Data Processing Agreement

Last Updated: March 20, 2026

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or other written or electronic agreement (the "Agreement") between FR&D LLC, a Florida limited liability company ("Processor," "FR&D," "we," "us," or "our") and the entity identified as the client under the Agreement ("Controller," "Client," "you," or "your") for the provision of the Arepo platform and related services ("Services").

This DPA reflects the parties' commitment to abide by applicable data protection laws, including Regulation (EU) 2016/679 (the "GDPR"), the UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection legislation.

1. Definitions

For the purposes of this DPA, the following terms have the meanings set forth below. Terms not defined herein have the meaning given to them in the Agreement or in applicable data protection law.

2. Scope and Purpose of Processing

2.1 Scope

This DPA applies to all Personal Data processed by FR&D on behalf of the Controller in connection with the provision of the Services under the Agreement.

2.2 Purpose of Processing

FR&D processes Personal Data solely for the purpose of providing the Services, which includes:

2.3 Categories of Data Subjects

2.4 Types of Personal Data

The types of Personal Data processed depend on Client's use of the Services and may include:

2.5 Duration of Processing

Processing will continue for the duration of the Agreement, plus any retention period specified in Section 11 of this DPA.

3. Processor's Obligations

FR&D, as Processor, shall:

3.1 Lawful Processing

3.2 Confidentiality

3.3 Security Measures

Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex A.

3.4–3.9 Additional Obligations

4. Controller's Obligations

5. Sub-processing

The Controller grants FR&D general written authorization to engage Sub-processors. FR&D's current Sub-processors are listed in Annex B (Subprocessor List).

FR&D shall notify the Controller of changes to the Sub-processor list at least 30 days before the new Sub-processor begins processing. The Controller may object within 15 days.

6. Data Subject Rights

FR&D shall assist the Controller in responding to Data Subject requests, including rights of access, rectification, erasure, restriction, portability, and objection. If FR&D receives a request directly, it will redirect the Data Subject to the Controller.

7. Security Measures

FR&D implements the technical and organizational measures detailed in Annex A below, including:

8. Data Breach Notification

In the event of a Data Breach, FR&D shall notify the Controller within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, likely consequences, and measures taken to address it.

9. Audit Rights

The Controller may audit FR&D's compliance, subject to reasonable limitations: no more than one audit per 12 months, 30 days' prior notice, conducted remotely where feasible. FR&D may satisfy audit requests by providing relevant third-party certifications, audit reports, and compliance documentation.

10. International Data Transfers

The Services operate on Cloudflare's global edge network. For transfers outside the EEA/UK/Switzerland, the parties rely on Standard Contractual Clauses (Module Two: Controller to Processor) and the UK International Data Transfer Addendum.

11. Data Return and Deletion

12. AI-Specific Provisions

No Training on Client Data: FR&D does not use Personal Data to train, fine-tune, or improve AI models. Client data is used exclusively for providing the Services.

13. Duration and Termination

This DPA remains in effect for the duration of the Agreement. Either party may terminate for material uncured breach after 30 days' written notice.

Annex A: Technical and Organizational Security Measures

CategoryMeasure
Encryption in TransitTLS 1.2+ for all data in transit between clients, platform, and third parties.
Encryption at RestAES-256 encryption for data at rest in Cloudflare D1, R2, and KV storage.
Application EncryptionAPI keys and sensitive credentials encrypted at the application layer before database storage.
Optional E2EEClient-side end-to-end encryption available for zero-knowledge document storage.
Access ControlRole-based access control (RBAC); least-privilege access for all personnel.
AuthenticationPassphrase-based authentication; JWT session tokens with configurable TTL.
Tenant IsolationLogical tenant isolation via unique sub-tenant identifiers; per-tenant vector database namespacing.
InfrastructureCloudflare Workers (V8 isolate process isolation); Cloudflare global edge network with DDoS protection and WAF.
MonitoringApplication error tracking (Sentry); authentication and access logging; rate limiting.
Incident Response72-hour breach notification; designated security contact.
Data MinimizationAI inference uses minimum necessary context; vector embeddings are non-reversible.
Sub-processor ManagementWritten agreements with all Sub-processors; due diligence before engagement.

Annex B: Sub-processors

See the full Sub-processor List for details, DPA links, and change history.

Sub-processorPurposeLocation
Cloudflare, Inc.Infrastructure (Workers, D1, R2, KV, Vectorize, AI)Global
Anthropic, PBCAI model provider (inference)United States
OpenAI, Inc.AI model provider (inference)United States
Groq, Inc.AI model provider (inference)United States
Stripe, Inc.Payment processingUnited States
Sentry (Functional Software)Error monitoringUnited States

This Data Processing Agreement is a legal document of FR&D LLC. For questions, contact legal@arepo.cloud.