1. Parties, incorporation, and scope
This Data Processing Addendum is between Arga Core Inc., a Wyoming corporation (Arga Core or Processor), and the customer identified in an accepted Order (Customer). It applies only to personal data Arga Core processes on Customer's behalf under the specified Service. It becomes binding through express incorporation into an accepted agreement or execution by authorized representatives with the applicable schedules completed. Merely reading this document does not execute an individual customer agreement.
Arga Core's legal/data-protection contact is legal@argacore.com. Its business mailing address is 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Hosted infrastructure is located in Utah, United States. Customer's identity, address, contact, role, Service, and processing instructions are recorded in Annex A. This DPA does not replace the privacy notice for information a party processes for its own independent purposes.
2. Definitions and applicable law
Applicable Data Protection Law means privacy and data-protection law binding on the relevant processing, including the EU GDPR, applicable member-state law, UK GDPR and relevant UK legislation, Swiss law, and applicable U.S. state law where each applies. Personal Data, Processing, Controller, Processor, Data Subject, and Personal Data Breach have the meanings given by the applicable law. Customer Personal Data means personal information processed under Customer's instructions within this DPA.
A Subprocessor is a third party engaged by Arga Core to perform that instructed processing. A Restricted Transfer is a transfer requiring safeguards under the law governing that data. A Security Incident is an event affecting security; it becomes a reportable Personal Data Breach only when the applicable definition is met. A customer's own hosting providers are not automatically Arga Core's subprocessors.
3. Roles, processing description, and duration
Customer acts as Controller, or as a Processor lawfully authorized to appoint Arga Core as a further Processor. Arga Core processes Customer Personal Data only within that appointed role. Customer must disclose its role and any upstream controller restrictions in Annex A. Each party remains responsible for obligations applying to its actual role; the labels in a contract do not change the factual purpose and means of processing.
Annex A specifies the subject matter, duration, nature and purpose, data types, Data Subject categories, operations, frequency, and permitted locations. Processing lasts for the agreed Service and limited exit/recovery obligations, not indefinitely. Where an installation is wholly customer-controlled and Arga Core does not access its personal data, this DPA does not invent processor access; any authorized support, relay, or hosted function is separately described.
Customers retain ownership and control of their product content and may export it at any time while retained. Content is encrypted and Arga Core has no access to it in readable form. Authorized administration or deletion of encrypted records does not confer permission to read their contents. Contact correspondence, account administration, billing information, and necessary security metadata are distinguished from protected product content and processed under their applicable roles and notices.
4. Documented instructions and purpose limits
Arga Core processes Customer Personal Data only on documented lawful instructions comprising the accepted agreement, completed schedules, authorized configuration, and additional instructions accepted within scope. Instructions include any permitted disclosure and international transfer. Arga Core will not determine unrelated purposes or use Customer Personal Data for advertising, sale, independent profiling, or general model training.
If law requires processing beyond those instructions, Arga Core informs Customer before processing unless the law prohibits notice. If an instruction appears to violate applicable data-protection law, Arga Core informs Customer promptly and may pause the affected operation while the issue is resolved. Customer cannot require unlawful processing. Material changes in instructions, cost, or risk require an agreed change to the scope; they cannot silently expand an authorization.
Training or fine-tuning on Customer Personal Data, use by an AI provider for its own purposes, and sensitive-data processing require a separate express and lawful arrangement. A general Beta invitation or technical integration toggle is not permission to repurpose the data.
5. Customer responsibilities
Customer determines and documents a lawful basis, provides required notices, obtains required consents, validates its authority to appoint a Processor, and minimizes the data supplied. Customer is responsible for the lawfulness and accuracy of its content and instructions, managing its users, configuring access and retention choices, and responding to Data Subjects as Controller.
Customer will not submit special-category, criminal-offence, children's, payment-card, health, biometric-identification, or similarly regulated data unless Annex A expressly permits it and the necessary legal/technical safeguards are in place. Financial or freight records may include sensitive operational or personal information even if they are not GDPR special-category data; their controls must still fit the risks. Neither party assumes authority to record third parties or process their voice or documents without the necessary legal permissions.
6. Confidentiality and personnel access
Arga Core will restrict administrative access to encrypted records and necessary service metadata to authorized persons with a need for the instructed processing and appropriate confidentiality obligations or statutory duties. This administrative access does not permit reading protected customer content. Access authorization, training, changes in responsibility, and removal of access follow the controls in Annex B.
Customer information must not be made available to unrelated customers or used by personnel for unrelated purposes. Support operates within the documented instructions and does not require customers to disclose passwords, decryption material, or readable product content. Information a customer voluntarily submits as support correspondence is separately handled as correspondence under the Privacy Policy. Confidentiality duties survive termination for retained data, subject to lawful reporting and required disclosures.
7. Technical and organizational measures
Arga Core maintains encryption and customer control for protected product content, without access to its readable contents. The measures in Annex B address access control, appropriate transport and storage protection, isolation, change control, resilience, recovery, logging, and incident response for the applicable processing. No particular cryptographic algorithm, key-management design, independently verified zero-knowledge implementation, or certification is claimed through this general DPA.
Measures may be updated if overall protection is not materially reduced and the agreed obligations remain met. A material reduction requires notice and any required agreement or remedy. Arga Core will assess reasonably foreseeable risks and review relevant controls. Customer's configuration duties and any customer-managed keys, hosts, backup systems, or devices must be identified rather than assumed to be managed by Arga Core.
8. Subprocessor authorization and changes
Customer authorizes only the subprocessors identified in a completed Annex C or a specifically approved written update. An incomplete provider register does not create blanket authorization. Arga Core must bind subprocessors to data-protection obligations providing the protection required by the applicable law and this DPA, and remains responsible for its subprocessor obligations as the law requires.
For general written authorization, Arga Core provides advance written notice of additions or replacements at least 30 days before the new instructed processing, with 14 days for Customer to raise a reasonable data-protection objection, unless a signed agreement lawfully provides a different process. The notice identifies the provider, purpose, data, location, and relevant transfer safeguard. Immediate changes necessary for security or law require an agreed lawful emergency process, not silent removal of the right to object.
The parties will seek a reasonable alternative or mitigation for an objection. If no suitable solution is available, Customer may end the affected processing or Service under the agreed remedy without requiring unlawful continued processing. Subprocessor identity and changes remain available in a maintained register. Unrelated software dependencies or certificate infrastructure are not listed as Customer-data subprocessors merely because they exist in the build or deployment.
9. Data Subject requests and other Controller assistance
Taking account of the nature of processing, Arga Core will assist Customer with appropriate technical and organizational measures for lawful Data Subject requests, including access, correction, deletion, restriction, objection, and portability where those rights apply. Requests received directly concerning Customer-controlled records are referred to Customer unless law or Customer's instructions require another response. Arga Core does not independently decide the substantive outcome on Customer's behalf.
Arga Core will provide reasonable information and assistance concerning processing security, Personal Data Breaches, data-protection impact assessments, and regulator consultations, taking account of the information available to it. Assistance fees, if any, must be reasonable and agreed and must not prevent a mandatory response, incident notification, or other legally required cooperation. Customer supplies timely instructions and accurate contact details for this cooperation.
10. Personal Data Breach notification and cooperation
Arga Core notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Any tighter contractual target must be stated in the approved incident schedule. Notification does not wait for a complete investigation. An unsuccessful attack or routine access denial does not automatically establish a Personal Data Breach, but must be assessed where evidence indicates compromise.
As information becomes available, notice describes the nature of the breach, affected data and people where ascertainable, likely consequences, contact point, containment steps, and mitigation or recovery measures. Information may be provided in stages with prompt updates. Arga Core will preserve appropriate evidence, investigate, mitigate, and cooperate with Customer on response and notices without disclosing another customer's confidential information.
Customer retains responsibility for Controller notifications and communications unless the law imposes a separate obligation on Arga Core. Processor notification is not a substitute for Customer's own deadline; for example, a Controller subject to GDPR must separately evaluate its supervisory-authority notification requirements. The parties will not issue statements on the other's behalf without authority, except where law requires them.
11. International transfers and safeguards
Permitted processing locations and remote-access locations must be recorded in Annex A and Annex C. Arga Core will not make a Restricted Transfer on Customer's behalf without the required instructions and a valid safeguard or other legally permitted mechanism for that transfer. The parties assess the transfer, relevant local laws, and supplementary measures where required.
If EU Standard Contractual Clauses for transfers are needed, the parties must separately select the appropriate module from Commission Decision 2021/914, complete the annexes and options, identify the relevant parties and supervisory authority, and execute or validly incorporate the clauses without impermissible modification. For UK transfers, the applicable UK IDTA or Addendum and required assessment must be completed; Swiss adaptations are addressed where relevant.
This generic DPA does not deem incomplete SCCs, an adequacy mechanism, or a certification program executed or available. Controller/processor standard clauses under Decision 2021/915 are distinct from the international-transfer clauses under Decision 2021/914. Mandatory transfer provisions prevail over incompatible commercial clauses, including a conflicting choice of governing law or forum.
12. Information, audits, and inspections
Arga Core will make available information reasonably necessary to demonstrate compliance with its processor obligations and permit and contribute to audits and inspections by Customer or a qualified auditor mandated by Customer, as required by applicable law. Relevant evidence or independent reports may be used where sufficient, but do not extinguish a legally required inspection right.
Audits normally use reasonable notice, confidentiality, secure handling of findings, and proportionate scheduling to protect other customers and service operation. Those arrangements cannot obstruct regulator access, urgent breach-related review, or a mandatory right. Scope and fees for additional discretionary work are agreed. Arga Core does not claim SOC 2 or another independent certification through this DPA and does not substitute an unverified marketing statement for audit evidence.
13. Return, deletion, and retained copies
Customers may export retained product content at any time and direct its deletion through supported controls or a verified request to legal@argacore.com. Encrypted customer content is retained for up to five years, subject to earlier deletion and narrowly applicable legal retention duties. The five-year ceiling does not postpone a valid earlier deletion instruction. On completion of the processing, Arga Core returns or deletes the data at Customer's choice, subject to mandatory law.
Annex D specifies export formats, active-system deletion, backup expiry, and recovery restrictions. Any unavoidable backup-cycle delay is disclosed in the service schedule or response; this DPA does not promise an unspecified instantaneous purge. Deleting stored encrypted records does not give Arga Core access to their readable contents. Independent administrative or legally required records are processed under their separate applicable purpose and retention duties.
Data retained solely for legal duties or an agreed recovery cycle remains protected, access-restricted, and excluded from unrelated use. Backup data restored after a deletion request must be re-subjected to the relevant deletion instruction. Arga Core will provide reasonable confirmation of completed deletion or the lawful basis and scope of any retained data when requested.
14. U.S. service-provider and contractor restrictions
Where applicable state law treats Arga Core as a service provider, contractor, or processor, it will process Customer Personal Data only for the specified contracted purposes and permitted operational uses. It will not sell or share that data for covered cross-context advertising, retain/use/disclose it outside the permitted relationship, or combine it with unrelated data except as the applicable law expressly allows.
Customer may take reasonable steps to assess and enforce compliance, and Arga Core will provide required assistance and notify Customer if it can no longer meet the applicable restrictions. Customer may direct remediation or cessation of affected processing as the law requires. These restrictions supplement, rather than replace, the law's required specific-purpose, rights-assistance, security, assessment, and subprocessor terms. The parties must confirm which state laws apply to their particular processing.
15. Liability, priority, and term
This DPA applies for the duration of the instructed processing and its protected exit obligations. Any liability allocation follows the final accepted agreement only to the extent lawful; nothing restricts non-waivable Data Subject remedies, supervisory powers, or mandatory transfer-clause rights. A general commercial cap must not be assumed to resolve data-protection carve-outs that have not been agreed.
Within its subject matter this DPA prevails over conflicting general service terms; mandatory law and valid transfer clauses prevail within their scope. The final agreement's otherwise applicable law and notice rules govern residual contract matters subject to those priorities. Material changes require the agreed change process and cannot unilaterally reduce Customer's statutory protection.
Annex A. Parties and processing particulars
Complete this schedule for the actual deployment before instructed processing begins. The examples are scope aids, not permission to process every category or use every product. Customer must select the actual functions and minimum data needed.
| Required entry | Schedule to complete |
|---|---|
| Customer and upstream Controller | [Legal name, address, registration information where relevant, Customer's role, upstream authority if Customer is a Processor] |
| Contacts | Arga Core Inc.: legal@argacore.com; 30 N Gould St, Ste R, Sheridan, WY 82801. Customer: privacy/security contact and notification method identified in the Order. |
| Service, deployment, and duration | [Product IDs, permitted features, hosted/self-hosted/support scope, Order reference, term, and processing frequency] |
| Purpose and operations | [Storage, retrieval, synchronization, signing, communication, analysis, transcription, or other selected operations required for the contracted service] |
| Data Subjects | [Select relevant users, staff, customers, drivers/carriers, signers, business contacts, or other lawful categories] |
| Personal-data types | [Select relevant identity/contact, task, document/signature, freight, financial, communication, audio/transcript, and necessary security/usage records] |
| Restricted or sensitive data | [Explicit permitted categories, lawful authority, additional protections, or confirmation that they are excluded] |
| Locations and transfers | Hosted infrastructure: Utah, United States. Any additional support, customer-selected integration, or provider locations and required transfer mechanisms are recorded in the service schedule before the relevant processing. |
| AI-specific instructions | [Model/provider, data sent, provider retention, training restrictions, human review, and external-processing permissions; otherwise no additional authorization] |
Annex B. Security measures and responsibility allocation
The baseline is encrypted, customer-controlled product content without Arga Core access to readable contents; customer export at any time; and up to five years of encrypted retention subject to earlier deletion. This schedule allocates deployment-specific measures and responsibilities without claiming certification or a particular key-management architecture. Record the actual measure, party, scope, and evidence for each contracted Service.
| Control area | Minimum matters to specify and verify |
|---|---|
| Identity and access | Authorized roles, least privilege, authentication strength, credential handling, access reviews and timely removal |
| Data protection | Encrypted customer content; no Arga Core access to readable contents; appropriate transport protection, secret handling and isolation; product-specific key responsibilities stated in the service schedule |
| Development and changes | Review, deployment authorization, dependency/vulnerability management, configuration control and rollback |
| Logging and monitoring | Necessary events, sensitive-field minimization, access restrictions, retention, monitoring and investigation responsibility |
| Availability and recovery | Backup scope, encryption if applicable, recovery testing, agreed recovery objectives, failure response and restore restrictions |
| Incident management | Detection, triage, contact method, notification, evidence preservation, containment and follow-up |
| Personnel and vendors | Confidentiality, appropriate training, permitted support access, vendor due diligence and subprocessor contracts |
| Data lifecycle | Customer control and export at any time while retained; encrypted retention up to five years; earlier customer deletion/request; backup expiration, legal-hold handling and confirmation |
| Customer responsibilities | Customer-controlled hosts, endpoints, accounts, keys, configuration, user permissions, integrations and backups |
Annex C. Authorized subprocessor register
Hosted infrastructure is located in Utah, United States. The written subprocessor register for the applicable Service identifies any engaged provider, its purpose, received data, location, and required safeguards before authorization and use. This general DPA does not identify an unnamed vendor as approved or imply that a customer's own provider or an unrelated build dependency is automatically Arga Core's subprocessor. Request the applicable register at legal@argacore.com.
| Provider / status | Function and data | Location and safeguard |
|---|---|---|
| Hosting/compute, if a subprocessor is engaged | Identity and actual encrypted-data/metadata scope are provided in the service register | Utah hosting baseline; any additional access location and transfer mechanism are disclosed before authorization |
| Storage/backup, if used | Provider identity, encrypted recovery scope, access and expiry are specified in the register | Actual countries and contractual protections are recorded for that Service |
| Email/support, if customer records are sent | Provider identity, correspondence or metadata scope and retention are disclosed | Actual processing locations and contractual limits are recorded |
| AI/model, only if expressly authorized | Provider, inputs/outputs, purpose, retention and training restrictions are specified | Customer instructions and the required locations/safeguards are recorded before use |
Annex D. Retention, exit, notices, and execution
Retention and exit baseline: customer-controlled encrypted content; export at any time while retained; retention no longer than five years unless narrowly required by law; earlier customer deletion or verified request. The applicable service schedule records export format, access to retained data after termination, active-system deletion, backup expiration and restore handling, and any lawful retained-record category. It also identifies the Customer incident contact, escalation method, any agreed notification target, and each party's communications role.
For each customer agreement, record the parties and authorized representatives, Order reference, accepted DPA version, completed service schedules, any separately executed transfer clauses, acceptance or signature method, and date. Maintain the record of electronic incorporation or signatures. This DPA is effective October 6, 2026 as the published framework; it does not by itself execute an individual Customer agreement or incomplete international-transfer clauses.
Contact Arga Core Inc.
Wyoming corporation · Wyoming, California, and Utah.
Legal and privacy enquiries: legal@argacore.com
30 N Gould St, Ste R, Sheridan, WY 82801