ATLAS Globe
ATLAS
byArcSense

Legal

Data Processing Addendum

Effective July 24, 2026 · ArcSense Consulting Inc.

1. Purpose and scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer organization ("Customer") and ArcSense Consulting Inc. ("ArcSense", "we", "us", "our") and applies whenever ArcSense processes personal data on Customer's behalf in connection with the ATLAS platform ("the Service").

This DPA reflects the commitments already described in our Privacy Policy and Trust Center. Where this DPA and the Terms of Service conflict on data processing matters, this DPA controls. It is incorporated by reference into every ATLAS subscription and does not require a separate signature — organizations that need a countersigned copy for their own records may request one at info@arcsense.ca.

2. Roles of the parties

For the purposes of applicable data protection law (including the GDPR and PIPEDA), Customer is the controller (or, where Customer processes personal data on behalf of its own customers, a processor) of the personal data it submits to the Service ("Customer Data"), and ArcSense is a processor acting on Customer's documented instructions.

ArcSense processes Customer Data solely to provide, secure, and support the Service, as instructed by Customer through its configuration and use of the platform, and as necessary to comply with applicable law.

3. Details of processing

Subject matter: provision of the ATLAS strategic operations platform. Duration: for as long as Customer maintains an active organization on the Service, as described in our data retention practices.

Categories of data subjects: Customer's employees, contractors, and other individuals whose information Customer or its users choose to enter into the Service (e.g., names and roles recorded in governance artifacts, shareholder registers, or vendor assessments).

Categories of personal data: account identifiers (name, email, organization membership) and any personal data Customer includes within the strategic, governance, security, or operational content it creates in the Service ("Platform Content"). ArcSense does not require or request special categories of personal data and Customer should not submit such data to the Service.

Nature of processing: storage, hosting, transmission, and display of Customer Data as needed to operate the Service, including backups and the security monitoring described in Section 6.

4. Processor obligations

ArcSense will: (a) process Customer Data only on Customer's documented instructions, including those given through ordinary use and configuration of the Service; (b) ensure personnel authorized to process Customer Data are bound by confidentiality obligations; (c) implement the technical and organizational security measures described in Section 6; (d) assist Customer in responding to data subject requests as described in Section 7; and (e) not sell Customer Data or use it to train machine learning or AI models.

5. Sub-processors

ArcSense engages a limited set of sub-processors to operate the Service. The current list is published and kept up to date at arcsense.ca/trust rather than reproduced here, so that it always reflects the providers actually in use. ArcSense imposes data protection obligations on each sub-processor materially equivalent to those in this DPA.

ArcSense will provide notice via the Trust Center (and, on request, by email) before adding a new sub-processor with access to Customer Data, and Customer may object on reasonable data-protection grounds by contacting info@arcsense.ca within 14 days of that notice.

6. Security and international transfers

ArcSense maintains the security controls described in our Privacy Policy and Trust Center, including encryption in transit and at rest, database-level row security enforcing per-organization isolation, access logging, and continuous monitoring.

Customer Data is primarily hosted in the United States and Canada, as reflected in the regions listed for each sub-processor on the Trust Center. Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, ArcSense relies on the Standard Contractual Clauses (or an equivalent recognized transfer mechanism) with the relevant sub-processor.

7. Data subject requests and breach notification

Customer is responsible for responding to requests from its own data subjects. Most access, export, and deletion requests can be self-served directly within the Service; for anything else, ArcSense will provide reasonable assistance if Customer contacts info@arcsense.ca.

If ArcSense becomes aware of a security incident affecting the confidentiality, integrity, or availability of Customer Data, it will notify Customer without undue delay and in any case consistent with the timelines in our incident response practices, providing the information reasonably available to help Customer meet its own regulatory notification obligations.

8. Audit rights

ArcSense will make available the information reasonably necessary to demonstrate compliance with this DPA, including relevant sections of its penetration test summary and SOC 2 report once available (see our Trust Center for current status). Where that documentation is insufficient, ArcSense will support a reasonable audit by Customer or its appointed auditor, subject to reasonable advance notice, confidentiality protections, and no more than once per 12 months absent a security incident.

9. Return or deletion of data

On termination of Customer's subscription, ArcSense will make Customer Data available for export for the period described in our data retention practices, after which it will delete Customer Data from active systems and purge it from backups within 90 days, except where retention is required by law.

10. General

This DPA is governed by the same governing law and liability terms set out in our Terms of Service. It remains in effect for as long as ArcSense processes Customer Data on Customer's behalf under the Service.

11. Contact

Questions about this DPA, or requests for a countersigned copy, may be directed to: info@arcsense.ca