Legal

Data Processing Agreement

Draft — not yet reviewed by a lawyer. Not in force.

Draft of 2026-09-29 · Contact: [email protected]

This agreement is part of the contract between [Company legal name] ("Arettic", "we"), [registered address], and a Max customer ("you") when you sign it. When your agents send personal data to Arettic (a person's name, work email or profile, for instance), you decide why and how it's processed and we process it on your behalf: you are the controller (the data fiduciary under India's DPDP Act 2023) and we are the processor (data processor). If this agreement and the terms differ on personal data, this agreement wins.

1. What we process, and why

Details
PurposeRunning the service you use: recommending tools, running purchases through data providers, checking results against pass rules, settling charges, receipts, disputes, audits and the deletion of stored data.
DataWhat your agents send and buy: typically business contact data (names, work emails, job titles, company domains, public profile URLs), company records and the text of web pages. Also your team's account details (names, emails, phone numbers) and billing details.
PeopleYour prospects, contacts, candidates and the people your agents look up; your team members.
Not to be sentSpecial categories (health, religion, biometrics and the like), government IDs, financial account numbers and children's data. Our tools are for business data; don't send these.
DurationFor as long as the contract runs, plus the retention below. Purchase inputs and results are kept encrypted for 7 days, then deleted.

2. We follow your instructions

We process personal data only to provide the service, as your agents' requests, your settings (routing rules, budgets, custom pass rules) and this agreement instruct, and as the law requires (in which case we tell you first, unless the law forbids it). If we think an instruction breaks data protection law, we tell you.

We never sell your data, share it between customers, cache one customer's results for another or use it to train models.

3. Our people

Only people who need access to run or support the service have it, and they are bound to confidentiality. Every look at stored inputs or results and every staff action is logged, with who and why.

4. Security

  • Encryption in transit (TLS) for every connection to the site, the API and our providers.
  • Inputs and results encrypted at rest per org (AES-256-GCM) with a key wrapped by a master key in the host's secret store; deleting your data destroys your org's key.
  • API keys, session tokens, sign-in links and SMS codes stored only as hashes; keys can be limited to IP ranges and revoked at once.
  • The admin console is separate from the site and needs a password and an authenticator app. Staff actions go to an append-only log.
  • Single sign-on with your identity provider, an audit log of changes in your workspace and per-agent budgets and approvals.
  • Daily database backups, kept [period: to confirm], and a tested restore.
  • [To add after review: vulnerability management, penetration testing, incident response plan, business continuity.]

5. Sub-processors

You authorise the sub-processors listed in our privacy policy (Who we share it with): our host, our payment provider, the data providers whose tools your agents run, our email verifier, and others listed there. Each is bound by written terms that protect personal data at least as well as this agreement, and we stay responsible for them.

We give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data-protection grounds and we can't address it, you may end the affected part of the service without penalty.

[Counsel to confirm the list is complete, including any intermediary that carries requests to data providers.]

6. Where data goes

[To fill in: the region where the database and the apps run, and where backups are kept.] Data providers process each request where they operate.

For personal data from the EEA, the UK or Switzerland sent outside them, the parties agree to the European Commission's Standard Contractual Clauses (Module 2, controller to processor; Module 3 where you are a processor), with the UK Addendum and the Swiss amendments as needed. [Counsel to attach the completed clauses.]

7. Helping with people's requests

We help you answer requests from the people whose data you send us (access, correction, deletion, grievances): the API gives you every stored record, and an owner's deletion request removes your org's stored inputs, results and private test sets within 24 hours. If someone contacts us directly about your data, we pass the request to you rather than answer it ourselves.

We also help with data protection impact assessments and consultations with regulators where they concern our processing, with the information we hold.

8. Personal data breaches

If a breach affects your personal data, we tell you without undue delay and within 48 hours of becoming aware of it, by email to your owners, so you can meet your own duties (72 hours to the supervisory authority under the GDPR; the Data Protection Board and the people affected under the DPDP Act). We tell you what happened, what data and people are affected, the likely consequences and what we've done, and keep you updated. [Counsel to confirm the 48-hour period.]

9. Deletion at the end

Stored inputs and results are deleted 7 days after each purchase anyway. When the contract ends, we delete your remaining personal data within 30 days (or sooner on request), and confirm it in writing. We keep receipts, invoices and the ledger as tax and accounting law requires [period: confirm with the CA]; they hold hashes, not inputs or results.

10. Information and audits

We answer reasonable security questionnaires and give you the information you need to show this agreement is met. Once a year, or after a breach, you may audit our compliance yourself or through an independent auditor bound to confidentiality, with 30 days' notice, during business hours and at your cost. [Counsel to review the audit terms.]

11. Liability and term

Each party's liability under this agreement follows the limits in the terms. This agreement lasts as long as we process personal data for you. Questions: [email protected].