Data Processing Addendum
Effective July 19, 2026 · Last updated July 19, 2026
Arka Intelligence is a MSMM Engineering product. This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (the “Agreement”) between MSMM Engineering (“MSMM”, “Processor”) and the customer entity identified in the Agreement (“Customer”, “Controller”) for the Arka Intelligence platform (the “Service”).
This DPA applies where MSMM processes Personal Data on Customer’s behalf. Where it conflicts with the Agreement, this DPA prevails as to the processing of Personal Data.
1. Definitions
- “Data Protection Laws” — all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as incorporated into UK law (“UK GDPR”) with the Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and comparable US state privacy laws.
- “Personal Data” — information within Customer Data relating to an identified or identifiable natural person, or that is “personal information” or equivalent under applicable Data Protection Laws.
- “Customer Data” — as defined in the Agreement: content Customer or its users submit to or connect to the Service, including documents, connected mailbox and calendar content, and prompts.
- “Personal Data Breach” — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by MSMM.
- “Subprocessor” — a third party engaged by MSMM to process Personal Data on Customer’s behalf.
- “Standard Contractual Clauses” or “SCCs” — the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A DPA 2018.
- Controller, Processor, Data Subject, Processing, and Supervisory Authority have the meanings given in the GDPR. For CCPA purposes, Customer is a Business and MSMM is a Service Provider.
2. Roles and scope
2.1 Roles. For Personal Data within Customer Data, Customer is the Controller and MSMM is the Processor. Where Customer is itself a processor for a third-party controller, Customer warrants it has authority to engage MSMM as a subprocessor and that this DPA reflects that controller’s instructions.
2.2 MSMM as Controller. MSMM is an independent Controller for a limited set of data it processes for its own purposes — account records, authentication and audit logs, billing records, and Service telemetry — as described in the Privacy Policy. This DPA does not govern that processing.
2.3 Details of processing. The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are set out in Annex I.
3. Processing instructions
3.1 MSMM will process Personal Data only on Customer’s documented instructions, including as to international transfers, unless required otherwise by law to which MSMM is subject. Where law compels processing, MSMM will inform Customer before processing unless that law prohibits it on important grounds of public interest.
3.2 The Agreement, this DPA, and Customer’s configuration and use of the Service constitute Customer’s complete documented instructions. Additional instructions outside their scope require written agreement and may be subject to fees.
3.3 MSMM will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. MSMM may suspend the affected processing until the instruction is withdrawn, amended, or confirmed.
3.4 Customer responsibilities. Customer warrants that: it has a lawful basis for the processing it instructs; it has provided any notices and obtained any consents required, including from its own personnel and from individuals whose mailboxes are connected to the Service; and its instructions comply with Data Protection Laws. Customer is solely responsible for determining what Personal Data it submits or connects to the Service and for the accuracy and legality of that data.
3.5 No secondary use. MSMM will not sell or share Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service and the business purposes in Annex I, and will not combine it with personal information from other sources except as permitted by Data Protection Laws. MSMM does not use Personal Data to train, fine-tune, or improve generalized artificial intelligence or machine learning models.
4. Confidentiality
MSMM will ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations (contractual or statutory), are informed of the confidential nature of the data, and access it only as necessary to perform their duties and support the Service.
5. Security
5.1 MSMM will implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.
5.2 MSMM may update those measures provided the level of protection is not materially reduced.
5.3 Customer is responsible for its own security within its control, including access management for its users, credential hygiene, multi-factor authentication enrollment, permission and access-control configuration inside the Service, and prompt de-provisioning of departed users. Customer acknowledges that the Service’s access controls are configurable and that MSMM cannot assess whether Customer’s chosen configuration is appropriate for its data.
6. Subprocessors
6.1 General authorization. Customer grants MSMM general written authorization to engage Subprocessors, subject to this Section. The Subprocessors engaged as of the Effective Date are listed in Annex III.
6.2 Terms. MSMM will impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA to the extent applicable to the services the Subprocessor provides. MSMM remains fully liable to Customer for its Subprocessors’ performance of those obligations.
6.3 Changes and objection. MSMM will notify Customer at least thirty (30) days before adding or replacing a Subprocessor. Customer may object on reasonable data-protection grounds within that period by written notice to contact@msmmeng.com. The parties will discuss in good faith. If the objection is not resolved, Customer’s sole and exclusive remedy is to terminate the affected portion of the Service on written notice, with a pro-rata refund of prepaid fees for the terminated portion. Absent timely objection, the change is deemed approved.
6.4 Emergency replacement. Where a Subprocessor must be replaced urgently for security or continuity reasons, MSMM may do so and will notify Customer as soon as practicable thereafter.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the processing, MSMM will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to Data Subject requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.
7.2 The Service provides self-service functionality — search, export, deletion, and mailbox disconnection — that Customer may use to respond to such requests directly. Customer will use that functionality where it is sufficient.
7.3 If MSMM receives a request directly from a Data Subject relating to Customer’s Personal Data, MSMM will not respond substantively except to confirm receipt and direct the individual to Customer, and will notify Customer without undue delay unless legally prohibited.
7.4 Assistance beyond the self-service functionality and beyond what is reasonably required by Data Protection Laws may be provided at MSMM’s then-current professional-services rates, on prior written notice of the estimated cost.
8. Personal Data Breach
8.1 MSMM will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer’s Personal Data.
8.2 The notification will describe, to the extent known and as information becomes available: the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate adverse effects; and a contact point for further information. MSMM will provide updates as the investigation progresses.
8.3 MSMM will take reasonable steps to contain, investigate, and remediate the breach, and will reasonably cooperate with Customer’s own notification obligations to Supervisory Authorities and Data Subjects.
8.4 Customer is responsible for notifying Supervisory Authorities and Data Subjects where required; MSMM will not make such notifications on Customer’s behalf, and will not identify Customer publicly in connection with a breach without Customer’s consent unless legally required.
8.5 MSMM’s notification is not an acknowledgement of fault or liability.
9. Data protection impact assessments
Taking into account the nature of processing and the information available to it, MSMM will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities under GDPR Articles 35 and 36. MSMM’s security documentation, the Privacy Policy, and Annexes I–III are intended to supply the information Customer needs; assistance beyond that may be chargeable under Section 7.4.
10. Deletion and return
10.1 On termination or expiry of the Agreement, MSMM will, at Customer’s election, delete or return Personal Data. Customer may export Customer Data using the Service for thirty (30) days after termination.
10.2 After that period MSMM will delete Personal Data in accordance with the retention schedule in the Privacy Policy, except to the extent MSMM is required by law to retain a copy.
10.3 Customer acknowledges that encrypted backups may retain copies after deletion from live systems; those copies are isolated from the live Service and age out on the backup rotation cycle. MSMM will continue to protect them under this DPA until deleted.
10.4 Disconnecting a mailbox in the Service stops synchronization immediately and removes the stored message content and its derived index entries.
11. Audits and information
11.1 MSMM will make available to Customer the information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA.
11.2 Customer’s audit rights are satisfied in the first instance by MSMM’s security documentation, Annex II, and MSMM’s responses to a reasonable security questionnaire, which MSMM will provide no more than once in any twelve (12) month period absent a Personal Data Breach or a Supervisory Authority requirement.
11.3 Where that documentation is demonstrably insufficient, Customer or a mutually agreed independent auditor may conduct an audit, subject to: at least thirty (30) days’ prior written notice; no more than once in any twelve (12) month period (unless a Personal Data Breach has occurred or a Supervisory Authority requires otherwise); conduct during normal business hours without unreasonable disruption; scope limited to systems and records relevant to the processing of Customer’s Personal Data; execution of confidentiality undertakings; and Customer bearing its own and MSMM’s reasonable costs.
11.4 Audits will not include penetration testing, vulnerability scanning, or access to: MSMM’s source code; data of other customers; or infrastructure operated by Subprocessors, for which MSMM will instead supply the relevant Subprocessor documentation it is permitted to share.
12. International transfers
12.1 The Service is hosted in the United States (AWS us-east-1). Personal Data submitted to the Service will be transferred to and processed there.
12.2 EEA transfers. Where Customer transfers Personal Data subject to the GDPR to MSMM, the SCCs, Module Two (controller to processor), are incorporated into this DPA by reference and apply, with: Clause 7 (docking) included; Clause 9, Option 2 (general written authorization), notice period as in Section 6.3; Clause 11 optional redress body not selected; Clause 17 governed by the law of Ireland; Clause 18(b) forum Ireland; Annex I, II and III of the SCCs populated by Annexes I, II and III of this DPA respectively.
12.3 UK transfers. The UK Addendum is incorporated and applies to transfers subject to the UK GDPR, with Tables 1–3 populated by the Annexes to this DPA, Table 4 “neither party” may end the Addendum on changes, and the SCCs as modified by the Addendum.
12.4 Swiss transfers. The SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as competent authority, and “member state” not to be read so as to prevent Data Subjects in Switzerland from suing in their place of habitual residence.
12.5 If a transfer mechanism is invalidated or supplemented by regulatory guidance, the parties will cooperate in good faith to implement a valid alternative. Where MSMM adopts an approved certification (for example, the EU-US Data Privacy Framework), it may notify Customer and rely on it in place of the SCCs for covered transfers.
13. United States state privacy laws
13.1 CCPA. MSMM is a Service Provider and processes personal information only to perform the Service and the business purposes in Annex I. MSMM will not: sell or share personal information; retain, use, or disclose it for any purpose other than performing the Service, including for a commercial purpose other than the Service; retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal information received from another source, except as permitted by the CCPA.
13.2 MSMM certifies that it understands the restrictions in Section 13.1 and will comply with them. MSMM will notify Customer if it determines it can no longer meet its obligations, and Customer may on notice take reasonable steps to stop and remediate unauthorized use.
13.3 Other US state laws. Where Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or comparable state privacy laws apply, MSMM acts as a processor and the obligations in this DPA are intended to satisfy the contractual requirements those laws impose on controller-processor arrangements.
13.4 Deidentified data. If MSMM holds deidentified data, it will maintain it in deidentified form, publicly commit not to attempt reidentification, and contractually obligate recipients to the same.
14. Liability
14.1 Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s aggregate liability means aggregate liability under the Agreement and this DPA together.
14.2 Section 14.1 does not limit either party’s liability to Data Subjects or to a Supervisory Authority under Data Protection Laws, or any liability that cannot be limited by law, and does not affect the rights of Data Subjects under the SCCs.
15. General
- 15.1 Term. This DPA takes effect on the Effective Date and continues while MSMM processes Personal Data on Customer’s behalf under the Agreement.
- 15.2 Order of precedence. In case of conflict: (a) the SCCs and UK Addendum; (b) this DPA; (c) the Agreement.
- 15.3 Changes. MSMM may update this DPA where required by Data Protection Laws, a Supervisory Authority, a change in Subprocessors under Section 6, or a change to a transfer mechanism, provided the update does not materially reduce protection for Personal Data.
- 15.4 Severability. If a provision is invalid, the remainder stays in force and the parties will replace the invalid provision with a valid one of equivalent effect.
- 15.5 Governing law. Except where the SCCs or UK Addendum specify otherwise (Sections 12.2–12.4), this DPA is governed by the law stated in the Agreement.
- 15.6 Contact. All notices under this DPA: contact@msmmeng.com.
Annex I — Details of processing
A. List of parties
Data exporter (Controller): the Customer entity identified in the Agreement. Contact: as stated in Customer’s account. Activities: use of the Service for search, retrieval, and AI-assisted analysis of its own content. Role: Controller.
Data importer (Processor): MSMM Engineering. Contact: contact@msmmeng.com. Activities: provision, operation, security, and support of the Arka Intelligence platform. Role: Processor.
B. Description of processing
Categories of Data Subjects
- Customer’s personnel and authorized users of the Service.
- Senders, recipients, and other individuals appearing in mailboxes, calendars, and contacts that Customer’s users connect to the Service.
- Individuals whose personal data appears within documents, drawings, spreadsheets, structured data, or other files Customer uploads or makes available for indexing.
Categories of Personal Data
- Account and identity data: name, email address, organization and project membership, role assignments, authentication material (password hashes, TOTP enrollment), API keys, session records.
- Communications data: email message content, headers, addresses, timestamps, labels/folders, and attachments from connected mailboxes; calendar event content and participants where the Customer enables calendar access.
- Content data: any personal data contained within documents and files Customer submits, and within prompts, chat history, and generated outputs.
- Technical data: IP address, user-agent, request paths, audit records, and operational logs.
Sensitive data. The Service is not designed for, and Customer is instructed not to submit, special categories of personal data (GDPR Art. 9), criminal offence data (Art. 10), government identifiers, payment card data, or protected health information. Customer acknowledges that free-text content and mailbox content may nonetheless contain such data and that Customer alone determines what it submits. Where sensitive data is present, the measures in Annex II apply to it; MSMM offers no additional sector-specific safeguards and is not a HIPAA Business Associate.
Frequency. Continuous, for the duration of the Agreement.
Nature and purpose of processing
- Storage, hosting, and backup.
- Indexing: parsing, text extraction, chunking, and generation of vector embeddings to make content searchable.
- Retrieval and question answering over content the requesting user is permitted to access.
- Synchronization of connected mailboxes and calendars, and execution of user-initiated actions (send, label, archive, schedule).
- Automated classification and tagging of email.
- Security monitoring, abuse detection, audit logging, and incident response.
- Support and troubleshooting at Customer’s request.
Duration. For the term of the Agreement, plus the deletion periods in Section 10 and the retention schedule in the Privacy Policy.
Subprocessor processing. As set out in Annex III, for the duration of the Agreement.
C. Competent supervisory authority
Determined under SCC Clause 13 — the supervisory authority of the EEA member state in which the data exporter is established, or, where the exporter is not established in the EEA, of the member state where its Art. 27 representative is established or where the relevant Data Subjects are located. For UK transfers: the UK Information Commissioner’s Office. For Swiss transfers: the Swiss FDPIC.
Annex II — Technical and organizational measures
Measures in force as of the Effective Date. MSMM may update them provided protection is not materially reduced (Section 5.2).
Encryption
- Personal Data is encrypted in transit using TLS, between users and the Service and between internal components crossing a network boundary.
- Personal Data is encrypted at rest. Block storage, object storage, the secrets store, and backups are encrypted using AWS KMS customer-managed keys under MSMM’s exclusive control; certain object stores use AES-256 server-side encryption. Key policies restrict use to the roles that require it.
- Provider OAuth refresh tokens and credentials are encrypted with dedicated keys and held in a managed secrets service; they are excluded from application logs and are not present in source code. Multi-factor authentication secrets are encrypted at rest.
Tenant separation
- Each customer deployment runs in dedicated infrastructure — its own cluster, database, object storage buckets, search and vector indexes, and secrets namespace. Customer Personal Data is not stored in a datastore shared with another customer.
- Every record carries organization and project scoping enforced at the storage layer.
Access control
- Role-based access control for Service users, administered by Customer.
- Per-document and per-folder access controls that default to closed: a user has no access to content until access is granted.
- Mailbox isolation that fails closed: retrieval and question answering cannot return mailbox content belonging to another user; where ownership cannot be established, access is denied rather than permitted.
- Multi-factor authentication (TOTP, RFC 6238) is available for user accounts.
- Sessions are server-side and revocable; API keys are scoped to a principal.
- MSMM internal administrative access is limited to personnel who require it, authenticated, least-privilege, and logged.
Logging and monitoring
- Application audit logging of security-relevant and administrative events, categorized and severity-rated.
- Infrastructure and control-plane audit logging, with monitoring and alerting on infrastructure and application events.
- Operational telemetry is retained for 90 days.
Resilience and recovery
- Replicated database and storage tiers.
- Encrypted, access-controlled backups held separately from live systems.
- Infrastructure defined as code, enabling reproducible rebuild.
Software and change management
- Version-controlled source with peer review before merge.
- Automated static analysis, type checking, and test suites in the development workflow.
- Immutable, pinned container images; deployments reconciled from version control.
Personnel and subprocessor governance
- Access conditioned on need; confidentiality obligations as per Section 4.
- Credentials and secrets are provisioned per-role and revocable.
- Written contracts imposing equivalent data protection obligations (Section 6.2); subprocessor list maintained at Annex III.
Assistance measures
- Self-service export, deletion, and mailbox disconnection to support Data Subject rights (Section 7.2).
- Breach notification process per Section 8.
- Documentation and questionnaire responses to support Customer audits (Section 11).
Certifications — statement of fact
MSMM’s infrastructure includes audit tooling aligned to SOC 2 control criteria (centralized cloud audit trail, configuration recording, threat detection, and security posture monitoring). MSMM does not currently hold a SOC 2 Type I or Type II attestation report, an ISO 27001 certificate, or any equivalent third-party certification, and none is represented here. MSMM does not currently conduct scheduled third-party penetration testing. Customer should account for this in its own risk assessment.
Annex III — Subprocessors
Authorized as of the Effective Date under Section 6.1.
| Subprocessor | Role / processing activity | Personal Data processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure: compute, block and object storage, managed database, key management, networking, logging | All Customer Personal Data held by the Service, encrypted at rest | United States (us-east-1) |
| Anthropic, PBC | AI processing: automated email classification and tagging; document synthesis where Customer enables it | Email subject, sender metadata, and up to 10,000 characters of message body per message; document content where synthesis is enabled. Not retained by the subprocessor for model training | United States |
Connected providers. Where Customer connects a mailbox or calendar, Google LLC and Microsoft Corporation process that data as Customer’s own providers under Customer’s separate agreements with them. They are not MSMM Subprocessors; MSMM accesses that data only under the authorization Customer’s user grants, and MSMM is not responsible for those providers’ processing.
Current list. The authoritative list is maintained in this Annex. Notification of changes is given per Section 6.3 to the Customer contact on the account.