Data Processing Agreement (DPA)
Version 1.0 · Last updated: 4 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Arkavio Ltd(“Arkavio”, “Processor”) and the customer (“Customer”, “Controller”). It governs Arkavio’s processing of personal data contained in Customer Data on the Customer’s behalf, and reflects the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018. Where the Terms and this DPA conflict in respect of personal-data processing, this DPA prevails.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the UK GDPR. “Sub-processor” means any third party engaged by Arkavio to process Customer personal data.
2. Roles of the parties
2.1 The Customer is the controller and Arkavio is the processor of the personal data within Customer Data described in Annex 1.
2.2 The Customer warrants that it has a lawful basis to provide that personal data (including third-party personal data such as its clients’ contacts and its staff) to the Service, and that its instructions comply with data protection law.
3. Processing details
3.1 Subject matter & duration.Processing for the duration of the Customer’s Subscription, plus the post-termination period in clause 11.
3.2 Nature & purpose. Hosting, storing, organising and making available Customer Data so the Customer can operate its practice (proposals, CRM, invoicing, fee/cashflow management, timesheets) — see Annex 1.
3.3 Instructions.Arkavio will process personal data only on the Customer’s documented instructions, which include the Terms, this DPA and the Customer’s use of the Service’s features, unless required by law (in which case Arkavio will inform the Customer unless legally prohibited).
4. Arkavio’s obligations
Arkavio will:
- (a) process personal data only as set out in clause 3;
- (b) ensure persons authorised to process the data are bound by confidentiality;
- (c) implement appropriate technical and organisational measures under Article 32 (see Annex 2);
- (d) respect the conditions in clauses 6–7 for engaging sub-processors;
- (e) assist the Customer by appropriate measures to respond to data-subject requests (Articles 12–23);
- (f) assist the Customer with its obligations under Articles 32–36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available;
- (g) at the Customer’s choice, delete or return personal data after the end of services (clause 11); and
- (h) make available information necessary to demonstrate compliance and allow for audits under clause 8.
5. Personal data breaches
Arkavio will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information the Customer reasonably needs to meet its own obligations (including, where relevant, notifying the ICO within 72 hours). Notifications go to the Customer’s account administrator and/or the contact the Customer provides.
6. Sub-processors — general authorisation
6.1 The Customer provides general authorisation for Arkavio to engage the sub-processors listed in Annex 3 to provide the Service.
6.2 Arkavio will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors’ performance.
6.3 Arkavio will give the Customer advance notice of any intended addition or replacement of a sub-processor (by updating Annex 3 and/or by notice), giving the Customer the opportunity to object on reasonable data-protection grounds.
7. International transfers
Where processing involves transferring personal data outside the UK, Arkavio will ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, and/or reliance on UK adequacy regulations — together with any additional safeguards required. See Annex 3 for sub-processor locations.
8. Audit
Arkavio will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer (who must not be a competitor of Arkavio), on reasonable prior notice, no more than once per year unless required by a supervisory authority or following a breach, and subject to confidentiality. Audits must not unreasonably disrupt Arkavio’s operations.
9. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
10. Conflicts and term
This DPA takes effect alongside the Terms and continues while Arkavio processes Customer personal data. In the event of conflict regarding personal-data processing, this DPA prevails over the Terms.
11. Return or deletion on termination
On termination, Arkavio will make Customer Data available for export for 30 days, then delete or anonymise it, except where retention is required by law (for example, financial records retained for 6 years to meet UK tax obligations), in which case the data remains protected under this DPA until deleted.
12. Contact
Data protection contact: Arkavio Ltd, 7 The Broadway, Wembley, London HA9 8JT — privacy@arkavio.com.
Annex 1 — Details of processing
| Categories of data subjects | The Customer’s clients and client contacts; the Customer’s staff/employees; the Customer’s project stakeholders |
| Categories of personal data | Names, business contact details (email, phone), job titles; staff cost data (salary, employment costs, rates); time recorded against projects; project and financial records that may contain personal data; the Customer's own bank account details (account name, sort code, account number) displayed on the invoices it issues — these can be personal data where the Customer is a sole trader or partnership |
| Special category data | None intended or requested. The Customer must not upload special-category data. |
| Nature of processing | Storage, hosting, organisation, retrieval, display, transmission, backup and deletion |
| Purpose | Providing the Arkavio Service (fee proposals, CRM, invoicing, fee/cashflow management, timesheets) to the Customer |
| Duration | Term of the Subscription plus the post-termination period in clause 11 |
Annex 2 — Technical and organisational measures (summary)
See the full Security overview. In summary, Arkavio applies:
- Tenant isolation via database row-level security (RLS); all data scoped by organisation.
- Access control — role-based access (director / manager / project architect / staff); least-privilege internal access; project-scoped access for project architects.
- Encryption — in transit (TLS) and at rest.
- Authentication — managed authentication provider; bot/abuse protection (Cloudflare Turnstile) on public forms; personal-email-domain blocking on sign-up.
- Monitoring — error/performance monitoring configured to minimise the personal data captured.
- Session replay — input-masked and consent-gated.
- Data minimisation — e.g. IP addresses hashed in consent records rather than stored raw.
- Backups — managed, regular backups via the hosting/database provider.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Personal data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All Customer Data, account data | UK/EU | UK adequacy / IDTA as applicable |
| Stripe | Subscription billing & payments | Billing contact, subscription identifiers (no full card data stored by Arkavio) | US | UK IDTA / SCCs |
| Resend | Transactional email delivery | Recipient email, email content (e.g. proposals/invoices) | US | UK IDTA / SCCs |
| PostHog | Product analytics & session replay (consent-gated) | Usage events, masked recordings | EU | UK adequacy (EU) |
| Sentry | Error & performance monitoring | Diagnostic data (personal data filtered) | US | UK IDTA / SCCs |
| Vercel | Application hosting & CDN | Data in transit, request logs | US | UK IDTA / SCCs |
| Cloudflare | Bot/abuse protection (Turnstile) on public forms | IP, user agent, challenge tokens | Global edge | UK IDTA / SCCs |
| Google Places API | Address autocomplete & lookup for practice/client addresses | Address text entered, IP | US | UK IDTA / SCCs |
| Adobe Fonts | Web font delivery | IP/request data for font loading | US | UK IDTA / SCCs |