Files
docs/content/legal/dpa.md
2026-07-28 07:20:32 -05:00

8.3 KiB

Data Processing Agreement (DPA)

Arcline IT LLC Last updated: May 2026

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement ("MSA") between Arcline IT LLC ("Data Processor", "Arcline", "we", "us") and the Customer ("Data Controller", "you").


1. Definitions

Term Definition
Controller The entity that determines the purposes and means of processing personal data
Processor The entity that processes personal data on behalf of the Controller
Data Subject An identified or identifiable natural person
Personal Data Any information relating to an identified or identifiable natural person
Processing Any operation performed on personal data (collection, storage, retrieval, transmission, deletion, etc.)
GDPR Regulation (EU) 2016/679, the General Data Protection Regulation
CCPA California Consumer Privacy Act, as amended
Sub-processor A third party engaged by the Processor to process personal data

2. Scope and Purpose

2.1 Application

This DPA applies whenever Arcline processes personal data on behalf of Customer in the course of providing Services under the MSA.

2.2 Relationship

  • Customer is the Data Controller
  • Arcline is the Data Processor
  • Customer retains full control over their personal data
  • Arcline processes data only on Customer's documented instructions

2.3 Duration

This DPA remains in effect for as long as Arcline processes personal data on behalf of Customer, plus the duration of any data retention obligations.


3. Description of Processing

3.1 Categories of Data Subjects

  • Customer's employees, contractors, and agents
  • Customer's end users and website visitors
  • Individuals who communicate with Customer through their Arcline-hosted services

3.2 Categories of Personal Data

  • Account information: name, email address, billing address, phone number
  • Technical data: IP addresses, server access logs, browser user-agent strings
  • Content data: files, databases, emails, and other content stored on Arcline infrastructure at Customer's direction
  • Payment data: processed through Stripe (PCI-DSS compliant); Arcline does not store full credit card numbers

3.3 Special Categories of Data

Arcline does not intentionally process special categories of data (health information, biometric data, political opinions, religious beliefs, etc.). Customer agrees not to upload special category data to Arcline infrastructure without additional contractual safeguards.

3.4 Processing Activities

  • Storage: Customer data stored on Arcline's servers
  • Hosting: Serving Customer's websites and applications to visitors
  • Backup: Creating and maintaining backup copies for disaster recovery
  • Email: Routing and storing email messages (where applicable)
  • Support: Accessing data for troubleshooting and support purposes

4. Processor Obligations

4.1 Instructions

Arcline will process personal data only on documented instructions from Customer, unless required to do otherwise by applicable law (in which case Arcline will notify Customer of that legal requirement before processing, unless prohibited by law).

4.2 Confidentiality

Arcline ensures that all personnel authorized to process personal data have committed to confidentiality obligations.

4.3 Security

Arcline maintains appropriate technical and organizational security measures, including:

Technical Measures:

  • Encryption in transit (TLS 1.2+ for all services)
  • Firewalls with default-deny rules
  • Network segmentation (VLANs)
  • Regular security patching
  • Intrusion detection and prevention systems (Suricata)
  • Access logging and monitoring
  • Encrypted off-site backups

Organizational Measures:

  • Access control based on least privilege
  • Security training for personnel
  • Incident response procedures
  • Regular security assessments
  • Vendor due diligence for sub-processors

4.4 Sub-processors

Customer authorizes Arcline to engage the following sub-processors:

Sub-processor Service Location
Stripe, Inc. Payment processing United States
Let's Encrypt / ISRG SSL certificate issuance United States
GitLab B.V. CI/CD and source control United States/Europe

Arcline will notify Customer of any intended changes to sub-processors. Customer may object within 14 days. If reasonable objections cannot be resolved, Customer may terminate the affected services.

4.5 Data Subject Rights

Arcline will assist Customer in responding to data subject requests under applicable privacy laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object

Customer should forward any data subject requests they receive to privacy@arcline.it. Arcline will respond within the timeframe required by applicable law.

4.6 Data Breach Notification

In the event of a personal data breach, Arcline will:

  1. Notify Customer within 72 hours of becoming aware of the breach
  2. Provide details of the nature, scope, and impact of the breach
  3. Describe measures taken to address the breach
  4. Cooperate with Customer in notifying supervisory authorities and affected data subjects, where required

4.7 Data Protection Impact Assessments

Arcline will provide reasonable assistance to Customer in conducting data protection impact assessments, where required by applicable law.


5. International Transfers

5.1 Data Location

Customer data is primarily stored on servers located in the United States.

5.2 Adequacy

For transfers of personal data from the European Economic Area (EEA), Switzerland, or the United Kingdom to the United States, the parties agree that the Standard Contractual Clauses (SCCs) approved by the European Commission shall govern such transfers.

5.3 Alternative Mechanism

If the SCCs are deemed invalid or insufficient by a competent authority, Arcline will implement an alternative lawful transfer mechanism.


6. Data Retention and Deletion

6.1 During the Term

Customer data is retained for the duration of the MSA or until Customer requests deletion.

6.2 Upon Termination

Following termination of the MSA:

  • Active data: Deleted within 30 days of termination
  • Backups: Deleted within 90 days of termination
  • Access logs: Anonymized or deleted within 12 months

6.3 Deletion Procedures

Data is securely deleted using:

  • Secure file deletion (shred/overwrite) for files
  • DROP TABLE for SQLite databases
  • Cryptographic erasure for encrypted backups

6.4 Certificate of Deletion

Upon request, Arcline will provide a written certificate confirming that Customer's data has been securely deleted.


7. Audit and Compliance

7.1 Right to Audit

Customer may request an audit of Arcline's data processing operations, at Customer's expense, no more than once per 12-month period. Audits must:

  • Be conducted during normal business hours
  • Give at least 30 days notice
  • Not unreasonably interfere with Arcline's operations
  • Be performed by a mutually agreed independent auditor

7.2 Records of Processing

Arcline maintains written records of all processing activities conducted on behalf of Customer, as required by Article 30 of the GDPR.

7.3 Compliance

Arcline will promptly notify Customer if any instruction from Customer violates applicable data protection laws.


8. Liability

8.1 Liability Cap

Each party's liability under this DPA is subject to the limitations of liability set forth in the MSA.

8.2 Direct Damages

Notwithstanding the general limitation above, either party may seek direct damages for breaches of this DPA.

8.3 Regulatory Fines

Each party is responsible for administrative fines imposed on them by a supervisory authority for their own violations of applicable data protection law.


9. Governing Law

This DPA shall be governed by the same law as the MSA. Any dispute arising from this DPA shall be resolved under the dispute resolution provisions of the MSA.


10. Order of Precedence

In the event of any conflict or inconsistency between this DPA and the MSA, this DPA shall prevail with respect to data processing matters.


Questions about this DPA? Contact us at privacy@arcline.it