Roles and scope
This agreement applies when ArcDemo processes personal data for you as part of the Service. You (the customer) are the controller and Stackwise Oy is the processor. It forms part of our Terms of Service. For any processing of personal data, this DPA wins where the two differ.
Details of processing
- Subject matter and duration: providing the Service for as long as your subscription runs.
- Nature and purpose: capturing, storing, editing, hosting, sharing and analysing demos.
- Data subjects: your users, the people who view your demos, and anyone who appears in your captures.
- Categories of data: names, email addresses, identifiers visible in captures, form submissions, usage events, IP-derived location and device data.
- Special categories: none are intended. Don't capture them.
Your instructions
We process personal data only on your documented instructions, which are these terms and the way you configure the Service. If we think an instruction breaks data protection law, we'll tell you.
Confidentiality and security
Everyone who processes your data is bound by confidentiality. We maintain the technical and organizational measures described on our Security page and keep them up to date. They won't drop below the level described there.
Subprocessors
You authorize the subprocessors listed on our Subprocessors page. We hold each of them to data protection terms at least as protective as these. We'll give you 30 days' notice before adding or replacing one. If you object on reasonable grounds, we'll try to find a solution. If we can't, you may end the affected service.
International transfers
If personal data leaves the EEA, we use the European Commission's Standard Contractual Clauses or rely on an adequacy decision. Where needed, we add the UK and Swiss addenda.
Helping you meet your obligations
We'll help you respond to data subject requests, and with data protection impact assessments and consultations with supervisory authorities, as far as the nature of the processing allows.
Personal data breaches
We'll notify you without undue delay, and within 48 hours of becoming aware of a personal data breach that affects your data. We'll share what we know and what we're doing about it, and update you as we learn more.
Audits
We'll give you the information you need to show compliance with this agreement. We'll also allow a reasonable audit, no more than once a year, with 30 days' notice and under confidentiality, unless a supervisory authority requires more.
Return and deletion
When your subscription ends, you can export your content for 30 days. After that we delete personal data we hold for you, unless the law requires us to keep it. Backups expire on their own schedule.