data we process.

Data Segregation & PII

Data Segregation & PII

No customer data is ever commingled nor is customer-level information ever required to take advantage of the full feature set of Pendo products.

Resilience & Uptime

Resilience & Uptime

Pendo is designed for uninterrupted uptime and enterprise scale, processing millions of events per hour and billions per day, with no degradation of performance.

Looking Forward

Pendo continues to expand investment in areas of data privacy and compliance. In addition to the practices noted above, we have plans to pursue HIPAA and FedRAMP certifications in 2018.

Questions

For more information on security, privacy, and compliance please see our privacy policy, review the FAQs below, or contact us at gdpr@pendo.io for specific data privacy-related questions.

You can also download our engineering guide for best practices on deploying, configuring, and managing Pendo for maximum performance and security.

Privacy Policy Download Guide


Frequently Asked Questions

Where does Pendo store data?

Data submitted to Pendo, and Pendo’s application are hosted and stored in a secure, multi-tenant environment provided by Google’s Cloud Platform. Data is stored for each customer using separate Google AppEngine namespaces, and a variety of techniques for logical separation, to ensure that no data is co-mingled. Currently, the Google physical architecture that hosts Pendo is located in the United States.

Is the data encrypted?

All data hosted by Pendo is encrypted. Pendo uses industry-accepted encryption products to protect data at rest, with 256 bit AES encryption. All data transfers within the data center are secured by SSL. All of the Customer Data collected by Pendo is transmitted over SSL if the customer application is accessed via SSL.

Does Pendo collect any personally identifying
information?

The only identifying information that Pendo requires is a unique user ID for your end users. All other information is optional (but will provide for richer analysis and segmentation). Pendo does not collect any user-entered form field text in your application. You should avoid sending any of the following types of sensitive personal information to Pendo: government-issued identification numbers; specific financial information (such as credit or debit card numbers, any related security codes or passwords, and bank account numbers); information related to an individual’s physical or mental health; and information related to the provision or payment of health care.

How long does Pendo store customer information?

Pendo retains all customer data as long as you are an active subscriber. All data will be removed from Pendo starting 90 days after a subscription is cancelled. Pendo customers can request that specific records in their data be removed based on the request of an individual who is the subject of that data. Specific record removal may incur additional charges depending on your plan level.

Does Pendo support single sign on and/or 2-factor authentication?

You are in control of and responsible for user authentication. Access to Pendo requires an email address and password combination. We encourage you to use strong passwords. Alternatively, depending on your plan level, you can choose SAML for single sign-on or Google-based logins. Administrators can disable password-based logins, and require authentication through Google. Authentication through Google supports two factor authentication, as do many SAML implementations.

Is Pendo SOC 2 compliant?

Pendo has completed a SOC 2 Type 2 audit that included all five Trust Services Principles: Security, Availability, Processing Integrity, Confidentiality, and Privacy with no exceptions in related controls. In addition, Google AppEngine is SOC 2, SOC 3, ISO 27001, FISMA, and PCI compliant.

Is Pendo GDPR Compliant?

While there is no 3rd-party verified certification for GDPR compliance, Pendo is committed to acting in accordance with the GDPR regulations for all of our users - not just those in the EU. We are partnering with our customers to ensure the privacy and security of their and their customer’s data, and have implemented a number of data acquisition, access, and retention policy changes. See this article for additional detail about our GDPR support.

Does Pendo conduct security audits?

Pendo undergoes third-party penetration testing on an annual basis.

Will Pendo slow down my application?

Pendo is designed to minimize the impact on your application. The client-side agent is only about 50 Kb and loads asynchronously. Data transmissions are queued and sent to the server every 2 minutes. Data is compressed before sending so that each transmission is less than 2 Kb.

How is the client agent distributed?

The JavaScript code is hosted and deployed in Amazon’s Cloudfront Content Distribution Network (CDN), with an extremely broad network of servers and edge caching to ensure rapid loading times. Amazon service level agreements guarantee 99.9% uptime for the agent delivery.

How will guides and walk-throughs affect my
application?

Guides load with the Pendo agent. They will not be displayed until the current page is finished loading. The typical response time for guides is sub-second with guides almost always delivered in less than half a second.

© 2018 Pendo  |  Terms of Service  |  Privacy Policy

Let’s Get Started!

We’ll follow up straightaway to show you a quick product tour.

Sign Up for a Pendo Account!

Complete the form to register your free account.

Something went wrong, please try again.

Go Back
Close
Close Icon