Data Processing Agreement
Last Updated: March 20, 2026
This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or other written or electronic agreement (the "Agreement") between FR&D LLC, a Florida limited liability company ("Processor," "FR&D," "we," "us," or "our") and the entity identified as the client under the Agreement ("Controller," "Client," "you," or "your") for the provision of the Arepo platform and related services ("Services").
This DPA reflects the parties' commitment to abide by applicable data protection laws, including Regulation (EU) 2016/679 (the "GDPR"), the UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection legislation.
1. Definitions
For the purposes of this DPA, the following terms have the meanings set forth below. Terms not defined herein have the meaning given to them in the Agreement or in applicable data protection law.
- "Controller" means the natural or legal person which determines the purposes and means of the processing of Personal Data. For the purposes of this DPA, the Controller is the Client.
- "Processor" means the natural or legal person which processes Personal Data on behalf of the Controller. For the purposes of this DPA, the Processor is FR&D.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.
- "Personal Data" means any information relating to a Data Subject that is processed by the Processor on behalf of the Controller through the Services.
- "Processing" means any operation performed on Personal Data, whether or not by automated means.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses as approved by European Commission Decision 2021/914.
2. Scope and Purpose of Processing
2.1 Scope
This DPA applies to all Personal Data processed by FR&D on behalf of the Controller in connection with the provision of the Services under the Agreement.
2.2 Purpose of Processing
FR&D processes Personal Data solely for the purpose of providing the Services, which includes:
- Message processing: Receiving, routing, and processing messages between Client's end users and Client's AI agents across supported channels.
- Conversation storage: Storing conversation history and metadata to enable contextual AI agent responses.
- Document processing: Ingesting, chunking, embedding, and storing documents uploaded by Client for retrieval-augmented generation (RAG).
- AI inference: Transmitting message content and relevant context to AI model providers for generating agent responses.
- Database integration processing: Querying Client-connected databases as directed by Client's AI agent configuration.
- Account management: Processing Client account data for authentication, authorization, billing, and support.
2.3 Categories of Data Subjects
- Client's end users who interact with AI agents deployed through the Services.
- Client's authorized users who access the Arepo platform dashboard.
- Individuals whose Personal Data is contained in documents uploaded to the Services or in databases connected to the Services.
2.4 Types of Personal Data
The types of Personal Data processed depend on Client's use of the Services and may include:
- Contact information (names, email addresses, phone numbers).
- Communication content (messages, queries, responses).
- Technical data (IP addresses, device identifiers, session tokens).
- Document content (any Personal Data contained in uploaded files).
- Database content (any Personal Data in Client-connected databases).
- Usage data (timestamps, interaction logs, API call metadata).
2.5 Duration of Processing
Processing will continue for the duration of the Agreement, plus any retention period specified in Section 11 of this DPA.
3. Processor's Obligations
FR&D, as Processor, shall:
3.1 Lawful Processing
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
- Immediately inform the Controller if an instruction infringes Applicable Data Protection Law.
3.2 Confidentiality
- Ensure that all persons authorized to process Personal Data have committed themselves to confidentiality.
- Limit access to Personal Data to those personnel who require such access.
3.3 Security Measures
Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex A.
3.4–3.9 Additional Obligations
- Comply with Sub-processing conditions (Section 5).
- Assist the Controller with Data Subject requests (Section 6).
- Assist with compliance obligations under Articles 32–36 of the GDPR.
- Upon termination, comply with data return and deletion obligations (Section 11).
- Make available information necessary for compliance audits (Section 9).
- Not sell, share, or make available Personal Data for purposes other than providing the Services.
4. Controller's Obligations
- Ensure lawful collection and transfer of Personal Data to FR&D.
- Provide documented processing instructions.
- Ensure data minimization principles are followed.
- Ensure end users are informed about data processing, including AI processing.
- Conduct data protection impact assessments as required.
5. Sub-processing
The Controller grants FR&D general written authorization to engage Sub-processors. FR&D's current Sub-processors are listed in Annex B (Subprocessor List).
FR&D shall notify the Controller of changes to the Sub-processor list at least 30 days before the new Sub-processor begins processing. The Controller may object within 15 days.
6. Data Subject Rights
FR&D shall assist the Controller in responding to Data Subject requests, including rights of access, rectification, erasure, restriction, portability, and objection. If FR&D receives a request directly, it will redirect the Data Subject to the Controller.
7. Security Measures
FR&D implements the technical and organizational measures detailed in Annex A below, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Application-level encryption of API keys and credentials.
- Optional end-to-end encryption for zero-knowledge storage.
- Role-based access control and per-tenant data isolation.
- Cloudflare infrastructure with DDoS protection and WAF.
- Error monitoring, access logging, and rate limiting.
8. Data Breach Notification
In the event of a Data Breach, FR&D shall notify the Controller within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, likely consequences, and measures taken to address it.
9. Audit Rights
The Controller may audit FR&D's compliance, subject to reasonable limitations: no more than one audit per 12 months, 30 days' prior notice, conducted remotely where feasible. FR&D may satisfy audit requests by providing relevant third-party certifications, audit reports, and compliance documentation.
10. International Data Transfers
The Services operate on Cloudflare's global edge network. For transfers outside the EEA/UK/Switzerland, the parties rely on Standard Contractual Clauses (Module Two: Controller to Processor) and the UK International Data Transfer Addendum.
11. Data Return and Deletion
- During the Agreement, the Controller may export data at any time via the platform's API.
- Upon termination, FR&D will make data available for export for 30 days, then delete all Personal Data within 90 days.
- FR&D will provide written certification of deletion upon request.
12. AI-Specific Provisions
No Training on Client Data: FR&D does not use Personal Data to train, fine-tune, or improve AI models. Client data is used exclusively for providing the Services.
- Only minimum necessary data is transmitted to AI model providers for inference.
- FR&D selects providers that commit to not using API inputs/outputs for model training.
- AI inference processing is transient — providers do not retain input data beyond the immediate request.
- Vector embeddings are non-reversible and deleted when the corresponding document is deleted.
13. Duration and Termination
This DPA remains in effect for the duration of the Agreement. Either party may terminate for material uncured breach after 30 days' written notice.
Annex A: Technical and Organizational Security Measures
| Category | Measure |
|---|---|
| Encryption in Transit | TLS 1.2+ for all data in transit between clients, platform, and third parties. |
| Encryption at Rest | AES-256 encryption for data at rest in Cloudflare D1, R2, and KV storage. |
| Application Encryption | API keys and sensitive credentials encrypted at the application layer before database storage. |
| Optional E2EE | Client-side end-to-end encryption available for zero-knowledge document storage. |
| Access Control | Role-based access control (RBAC); least-privilege access for all personnel. |
| Authentication | Passphrase-based authentication; JWT session tokens with configurable TTL. |
| Tenant Isolation | Logical tenant isolation via unique sub-tenant identifiers; per-tenant vector database namespacing. |
| Infrastructure | Cloudflare Workers (V8 isolate process isolation); Cloudflare global edge network with DDoS protection and WAF. |
| Monitoring | Application error tracking (Sentry); authentication and access logging; rate limiting. |
| Incident Response | 72-hour breach notification; designated security contact. |
| Data Minimization | AI inference uses minimum necessary context; vector embeddings are non-reversible. |
| Sub-processor Management | Written agreements with all Sub-processors; due diligence before engagement. |
Annex B: Sub-processors
See the full Sub-processor List for details, DPA links, and change history.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Infrastructure (Workers, D1, R2, KV, Vectorize, AI) | Global |
| Anthropic, PBC | AI model provider (inference) | United States |
| OpenAI, Inc. | AI model provider (inference) | United States |
| Groq, Inc. | AI model provider (inference) | United States |
| Stripe, Inc. | Payment processing | United States |
| Sentry (Functional Software) | Error monitoring | United States |
This Data Processing Agreement is a legal document of FR&D LLC. For questions, contact legal@arepo.cloud.