For business customers · Last updated August 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into between:

each a "Party" and together the "Parties".

This DPA forms part of, and is subject to, the Terms of Service and any order or subscription between the Parties (the "Principal Agreement"). It governs our processing of Personal Data on your behalf when we provide our AI-assisted image generation and editing services through the ARC AI Portal (the "Services"). If there is a conflict on data protection matters, this DPA prevails over the Principal Agreement.

1. Definitions

2. Roles of the Parties

You are the Controller and we are the Processor in respect of the Client Personal Data. You are responsible for the lawfulness of the Client Personal Data and of your instructions. We process Client Personal Data only as a Processor on your behalf.

3. Scope and instructions

3.1 We will process Client Personal Data only on your documented instructions (including this DPA, the Principal Agreement, and your use of the portal), and as needed to provide the Services, unless required to do otherwise by law - in which case we will inform you first, unless the law prohibits it.

3.2 We will inform you if, in our opinion, an instruction infringes the Data Protection Laws.

3.3 The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subjects are set out in Annex 1.

4. Our obligations as Processor

We will:

(a) Confidentiality - ensure that persons authorised to process the Client Personal Data are bound by appropriate confidentiality obligations;

(b) Security - implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 of the UK GDPR;

(c) Sub-processors - comply with Section 5 in respect of engaging Sub-processors;

(d) Assistance with Data Subject rights - taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights;

(e) Assistance with compliance - assist you in ensuring compliance with your obligations relating to security of processing, Personal Data Breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to us;

(f) Breach notification - notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Client Personal Data, and provide reasonable information to help you meet your own notification obligations;

(g) Deletion or return - at the end of the Services, and at your choice, delete or return all Client Personal Data and delete existing copies, unless we are required by law to retain them. Uploaded images and generated revisions are deleted within 30 days of account closure or on request, in line with our Privacy Policy; financial records are retained for six years as required by law.

(h) Records and audits - make available to you information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice (no more than once per year except where required by a supervisory authority or following a Personal Data Breach), during normal business hours, subject to confidentiality and without compromising the security or data of our other clients.

5. Sub-processors

5.1 You give us general authorisation to engage the Sub-processors listed in Annex 3.

5.2 We will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for each Sub-processor's performance.

5.3 We will give you at least 14 days' prior notice of any intended addition or replacement of a Sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Services.

6. International transfers

The Services necessarily involve transferring the images and prompts you submit to third-party AI providers for processing. These providers are listed in Annex 3 and may be located outside the United Kingdom and the European Economic Area, including in the United States. Where an international transfer takes place we rely on an appropriate transfer mechanism under the Data Protection Laws, being (as applicable) the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or an adequacy decision. Copies of the relevant provider agreements and transfer mechanisms are available on request.

You confirm that you have the necessary rights and permissions to submit the content you upload for processing by these providers, including where that content is covered by an obligation of confidence to your own clients.

7. Your obligations and warranties

You warrant that: (a) you have a lawful basis to provide the Client Personal Data to us and to instruct us to process it; (b) your instructions are lawful; (c) you have provided all required notices and obtained all required consents from Data Subjects, including any depicted in uploaded images; (d) you have the right to submit the uploaded content to our sub-processors as described in this DPA; and (e) you will not provide us with Special Category Data unless agreed in writing with appropriate additional safeguards.

8. Liability

Each Party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.

9. Term and termination

This DPA takes effect on the date of the Principal Agreement and continues for as long as we process Client Personal Data on your behalf. Clauses that by their nature should survive termination (including confidentiality, deletion/return and audit) survive.

10. Governing law

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without affecting any mandatory rights you may have under your local law.


Annex 1 - Details of the processing

Annex 2 - Technical and organisational measures

Annex 3 - Approved Sub-processors

Sub-processorPurposePersonal DataLocation
Google (Gemini API) AI image generation and editing Uploaded images and prompts US / EU
Comfy Deploy (optional) Cloud image upscaling, only if enabled by the Controller The image being upscaled US
Stripe Card payments, subscriptions and invoicing Name, email, billing details; card details entered directly into Stripe hosted checkout and not stored by Arc-Squared EU / US
Resend Sign-in emails and account notifications Name, email address, email content US
Railway Application hosting and managed Postgres database All application data at rest and in transit US / EU
Cloudflare DNS and TLS for the portal domain Data in transit only Global edge

Important note on the AI providers: unlike some other Arc-Squared services, the AI Portal necessarily transmits uploaded images and prompts to Google (and, if enabled, Comfy Deploy) for processing. The Controller should ensure that all necessary rights, permissions and (where applicable) client consents are in place before uploading confidential material.


Signatures

Signed for and on behalf of the Controller

Name
Title
Signature
Date

Signed for and on behalf of Arc-Squared (Processor)

Name
Title
Signature
Date