ARCC Systems | Effective: August 2026 | Governing State: Idaho
This Data Processing Addendum ("DPA") forms part of the agreement between ARCC Systems ("Processor") and the Client ("Controller") and governs the processing of personal data carried out by ARCC Systems on behalf of the Client in the course of delivering services.
1. DEFINITIONS
"Personal Data" means any information relating to an identified or identifiable individual, including but not limited to names, email addresses, phone numbers, and booking or transaction records.
"Processing" means any operation performed on personal data, including collection, storage, use, transmission, or deletion.
"Data Controller" means the Client, who determines the purposes and means of processing personal data.
"Data Processor" means ARCC Systems, which processes personal data on behalf of and under the instruction of the Client.
2. SCOPE OF DATA PROCESSING
ARCC Systems processes personal data solely to deliver the services described in the Client's subscription plan. This includes:
• Storing and managing client-side customer contact records within the CRM platform
• Sending automated SMS, email, and communication sequences on behalf of the Client
Data is processed only as instructed by the Client or as required to deliver agreed-upon services.
3. ARCC SYSTEMS' OBLIGATIONS AS DATA PROCESSOR
ARCC Systems agrees to:
• Process personal data only on documented instructions from the Client
• Ensure that all personnel with access to personal data are bound by confidentiality obligations
• Implement reasonable technical and organizational security measures to protect personal data from unauthorized access, disclosure, or loss
• Not sell, share, or use Client customer data for any purpose outside of delivering the agreed-upon services
• Notify the Client without undue delay upon becoming aware of a personal data breach affecting Client data
• Assist the Client in responding to data subject rights requests (access, correction, deletion) where feasible
• Upon termination of services, return or delete Client personal data as requested, unless retention is required by law
4. CLIENT'S OBLIGATIONS AS DATA CONTROLLER
The Client, as Data Controller, is responsible for:
• Ensuring they have a lawful basis for collecting and sharing their customers' personal data with ARCC Systems
• Providing any required privacy notices to their own customers prior to data collection
• Ensuring the accuracy of personal data provided to ARCC Systems
¡ Instructing ARCC Systems on any data handling requirements specific to their business or jurisdiction
5. SUB-PROCESSORS
ARCC Systems may engage the following sub-processors to deliver services. All sub-processors are contractually bound to protect personal data in a manner consistent with this DPA:
ARCC Systems will notify the Client of any material changes to sub-processor arrangements that may affect data handling.
6. DATA SECURITY
ARCC Systems maintains reasonable administrative, technical, and physical safeguards designed to protect personal data, including:
• Access controls limiting data access to authorized personnel
• Use of secure, password-protected platforms and tools
• Reliance on third-party infrastructure with industry-standard security certifications (e.g., Stripe's PCI compliance)
7. DATA RETURN & DELETION
Upon termination of services, ARCC Systems will, at the Client's written request:
• Provide an export of the Client's customer data in a commonly used format (e.g., CSV), OR
• Permanently delete Client personal data from our systems
This request must be made within 30 days of service termination. After that period, ARCC Systems may delete data at its discretion unless otherwise required by law.
Note: Customer data already retained in the Client's own Stripe account, Google Business Profile, or other Client-owned platforms is outside the scope of this DPA and remains under the Client's control at all times.
8. GOVERNING LAW
This DPA is governed by the laws of the State of Idaho and is incorporated into the Terms & Conditions agreed to by the Client at the time of subscription.
This Data Processing Addendum ("DPA") forms part of the agreement between ARCC Systems ("Processor") and the Client ("Controller") and governs the processing of personal data carried out by ARCC Systems on behalf of the Client in the course of delivering services.
1. DEFINITIONS
"Personal Data" means any information relating to an identified or identifiable individual, including but not limited to names, email addresses, phone numbers, and booking or transaction records.
"Processing" means any operation performed on personal data, including collection, storage, use, transmission, or deletion.
"Data Controller" means the Client, who determines the purposes and means of processing personal data.
"Data Processor" means ARCC Systems, which processes personal data on behalf of and under the instruction of the Client.
2. SCOPE OF DATA PROCESSING
ARCC Systems processes personal data solely to deliver the services described in the Client's subscription plan. This includes:
• Storing and managing client-side customer contact records within the CRM platform
• Sending automated SMS, email, and communication sequences on behalf of the Client
Data is processed only as instructed by the Client or as required to deliver agreed-upon services.
3. ARCC SYSTEMS' OBLIGATIONS AS DATA PROCESSOR
ARCC Systems agrees to:
• Process personal data only on documented instructions from the Client
• Ensure that all personnel with access to personal data are bound by confidentiality obligations
• Implement reasonable technical and organizational security measures to protect personal data from unauthorized access, disclosure, or loss
• Not sell, share, or use Client customer data for any purpose outside of delivering the agreed-upon services
• Notify the Client without undue delay upon becoming aware of a personal data breach affecting Client data
• Assist the Client in responding to data subject rights requests (access, correction, deletion) where feasible
• Upon termination of services, return or delete Client personal data as requested, unless retention is required by law
4. CLIENT'S OBLIGATIONS AS DATA CONTROLLER
The Client, as Data Controller, is responsible for:
• Ensuring they have a lawful basis for collecting and sharing their customers' personal data with ARCC Systems
• Providing any required privacy notices to their own customers prior to data collection
• Ensuring the accuracy of personal data provided to ARCC Systems
¡ Instructing ARCC Systems on any data handling requirements specific to their business or jurisdiction
5. SUB-PROCESSORS
ARCC Systems may engage the following sub-processors to deliver services. All sub-processors are contractually bound to protect personal data in a manner consistent with this DPA:
ARCC Systems will notify the Client of any material changes to sub-processor arrangements that may affect data handling.
6. DATA SECURITY
ARCC Systems maintains reasonable administrative, technical, and physical safeguards designed to protect personal data, including:
• Access controls limiting data access to authorized personnel
• Use of secure, password-protected platforms and tools
• Reliance on third-party infrastructure with industry-standard security certifications (e.g., Stripe's PCI compliance)
7. DATA RETURN & DELETION
Upon termination of services, ARCC Systems will, at the Client's written request:
• Provide an export of the Client's customer data in a commonly used format (e.g., CSV), OR
• Permanently delete Client personal data from our systems
This request must be made within 30 days of service termination. After that period, ARCC Systems may delete data at its discretion unless otherwise required by law.
Note: Customer data already retained in the Client's own Stripe account, Google Business Profile, or other Client-owned platforms is outside the scope of this DPA and remains under the Client's control at all times.
8. GOVERNING LAW
This DPA is governed by the laws of the State of Idaho and is incorporated into the Terms & Conditions agreed to by the Client at the time of subscription.