Arkavio
How it worksFeatures
Log inJoin

Data Processing Agreement (DPA)

Version 1.0 · Last updated: 4 June 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Arkavio Ltd(“Arkavio”, “Processor”) and the customer (“Customer”, “Controller”). It governs Arkavio’s processing of personal data contained in Customer Data on the Customer’s behalf, and reflects the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018. Where the Terms and this DPA conflict in respect of personal-data processing, this DPA prevails.

1. Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the UK GDPR. “Sub-processor” means any third party engaged by Arkavio to process Customer personal data.

2. Roles of the parties

2.1 The Customer is the controller and Arkavio is the processor of the personal data within Customer Data described in Annex 1.

2.2 The Customer warrants that it has a lawful basis to provide that personal data (including third-party personal data such as its clients’ contacts and its staff) to the Service, and that its instructions comply with data protection law.

3. Processing details

3.1 Subject matter & duration.Processing for the duration of the Customer’s Subscription, plus the post-termination period in clause 11.

3.2 Nature & purpose. Hosting, storing, organising and making available Customer Data so the Customer can operate its practice (proposals, CRM, invoicing, fee/cashflow management, timesheets) — see Annex 1.

3.3 Instructions.Arkavio will process personal data only on the Customer’s documented instructions, which include the Terms, this DPA and the Customer’s use of the Service’s features, unless required by law (in which case Arkavio will inform the Customer unless legally prohibited).

4. Arkavio’s obligations

Arkavio will:

  • (a) process personal data only as set out in clause 3;
  • (b) ensure persons authorised to process the data are bound by confidentiality;
  • (c) implement appropriate technical and organisational measures under Article 32 (see Annex 2);
  • (d) respect the conditions in clauses 6–7 for engaging sub-processors;
  • (e) assist the Customer by appropriate measures to respond to data-subject requests (Articles 12–23);
  • (f) assist the Customer with its obligations under Articles 32–36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available;
  • (g) at the Customer’s choice, delete or return personal data after the end of services (clause 11); and
  • (h) make available information necessary to demonstrate compliance and allow for audits under clause 8.

5. Personal data breaches

Arkavio will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information the Customer reasonably needs to meet its own obligations (including, where relevant, notifying the ICO within 72 hours). Notifications go to the Customer’s account administrator and/or the contact the Customer provides.

6. Sub-processors — general authorisation

6.1 The Customer provides general authorisation for Arkavio to engage the sub-processors listed in Annex 3 to provide the Service.

6.2 Arkavio will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors’ performance.

6.3 Arkavio will give the Customer advance notice of any intended addition or replacement of a sub-processor (by updating Annex 3 and/or by notice), giving the Customer the opportunity to object on reasonable data-protection grounds.

7. International transfers

Where processing involves transferring personal data outside the UK, Arkavio will ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, and/or reliance on UK adequacy regulations — together with any additional safeguards required. See Annex 3 for sub-processor locations.

8. Audit

Arkavio will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer (who must not be a competitor of Arkavio), on reasonable prior notice, no more than once per year unless required by a supervisory authority or following a breach, and subject to confidentiality. Audits must not unreasonably disrupt Arkavio’s operations.

9. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

10. Conflicts and term

This DPA takes effect alongside the Terms and continues while Arkavio processes Customer personal data. In the event of conflict regarding personal-data processing, this DPA prevails over the Terms.

11. Return or deletion on termination

On termination, Arkavio will make Customer Data available for export for 30 days, then delete or anonymise it, except where retention is required by law (for example, financial records retained for 6 years to meet UK tax obligations), in which case the data remains protected under this DPA until deleted.

12. Contact

Data protection contact: Arkavio Ltd, 7 The Broadway, Wembley, London HA9 8JT — privacy@arkavio.com.


Annex 1 — Details of processing

Categories of data subjectsThe Customer’s clients and client contacts; the Customer’s staff/employees; the Customer’s project stakeholders
Categories of personal dataNames, business contact details (email, phone), job titles; staff cost data (salary, employment costs, rates); time recorded against projects; project and financial records that may contain personal data; the Customer's own bank account details (account name, sort code, account number) displayed on the invoices it issues — these can be personal data where the Customer is a sole trader or partnership
Special category dataNone intended or requested. The Customer must not upload special-category data.
Nature of processingStorage, hosting, organisation, retrieval, display, transmission, backup and deletion
PurposeProviding the Arkavio Service (fee proposals, CRM, invoicing, fee/cashflow management, timesheets) to the Customer
DurationTerm of the Subscription plus the post-termination period in clause 11

Annex 2 — Technical and organisational measures (summary)

See the full Security overview. In summary, Arkavio applies:

  • Tenant isolation via database row-level security (RLS); all data scoped by organisation.
  • Access control — role-based access (director / manager / project architect / staff); least-privilege internal access; project-scoped access for project architects.
  • Encryption — in transit (TLS) and at rest.
  • Authentication — managed authentication provider; bot/abuse protection (Cloudflare Turnstile) on public forms; personal-email-domain blocking on sign-up.
  • Monitoring — error/performance monitoring configured to minimise the personal data captured.
  • Session replay — input-masked and consent-gated.
  • Data minimisation — e.g. IP addresses hashed in consent records rather than stored raw.
  • Backups — managed, regular backups via the hosting/database provider.

Annex 3 — Sub-processors

Sub-processorPurposePersonal data processedLocationTransfer safeguard
SupabaseDatabase, authentication, file storageAll Customer Data, account dataUK/EUUK adequacy / IDTA as applicable
StripeSubscription billing & paymentsBilling contact, subscription identifiers (no full card data stored by Arkavio)USUK IDTA / SCCs
ResendTransactional email deliveryRecipient email, email content (e.g. proposals/invoices)USUK IDTA / SCCs
PostHogProduct analytics & session replay (consent-gated)Usage events, masked recordingsEUUK adequacy (EU)
SentryError & performance monitoringDiagnostic data (personal data filtered)USUK IDTA / SCCs
VercelApplication hosting & CDNData in transit, request logsUSUK IDTA / SCCs
CloudflareBot/abuse protection (Turnstile) on public formsIP, user agent, challenge tokensGlobal edgeUK IDTA / SCCs
Google Places APIAddress autocomplete & lookup for practice/client addressesAddress text entered, IPUSUK IDTA / SCCs
Adobe FontsWeb font deliveryIP/request data for font loadingUSUK IDTA / SCCs
Arkavio

All-in-one practice management for UK architecture practices. Built by a registered architect, in the UK, staying that way.

Product

  • How it works
  • Features

Company

  • Contact

Account

  • Log in
  • Start free trial

Legal

  • Privacy
  • Cookies
  • Terms
  • Security
  • All legal
© 2026 Arkavio Ltd. All rights reserved.Registered in England & Wales.