Data Processing Agreement | ArcaDesk
Legal Document

Data Processing
Agreement (DPA)

ArcaDesk acts as a Data Processor on behalf of every client. This page explains how we handle your clients' personal data — and how to request the full signable agreement.

Version 1.0
Effective date May 2025
Governing law Wyoming, United States
100%
Of clients receive a signed Confidentiality Agreement before work begins
0
Client data ever sold, shared, or used to train AI models without consent
72h
Maximum time to notify you of any security incident affecting your data
30d
To return or delete all your data after contract termination, on request
Data Controller
Your firm — the client entity named in the ArcaDesk Service Agreement
You determine the purposes and means of processing your clients' personal data. ArcaDesk acts only on your documented instructions.
Data Processor
ArcaDesk — arcadesk.io
We process personal data solely to deliver the AI revenue system services described in your Service Agreement. We take no independent decisions about your data.
01 — Scope

What This Agreement Covers

This DPA governs every instance where ArcaDesk processes personal data on your behalf — from the first inbound call to the final data deletion after your contract ends.

Regulations this DPA is designed to satisfy
GDPR (EU) 2016/679 UK GDPR CCPA / CPRA GLBA TCPA NAIC Model Privacy Act SOX (record-keeping) FCA (UK) State financial privacy laws US state data protection laws
📞

What data we process

Identity and contact data (names, phone numbers, emails), communication data (call recordings, transcripts, message content), transactional data (appointment records, booking history), and behavioural data (opt-out status, engagement history).

👤

Whose data we process

Your existing and prospective clients, leads who contact or are contacted through your ArcaDesk system, and any contacts in your connected CRM. We do not process special category data (health, financial account numbers) without a separate written addendum.

⚙️

How we process it

Inbound call handling and qualification, outbound call and SMS sequences, CRM data capture and management, appointment booking, automated follow-up, and revenue performance reporting.

📅

For how long

For the full term of your Service Agreement, plus any legally required retention periods thereafter. Upon termination, all data is returned or securely deleted within 30 days at your election.

02 — Our Obligations

What ArcaDesk Commits to

These are ArcaDesk's binding obligations as your Data Processor — written into every client agreement, not just stated as policy.

  • Process only on your documented instructions
    ArcaDesk will never process your clients' personal data for any purpose not set out in your Service Agreement or this DPA. If we believe an instruction would breach applicable law, we will notify you immediately and not carry it out.
  • Never sell, rent, or commercialise your data
    Personal data processed under this agreement is used exclusively to deliver your services. It is never sold, licensed, shared with advertisers, or used for ArcaDesk's own commercial benefit under any circumstances.
  • Never train AI on your data without written consent
    Your client data, call recordings, transcripts, and business information are never used to train, fine-tune, or improve any AI model — regardless of whether the data has been anonymised. Any such use requires your explicit prior written authorisation.
  • Maintain confidentiality across all staff and sub-processors
    Every team member and contractor with access to client data is bound by confidentiality obligations. Sub-processors who handle infrastructure are contractually required to meet equivalent standards.
  • Assist you with Data Subject rights requests
    If one of your clients requests access, rectification, erasure, or portability of their data, we will provide all reasonable assistance to help you respond within the required timeframes. Any requests received directly by ArcaDesk are forwarded to you within 5 business days.
  • Honour opt-out requests immediately and permanently
    Any contact who opts out of communications is removed from all active sequences immediately. Opt-out status is permanent and cannot be overridden by re-importing the contact. Consent records are retained for audit purposes.
03 — Security

How We Protect Your Data

ArcaDesk implements technical and organisational security measures appropriate to the sensitivity of the personal data we process on your behalf.

🔒

Encryption

All personal data is encrypted in transit (TLS 1.2+) and at rest. Call recordings and transcripts are encrypted and stored in access-controlled environments.

🧱

Data isolation

Each client's data is held in a logically isolated environment. No data from your firm is accessible to any other ArcaDesk client, regardless of sector or geography.

👥

Access controls

Role-based access ensures only personnel with a documented business need can access your data. All access is logged and reviewed regularly. Access is revoked immediately on personnel change.

🔔

Breach notification

In the event of a security incident, ArcaDesk will notify you without undue delay and in all cases within 72 hours — with full details of the incident, affected records, and remediation steps.

🗑️

Secure deletion

Data is securely deleted at the end of each defined retention period. Upon contract termination, all data is returned or deleted within 30 days, with written confirmation provided.

📋

Audit trails

All system access, data interactions, and consent records are logged with timestamps. For regulated sectors, extended audit trail retention is available on request.

04 — Sub-processors

Approved Sub-processors

ArcaDesk engages trusted third-party infrastructure providers to deliver the Services. All sub-processors are bound by data protection obligations equivalent to this DPA. You will be given advance notice of any changes.

Category Purpose Location Safeguard
Cloud Hosting & Infrastructure
Secure storage of personal data, call recordings, and CRM data US / EU SCCs / Adequacy
Telephony & VoIP Platform
Inbound and outbound call routing, recording, and transcription US DPA in place
CRM Platform
Contact management, workflow automation, pipeline tracking US DPA in place
Email & SMS Delivery
Outbound marketing and follow-up message delivery US DPA / SCCs
Analytics & Reporting
Revenue performance dashboards and anonymised usage analytics US / EU DPA in place
Calendar Integration
Appointment booking and confirmation automation US DPA in place

A full named sub-processor list with specific vendor names and data handling details is available on request at [email protected]. You will be notified with reasonable advance notice of any changes.

05 — Retention

Data Retention Periods

ArcaDesk retains personal data only as long as necessary. Default retention periods are set out below — extended retention is available for regulated sectors on request.

Data Category Default Retention Extended (on request)
Call recordings & transcripts
12 months from date of recording Up to 7 years — regulated sectors (SOX, FCA)
CRM contact records & interaction history
Duration of Service Agreement + 12 months As specified in writing by Controller
Consent records (TCPA, marketing)
5 years from date of consent As required by applicable law
Performance & analytics reports
24 months Indefinite (anonymised only)
Security & access logs
12 months 24 months
06 — Sector Provisions

Sector-Specific Commitments

In addition to the general DPA terms, ArcaDesk applies sector-specific provisions for professional services clients. Select your sector below.

GLBA compliance. As a service provider handling financial services client data, ArcaDesk operates as a GLBA-covered third party — bound by contractual safeguarding obligations equivalent to your firm's requirements under the Gramm-Leach-Bliley Act.

  • No financial data in intake scripts
    Scripts are written to avoid collecting specific financial figures, account numbers, tax IDs, or other non-public financial information (NPFI) during AI interactions. Qualification focuses on service fit and booking only.
  • Extended audit trails for SOX / FCA firms
    All call recordings, contact interactions, and consent records are timestamped with full audit trails. Extended retention up to 7 years is available for firms subject to SOX or FCA record-keeping obligations.
  • Vendor risk assessment pack available
    A completed security questionnaire, data handling summary, and sub-processor list is available on request — making your third-party vendor risk assessment process fast and straightforward.

E&O risk by design. ArcaDesk intake scripts for insurance clients are reviewed to ensure no coverage advice, policy recommendations, or binding commitments are made by the AI system. The AI qualifies and books — your licensed broker handles the rest.

  • GLBA privacy notice compliance
    Outbound sequences and intake flows include GLBA-aligned consent language. Opt-out requests are honoured immediately and permanently, with records retained for audit purposes.
  • State DOI configurable by jurisdiction
    Systems are configurable by state to align with local Department of Insurance rules on client communication, consent, and data handling — including California CCPA and New York requirements.
  • Sensitive data minimisation in all intake scripts
    Scripts avoid collecting health status, medical history, income specifics, or claims details during AI interactions. No underwriting-sensitive data is captured without explicit written authorisation.

Request the Full DPA

Complete the form below to receive the full, signable Data Processing Agreement by email — typically within one business day. No sales pitch. Just the document.

Email us directly

✓   Request received. The DPA will be in your inbox within one business day.