Legal · Data Processing Agreement

Data Processing Agreement

DRAFT — not yet legally reviewed. Final form will be provided via DocuSign on request. To execute, email trust@arendel.io.

1. Definitions

"Customer" means the entity that has entered into a Subscription Agreement with Arendel for use of the Service.

"Customer Data" means any data, content, or information that Customer or its Authorized Users upload to or generate within the Service.

"Personal Data" has the meaning given in applicable Data Protection Laws (including GDPR Article 4(1)).

"Data Protection Laws" means GDPR (Regulation 2016/679), UK GDPR, CCPA (Cal. Civ. Code §1798.100 et seq.), and any equivalent national or supra-national law applicable to the parties' processing of Personal Data.

"Sub-processor" means a third party engaged by Arendel to process Personal Data on its behalf. The current list is at /legal/sub-processors.

2. Roles

The parties acknowledge that, in respect of Customer Data, Customer is the Controller and Arendel is the Processor, except where Arendel acts as Controller for limited internal purposes (e.g. account administration, billing) where Arendel is the Controller.

3. Scope of processing

  • Subject matter: provision of the Arendel deal-management Service.
  • Duration: for the term of the Subscription Agreement plus any post-termination retention period.
  • Nature and purpose: hosting, processing, displaying, and transmitting Customer Data to authorized users of the Service.
  • Categories of data subjects: Customer's employees, contractors, advisors, deal counterparties, and any other natural persons whose Personal Data Customer chooses to upload.
  • Categories of Personal Data: identification data (names, emails, phone), professional data (job titles, firm affiliations), and any other categories Customer chooses to upload.

4. Arendel's obligations

Arendel shall:

  1. Process Personal Data only on documented instructions from Customer.
  2. Ensure personnel authorized to process Personal Data are subject to confidentiality obligations.
  3. Implement appropriate technical and organizational measures (Schedule 2).
  4. Assist Customer in fulfilling obligations to respond to data-subject requests under Data Protection Laws.
  5. Assist Customer with security incident response, data protection impact assessments, and consultations with supervisory authorities.
  6. Delete or return all Personal Data after the end of the provision of services, except where Union or Member State law requires retention.
  7. Make available to Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits.

5. Sub-processors

Customer hereby grants Arendel a general authorization to engage Sub-processors for the purpose of providing the Service. Arendel shall:

  1. Maintain an up-to-date list of Sub-processors at /legal/sub-processors.
  2. Notify Customer at least 30 days before adding or replacing any Sub-processor.
  3. Impose data protection obligations on Sub-processors that are no less protective than this DPA.
  4. Remain liable to Customer for any Sub-processor's failure to fulfill its obligations.

Customer may object to a new Sub-processor on reasonable grounds related to data protection. If the parties cannot resolve the objection within 30 days, either party may terminate the affected portion of the Service without penalty.

6. International transfers

Where Customer Data is transferred outside the customer's jurisdiction:

  • Transfers from the EEA, UK, or Switzerland to the United States are protected by the EU-US Data Privacy Framework where applicable, and by Standard Contractual Clauses (Module 2: Controller-to-Processor) attached as Schedule 1.
  • Enterprise customers may request EU data residency, in which case primary storage (Neon Postgres, Cloudflare R2) is pinned to EU regions and SCCs apply only to sub-processors that cannot offer EU residency.

7. Security incident notification

Arendel shall notify Customer without undue delay (and in any event within 72 hours of becoming aware) of any Personal Data Breach affecting Customer Data, providing:

  1. A description of the nature of the breach.
  2. The categories and approximate number of data subjects affected.
  3. The likely consequences of the breach.
  4. The measures taken or proposed to address the breach and mitigate its possible adverse effects.

8. Data-subject requests

Arendel shall provide reasonable assistance to Customer in responding to requests from data subjects under Articles 12-22 GDPR (or equivalent provisions). Self-service tools to fulfill most requests (export, deletion) are available within the Service at /settings/account for individual users and via Owner request for organization-wide exports.

9. Return or deletion of Customer Data

Upon termination of the Subscription Agreement, Arendel shall, at Customer's choice, return or delete all Customer Data within 30 days, unless Union or Member State law requires retention. Customer can initiate an organization-wide export at any time during the term via the Owner-only data export flow.

10. Audits

Customer may, upon at least 30 days' written notice and at its own expense, conduct an audit of Arendel's compliance with this DPA, no more than once per calendar year, during business hours and in a manner that does not unreasonably disrupt Arendel's operations. Customer agrees to accept Arendel's then-current SOC 2 Type II audit report (or equivalent) in lieu of an in-person audit, where commercially reasonable.

11. Liability

Each party's aggregate liability under this DPA is subject to the limitations of liability set out in the Subscription Agreement.

Schedule 1 — Standard Contractual Clauses

To be attached at execution. Module 2 (Controller-to-Processor), Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

Schedule 2 — Technical and organizational measures

See Arendel's Security page at /legal/security for the current set of technical and organizational measures, which are incorporated into this DPA by reference. Arendel may update these measures from time to time, provided that the updated measures are no less protective than those in effect at the time of execution.