Legal · Data Processing Addendum

DPA, for review.
Send it to your DPO.

This page summarizes the data-processing terms Arcus expects to use for launch customers. It is not a signed legal artifact. Final DPA terms, SCCs, subprocessors, and security commitments are confirmed in signed customer paperwork.

EffectiveBy signed agreement
Versionlaunch draft
CounterpartyNamed in order form
Ownerprivacy@usearcus.ai

01Parties & scope

This Data Processing Addendum ("DPA") is a review draft for agreements between Customer and Arcus. It applies only when incorporated into a signed order form, MSA, or other written agreement.

It is not automatically countersigned by viewing this page. Launch customers receive the operative DPA during procurement or pilot setup.

If your DPO needs a signed copy, request the current packet from privacy@usearcus.ai.

02Definitions

Personal Data
As defined in GDPR Art. 4(1) and equivalent definitions under applicable Data Protection Laws.
Data Protection Laws
GDPR, UK GDPR, the UK Data Protection Act 2018, the Swiss FADP, the CCPA/CPRA, and any other privacy laws applicable to Customer's use of the Service.
Controller / Processor
As defined in GDPR; for CCPA, "Business" and "Service Provider" respectively.
Sub-processor
Any third party engaged by Arcus to process Personal Data in connection with the Service.
Personal Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed.
SCCs
The European Commission's Standard Contractual Clauses (Decision 2021/914 of 4 June 2021).

03Roles & instructions

Customer is the Controller (or, where Customer acts on behalf of another Controller, a Processor) of Customer Personal Data. Arcus is a Processor (sub-processor in the latter case).

Arcus will process Customer Personal Data only on Customer's documented instructions, including with regard to transfers, unless required to do otherwise by Union or Member State law to which Arcus is subject. Customer's documented instructions are: (a) the Agreement, (b) this DPA, (c) any in-product configuration Customer makes, and (d) any further written instructions Customer reasonably gives.

Arcus will inform Customer if, in its opinion, an instruction violates Data Protection Laws, and may suspend the offending processing pending resolution.

04Subject & nature of processing

The full description of subject-matter, duration, nature, purpose, types of data, and categories of data subjects is in Annex I. In summary:

  • Subject: Provision of the Arcus reasoning workspace, including ingesting Customer queries, executing them against Customer's data sources, generating answers, and persisting metadata.
  • Duration: The term of the Agreement plus any agreed retention period.
  • Nature: Hosting, querying, AI-assisted synthesis, storage, transmission, and deletion of Customer data.
  • Purpose: To deliver the Service and the value Customer pays for.

05Technical & organizational measures

Arcus implements and maintains the technical and organizational measures described in Annex II, including encryption in transit, encryption for stored platform data, tenant-scoped application access, audit logging, and an incident response runbook. Annual third-party penetration testing and SOC 2 Type II controls are on the security roadmap.

Arcus reviews these measures at least annually and may update them, provided the update does not materially weaken the level of protection. Material updates are communicated to admins.

Personnel authorized to process Personal Data are expected to be bound by confidentiality obligations and security training requirements defined in the signed agreement and internal policy.

06Sub-processors

Customer authorizes Arcus to engage the sub-processors listed in the signed agreement or current security packet.

Subprocessor notice, objection rights, and any termination rights are handled in the signed agreement.

Arcus remains responsible for the acts and omissions of its sub-processors as if they were its own.

07International transfers

For transfers from the EEA, the parties incorporate the SCCs (Module 2 where Customer is Controller; Module 3 where Customer is Processor), with the docking clause (Clause 7) included and the optional clauses selected as set out in Annex IV. Governing law is Ireland; supervisory authority is the Irish Data Protection Commission.

For transfers from the United Kingdom, the parties incorporate the UK Addendum to the SCCs (issued 21 March 2022), as if it formed part of this DPA.

For transfers from Switzerland, the SCCs apply with the modifications required by the Swiss FADP (DSG 2020) and the FDPIC's guidance.

Transfer impact assessment materials are provided when applicable during contract review.

08Assistance & data subject rights

Arcus provides Customer with admin workflows or support-assisted processes to access, export, correct, and delete Customer Personal Data inside the Service. Data subject request support timelines are defined in the signed agreement and applicable law.

Arcus assists Customer, taking into account the nature of the processing, with: (a) data protection impact assessments (Art. 35 GDPR), (b) prior consultation with supervisory authorities (Art. 36), and (c) responses to data subject requests forwarded by Customer.

If Arcus receives a request directly from a data subject relating to Customer Personal Data, Arcus will not respond on Customer's behalf and will, without undue delay, route the request to Customer.

09Breach notification

Arcus notifies Customer of a confirmed Personal Data Breach affecting Customer Personal Data without undue delay and according to the signed agreement and applicable law. The notice describes the nature of the breach, affected data where known, likely consequences, remediation steps, and the contact point at Arcus.

If full information is not yet available, Arcus provides what it has and supplements promptly.

Arcus does not consider every operational anomaly to be a breach. We tell you when there is one, in plain language, fast.

10Audits & certifications

Arcus is working toward SOC 2 Type II. Where attestation reports are available, they are provided under NDA on request via security@usearcus.ai.

Customer (or a mutually agreed third-party auditor) may, no more than once per twelve-month period and on 30 days' written notice, audit Arcus's compliance with this DPA. Audit scope is reasonable and limited to information necessary for the audit; audit costs are borne by Customer unless the audit reveals a material non-compliance, in which case Arcus bears them.

Where Customer's auditor requests information that Arcus reasonably considers sensitive, Arcus may provide redacted reporting or a controlled review process.

11Return & deletion

On termination of the Agreement, export, retention, deletion, and any deletion attestation are handled according to the signed agreement and applicable law.

Where retention is required by law (tax, accounting, audit), Arcus retains the minimum necessary data for the minimum necessary period and applies the same protections.

12CCPA service-provider terms

Where Arcus processes Personal Information of California residents on Customer's behalf, Arcus acts as a Service Provider under the CCPA/CPRA. Arcus will not:

  • Sell or share Personal Information.
  • Retain, use, or disclose Personal Information outside the direct business relationship between the parties.
  • Combine Personal Information received from Customer with Personal Information from any other source, except as permitted under §1798.140(ag)(1).
  • Process Personal Information for any "Business Purpose" other than those expressly identified in the Agreement.

Arcus certifies that it understands the restrictions in this §12 and will comply with them.

13General & signature

This DPA forms part of the Agreement and is governed by the same law and dispute resolution provisions, except that for transfers governed by the SCCs the SCCs' provisions on governing law and forum prevail.

If a court holds any provision of this DPA invalid, the remainder remains in force. If a conflict arises between the Agreement and this DPA, this DPA controls for matters relating to the protection of Personal Data; if a conflict arises between this DPA and the SCCs, the SCCs control.

This public page is not signed. Signature authority and counterparty details are provided in the operative agreement.

name
Provided in signed paperwork
title
Provided in signed paperwork
countersigned
Provided in signed paperwork
date
Provided in signed paperwork

Customer's signature is established by accepting the Agreement under which this DPA is incorporated, or by countersignature on a wet copy if Customer prefers.

14Annexes

The annexes are part of this DPA and are kept current at usearcus.ai/trust. A short summary of each:

Annex I — Description of processing

ItemDescription
Categories of data subjectsCustomer's authorized users; Customer's customers and prospects whose data appears in connected sources.
Categories of dataIdentifiers (name, email, SSO ID), commercial information (transactions, purchase history), internet activity (sessions, events), inferences derived therefrom, and any data Customer chooses to load.
Special-category dataNone unless Customer signs a HIPAA BAA. Customer is responsible for not loading prohibited data.
FrequencyContinuous, on-demand and scheduled.
RetentionAs described in §11 and the Privacy Policy.

Annex II — Security measures

Current launch controls include encryption in transit, encryption for stored platform data, tenant-scoped authorization, audit logging, rate limiting, environment-based secret handling, and operational incident response. SSO, SCIM, SIEM export, BYOK, PrivateLink, custom data residency, formal RTO/RPO commitments, and SOC 2 reports are available only when explicitly scoped or completed.

Annex III — Sub-processors

The current subprocessor list is provided during contract review. Categories may include hosting and database infrastructure, LLM inference, observability, billing, analytics, support, transactional email, and integration providers.

Annex IV — Transfer impact assessment summary

Available under NDA. Covers (a) the legal regime of the destination country, (b) the supplementary measures (encryption, key control, contractual no-disclosure terms, transparency reporting), (c) the practical likelihood of foreign-government access, and (d) Arcus's response policy to government requests, including challenging overbroad demands and notifying customers where lawful.

Need redlines or a signature?

Send your edits to privacy@usearcus.ai. Turnaround and signature process are handled during procurement.

Talk to legal →