DRAFT — not yet legally reviewed. Final form will be provided via DocuSign on request. To execute, email trust@arendel.io.
"Customer" means the entity that has entered into a Subscription Agreement with Arendel for use of the Service.
"Customer Data" means any data, content, or information that Customer or its Authorized Users upload to or generate within the Service.
"Personal Data" has the meaning given in applicable Data Protection Laws (including GDPR Article 4(1)).
"Data Protection Laws" means GDPR (Regulation 2016/679), UK GDPR, CCPA (Cal. Civ. Code §1798.100 et seq.), and any equivalent national or supra-national law applicable to the parties' processing of Personal Data.
"Sub-processor" means a third party engaged by Arendel to process Personal Data on its behalf. The current list is at /legal/sub-processors.
The parties acknowledge that, in respect of Customer Data, Customer is the Controller and Arendel is the Processor, except where Arendel acts as Controller for limited internal purposes (e.g. account administration, billing) where Arendel is the Controller.
Arendel shall:
Customer hereby grants Arendel a general authorization to engage Sub-processors for the purpose of providing the Service. Arendel shall:
Customer may object to a new Sub-processor on reasonable grounds related to data protection. If the parties cannot resolve the objection within 30 days, either party may terminate the affected portion of the Service without penalty.
Where Customer Data is transferred outside the customer's jurisdiction:
Arendel shall notify Customer without undue delay (and in any event within 72 hours of becoming aware) of any Personal Data Breach affecting Customer Data, providing:
Arendel shall provide reasonable assistance to Customer in responding to requests from data subjects under Articles 12-22 GDPR (or equivalent provisions). Self-service tools to fulfill most requests (export, deletion) are available within the Service at /settings/account for individual users and via Owner request for organization-wide exports.
Upon termination of the Subscription Agreement, Arendel shall, at Customer's choice, return or delete all Customer Data within 30 days, unless Union or Member State law requires retention. Customer can initiate an organization-wide export at any time during the term via the Owner-only data export flow.
Customer may, upon at least 30 days' written notice and at its own expense, conduct an audit of Arendel's compliance with this DPA, no more than once per calendar year, during business hours and in a manner that does not unreasonably disrupt Arendel's operations. Customer agrees to accept Arendel's then-current SOC 2 Type II audit report (or equivalent) in lieu of an in-person audit, where commercially reasonable.
Each party's aggregate liability under this DPA is subject to the limitations of liability set out in the Subscription Agreement.
To be attached at execution. Module 2 (Controller-to-Processor), Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
See Arendel's Security page at /legal/security for the current set of technical and organizational measures, which are incorporated into this DPA by reference. Arendel may update these measures from time to time, provided that the updated measures are no less protective than those in effect at the time of execution.