DATA PROCESSING AGREEMENT (DPA)
Last Updated: January 15, 2025
Version: v1.0
PARTIES
On one hand,
[CLIENT'S LEGAL NAME], with registered address at [ADDRESS], and Tax ID [●], hereinafter, the Data Controller.
And on the other hand,
[ARION'S LEGAL NAME], with registered address at [FULL ADDRESS, SPAIN], and Tax ID [●], hereinafter, Arion or the Data Processor.
Both parties, acknowledging their legal capacity, agree to enter into this Data Processing Agreement in accordance with Regulation (EU) 2016/679 (GDPR).
1. Purpose of the Agreement
This agreement regulates the conditions under which Arion will process personal data on behalf of the Data Controller within the framework of services provided through the Arion platform.
2. Nature and Purpose of Processing
The Processor will process personal data solely following the documented instructions of the Controller, for the following purposes:
- Provide access to and use of the Arion platform
- Manage users, organizations, roles, and permissions
- Process studies, values, metrics, and audits
- Ensure security, traceability, and proper service operation
- Execute automated analysis or artificial intelligence functionalities, when authorized by the Controller
3. Categories of Personal Data and Data Subjects
3.1 Categories of Data Subjects
- Users authorized by the Controller
- Professional staff of the Controller
- Other data subjects whose data is introduced by the Controller under their sole responsibility
3.2 Categories of Data
- Identification data (name, professional email, identifiers)
- Professional and role data
- Technical data (logs, audit, access)
- Data included by the Controller in studies or documents
4. Obligations of the Data Processor
Arion commits to:
a) Process personal data solely according to the documented instructions of the Controller
b) Not use the data for its own purposes or purposes other than those provided in this agreement
c) Ensure that persons authorized to process personal data have committed to respect confidentiality
d) Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
e) Assist the Controller, when necessary, in fulfilling obligations regarding data subjects' rights
f) Notify the Controller without undue delay of any personal data security breach
g) Not communicate personal data to third parties without express authorization, except when legally obligated
5. Obligations of the Data Controller
The Controller guarantees that:
a) Has sufficient legal basis for data processing
b) Has adequately informed data subjects
c) Has obtained necessary consents, when applicable
d) Will not introduce personal data into the platform unlawfully or contrary to applicable regulations
6. Security Measures
Arion implements appropriate technical and organizational measures, including but not limited to:
- Communication encryption
- Role-based access control (RBAC)
- Activity and audit logging
- Principle of least privilege
- Logical separation of data by organization
Measures may evolve according to the state of the art and risk associated with processing.
7. Sub-processors
The Controller authorizes Arion to subcontract certain services that involve access to personal data, such as:
- Cloud infrastructure providers
- Authentication services
- Technology providers necessary for service delivery
Arion guarantees that such sub-processors:
- Comply with GDPR
- Are subject to contractual obligations equivalent to those established in this agreement
8. International Data Transfers
In case personal data is transferred outside the European Economic Area, Arion commits to:
- Ensure the existence of adequate legal mechanisms (standard contractual clauses or others)
- Inform the Controller when legally required
9. Assistance in Exercising Rights
Arion will assist the Controller, as much as possible, so that the Controller can comply with requests for exercising data subjects' rights (access, rectification, deletion, etc.).
10. Automated Processing and Artificial Intelligence
When the Controller enables automated analysis or artificial intelligence functionalities:
- Processing will be carried out exclusively according to their instructions
- Data will not be used for general model training without express authorization
- No automated decisions with legal effects on natural persons will be adopted
11. Duration and Termination
This agreement will have the same duration as the main contractual relationship.
Once service provision is finished, Arion will:
- Delete or return personal data to the Controller, as requested
- May retain properly blocked data when there is a legal obligation
12. Liability
Each party will be responsible for non-compliance with obligations corresponding to them under GDPR and this agreement.
13. Confidentiality
The parties commit to maintaining confidentiality of information and personal data processed, even after the agreement's termination.
14. Applicable Law and Jurisdiction
This agreement is governed by Spanish law.
Parties expressly submit to the Courts and Tribunals of [CITY, SPAIN], except where mandatory legal provisions apply otherwise.
15. Acceptance
This Data Processing Agreement is considered accepted through:
- Signature of the main contract, or
- Electronic acceptance of Arion's Terms of Service
In witness whereof, both parties accept this agreement.