Arch Grid
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData Processing Addendum

Data Processing Addendum

Effective July 1, 2026

For customers who need contractual data-processing commitments (e.g. for their own compliance program). This DPA supplements the Terms of Service and applies once signed or expressly incorporated by both parties.

This DPA is a template made available on request. It does not automatically apply to every account — it takes effect for a given Customer only once both parties expressly agree to incorporate it (for example, by countersigning or by referencing it in an order form). Contact hello@arch-grid.com to execute one for your Organization.

1. Definitions

Capitalized terms not defined here have the meaning given in the Arch Grid Terms of Service. "Personal Data," "Processing," "Controller," "Processor," and "Data Subject" have the meanings given under applicable Data Protection Law. "Data Protection Law" means all laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU/UK GDPR and U.S. state privacy laws such as the California Consumer Privacy Act (CCPA), as amended.

2. Roles of the Parties

Customer is the Controller (or "Business," under CCPA terminology) of Personal Data contained in Customer Content. Arch Grid is the Processor (or "Service Provider"), Processing that Personal Data solely on Customer's documented instructions, as set out in the Terms of Service and this DPA, and solely for the purpose of providing the Service.

3. Processing Instructions

Arch Grid will Process Personal Data only to provide, maintain, secure, and support the Service, to comply with Customer's documented instructions (which the Terms of Service and this DPA constitute), and as required by applicable law. Arch Grid will not sell Personal Data or retain, use, or disclose it for any purpose other than providing the Service, and will not combine Personal Data received from Customer with data from other sources except as permitted by Data Protection Law.

4. Personnel

Arch Grid limits access to Personal Data to personnel who need it to provide the Service and are bound by confidentiality obligations.

5. Subprocessors

Customer authorizes Arch Grid to engage the subprocessors listed below to Process Personal Data in connection with the Service. Arch Grid remains responsible for each subprocessor's compliance with the obligations of this DPA. Arch Grid will provide reasonable advance notice of any change to this list (for example, by updating this page) and, on request, will discuss any objection Customer has to a new subprocessor.

SubprocessorFunction
SupabaseDatabase, authentication, and file storage
VercelApplication hosting
PolarPayment processing (merchant of record)
Zoho ZeptoMailTransactional email delivery
SentryError and performance monitoring

6. Security Measures

Arch Grid implements technical and organizational measures designed to protect Personal Data, including: tenant-isolated data access controls (row-level security) so one Organization's data is not accessible to another absent an explicit cross-organization connection; encryption of data in transit; access controls limiting internal access to Personal Data; and reliance on infrastructure subprocessors' security certifications and controls for data at rest. Given Arch Grid's current stage as an early-stage company, Customer acknowledges that Arch Grid does not yet hold third-party security certifications (e.g., SOC 2) and should evaluate whether that meets Customer's own compliance requirements.

7. Assistance with Data Subject Requests

Where Arch Grid receives a request from a Data Subject relating to Personal Data Arch Grid Processes on Customer's behalf, Arch Grid will promptly redirect the request to Customer and will not respond except on Customer's instructions, unless required by law. Arch Grid will provide reasonable assistance to enable Customer to respond to Data Subject requests using the Service's existing functionality (for example, in-product data access, export, and deletion tools) and, beyond that, reasonable additional assistance on request.

8. Personal Data Breach Notification

Arch Grid will notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a Personal Data Breach affecting Customer's Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations. "Personal Data Breach" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

9. Data Return & Deletion

On termination of the Service, Arch Grid will, at Customer's choice and consistent with the Terms of Service, make Customer Content available for export for a reasonable period and thereafter delete or anonymize the remaining Personal Data, except where retention is required by law.

10. International Transfers

Where Processing Personal Data involves a transfer from the European Economic Area, United Kingdom, or Switzerland to a country not deemed to provide an adequate level of protection, the parties will rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses) to the extent applicable, incorporated by reference upon request.

11. Audit

On reasonable prior written notice, and no more than once per year absent a suspected Personal Data Breach or as required by a regulator, Arch Grid will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, which may include responding to a security questionnaire in lieu of an on-site audit.

12. Liability

Each party's liability arising out of this DPA is subject to the limitations of liability set out in the Terms of Service.

13. Term

This DPA remains in effect for as long as Arch Grid Processes Personal Data on Customer's behalf under the Terms of Service.

Questions about this document? Contact hello@arch-grid.com.
© 2026 Arch Grid LLC
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData Processing AddendumHome