1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Arcline Cloud Inc. ("Processor") and the customer ("Controller") for the processing of personal data. This DPA applies to all processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of Arcline Cloud's hosting services.
2. Definitions
For the purposes of this DPA, the following definitions apply in accordance with GDPR Article 4:
- Personal Data — any information relating to an identified or identifiable natural person ("Data Subject").
- Processing — any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Data Subject — an identified or identifiable natural person whose personal data is processed.
- Sub-processor — any third party engaged by the Processor to process personal data on behalf of the Controller.
3. Scope of Processing
The Processor processes personal data solely for the purpose of providing the hosting services described in the Terms of Service. The Processor does not process personal data for any other purpose unless instructed to do so by the Controller.
Categories of Data
- Account data — name, email address, billing information
- Application data — any personal data stored by the Controller's applications within Arcline Cloud containers and databases
- Usage data — server logs, performance metrics, access logs
Processing Activities
- Storage and hosting of application data
- Automated backups and disaster recovery
- Infrastructure monitoring and performance logging
4. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required to do so by applicable law.
- Ensure that all personnel authorised to process personal data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures to protect personal data. Details of our security practices are available on our Security page.
- Assist the Controller in responding to Data Subject requests, including requests for access, rectification, erasure, restriction of processing, data portability, and objection.
- Delete or return all personal data to the Controller upon termination of the service agreement, at the Controller's election.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.
5. Sub-processors
The Processor currently engages the following sub-processors:
- Cloudflare — CDN and DDoS protection
- Stripe — payment processing
- SendGrid — transactional email delivery
The Processor shall provide the Controller with at least 30 days' prior written notice before engaging any new sub-processor. The Controller may object to the appointment of a new sub-processor by notifying the Processor in writing within 14 days of receiving such notice. If the Controller objects, the parties shall work together in good faith to find a mutually acceptable resolution.
6. International Transfers
Personal data is processed in the United States. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, the Processor shall ensure that appropriate safeguards are in place. Standard Contractual Clauses (SCCs) are available upon request to provide adequate protection for international data transfers.
7. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach. The notification shall include:
- The nature of the personal data breach, including the categories and approximate number of Data Subjects and records affected
- The categories of personal data affected
- The likely consequences of the breach
- The measures taken or proposed to be taken to address the breach and mitigate its possible adverse effects
8. Term and Termination
This DPA shall be effective for the duration of the service agreement between the Controller and the Processor. Upon termination of the service agreement, the Processor shall delete all personal data within 30 days of account termination upon the Controller's written request, unless retention is required by applicable law.
9. Contact
For any questions or requests related to this Data Processing Agreement, please contact us at [email protected].