Arcops
FeaturesUse casesResourcesPricing
Start for $0

On this page

    Data Processing Addendum

    Effective date: August 31, 2026

    1. Overview

    This Data Processing Addendum (“DPA”) forms part of the agreement between a workspace customer (“Customer” or “Controller”) and Arco Labs LLC (“Arco Labs,” “we,” “us,” or “our”) governing the use of arcops (the “Services”). It applies where privacy law, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, or the CCPA, governs the personal data Customer submits to the Services. Capitalized terms not defined here have the meanings in our Terms of Service.

    2. Roles

    Customer decides what product, visitor, customer, inbox, billing, and Search Console data to connect and the purposes for which it is processed, and is the controller (or, in CCPA terms, the business) of that data. For that workspace data, Arco Labs processes it on Customer's documented instructions as a processor (or, in CCPA terms, a service provider) and does not sell it or use it for purposes other than providing the Services.

    For account, login, billing, security, and direct support information about Customer's members and administrators, Arco Labs is the controller, as described in our Privacy Policy.

    3. Details of processing

    • Data subjects: Customer's members and administrators, and the individuals whose data Customer submits, including product users, site visitors, customers, and inbox correspondents.
    • Categories of personal data: identity and contact details; product events, pageviews, sessions, and attribution fields; customer and revenue records; inbox messages and attachments; Search Console query and dimension data; agent actions, approvals, signals, and audit records.
    • Purposes: providing the data, analytics, inbox, integration, event, and agent-operation surfaces that make up the Services, and securing and maintaining them.
    • Retention: for the term of the agreement plus the retention periods described in our Privacy Policy, unless law requires otherwise.

    4. Processor obligations

    Where Arco Labs processes personal data as a processor, it will:

    • process personal data only on Customer's documented instructions, unless required to do so by law, in which case it will inform Customer before processing unless law prevents it;
    • ensure that persons authorized to process personal data are subject to confidentiality obligations;
    • implement and maintain appropriate technical and organizational security measures as described in section 8;
    • not engage a subprocessor without a contract that imposes at least the same obligations as this DPA;
    • assist Customer with its obligations to respond to data subject requests, to the extent the request relates to Customer's workspace data and Arco Labs can lawfully do so;
    • assist Customer with its obligations relating to security, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of the processing and the information available to Arco Labs; and
    • delete or return personal data at the end of the Services in accordance with section 12, unless law requires retention.

    5. Customer responsibilities

    Customer must provide all notices and obtain all consents required by law for the data it submits, including for its tracker, identity, event, inbox, Stripe, and Search Console data, and must give Arco Labs lawful instructions for that data. Customer is responsible for the accuracy and lawfulness of the data it submits, for the decisions of the agents and people it authorizes to use the Services, and for its own role as controller or business under applicable privacy law.

    6. Subprocessors

    Customer authorizes Arco Labs to engage the following subprocessors. Each is bound by a contract that protects personal data to at least the standard of this DPA.

    SubprocessorServiceWhat it processes
    Neon, Inc.Managed PostgreSQL databaseHosting of workspace and account data
    ZeaburCloud application hosting (Hetzner region)Hosting of the Services
    Stripe, Inc.Payment processingBilling, subscription, and payment records
    Google LLCGoogle sign-in and Google Search Console APIAuthentication and search analytics data
    Cloudflare, Inc.CDN, edge proxy, and inbound email routingDelivery and protection of the Services; inbound inbox email
    ResendTransactional email deliveryLogin codes and service notifications

    Integrations that Customer connects from its own accounts (for example PostHog, Slack, an email provider, or another analytics source) are Customer's processors, not Arco Labs's subprocessors, and remain governed by their own terms.

    Arco Labs will provide notice of any intended change to this subprocessor list by updating this page.

    7. International transfers

    Personal data may be processed in the United States and other countries where Arco Labs and its subprocessors operate. This DPA does not by itself incorporate a transfer mechanism; where a customer needs Standard Contractual Clauses or another safeguard for its transfers, the parties can agree on the applicable terms in a signed order form.

    8. Security measures

    Arco Labs maintains technical and organizational security measures appropriate to the risk, including:

    • encryption of data in transit over HTTPS;
    • encryption at rest for sensitive integration credentials using AES-256-GCM;
    • managed PostgreSQL infrastructure with access controls and encryption;
    • organization and site access boundaries, per-organization API rate limits, and audit logging of privileged actions;
    • verified webhook signatures and fail-closed tenant checks on data access; and
    • segregated database access through a tenant-aware access layer.

    9. Confidentiality

    Arco Labs and any person authorized to process personal data under this DPA will keep that data confidential, except where disclosure is required by law or authorized by Customer.

    10. Data breach

    Arco Labs will notify Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data processed under this DPA, where such notification is required by applicable law, and will provide reasonable information and assistance so Customer can meet its own notification obligations.

    11. Audit

    Upon Customer's written request and no more than once per year, Arco Labs will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality obligations and to Customer covering reasonable costs of any audit that goes beyond that information.

    12. Return and deletion

    At the end of the Services, upon Customer's request, Arco Labs will delete or return the personal data processed under this DPA in accordance with the retention and deletion practices in our Privacy Policy, unless applicable law requires retention. Deleting an individual login is separate from deleting a workspace, and does not silently delete workspace-owned data.

    13. CCPA terms

    For personal information subject to the California Consumer Privacy Act, Arco Labs processes that information as a service provider on Customer's behalf, will not retain, use, or disclose it for a purpose other than providing the Services (or as otherwise permitted by the CCPA), and will not combine it with personal information it receives from, or on behalf of, another person except as permitted by law. Arco Labs does not sell or share personal information and has no actual knowledge of any sale or sharing of personal information of anyone under 16.

    14. Liability and governing law

    Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, and this DPA does not expand either party's aggregate liability beyond the limits in those Terms. This DPA is governed by the laws of the State of Wyoming and the dispute provisions of the Terms of Service apply.

    15. Contact

    Questions about this DPA, including subprocessor changes, can be sent to [email protected].

    Product

    • How it works
    • Who it's for
    • Pricing

    Resources

    • Coding-agent bridge
    • Setup guide
    • Updates

    Company

    • Contact

    Legal

    • Terms
    • Privacy
    • DPA

    © 2026 arcops