Arkus data processing agreement

This Data Processing Agreement (the “DPA”) forms part of the Arkus Terms of Service or any other written agreement governing a Customer’s use of the Services (the “Agreement”) between Arkus AI AB, a company incorporated in Sweden with organisation number 559239-8811 and registered office at Hagaesplanaden 1, 113 68 Stockholm, Sweden (“Arkus”), and the person or entity that has entered into the Agreement (“Customer”).

The parties expressly acknowledge and agree that:

  • Customer determines the purposes and means of Processing Customer Personal Data and acts as Controller, or as a Processor acting for another Controller. Arkus acts as Customer’s Processor or Subprocessor, as applicable.
  • Customer is responsible for ensuring that it has a valid legal basis, provides required notices, and lawfully configures and uses the Services for all Customer Personal Data submitted to the Services.
  • Arkus Processes Customer Personal Data only to provide, secure, maintain and support the Services, in accordance with the Agreement, this DPA, Customer’s use and configuration of the Services, and applicable law.
  • Arkus does not use Customer Personal Data to train, fine-tune or otherwise develop Arkus artificial intelligence models.
  • Arkus’s hosting environment is located in the European Union. Where a Restricted Transfer occurs, Arkus will use an appropriate transfer safeguard as required by Applicable Data Protection Law.
  • The Arkus AI Agent Builder does not itself collect health or other sensitive or special-category Personal Data directly from end users. Customer may configure Customer Agents to collect and Process such data and controls whether that data is transmitted to an AI model or other component.
  • Arkus may use authorised Subprocessors under Section 9. The current Subprocessor list is maintained separately and incorporated into this DPA by reference.
  • This DPA supports the parties’ compliance obligations but does not, by itself, make a Customer Agent or Customer’s Processing activities compliant with privacy, healthcare, medical-device or other sector-specific laws.

1. Parties and application

  1. This DPA applies automatically whenever Arkus Processes Customer Personal Data on Customer’s behalf in connection with the Services. No separate signature is required.
  2. This DPA takes effect when Customer accepts the Agreement or the parties otherwise agree that Arkus will Process Customer Personal Data. It remains effective for as long as Arkus Processes Customer Personal Data on Customer’s behalf.
  3. If the parties have signed a separate data processing agreement governing the same Processing, that signed agreement will prevail to the extent of any conflict.
  4. Sections that by their nature should survive termination, including confidentiality, deletion, liability and cross-border-transfer provisions, will survive for as long as Arkus retains Customer Personal Data.

2. Definition

Capitalised terms not defined in this DPA have the meanings given in the Agreement.

  1. Applicable Data Protection Law means, to the extent applicable to the Processing of Customer Personal Data under the Agreement:

    • Regulation (EU) 2016/679 (the “EU GDPR”);
    • the EU GDPR as incorporated into EEA member-state law;
    • the United Kingdom General Data Protection Regulation and the UK Data Protection Act 2018 (together, the “UK Data Protection Laws”); and
    • any legislation that implements, replaces or supplements the foregoing.
  2. Customer Personal Data means Personal Data contained in Customer Data that Arkus Processes on Customer’s behalf in providing the Services. Customer Personal Data does not include data for which Arkus acts as an independent Controller, as described in Arkus’s Privacy Policy.

  3. Data Subject, Controller, Processor, Processing, Personal Data, Personal Data Breach and Supervisory Authority have the meanings given in Applicable Data Protection Law.

  4. EEA means the European Economic Area.

  5. Restricted Transfer means a transfer of Customer Personal Data from the EEA or United Kingdom to a country that is not recognised as providing an adequate level of protection under the Applicable Data Protection Law governing that transfer.

  6. Security Measures means the technical and organisational measures described in Annex 2.

  7. Customer Agent means an agent, application or workflow created, configured, deployed or operated by or for Customer using the Services.

  8. Services means the Arkus AI Agent Builder, arkus.ai, and the related APIs, hosting, infrastructure, integrations, components and support services provided by Arkus under the Agreement.

  9. Standard Contractual Clauses or EU SCCs means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, as amended, replaced or superseded.

  10. Subprocessor means a third party appointed by or on behalf of Arkus to Process Customer Personal Data.

  11. UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended, replaced or superseded.

3. Roles and Processing

  1. As between the parties, Customer is the Controller of Customer Personal Data and Arkus is the Processor. If Customer acts as a Processor for another Controller, Arkus acts as Customer’s Subprocessor. Each party will comply with its obligations under Applicable Data Protection Law.
  2. Arkus will Process Customer Personal Data only to provide, secure, maintain and support the Services in accordance with the Agreement, this DPA, Customer’s use and configuration of the Services, other written directions agreed by the parties, or as required by applicable law.
  3. If applicable law requires Arkus to Process Customer Personal Data for another purpose, Arkus will inform Customer before Processing unless the law prohibits notice on important grounds of public interest.
  4. The subject matter, duration, nature and purpose of the Processing, and the categories of Personal Data and Data Subjects, are described in Annex 1.
  5. Arkus may Process account, billing, security, support and service-usage information as an independent Controller where necessary to administer the customer relationship, secure and prevent abuse of the Services, comply with law, enforce the Agreement, process billing, maintain business records, and improve the Services using aggregated or appropriately de-identified information. Such Processing is governed by the Arkus Privacy Policy and is outside this DPA.

4. Customer Obligations

  1. Customer is responsible for:

    • ensuring that its use and configuration of the Services comply with Applicable Data Protection Law;
    • providing all required notices and obtaining all required consents or other lawful bases for Processing;
    • ensuring that Customer Personal Data is accurate, relevant and limited to what is necessary;
    • determining whether the Services and Security Measures are appropriate for Customer’s intended use;
    • configuring and operating Customer Agents, integrations and access permissions lawfully and securely; and
    • responding to requests from Data Subjects concerning Customer Personal Data.
  2. The Arkus AI Agent Builder is a development environment and does not itself collect health data or other sensitive or special-category Personal Data directly from end users. Customer may configure a Customer Agent to collect, receive, store or otherwise Process such data.

  3. Where a Customer Agent Processes health data or other sensitive or special-category Personal Data, Customer is responsible for:

    • establishing an appropriate legal basis and, where applicable, a condition under Article 9 EU GDPR or equivalent law;
    • providing required privacy and AI notices and obtaining any required consent or authorisation;
    • conducting any required data protection impact assessment or prior consultation;
    • applying appropriate data-minimisation, access, retention and security measures; and
    • complying with applicable healthcare, clinical-research, medical-device and other sector-specific laws.
  4. PHI or other data requiring additional sector-specific safeguards or contractual terms must not be submitted without Arkus’s prior written approval.

  5. Customer controls whether Customer Personal Data processed by a Customer Agent is transmitted to an AI model, Third-Party Component or Customer-Connected Provider through Customer’s configuration and provider selection.

  6. Customer may use available anonymisation, pseudonymisation, redaction or data-minimisation measures before data is transmitted. Customer is responsible for assessing whether those measures are appropriate. Pseudonymised data remains Personal Data where it can be attributed to an individual using additional information; data is anonymous only where individuals are not identifiable by means reasonably likely to be used.

  7. Customer is responsible for determining which categories of Customer Personal Data may be sent to each AI model, Third-Party Component or Customer-Connected Provider. Arkus-appointed providers that Process Customer Personal Data on Arkus’s behalf are Subprocessors governed by Section 9. A Customer-Connected Provider may act directly for Customer under Customer’s separate agreement, as described in the Agreement.

  8. Nothing in this DPA represents that a Customer Agent is clinically validated, certified or legally compliant, or that the Services are suitable for a regulated clinical purpose. Any additional sector-specific contractual or security requirements must be separately agreed in writing.

  9. Customer must notify Arkus promptly of any suspected compromise of Customer accounts, credentials, Customer Agents or integrations.

5. Arkus Obligations

  1. Arkus will ensure that employees authorised to Process Customer Personal Data:

    • are subject to an appropriate duty of confidentiality;
    • receive access only where necessary for their responsibilities; and
    • receive appropriate privacy and security training.
  2. Arkus will take reasonable steps to ensure the reliability of employees who have access to Customer Personal Data.

  3. Arkus will not use Customer Personal Data to train, fine-tune or otherwise develop an Arkus artificial intelligence model.

  4. Taking into account the nature of the Processing, Arkus will provide reasonable assistance through appropriate technical and organisational measures, insofar as possible, to help Customer respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.

  5. If Arkus receives a request directly from a Data Subject relating to Customer Personal Data, Arkus will, where legally permitted, direct the Data Subject to Customer or notify Customer. Arkus will not respond substantively on Customer’s behalf unless Customer requests it or applicable law requires it.

  6. Taking into account the nature of Processing and information available to Arkus, Arkus will provide reasonable assistance to Customer with security and breach-notification obligations, data protection impact assessments, and prior consultation with a Supervisory Authority where required.

  7. If a Supervisory Authority contacts Arkus about Customer’s Processing, Arkus may notify Customer where legally permitted and will reasonably cooperate with Customer.

  8. Arkus will inform Customer if, in Arkus’s reasonable opinion, Customer’s requested Processing infringes Applicable Data Protection Law. Arkus may suspend the affected Processing while the parties work in good faith to identify a lawful alternative.

  9. Assistance that is unusually burdensome, repetitive or outside the standard functionality or scope of the Services may be subject to reasonable fees disclosed and agreed in advance.

6. Security

  1. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, Arkus will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
  2. The Security Measures in Annex 2 describe Arkus’s current minimum commitments. Arkus may update the Security Measures where the update does not materially reduce the overall protection of Customer Personal Data during the term of the Agreement.
  3. Customer acknowledges that the Services operate under a shared-responsibility model. Customer is responsible for securing its accounts, credentials, configurations, integrations, agents and applications, and for using available security features appropriately.

7. Data Breach Notification

  1. Arkus will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

  2. To the extent information is reasonably available, the notice will include:

    • the nature of the Personal Data Breach, including the categories of affected Data Subjects and data;
    • the likely consequences of the Personal Data Breach;
    • the measures taken or proposed to address and mitigate the Personal Data Breach; and
    • a contact point from whom further information may be obtained.
  3. Where not all information is available at the same time, Arkus may provide it in phases without undue further delay.

  4. Arkus will take reasonable steps to contain, investigate and remediate the Personal Data Breach and will reasonably cooperate with Customer in meeting Customer’s applicable notification obligations.

  5. Arkus’s notice or response to a Personal Data Breach is not an acknowledgement of fault or liability. Customer is responsible for determining whether it must notify a Supervisory Authority, affected Data Subjects or any other party, except where Applicable Data Protection Law assigns that obligation directly to Arkus.

8. Cross-Border Data Transfers

  1. Arkus’s primary hosting environment for Customer Personal Data is located in the European Union. Further information about relevant infrastructure and Processing locations will be identified in the Subprocessor list.

  2. Customer authorises Arkus and its Subprocessors to Process Customer Personal Data in the countries identified in the Subprocessor list, subject to this section.

  3. Arkus will not make a Restricted Transfer unless it has implemented an appropriate transfer mechanism under Applicable Data Protection Law, which may include an adequacy decision, the EU SCCs, the UK Addendum or another legally recognised safeguard.

  4. For Restricted Transfers from the EEA that are subject to the EU GDPR, the EU SCCs are incorporated into this DPA as follows:

    • Module Two applies where Customer is a Controller and Arkus is a Processor;
    • Module Three applies where Customer is a Processor and Arkus is a Subprocessor;
    • the optional docking clause in Clause 7 applies;
    • in Clause 9, Option 2 applies and the notice period is the period specified in Section 9.3 of this DPA;
    • the optional language in Clause 11 does not apply;
    • in Clause 17, Option 1 applies and the governing law is the law of Sweden;
    • under Clause 18, the courts of Sweden have jurisdiction; and
    • Annexes 1 and 2 of this DPA, together with the Subprocessor list, complete the corresponding annexes to the EU SCCs.
  5. For Restricted Transfers governed by UK Data Protection Laws, the EU SCCs completed as stated above apply together with the UK Addendum, which is incorporated into this DPA. For purposes of the UK Addendum:

    • the parties and their contact details are set out in the Agreement and Annex 1;
    • the selected SCC modules and clauses are set out in Section 8.4;
    • the information required by Tables 1 to 3 is provided by the Agreement, Annexes 1 and 2, and the Subprocessor list; and
    • either party may end the UK Addendum as permitted by its mandatory Part 2.
  6. If a transfer mechanism used under this DPA is invalidated or materially changed, the parties will cooperate in good faith to implement a valid alternative.

9. Subprocessors

  1. Customer gives Arkus general written authorisation to appoint Subprocessors to Process Customer Personal Data in accordance with this section.
  2. Arkus maintains a current list of Subprocessors at arkus.ai/subprocessors, including their Processing purposes and locations. Customer may subscribe to receive notice of new Subprocessors through the mechanism described on that page.
  3. Arkus will provide advance notice of a new Subprocessor that will Process Customer Personal Data. Customer may object on reasonable data-protection grounds by notifying Arkus at legal@arkus.ai within ten business days after the notice.
  4. If Customer makes a valid objection, the parties will work in good faith to find a commercially reasonable solution. If no solution is reasonably available, Arkus may choose not to provide the affected feature or either party may terminate the affected portion of the Services. Customer’s sole remedy will be a pro-rata refund of prepaid fees for the terminated portion covering the period after termination.
  5. Before a Subprocessor Processes Customer Personal Data, Arkus will enter into a written agreement requiring the Subprocessor to provide protections no less protective in substance than those required of Arkus under this DPA, to the extent applicable to the Subprocessor’s services.
  6. Arkus remains responsible for each Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law.

10. Deletion and Return of Data

  1. Upon termination or expiry of the Agreement, Arkus will stop Processing Customer Personal Data except as necessary to provide an agreed data-export period, securely store data pending deletion, or comply with applicable law.
  2. Customer may request Arkus to return or delete Customer Personal Data. Unless the Agreement or applicable plan provides a different export period, Customer must submit any return request before termination or expiry.
  3. Arkus will delete or render inaccessible Customer Personal Data in its active systems within thirty calendar days after termination or expiry, unless applicable law requires continued retention.
  4. Customer Personal Data may remain in encrypted backups until those backups are overwritten or expire in accordance with Arkus’s standard backup-retention cycle. While retained in backup, the data will remain protected under this DPA and will not be restored except where necessary for disaster recovery, security or legal compliance.
  5. Arkus may retain data that it is legally required to retain, provided it isolates and protects that data and Processes it only for the legally required purpose.
  6. Customer is responsible for exporting Customer Personal Data before the applicable export period ends. Custom export, retrieval or deletion work outside the standard functionality of the Services may be subject to reasonable fees agreed in advance.

11. Compliance Information and Audits

  1. Arkus will make available information reasonably necessary to demonstrate compliance with this DPA, which may include current security documentation, summaries of independent assessments or certifications, and responses to reasonable security questionnaires.

  2. If the information supplied under Section 11.1 is not reasonably sufficient, Customer may request an audit no more than once in any twelve-month period, unless a confirmed Personal Data Breach or a Supervisory Authority requires an additional audit.

  3. An audit must:

    • be conducted by Customer or a qualified independent auditor bound by confidentiality;
    • occur during normal business hours on reasonable advance notice;
    • avoid unreasonable disruption to Arkus, other customers and the Services;
    • comply with Arkus’s reasonable security requirements; and
    • exclude access to data belonging to other customers, privileged information and information that would compromise security.
  4. The parties will first attempt to satisfy the audit request through documentation and remote review. Customer will bear its audit costs and reimburse Arkus’s reasonable costs where an audit is unusually burdensome, unless the audit identifies a material breach of this DPA by Arkus.

12. Liability, Order of Precedence and Changes

  1. Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Law. This DPA does not limit Data Subjects’ rights under the EU SCCs or Applicable Data Protection Law.

  2. If there is a conflict concerning the Processing of Customer Personal Data, the following order of precedence applies:

    • the mandatory terms of the EU SCCs or UK Addendum;
    • this DPA;
    • the Terms of Service Agreement; and
    • the Arkus Privacy Policy.
  3. Arkus may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, the Services or Arkus’s Processing practices. Arkus will provide reasonable advance notice of a material change that reduces Customer’s rights or Arkus’s data-protection obligations. Changes required by law may take effect sooner.

13. Governing Law

This DPA is governed by Swedish law. The courts of Sweden have exclusive jurisdiction over disputes arising out of or relating to this DPA, except where Applicable Data Protection Law, the EU SCCs or the UK Addendum require otherwise.

14. Contact

Questions or notices concerning this DPA may be sent to:

Arkus AI AB
Organisation number: 559239-8811
Hagaesplanaden 1
113 68 Stockholm
Sweden
Privacy email: legal@arkus.ai
Website: arkus.ai

Annex 1 — Details of Processing

A. Parties

Data exporter / Customer

The Customer identified in the Agreement. Customer’s contact details and, where applicable, data-protection contact are those provided through the Customer account or order form.

Data importer / Processor

Arkus AI AB, organisation number 559239-8811, with registered office at Hagaesplanaden 1, 113 68 Stockholm, Sweden. Privacy contact: legal@arkus.ai

B. Subject matter and duration

The Processing of Customer Personal Data as necessary to provide, secure, maintain and support the Services under the Agreement. Processing continues for the term of the Agreement and any limited period during which Arkus retains Customer Personal Data in accordance with Section 10.

C. Nature and purpose

Depending on Customer’s use and configuration of the Services, Processing may include collecting, recording, organising, structuring, storing, retrieving, consulting, transmitting to Customer-selected integrations or model providers, generating outputs, restricting, deleting and otherwise Processing Customer Personal Data to:

  • create, configure, test, deploy and operate Customer Agents;
  • authenticate users and manage access;
  • execute Customer configurations and integrations;
  • host Customer applications and related data;
  • provide technical support requested by Customer;
  • monitor performance, reliability, security and abuse; and
  • maintain, back up and recover the Services.

D. Categories of Data Subjects

Depending on Customer’s use of the Services:

  • Customer’s authorised users, personnel, contractors and representatives;
  • users of Customer Agents built or operated by Customer;
  • Customer’s prospective and existing customers, suppliers and business contacts; and
  • other individuals whose Personal Data Customer lawfully submits to the Services.

Data Subjects may include individuals whose health or other sensitive or special-category Personal Data is collected through a Customer Agent configured by Customer.

E. Categories of Personal Data

Depending on Customer’s use and configuration:

  • identity and contact data, such as names, usernames, business email addresses and telephone numbers;
  • account, role and authentication information;
  • prompts, messages, files, form submissions and other content provided to Customer Agents;
  • personal, health and other sensitive or special-category Personal Data that Customer configures a Customer Agent to collect or Process;
  • workflow configurations, application data and generated outputs;
  • IP addresses, device and browser information, timestamps and activity logs;
  • integration identifiers, tokens or credentials where Customer configures an integration; and
  • support and troubleshooting information submitted by Customer.

F. Sensitive data

Depending on Customer’s configuration, Customer Personal Data may include health data and other sensitive or special-category Personal Data collected or Processed through a Customer Agent. Customer determines whether to collect such data and whether it may be transmitted to an AI model, Third-Party Component or Customer-Connected Provider. The responsibilities and safeguards in Section 4 apply.

G. Frequency

Continuous or intermittent, depending on Customer’s use of the Services.

H. Retention

For the term of the Agreement and the deletion periods described in Section 10, unless a shorter period is configured by Customer or a longer period is required by law.

I. Competent Supervisory Authority

For purposes of the EU SCCs, the competent Supervisory Authority will be determined in accordance with Clause 13 of the EU SCCs. Where Arkus is established in Sweden and the EU GDPR applies, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) will ordinarily be the relevant Supervisory Authority for Arkus.

Annex 2 — Technical and Organisational Measures

Arkus maintains a security programme designed to protect the confidentiality, integrity and availability of Customer Personal Data. Measures appropriate to the relevant Services include:

1. Governance and risk management

  • documented information-security and privacy responsibilities;
  • periodic risk assessments and review of material service changes;
  • security and privacy training for personnel with relevant access; and
  • processes managing acceptable use, access, and incident response.

2. Access control

  • unique user accounts and authentication controls;
  • role-based and least-privilege access to production systems;
  • documented access approval and revocation procedures; and
  • periodic review of privileged access.

3. Encryption and communications security

  • encryption of Customer Personal Data in transit using current industry-standard transport encryption;
  • encryption at rest for production data stores and backups where supported by the relevant infrastructure;
  • secure management of encryption keys and secrets.

4. Infrastructure and tenant protection

  • hosting within the European Union for Arkus’s primary production environment;
  • logical separation of customer environments and data;
  • network security controls and restricted administrative interfaces;
  • hardened configurations and change-management procedures; and
  • monitoring designed to identify anomalous or unauthorised activity.

5. Application and development security

  • version control and peer review for material code changes;
  • testing before material changes are released to production;
  • ongoing dependency and vulnerability monitoring;
  • remediation processes prioritised according to risk; and
  • separation of development, testing and production access where appropriate.

6. Logging and monitoring

  • logging of relevant administrative, security and service events;
  • restricted access to logs;
  • monitoring material security events; and
  • retention of logs for periods appropriate to their purpose and risk.

7. Availability, backup and recovery

  • backups of critical material production data according to documented schedules;
  • protection of backup data against unauthorised access.

8. Incident management

  • a documented security-incident response process;
  • defined escalation, investigation, containment and remediation responsibilities;
  • preservation of relevant evidence; and
  • post-incident review where appropriate.

9. Subprocessor and supplier management

  • security and privacy assessment of relevant vendors before or during engagement;
  • written data-protection and confidentiality obligations;
  • review of material vendor risks.

10. Data lifecycle

  • data minimisation and purpose limitation;
  • tools or procedures supporting export and deletion;
  • controlled retention of critical production data and backups; and
  • secure deletion or rendering data inaccessible when retention ends.

11. Customer-controlled safeguards

Depending on the plan and Services, Customer may be able to use account permissions, authentication controls, integrations and other settings. Customer is responsible for configuring these safeguards appropriately for its use case.