Effective Date: August 31, 2026
What this is. This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the agreement between ArcGlass, Inc. ("ArcGlass", "we") and the customer organization ("Customer", "you") that governs your use of the ArcGlass services (the "Agreement"). It applies where ArcGlass processes personal data contained in Customer Content on the Customer's behalf, and reflects the roles described in Privacy Policy Section 1. A signable copy is available from legal@arcglass.io.
Capitalized terms not defined here have the meaning given in the Agreement or the Privacy Policy. "Data Protection Laws" means all laws applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in the GDPR (or the equivalent terms, such as "Business" and "Service Provider", under US state laws). "Customer Personal Data" means Personal Data within Customer Content that ArcGlass processes on the Customer's behalf, as described in Annex I.
For Customer Personal Data, the Customer is the Controller (or Business) and ArcGlass is the Processor (or Service Provider), consistent with Privacy Policy Section 1. ArcGlass processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to act otherwise by applicable law (in which case ArcGlass will inform the Customer of that legal requirement before processing, unless the law prohibits such notice). The Agreement, this DPA, the Customer's configuration of the Services (for example, which data sources it connects and what it directs the Services to analyze), and any written instructions the Customer gives constitute the Customer's complete documented instructions. ArcGlass will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
ArcGlass ensures that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are trained on their data-protection responsibilities. Access to Customer Personal Data is limited to personnel who need it to provide, support, or secure the Services.
ArcGlass implements and maintains the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. ArcGlass may update these measures from time to time provided the updates do not materially reduce the overall level of security.
The Customer grants ArcGlass general authorization to engage the sub-processors listed in Annex III to process Customer Personal Data. ArcGlass: (a) enters a written contract with each sub-processor imposing data-protection obligations no less protective than those in this DPA; (b) remains liable for its sub-processors' performance of those obligations; and (c) will give the Customer at least 30 days' notice, by email or in-product, before authorizing any new sub-processor. During that period the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected Services. The current list of sub-processors mirrors Privacy Policy Section 6.3.
Taking into account the nature of the processing, ArcGlass provides controls within the Services that enable the Customer to access, correct, delete, export, and restrict Customer Personal Data. Where a Data Subject sends a request directly to ArcGlass concerning Customer Content, ArcGlass will not respond except on the Customer's instructions or as legally required, and will promptly forward the request to the Customer. ArcGlass provides reasonable assistance, by appropriate technical and organizational measures and insofar as possible, for the Customer to fulfill its obligation to respond to Data Subject requests.
ArcGlass notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides the Customer with information reasonably available to it to help the Customer meet its own breach-notification obligations. This reflects the commitment in Privacy Policy Section 9. ArcGlass's notification is not an acknowledgment of fault or liability.
Taking into account the nature of processing and the information available to ArcGlass, ArcGlass provides reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities that the Customer is required to carry out under Data Protection Laws in relation to its use of the Services.
Where ArcGlass's processing of Customer Personal Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree that such transfers are governed by the appropriate transfer mechanism, which the parties incorporate by reference:
This reflects the transfer commitments summarized in Privacy Policy Section 13. Where the SCCs require details, the information in Annex I, Annex II, and Annex III populates the corresponding appendices.
On termination or expiry of the Agreement, ArcGlass will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies unless applicable law requires continued storage. Deletion follows the timelines described in Privacy Policy Section 11, including removal from backups on a rolling basis.
ArcGlass makes available its current security documentation, and any third-party audit reports or certifications it holds, to demonstrate compliance with this DPA. The Customer may request these once per year, or after a Personal Data Breach, subject to confidentiality. Where those materials are insufficient and the Customer is required by a Supervisory Authority to conduct a further audit, the parties will agree the scope, timing, and cost in advance; any on-site inspection occurs on at least 30 days' notice, no more than once per year, during business hours, and must not compromise the security or data of other customers.
To the extent ArcGlass processes Customer Personal Data that is subject to the CCPA or other US state privacy laws as a Service Provider (or processor), ArcGlass: processes such data only to provide the Services and for the business purposes specified in the Agreement; does not sell or share it; does not retain, use, or disclose it outside the direct business relationship or for any purpose other than those permitted; and does not combine it with data from other sources except as permitted for a Service Provider. ArcGlass certifies that it understands and will comply with these restrictions.
This DPA is subject to the Agreement, including its limitations of liability, which apply to all claims under this DPA in the aggregate with claims under the Agreement. Where this DPA conflicts with the Agreement or the Privacy Policy on the processing of Customer Personal Data, this DPA controls. Governing law and jurisdiction are as stated in the Agreement (or, for the SCCs, as set out in Annex I). If any provision of this DPA is found unenforceable, the remaining provisions remain in effect.
Data exporter (Controller): the Customer organization
identified in the Agreement.
Data importer (Processor): ArcGlass, Inc.,
legal@arcglass.io.
Individuals whose personal data appears in the Customer Content the Customer directs the Services to process — for example, the Customer's personnel and authorized users, and the customers, prospects, partners, and other third parties who participate in the Customer's conversations, meetings, emails, messages, and tickets.
Identifiers and contact details (name, email address, job title, organization); the content and metadata of conversations, meetings, transcripts, emails, chat messages, tickets, calendar details, documents, and files that the Customer submits or connects; and the AI-derived analysis of that content (for example sentiment, topics, intent, and action items). ArcGlass does not require special-category data to provide the Services and asks Customers not to submit it; to the extent such data incidentally appears in Customer Content, it is processed under the same safeguards as other Customer Personal Data.
Ingesting, storing, analyzing, and surfacing Customer Content to provide the ArcGlass conversation-intelligence Services and the features the Customer enables, as described in the Agreement and Privacy Policy. Customer Content is not used to train ArcGlass's or any provider's AI models.
For the term of the Agreement and until deletion or return of Customer Personal Data under Section 10, subject to the retention and backup-deletion timelines in Privacy Policy Section 11.
For the EU SCCs: Module Two (Controller to Processor) applies. The docking clause (Clause 7) applies. Sub-processor authorization under Clause 9 is by general written authorization with the 30-day notice described in Section 5. The optional independent dispute-resolution body under Clause 11 is not selected. Clause 17 (governing law) and Clause 18 (forum) are the law and courts of Ireland, unless the Agreement specifies another EEA member state. The competent Supervisory Authority is the authority of the EEA member state in which the data exporter is established, or, where the exporter is not established in the EEA, the Irish Data Protection Commission.
ArcGlass maintains the following measures, consistent with Privacy Policy Section 9 and its security posture:
The following sub-processors are authorized to process Customer Personal Data. This list mirrors Privacy Policy Section 6.3 and is kept current there.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, database, storage, AI inference (Vertex AI) | United States |
| Microsoft Azure | AI inference (Azure OpenAI Service) | United States |
| Groq | AI inference | United States |
| Render | Hosting for auxiliary services | United States |
| Cloudflare | Content delivery, TLS, network security | Global |
| Stripe | Payment processing | United States |
| Twilio SendGrid | Transactional email delivery | United States |
| Recall.ai | Meeting notetaker infrastructure | United States (region configurable) |
| GitHub | Listen App release hosting and update delivery | United States |
| Google Analytics | Website and Platform analytics (only with cookie consent) | United States |
| Discord | Internal operations alerting | United States |
ArcGlass, Inc.
Legal and DPA requests: legal@arcglass.io
Privacy: privacy@arcglass.io