DATA PROCESSING ADDENDUM (DPA)

ARCC Systems | Effective: August 2026 | Governing State: Idaho


This Data Processing Addendum ("DPA") forms part of the agreement between ARCC Systems ("Processor") and the Client ("Controller") and governs the processing of personal data carried out by ARCC Systems on behalf of the Client in the course of delivering services.


1. DEFINITIONS


"Personal Data" means any information relating to an identified or identifiable individual, including but not limited to names, email addresses, phone numbers, and booking or transaction records.


"Processing" means any operation performed on personal data, including collection, storage, use, transmission, or deletion.


"Data Controller" means the Client, who determines the purposes and means of processing personal data.


"Data Processor" means ARCC Systems, which processes personal data on behalf of and under the instruction of the Client.


2. SCOPE OF DATA PROCESSING


ARCC Systems processes personal data solely to deliver the services described in the Client's subscription plan. This includes:

• Storing and managing client-side customer contact records within the CRM platform

• Sending automated SMS, email, and communication sequences on behalf of the Client

• Processing booking and appointment data

• Managing review request campaigns

• Operating automations (reminders, follow-ups, re-engagement)


Data is processed only as instructed by the Client or as required to deliver agreed-upon services.


3. ARCC SYSTEMS' OBLIGATIONS AS DATA PROCESSOR


ARCC Systems agrees to:

• Process personal data only on documented instructions from the Client

• Ensure that all personnel with access to personal data are bound by confidentiality obligations

• Implement reasonable technical and organizational security measures to protect personal data from unauthorized access, disclosure, or loss

• Not sell, share, or use Client customer data for any purpose outside of delivering the agreed-upon services

• Notify the Client without undue delay upon becoming aware of a personal data breach affecting Client data

• Assist the Client in responding to data subject rights requests (access, correction, deletion) where feasible

• Upon termination of services, return or delete Client personal data as requested, unless retention is required by law


4. CLIENT'S OBLIGATIONS AS DATA CONTROLLER


The Client, as Data Controller, is responsible for:

• Ensuring they have a lawful basis for collecting and sharing their customers' personal data with ARCC Systems

• Providing any required privacy notices to their own customers prior to data collection

• Ensuring the accuracy of personal data provided to ARCC Systems

¡ Instructing ARCC Systems on any data handling requirements specific to their business or jurisdiction


5. SUB-PROCESSORS


ARCC Systems may engage the following sub-processors to deliver services. All sub-processors are contractually bound to protect personal data in a manner consistent with this DPA:

• Stripe — payment processing

• Google — calendar, email, and GMB management

• Our CRM platform — contact management, automations, booking, and communications delivery


ARCC Systems will notify the Client of any material changes to sub-processor arrangements that may affect data handling.

6. DATA SECURITY


ARCC Systems maintains reasonable administrative, technical, and physical safeguards designed to protect personal data, including:

• Access controls limiting data access to authorized personnel

• Use of secure, password-protected platforms and tools

• Reliance on third-party infrastructure with industry-standard security certifications (e.g., Stripe's PCI compliance)


7. DATA RETURN & DELETION


Upon termination of services, ARCC Systems will, at the Client's written request:

• Provide an export of the Client's customer data in a commonly used format (e.g., CSV), OR

• Permanently delete Client personal data from our systems


This request must be made within 30 days of service termination. After that period, ARCC Systems may delete data at its discretion unless otherwise required by law.


Note: Customer data already retained in the Client's own Stripe account, Google Business Profile, or other Client-owned platforms is outside the scope of this DPA and remains under the Client's control at all times.


8. GOVERNING LAW


This DPA is governed by the laws of the State of Idaho and is incorporated into the Terms & Conditions agreed to by the Client at the time of subscription.



CONTACT

For data-related inquiries or requests:

[email protected]

ARCC Systems — Boise, Idaho

DATA PROCESSING ADDENDUM (DPA)

ARCC Systems

Effective: August 2026

Governing State: Idaho


This Data Processing Addendum ("DPA") forms part of the agreement between ARCC Systems ("Processor") and the Client ("Controller") and governs the processing of personal data carried out by ARCC Systems on behalf of the Client in the course of delivering services.


1. DEFINITIONS


"Personal Data" means any information relating to an identified or identifiable individual, including but not limited to names, email addresses, phone numbers, and booking or transaction records.


"Processing" means any operation performed on personal data, including collection, storage, use, transmission, or deletion.


"Data Controller" means the Client, who determines the purposes and means of processing personal data.


"Data Processor" means ARCC Systems, which processes personal data on behalf of and under the instruction of the Client.


2. SCOPE OF DATA PROCESSING


ARCC Systems processes personal data solely to deliver the services described in the Client's subscription plan. This includes:

• Storing and managing client-side customer contact records within the CRM platform

• Sending automated SMS, email, and communication sequences on behalf of the Client

• Processing booking and appointment data

• Managing review request campaigns

• Operating automations (reminders, follow-ups, re-engagement)


Data is processed only as instructed by the Client or as required to deliver agreed-upon services.


3. ARCC SYSTEMS' OBLIGATIONS AS DATA PROCESSOR


ARCC Systems agrees to:

• Process personal data only on documented instructions from the Client

• Ensure that all personnel with access to personal data are bound by confidentiality obligations

• Implement reasonable technical and organizational security measures to protect personal data from unauthorized access, disclosure, or loss

• Not sell, share, or use Client customer data for any purpose outside of delivering the agreed-upon services

• Notify the Client without undue delay upon becoming aware of a personal data breach affecting Client data

• Assist the Client in responding to data subject rights requests (access, correction, deletion) where feasible

• Upon termination of services, return or delete Client personal data as requested, unless retention is required by law


4. CLIENT'S OBLIGATIONS AS DATA CONTROLLER


The Client, as Data Controller, is responsible for:

• Ensuring they have a lawful basis for collecting and sharing their customers' personal data with ARCC Systems

• Providing any required privacy notices to their own customers prior to data collection

• Ensuring the accuracy of personal data provided to ARCC Systems

¡ Instructing ARCC Systems on any data handling requirements specific to their business or jurisdiction


5. SUB-PROCESSORS


ARCC Systems may engage the following sub-processors to deliver services. All sub-processors are contractually bound to protect personal data in a manner consistent with this DPA:

• Stripe — payment processing

• Google — calendar, email, and GMB management

• Our CRM platform — contact management, automations, booking, and communications delivery


ARCC Systems will notify the Client of any material changes to sub-processor arrangements that may affect data handling.

6. DATA SECURITY


ARCC Systems maintains reasonable administrative, technical, and physical safeguards designed to protect personal data, including:

• Access controls limiting data access to authorized personnel

• Use of secure, password-protected platforms and tools

• Reliance on third-party infrastructure with industry-standard security certifications (e.g., Stripe's PCI compliance)


7. DATA RETURN & DELETION


Upon termination of services, ARCC Systems will, at the Client's written request:

• Provide an export of the Client's customer data in a commonly used format (e.g., CSV), OR

• Permanently delete Client personal data from our systems


This request must be made within 30 days of service termination. After that period, ARCC Systems may delete data at its discretion unless otherwise required by law.


Note: Customer data already retained in the Client's own Stripe account, Google Business Profile, or other Client-owned platforms is outside the scope of this DPA and remains under the Client's control at all times.


8. GOVERNING LAW


This DPA is governed by the laws of the State of Idaho and is incorporated into the Terms & Conditions agreed to by the Client at the time of subscription.



CONTACT

For data-related inquiries or requests:

[email protected]

ARCC Systems — Boise, Idaho

© 2026 | All Rights Reserved | ARCC Systems