Data Processing Addendum
Effective date: August 31, 2026
1. Overview
This Data Processing Addendum (“DPA”) forms part of the agreement between a workspace customer (“Customer” or “Controller”) and Arco Labs LLC (“Arco Labs,” “we,” “us,” or “our”) governing the use of arcops (the “Services”). It applies where privacy law, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, or the CCPA, governs the personal data Customer submits to the Services. Capitalized terms not defined here have the meanings in our Terms of Service.
2. Roles
Customer decides what product, visitor, customer, inbox, billing, and Search Console data to connect and the purposes for which it is processed, and is the controller (or, in CCPA terms, the business) of that data. For that workspace data, Arco Labs processes it on Customer's documented instructions as a processor (or, in CCPA terms, a service provider) and does not sell it or use it for purposes other than providing the Services.
For account, login, billing, security, and direct support information about Customer's members and administrators, Arco Labs is the controller, as described in our Privacy Policy.
3. Details of processing
- Data subjects: Customer's members and administrators, and the individuals whose data Customer submits, including product users, site visitors, customers, and inbox correspondents.
- Categories of personal data: identity and contact details; product events, pageviews, sessions, and attribution fields; customer and revenue records; inbox messages and attachments; Search Console query and dimension data; agent actions, approvals, signals, and audit records.
- Purposes: providing the data, analytics, inbox, integration, event, and agent-operation surfaces that make up the Services, and securing and maintaining them.
- Retention: for the term of the agreement plus the retention periods described in our Privacy Policy, unless law requires otherwise.
4. Processor obligations
Where Arco Labs processes personal data as a processor, it will:
- process personal data only on Customer's documented instructions, unless required to do so by law, in which case it will inform Customer before processing unless law prevents it;
- ensure that persons authorized to process personal data are subject to confidentiality obligations;
- implement and maintain appropriate technical and organizational security measures as described in section 8;
- not engage a subprocessor without a contract that imposes at least the same obligations as this DPA;
- assist Customer with its obligations to respond to data subject requests, to the extent the request relates to Customer's workspace data and Arco Labs can lawfully do so;
- assist Customer with its obligations relating to security, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of the processing and the information available to Arco Labs; and
- delete or return personal data at the end of the Services in accordance with section 12, unless law requires retention.
5. Customer responsibilities
Customer must provide all notices and obtain all consents required by law for the data it submits, including for its tracker, identity, event, inbox, Stripe, and Search Console data, and must give Arco Labs lawful instructions for that data. Customer is responsible for the accuracy and lawfulness of the data it submits, for the decisions of the agents and people it authorizes to use the Services, and for its own role as controller or business under applicable privacy law.
6. Subprocessors
Customer authorizes Arco Labs to engage the following subprocessors. Each is bound by a contract that protects personal data to at least the standard of this DPA.
| Subprocessor | Service | What it processes |
|---|---|---|
| Neon, Inc. | Managed PostgreSQL database | Hosting of workspace and account data |
| Zeabur | Cloud application hosting (Hetzner region) | Hosting of the Services |
| Stripe, Inc. | Payment processing | Billing, subscription, and payment records |
| Google LLC | Google sign-in and Google Search Console API | Authentication and search analytics data |
| Cloudflare, Inc. | CDN, edge proxy, and inbound email routing | Delivery and protection of the Services; inbound inbox email |
| Resend | Transactional email delivery | Login codes and service notifications |
Integrations that Customer connects from its own accounts (for example PostHog, Slack, an email provider, or another analytics source) are Customer's processors, not Arco Labs's subprocessors, and remain governed by their own terms.
Arco Labs will provide notice of any intended change to this subprocessor list by updating this page.
7. International transfers
Personal data may be processed in the United States and other countries where Arco Labs and its subprocessors operate. This DPA does not by itself incorporate a transfer mechanism; where a customer needs Standard Contractual Clauses or another safeguard for its transfers, the parties can agree on the applicable terms in a signed order form.
8. Security measures
Arco Labs maintains technical and organizational security measures appropriate to the risk, including:
- encryption of data in transit over HTTPS;
- encryption at rest for sensitive integration credentials using AES-256-GCM;
- managed PostgreSQL infrastructure with access controls and encryption;
- organization and site access boundaries, per-organization API rate limits, and audit logging of privileged actions;
- verified webhook signatures and fail-closed tenant checks on data access; and
- segregated database access through a tenant-aware access layer.
9. Confidentiality
Arco Labs and any person authorized to process personal data under this DPA will keep that data confidential, except where disclosure is required by law or authorized by Customer.
10. Data breach
Arco Labs will notify Customer without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data processed under this DPA, where such notification is required by applicable law, and will provide reasonable information and assistance so Customer can meet its own notification obligations.
11. Audit
Upon Customer's written request and no more than once per year, Arco Labs will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality obligations and to Customer covering reasonable costs of any audit that goes beyond that information.
12. Return and deletion
At the end of the Services, upon Customer's request, Arco Labs will delete or return the personal data processed under this DPA in accordance with the retention and deletion practices in our Privacy Policy, unless applicable law requires retention. Deleting an individual login is separate from deleting a workspace, and does not silently delete workspace-owned data.
13. CCPA terms
For personal information subject to the California Consumer Privacy Act, Arco Labs processes that information as a service provider on Customer's behalf, will not retain, use, or disclose it for a purpose other than providing the Services (or as otherwise permitted by the CCPA), and will not combine it with personal information it receives from, or on behalf of, another person except as permitted by law. Arco Labs does not sell or share personal information and has no actual knowledge of any sale or sharing of personal information of anyone under 16.
14. Liability and governing law
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, and this DPA does not expand either party's aggregate liability beyond the limits in those Terms. This DPA is governed by the laws of the State of Wyoming and the dispute provisions of the Terms of Service apply.
15. Contact
Questions about this DPA, including subprocessor changes, can be sent to [email protected].
