Data Processing Agreement (DPA)
Last updated: October 9, 2026
English version provided for information only. In case of discrepancy, the French version prevails (section 5.7).
1. Purpose, parties and term
1.1 Parties. This agreement is entered into between the customer, the legal entity subscribing to the Arcane CRM service (the "Customer", controller), and Arcane Powered, a French SASU with share capital of €1,000, 142 rue de Rivoli, 75001 Paris, France, RCS Paris 109 293 266 ("Arcane", processor).
1.2 Purpose. It sets out how Arcane processes, on the Customer's behalf, the personal data held in the Customer's CRM, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").
1.3 Relationship with the terms. This agreement forms part of the Terms of Service and of the General Terms of Sale and Subscription ("CGV", Articles 1.3, 4.1 and 23.1), and is accepted with them at sign-up. In case of conflict on data protection, this agreement prevails.
1.4 Term. It applies for as long as Arcane processes data for the Customer, and until that data is deleted under section 3.7.
1.5 Out of scope. Processing for which Arcane is itself the controller (user accounts, billing, service security, support) is covered by the privacy policy, not by this agreement.
2. Description of the processing (Annex 1)
| Item | Content |
|---|---|
| Nature | Hosting, synchronisation, storage, search, AI analysis, meeting recording and transcription, sending e-mails on a user's action, export and deletion |
| Purpose | Providing the Arcane CRM service: contacts, companies and deals, Gmail and Outlook mail, calendar, meetings, documents and e-signature, automations, AI agent |
| Data subjects | The Customer's users; the Customer's contacts, prospects, clients and partners; correspondents of connected mailboxes; participants in recorded meetings; document signers |
| Categories of data | Identity and business contact details; e-mails, attachments and metadata; calendar events; meeting video, audio and transcripts; documents and signature evidence; commercial data and, if the Customer connects Stripe, its customers' billing data; any field added by the Customer |
| Special categories | Not intended. The Customer undertakes not to enter any without a legal basis |
| Duration | Term of the subscription, then deletion under section 3.7 and the periods in section 3.8 |
| Location | Database, files and backups in the European Union (Railway); see Annex 2 for providers outside the EU |
3. Arcane's obligations
3.1 Instructions. Arcane processes the data only on the Customer's documented instructions. These instructions are this agreement, the terms and the settings the Customer chooses in Arcane CRM (connected mailboxes, visibility, recording policy, region, retention periods). Arcane immediately informs the Customer if an instruction appears to infringe the GDPR. Where Union or Member State law requires processing, Arcane informs the Customer beforehand unless that law prohibits it.
3.2 Confidentiality. Persons authorised to process the data are bound by a contractual or statutory duty of confidentiality. Staff access to an organisation's data is limited to support and maintenance, logged, and visible to the account owner.
3.3 Security. Arcane implements the Article 32 GDPR measures described in Annex 3.
3.4 Sub-processors. Arcane engages another processor only under section 4.
3.5 Data subject rights. Arcane helps the Customer answer data subject requests through in-app features (access, rectification, export, deletion, forgetting e-mail addresses) and on request. The Customer answers them itself, instantly, in the application whenever it has access to the data concerned. Otherwise, and for any request received directly by Arcane, Arcane handles it or forwards it to the Customer within 5 business days.
3.6 Assistance. Arcane assists the Customer with its obligations on security, breach notification, impact assessments and prior consultation (Articles 32 to 36 GDPR), taking into account the information available to it.
3.7 End of contract. The account owner can export its data. Arcane then deletes it 30 days after an organisation's deletion request, or on day 120 of non-payment. Deleted data may remain for up to 30 days in technical backups, inaccessible and unused, before being erased. Arcane keeps no copy unless required by law.
3.8 Retention during the contract.
- Meeting recordings (video, audio, transcript): 30 days by default, extendable by the Customer up to 6 months (or its plan's maximum), then deleted automatically. Media is deleted at the recording provider after copying.
- Revoking access to a mailbox: processing stops at once, unaccepted suggestions are deleted at once, history e-mails unrelated to a CRM contact are purged within 30 days.
- A member leaving: their private e-mails and meetings are deleted 30 days after departure.
- End of the trial: data exceeding the Free plan's limits becomes read-only for 30 days, is then archived for 90 days, then deleted after notice by e-mail (CGV, Article 7.6).
3.9 Artificial intelligence. Only the content needed for the requested function is sent to models. Customer data is not used to train models. No e-mail is sent without a user's approval.
3.10 Audits. Arcane makes available to the Customer the information needed to demonstrate compliance with this agreement. The Customer may have an audit carried out, by itself or by an independent auditor bound by confidentiality, at most once a year, with 30 days' notice and at its own cost, except in case of a proven breach.
4. Sub-processors (Annex 2)
4.1 General authorisation. The Customer authorises Arcane to use the sub-processors listed below and on arcane-crm.com/fr/third-parties. Arcane imposes on them by contract data protection obligations at least equivalent to this agreement, and remains liable to the Customer for their failures.
4.2 Changes. Arcane informs the Customer of any addition or replacement at least 30 days in advance. The Customer may object within that period on data protection grounds. Arcane may then propose an alternative, for example not entrusting the Customer's data to that sub-processor or disabling the affected feature. Failing agreement, the Customer may terminate the affected service at no cost, with a pro-rata refund of the unused paid period.
| Sub-processor | Function | Data location | Safeguard outside the EU |
|---|---|---|---|
| Railway Corporation | Hosting of the application, database, files, backups | EU (US company) | SCCs (Railway DPA), declared DPF |
| Cloudflare, Inc. | Proxy, DNS, CDN, protection, service e-mails | Global network | SCCs and DPF (Cloudflare DPA) |
| OpenAI Ireland Ltd / OpenAI OpCo, LLC | AI features: agent, chat, writing, summaries, tasks | United States | SCCs (OpenAI DPA); no training; abuse logs up to 30 days |
| Mistral AI | Meeting transcription, EU-region organisations | EU (Paris) | Not applicable |
| xAI (SpaceXAI LLC) | Meeting transcription, US-region organisations | United States | SCCs (xAI DPA), zero retention |
| Recall.ai (Hyperdoc Inc.) | Meeting recording bot | EU or United States depending on the organisation's region | EU and UK SCCs (Recall.ai DPA) |
| Crisp IM SAS | Support chat | France | Not applicable |
| TypeSafe AI, Inc. | Checking and classifying attachments (Verdict) | United States | No training. Verdict is only enabled once SCCs are signed with TypeSafe |
4.3 Services connected by the Customer. Google (Gmail, Calendar), Microsoft (Outlook), Youtrust, DocuSign, the Customer's own Stripe account, Jira and the services called by its automations are not Arcane sub-processors. The Customer connects them with its own accounts, and its contracts with them apply.
4.4 Stripe. Stripe, used to pay for the Arcane CRM subscription, is not a sub-processor under this agreement: it only processes the Customer's billing data, for which Arcane is the controller (section 1.5).
4.5 Technical monitoring. SigNoz, Inc., which receives the service's technical traces, logs and metrics, is not a sub-processor under this agreement: no CRM content (e-mails, records, transcripts, AI prompts and answers) is sent to it, and e-mail addresses are masked before export. This technical data concerns the security and operation of the service, for which Arcane is the controller (section 1.5).
5. Transfers, breaches, liability
5.1 Transfers outside the EU. Stored data stays in the European Union. AI features run in the United States whatever the organisation's region; meeting recording and transcription do too for US-region organisations. Each transfer relies on the European Commission's standard contractual clauses and, where applicable, the Data Privacy Framework (Annex 2). A Customer administrator can change the recording and transcription region; the change is logged.
5.2 Personal data breaches. Arcane notifies the Customer of any personal data breach affecting it without undue delay and no later than 48 hours after becoming aware of it. The notice describes the nature of the breach, the data and data subjects concerned, its likely consequences and the measures taken or proposed. Arcane helps the Customer notify the supervisory authority and, where needed, the data subjects.
5.3 Customer obligations. The Customer has a legal basis for the data it entrusts to Arcane, informs data subjects, obtains participants' consent before recording a meeting where the law requires it, and uses the visibility and retention settings in line with the GDPR.
5.4 Liability. Each party's liability is governed by Article 19 of the CGV, including its cap (Article 19.3).
5.5 Governing law. This agreement is governed by French law. Disputes are handled under Article 27 of the CGV: an amicable solution is sought first, then the competent court.
5.6 Contact. Questions about this agreement: [email protected], or Arcane Powered, 142 rue de Rivoli, 75001 Paris, France. Data protection contact: Rayane Abdi, President.
5.7 Language. This agreement is drafted in French. The English version is provided for information only; in case of discrepancy, the French version prevails, as for the CGV (Article 26.4).
Annex 3: security measures
- Encryption in transit (TLS).
- Encryption at rest of data and backups (AES-256, Railway).
- Application-level encryption of OAuth tokens and integration secrets (AES-256-GCM).
- Segregation of organisations.
- Limited access rights; e-mails and meetings private by default, widened visibility logged and shown to members.
- Audit log; support access logged and visible to the account owner.
- Backups kept for at most 30 days.