PandaDoc
US document automation platform with AI-powered proposal and contract creation
About PandaDoc
PandaDoc was founded in 2013 by Mikita Mikado and Serge Barysiuk (Belarusian founders) and is now headquartered in San Francisco with development centres across Europe and the Americas. The platform covers the full document workflow: AI-powered proposal and contract creation, template management, document editing, e-signatures (eIDAS and ESIGN compliant), payment collection, and analytics on document engagement. PandaDoc's AI features include AI-assisted document drafting, clause suggestions, content library recommendations, and a document summarisation capability that helps reviewers quickly parse lengthy contracts. The AI layer is powered by OpenAI, and PandaDoc has published that it uses OpenAI's enterprise API with zero-retention settings for AI-processed content. For European compliance teams, PandaDoc occupies a middle ground. The company is US-incorporated and subject to the CLOUD Act, but it has made meaningful investments in EU compliance. PandaDoc offers EU data residency (AWS eu-west-1) as a paid add-on for Business and Enterprise customers, and provides a GDPR-compliant DPA with SCCs. eIDAS-compliant electronic signatures are supported, making it suitable for EU-governed contract workflows. The company holds SOC 2 Type II certification. One historical consideration: PandaDoc has had significant development operations in Belarus, a country with complex geopolitical considerations for European businesses. The company has relocated and restructured these operations in response to the post-2020 political situation, but procurement teams with strict supply chain requirements may wish to verify the current state of development and data access from Belarusian entities. Pricing includes an Essentials plan at $19/user/month, a Business plan at $49/user/month, and Enterprise with custom pricing. The EU data residency add-on is available at Business and Enterprise tiers. For European sales, legal, and operations teams working on document automation, PandaDoc is a capable tool, but the EU data residency must be explicitly activated and contractually confirmed.
TrustKit Score Breakdown
?60% ModeratePricing
Subscription14-day trialQuick Facts
Frequently Asked Questions
Is PandaDoc GDPR compliant?
PandaDoc has a TrustKit compliance score of 60% (Moderate). Data Residency: EU data residency available as add-on for Business/Enterprise; US default on lower tiers. Legal Jurisdiction: US Delaware corporation; CLOUD Act applies; DPA with SCCs available; Belarusian dev history warrants supply chain review.
Where does PandaDoc store data?
PandaDoc hosts data in: US (default); EU available on Business/Enterprise. EU data residency available as add-on for Business/Enterprise; US default on lower tiers
Does PandaDoc train on user data?
PandaDoc: Not used for training. No training on customer documents; OpenAI zero-retention API for AI features; DPA available
What certifications does PandaDoc hold?
PandaDoc holds: SOC 2 Type II, GDPR. SOC 2 Type II certified; ISO 27001 not confirmed; eIDAS-compliant e-signatures