Copy logo as SVG
Copy wordmark as SVG
Brand guidelines
Product
Features
AI Videos
On-brand videos in minutes
Agents
Power your workflows with agents
Interactive Demos
Effortlessly beautiful demos
Personalization
Tailored storytelling at scale
Integrations
Connect Arcade to other tools
Tools
Browser Extension
Capture from your browser
Desktop App
Capture multiple apps at once
Figma Plugin
Turn your designs into demos
Solutions
Product Marketing
From passive to interactive storytelling
Growth Marketing
Turn product demos and videos into pipeline
Product Management
From idea to launch
Sales Engineering
Better conversations ahead
Resources
State of AI Video 2026
New research on trust and adoption
Blog
The latest in visual storytelling
Knowledge Base
Unlock your creativity and learning
Guides
Hands-on guides to top software
Changelog
What’s new in Arcade
Events
Live sessions to learn and connect
Showcase
See best-in-class examples
Case studies
Stories from leading customers
EnterprisePricingOpen appSign up for freeTalk to sales
Talk to salesSign up for freeOpen app
Legal
Terms of ServicePrivacy policyData Processing AddendumAI AddendumSubprocessors

Data Processing Addendum

Last Updated: October 2, 2026

‍

This Data Processing Addendum (“DPA”) supplements the Terms of Service, or other agreement (the “Agreement”), entered into by and between Customer and Arcade Software, Inc., a Delaware corporation (“Arcade”). By executing the Agreement, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws (defined below), in the name and on behalf of its Affiliates (defined below), if any. This DPA incorporates the terms of the Agreement, and any terms not defined in this DPA shall have the meaning set forth in the Agreement.

‍

1. Definitions

1.1 “Affiliate” means (i) an entity of which a party directly or indirectly owns fifty percent (50%) or more of the stock or other equity interest, (ii) an entity that owns at least fifty percent (50%) or more of the stock or other equity interest of a party, or (iii) an entity which is under common control with a party by having at least fifty percent (50%) or more of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists. For the avoidance of doubt, and subject to Section 3 (Authorized Sub-Processors), Arcade’s obligations under this DPA do not extend to any Affiliate of Customer that has not separately executed an Order or agreement with Arcade.

‍

1.2 “Authorized Sub-Processor” means a third-party who has a need to know or otherwise access Customer’s Personal Data to enable Arcade to perform its obligations under this DPA or the Agreement, pursuant to Section 3.2 of this DPA.

‍

1.3 “Customer Account Data” means personal data that relates to Customer’s relationship with Arcade, including the names or contact information of individuals authorized by Customer to access Customer’s account and billing information of individuals that Customer has associated with its account. Customer Account Data also includes any data Arcade may need to collect for the purpose of managing its relationship with Customer, identity verification, or as otherwise required by Data Protection Laws and regulations.

‍

1.4 “Customer Usage Data” means Service usage data collected and processed by Arcade in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.

‍

1.5 “Data Exporter” means Customer.

‍

1.6 “Data Importer” means Arcade.

‍

1.7 “Data Protection Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the use or processing of Personal Data including: (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), (ii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR” or “GDPR”), (iii) the Swiss Federal Act on Data Protection (“FADP”), (iv) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”); (v) the UK Data Protection Act 2018; (vi) the Privacy and Electronic Communications (EC Directive) Regulations 2003; and (vii) any other applicable data protection or privacy law to the extent it applies to the processing of Personal Data under this DPA; in each case, as updated, amended or replaced from time to time. The terms “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing”, “processor,” “controller,” and “supervisory authority” shall have the meanings set forth under Data Protection Laws.

‍

1.8 “EU SCCs” means the standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time).

‍

1.9 “ex-EEA Transfer” means the transfer of Personal Data, which is processed in accordance with the GDPR, from the Data Exporter to the Data Importer (or its premises) outside the European Economic

Area (the “EEA”), and such transfer is not governed by an adequacy decision made by the European Commission in accordance with the relevant provisions of the GDPR.

‍

1.10 “ex-UK Transfer” means the transfer of Personal Data, which is processed in accordance with the UK GDPR and the Data Protection Act 2018, from the Data Exporter to the Data Importer (or its premises) outside the United Kingdom (the “UK”), and such transfer is not governed by an adequacy decision made by the Secretary of State in accordance with the relevant provisions of the UK GDPR and the Data Protection Act 2018.

‍

1.11 “Services” shall have the meaning set forth in the Agreement.

‍

1.12 “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018, as may be amended, updated or replaced from time to time.

‍

2. Relationship of the Parties; Processing of Data

2.1 The parties acknowledge and agree that with regard to the processing of Personal Data, Customer may act either as a controller or processor and, except as expressly set forth in this DPA or the Agreement, Arcade is a processor. Customer shall, in its use of the Services, process Personal Data, and provide instructions for the processing of Personal Data, in compliance with Data Protection Laws. Customer shall ensure that the processing of Personal Data in accordance with Customer’s instructions will not cause Arcade to be in breach of the Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Arcade by or on behalf of Customer, (ii) the means by which Customer acquired any such Personal Data, and (iii) the instructions it provides to Arcade regarding the processing of such Personal Data. Customer shall not provide or make available to Arcade any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services. Customer shall defend, indemnify and hold harmless Arcade from and against any third-party claims, damages, losses, costs (including reasonable attorneys’ fees) and other expenses arising from or relating to (a) Personal Data provided to Arcade by or on behalf of Customer, (b) Customer’s instructions to Arcade regarding processing, or (c) any breach by Customer of its obligations under this Section 2.1.

‍

2.2 Arcade shall not process Personal Data (i) for purposes other than those set forth in the Agreement and/or Exhibit A, (ii) in a manner inconsistent with the terms and conditions set forth in this DPA or any other documented instructions provided by Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which Arcade is subject; in such a case, Arcade shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest, or (iii) in violation of Data Protection Laws. Customer hereby instructs Arcade to process Personal Data in accordance with the foregoing and as part of any processing initiated by Customer in its use of the Services.

‍

2.3 The subject matter, nature, purpose, and duration of this processing, as well as the types of Personal Data collected and categories of Data Subjects, are described in Exhibit A to this DPA.

‍

2.4 Following completion of the Services, at Customer’s choice, Arcade shall return or delete Customer’s Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. Customer must make such election in writing within thirty (30) days after termination or expiration of the Agreement; if Customer does not make a timely election, Arcade shall delete Customer’s Personal Data. Arcade will complete a return request within thirty (30) days of receipt and a deletion request within sixty (60) days of receipt. Arcade's obligation to delete is satisfied by deleting the Customer's workspace and associated account data from Arcade's production systems and from its primary third-party storage and media-processing providers. That obligation does not extend to (a) copies held in automated backup, archival or disaster-recovery systems, or (b) usage, telemetry and analytics records, in each case which cannot be deleted without unreasonable effort. Personal Data retained under (a) or (b) will be deleted in the ordinary course of Arcade's data-retention cycle and will remain subject to the confidentiality and security obligations of this DPA for so long as it is retained. If return or destruction is impracticable or prohibited by law, rule or regulation, Arcade shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control. If Arcade will be transferring Personal Data outside of the European Union under the EU SCCs or the UK Addendum as described in Section 5 (Transfers of Personal Data), the parties agree that the certification of deletion of Personal Data shall be provided by Arcade to Customer only upon Customer’s written request.

‍

2.5 CCPA. Except with respect to Customer Account Data and Customer Usage Data, the parties acknowledge and agree that Arcade is a service provider for the purposes of the CCPA (to the extent it applies) and is receiving personal information from Customer in order to provide the Services pursuant to the Agreement, which constitutes a business purpose. Arcade shall not sell or share any such personal information. Arcade shall not retain, use or disclose any personal information provided by Customer pursuant to the Agreement except as necessary for the specific purpose of performing the Services for Customer pursuant to the Agreement, or otherwise as set forth in the Agreement or as permitted by the CCPA. The terms “personal information,” “service provider,” “sale,” and “sell” are as defined in Section 1798.140 of the CCPA. Arcade certifies that it understands the restrictions of this Section 2.5.

‍

3. Authorized Sub-Processors

3.1 Customer acknowledges and agrees that Arcade may (1) engage its Affiliates and the Authorized Sub-Processors (defined below) to access and process Personal Data in connection with the Services and (2) from time to time engage additional third parties for the purpose of providing the Services, including without limitation the processing of Personal Data. By way of this DPA, Customer provides general written authorization to Arcade to engage sub-processors as necessary to perform the Services. 

‍

3.2 Arcade's Authorized Sub-Processors (the "List") are published at https://www.arcade.software/subprocessors and the version in effect as of the date of this DPA is attached as Exhibit D. The List may be updated from time to time, and the current version of the List is incorporated into this DPA at https://www.arcade.software/dpa. At least fifteen (15) days before enabling any third party other than existing Authorized Sub-Processors to access or participate in the processing of Personal Data, Arcade will add such third party to the List, publish the updated List at that address, and record the date of the change. Arcade will additionally notify by email any Customer that has requested notice of sub-processor changes in writing. Customer may object to such an engagement by informing Arcade within ten (10) days of the date of such notice, provided such objection is in writing and based on reasonable grounds relating to data protection. Customer acknowledges that certain sub-processors are essential to providing the Services and that objecting to the use of a sub-processor may prevent Arcade from offering the Services to Customer.

‍

3.3 If Customer reasonably objects to an engagement in accordance with Section 3.2, and Arcade cannot provide a commercially reasonable alternative within a reasonable period of time, Customer may discontinue the use of the affected Service by providing written notice to Arcade. Discontinuation shall not relieve Customer of any fees owed to Arcade under the Agreement.

‍

3.4 If Customer does not object to the engagement of a third party in accordance with Section 3.2 within ten (10) days of notice by Arcade, that third party will be deemed an Authorized Sub-Processor for the purposes of this DPA.

‍

3.5 Arcade will enter into a written agreement with each Authorized Sub-Processor imposing on that Authorized Sub-Processor, in substance, the same data protection obligations as those imposed on Arcade under this DPA with respect to the protection of Personal Data, including in terms of third-party beneficiary rights for data subjects where the EU SCCs or the UK Addendum apply, and in particular requiring the Authorized Sub-Processor to provide sufficient guarantees to implement appropriate technical and organizational measures such that the processing meets the requirements of Data Protection Laws. In case an Authorized Sub-Processor fails to fulfill its data protection obligations under such written agreement with Arcade, Arcade will remain fully liable to Customer for the performance of the Authorized Sub-Processor's obligations under such agreement. 

‍

3.6 If Customer and Arcade have entered into EU SCCs or the UK Addendum as described in Section 5 (Transfers of Personal Data), (i) the above authorizations will constitute Customer’s prior written consent to the subcontracting by Arcade of the processing of Personal Data if such consent is required under the EU SCCs or the UK Addendum , and (ii) the parties agree that the copies of the agreements with Authorized Sub-Processors that must be provided by Arcade to Customer may have commercial information, or information unrelated to the EU SCCs or the UK Addendum or their equivalent, removed by Arcade beforehand, and that such copies will be provided by Arcade only upon request by Customer.

‍

4. Security of Personal Data.

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Arcade shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data. Exhibit C sets forth additional information about Arcade’s technical and organizational security measures.

‍

5. Transfers of Personal Data

5.1 The parties agree that Arcade may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services. Customer acknowledges that Arcade’s primary processing operations take place in the United States, and that the transfer of Customer’s Personal Data to the United States is necessary for the provision of the Services to Customer. If Arcade transfers Personal Data protected under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Arcade will ensure that appropriate safeguards have been implemented for the transfer of Personal Data in accordance with Data Protection Laws.

‍

5.2 Ex-EEA Transfers. The parties agree that ex-EEA Transfers are made pursuant to the EU SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:

‍

5.2.1 Module One (Controller to Controller) of the EU SCCs apply when Arcade is processing Personal Data as a controller pursuant to Section 8 of this DPA.

‍

5.2.2 Module Two (Controller to Processor) of the EU SCCs apply when Customer is a controller and Arcade is processing Personal Data for Customer as a processor pursuant to Section 2 of this DPA.

‍

5.2.3 Module Three (Processor to Sub-Processor) of the EU SCCs apply when Customer is a processor and Arcade is processing Personal Data on behalf of Customer as a sub-processor.

‍

5.3 For each module, where applicable the following applies:

‍

5.3.1 The optional docking clause in Clause 7 does not apply.

‍

5.3.2 In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of sub-processor changes shall be as set forth in Section 3.2 of this DPA; 

‍

5.3.3 In Clause 11, the optional language does not apply; 

‍

5.3.4 All square brackets in Clause 13 are hereby removed; 

‍

5.3.5 In Clause 17 (Option 1), the EU SCCs will be governed by Irish law; 

‍

5.3.6 In Clause 18(b), disputes will be resolved before the courts of the Republic of Ireland; 

‍

5.3.7 Exhibit B to this DPA contains the information required in Annex I of the EU SCCs; 

‍

5.3.8 Exhibit C to this DPA contains the information required in Annex II of the EU SCCs; and

‍

5.3.9 By entering into this DPA, the parties are deemed to have signed the EU SCCs incorporated herein, including their Annexes.

‍

5.4 Ex-UK Transfers. The parties agree that the UK Addendum will apply to Personal Data that is transferred via the Services from the United Kingdom, either directly or via onward transfer, to any country or recipient outside of the United Kingdom that is not recognized by the competent United Kingdom regulatory authority or governmental body for the United Kingdom as providing an adequate level of protection for Personal Data. For data transfers from the United Kingdom that are subject to the UK Addendum, the UK Addendum will be deemed entered into (and incorporated into this Addendum by this reference) and completed as follows:

(a) In Table 1 of the UK Addendum, the parties' details and key contact information is located in Exhibit B.

(b) In Table 2 of the UK Addendum, information about the version of the Approved EU SCCs, modules and selected clauses which this UK Addendum is appended to is located in Section 5 above.

(c) In Table 3 of the UK Addendum:

The list of Parties is located in Exhibit B.

The description of the transfer is set forth in Exhibit B.

Annex II is located in Exhibit C (Technical and Organizational Security Measures)

The list of Sub-processors is located at https://www.arcade.software/subprocessors

(d) In Table 4 of the UK Addendum, both the Importer and the Exporter may end the UK Addendum in accordance with the terms of the UK Addendum.

To the extent there is any conflict or inconsistency between the EU SCCs or UK Addendum and any other terms in this Addendum, the provisions of the EU SCCs or UK Addendum, as applicable, will prevail.

‍

5.5 Ex-Switzerland Transfers. The parties agree that transfers of Personal Data subject to the Swiss Federal Act on Data Protection ("FADP") are made pursuant to the EU SCCs as incorporated by Section 5.3, subject to the following: (a) references to the GDPR are to be understood as references to the FADP; (b) references to "Member State" and "EU" are to be understood as including Switzerland, and Data Subjects in Switzerland may enforce their rights in Switzerland under Clause 18(c); (c) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner in respect of transfers governed by the FADP; and (d) the EU SCCs also protect the data of legal entities until the entry into force of the revised FADP.

5.6 Supplementary Measures. In respect of any ex-EEA Transfer or ex-UK Transfer, the following supplementary measures shall apply:

‍

5.6.1 As of the date of this DPA, the Data Importer has not received any formal legal requests from any government intelligence or security service/agencies in the country to which the Personal Data is being exported, for access to (or for copies of) Customer’s Personal Data (“Government Agency Requests”); 

‍

5.6.2 If, after the date of this DPA, the Data Importer receives any Government Agency Requests, Arcade shall attempt to redirect the law enforcement or government agency to request that data directly from Customer. As part of this effort, Arcade may provide Customer’s basic contact information to the government agency. If compelled to disclose Customer’s Personal Data to a law enforcement or government agency, Arcade shall give Customer reasonable notice of the demand and cooperate to allow Customer to seek a protective order or other appropriate remedy unless Arcade is legally prohibited from doing so. Arcade shall not voluntarily disclose Personal Data to any law enforcement or government agency. Data Exporter and Data Importer shall (as soon as reasonably practicable) discuss and determine whether all or any transfers of Personal Data pursuant to this DPA should be suspended in the light of the such Government Agency Requests; and

‍

5.6.3 The Data Exporter and Data Importer will meet regularly to consider whether:

‍

(i) the protection afforded by the laws of the country of the Data Importer to data subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, whichever the case may be;

‍

(ii) additional measures are reasonably necessary to enable the transfer to be compliant with the Data Protection Laws; and

‍

(iii) it is still appropriate for Personal Data to be transferred to the relevant Data Importer, taking into account all relevant information available to the parties, together with guidance provided by the supervisory authorities.

‍

5.6.4 If Data Protection Laws require the Data Exporter to execute the EU SCCs or the UK Addendum applicable to a particular transfer of Personal Data to a Data Importer as a separate agreement, the Data Importer shall, on request of the Data Exporter, promptly execute such EU SCCs or the UK Addendum incorporating such amendments as may reasonably be required by the Data Exporter to reflect the applicable appendices and annexes, the details of the transfer and the requirements of the relevant Data Protection Laws.

‍

5.6.5 If either (i) any of the means of legitimizing transfers of Personal Data outside of the EEA or UK set forth in this DPA cease to be valid or (ii) any supervisory authority requires transfers of Personal Data pursuant to those means to be suspended, then Data Importer may by notice to the Data Exporter, with effect from the date set out in such notice, amend or put in place alternative arrangements in respect of such transfers, as required by Data Protection Laws.

‍

6. Rights of Data Subjects

6.1 Arcade shall, to the extent permitted by law, notify Customer upon receipt of a request by a Data Subject to exercise the Data Subject’s right of: access, rectification, erasure, data portability, restriction or cessation of processing, withdrawal of consent to processing, and/or objection to being subject to processing that constitutes automated decision-making (such requests individually and collectively “Data Subject Request(s)”). If Arcade receives a Data Subject Request in relation to Customer’s data, Arcade will advise the Data Subject to submit their request to Customer and Customer will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Customer is solely responsible for ensuring that Data Subject Requests for erasure, restriction or cessation of processing, or withdrawal of consent to processing of any Personal Data are communicated to Arcade, and, if applicable, for ensuring that a record of consent to processing is maintained with respect to each Data Subject.

‍

6.2 Arcade shall, at the request of the Customer, and taking into account the nature of the processing applicable to any Data Subject Request, apply appropriate technical and organizational measures to assist Customer in complying with Customer’s obligation to respond to such Data Subject Request and/or in demonstrating such compliance, where possible, provided that (i) Customer is itself unable to respond without Arcade’s assistance and (ii) Arcade is able to do so in accordance with all applicable laws, rules, and regulations. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Arcade.

‍

7. Actions and Access Requests; Audits

7.1 Arcade shall, taking into account the nature of the processing and the information available to Arcade, provide Customer with reasonable cooperation and assistance where necessary for Customer to comply with its obligations under the GDPR to conduct a data protection impact assessment and/or to demonstrate such compliance, provided that Customer does not otherwise have access to the relevant information. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Arcade.

‍

7.2 Arcade shall, taking into account the nature of the processing and the information available to Arcade, provide Customer with reasonable cooperation and assistance with respect to Customer’s cooperation and/or prior consultation with any Supervisory Authority, where necessary and where required by the GDPR. Customer shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Arcade.

‍

7.3 Arcade shall maintain records sufficient to demonstrate its compliance with its obligations under this DPA, and retain such records for a period of three (3) years after the termination of the Agreement. Any review or inspection of such records by Customer is subject to, and shall be exercised solely in accordance with, Section 7.4.

‍

7.4 Upon Customer’s written request at reasonable intervals, and subject to reasonable confidentiality controls, Arcade shall, either (i) make available for Customer’s review copies of certifications or reports demonstrating Arcade’s compliance with prevailing data security standards applicable to the processing of Customer’s Personal Data, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under Data Protection Laws, allow Customer’s independent third party representative to conduct an audit or inspection of Arcade’s data security infrastructure and procedures that is sufficient to demonstrate Arcade’s compliance with its obligations under Data Protection Laws, provided that (a) Customer provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Arcade’s business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Arcade for any time expended for on-site audits. If Customer and Arcade have entered into EU SCCs or the UK Addendum as described in Section 5 (Transfers of Personal Data), the parties agree that the audits described in the UK Addendum and Clause 8.9 of the EU SCCs shall be carried out in accordance with this Section 7.4. 

‍

7.5 Arcade shall promptly notify Customer if an instruction, in Arcade’s opinion, infringes the Data Protection Laws.

‍

7.6 In the event of a Personal Data Breach, Arcade shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as Arcade in its sole discretion deems necessary and reasonable to remediate such violation (to the extent that remediation is within Arcade’s reasonable control).

‍

7.7 In the event of a Personal Data Breach, Arcade shall, taking into account the nature of the processing and the information available to Arcade, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under the GDPR with respect to notifying (i) the relevant Supervisory Authority and (ii) Data Subjects affected by such Personal Data Breach without undue delay.

‍

The obligations described in Sections 7.6 and 7.7 shall not apply in the event that a Personal Data Breach results from the actions or omissions of Customer. Arcade’s obligation to report or respond to a Personal Data Breach under Sections 7.6 and 7.7 will not be construed as an acknowledgement by Arcade of any fault or liability with respect to the Personal Data Breach.

‍

8. Arcade’s Role as a Controller

The parties acknowledge and agree that with respect to Customer Account Data and Customer Usage data, Arcade is an independent controller, not a joint controller with Customer. Arcade will process Customer Account Data and Customer Usage Data as a controller (i) to manage the relationship with Customer; (ii) to carry out Arcade’s core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Customer; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Arcade is subject; and (vi) as otherwise permitted under Data Protection Laws and in accordance with this DPA and the Agreement. Arcade may also process Customer Usage Data as a controller to provide, optimize, and maintain the Services, to the extent permitted by Data Protection Laws. Any processing by Arcade as a controller of Customer Usage Data is processed for “contractual necessity”, meaning that Arcade needs to process such data to perform under the Agreement, which enables Arcade to provide and improve the Services, or in furtherance of the legitimate interests of Arcade or third parties. Arcade may also de-identify or anonymize Personal Data to further Arcade’s legitimate interests. When Arcade processes data due to contractual necessity, failure to provide such data, even Personal Data will result in Customer’s inability to use some or all portions of the Services that require such data. From time to time Arcade may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of Customer or other data subjects, or if it is necessary for a task carried out in the public interest.

‍

9. Conflict

In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the EU SCCs or the UK Addendum; (2) any separately negotiated written agreement mutually executed by authorized representatives of the parties, including any negotiated amendment to this DPA, provided that no such agreement reduces the obligations required of Arcade under Data Protection Laws; (3) the terms of this DPA; (4) the AI Addendum, solely to the extent set out in Section 10.1; (5) the Agreement; and (6) the Privacy Policy. Any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations of liability set forth in the Agreement.

‍

10. AI Processing

10.1 Artificial Intelligence. Where Arcade uses artificial-intelligence or machine-learning services to provide the Services, that processing is governed by the Arcade AI Addendum at https://www.arcade.software/ai-terms. For clarity: (a) Arcade does not use Customer Personal Data to train, fine-tune or otherwise modify the weights of any artificial-intelligence model, whether Arcade's or a third party's, and does not permit its AI sub-processors to do so; (b) "Model Training" and "Service Evaluation and Improvement" have the meanings given in the AI Addendum, and Arcade's use of Customer Personal Data for Service Evaluation and Improvement is limited as set out there; and (c) the AI providers engaged by Arcade are Authorized Sub-Processors and are subject to Section 3. In the event of a conflict between this DPA and the AI Addendum, this DPA controls with respect to the processing of Customer Personal Data, except that the AI Addendum controls solely with respect to (i) the meanings of "Model Training" and "Service Evaluation and Improvement" and Arcade's use of Input Data for those activities, and (ii) the allocation of rights in Input Data and Output.

‍

Exhibit A

‍

Details of Processing

‍

Nature and Purpose of Processing: Arcade will process Customer’s Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Customer’s instructions as set forth in this DPA.

‍

Duration of Processing: Arcade will process Customer’s Personal Data as long as required (i) to provide the Services to Customer under the Agreement; (ii) for Arcade’s legitimate business needs; or (iii) by applicable law or regulation. Customer Account Data and Customer Usage Data will be processed and stored as set forth in the Agreement and this DPA. 

‍

Categories of Data Subjects: Customer end-users/customers, Customer employees, viewers of Arcades published by Customer, and individuals whose Personal Data appears in content Customer captures or submits to the Services.

‍

Categories of Personal Data: Arcade processes Personal Data contained in Customer Account Data, Customer Usage Data, and any Personal Data provided by Customer (including any Personal Data Customer collects from its end users and processes through its use of the Services) or collected by Arcade in order to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include: name, email address, physical address, location, and authentication credentials; screenshots, screen recordings, and page data captured by Customer, which may contain any information displayed on the captured screen; audio recorded during a capture where Customer enables audio recording; media, brand assets, prompts, and instructions submitted by Customer to the Services, and outputs generated from them; and information relating to viewers of a published Arcade, including IP address, approximate location derived from IP address, device and browser information, viewing activity and interactions, information submitted through forms within an Arcade, and organisation-level information obtained through enrichment.

‍

Sensitive Data or Special Categories of Data: No sensitive data is intended to be transferred, unless Customer includes it unexpectedly in unstructured data such as a screen capture. Arcade does not create or derive biometric identifiers, including voiceprints or facial templates, from Customer's Personal Data.

‍

Exhibit B

‍

The following includes the information required by Annex I and Annex III of the EU SCCs, and the UK Addendum.

‍

1. The Parties

Data exporter(s):

Name: Customer, as stated and defined in the applicable Order (as such term is defined under the Agreement).

Address: Customer’s registered business address and any address provided to Arcade at the time that Customer uses the Services.

Contact person’s name, position and contact details: Customer’s contact for the purposes of the SCCs will be the contact of the person that properly accepts and binds Customer to the Agreement unless another contact person’s information is specifically provided to Arcade in writing.

Activities relevant to the data transferred under these Clauses: Submission of personal data to the data importer through the data exporter's use of the Services, including capturing screen recordings, screenshots, audio and page data; uploading media and brand assets; submitting prompts and instructions to AI Features; and publishing Arcades, demos and videos to viewers.

Signature and date: The UK Addendum and EU SCCs will be considered executed upon Customer’s proper acceptance of the Agreement.

Role (controller/processor): Controller, or processor where the data exporter processes on behalf of another controller, as determined under Section 2.1 of this DPA.

Data importer(s):

Name: Arcade Software, Inc.

Address: 445 Bush Street, Suite 400, San Francisco, CA 94108

Email: [email protected]
Contact person's name, position and contact details: Sydney Palumbo, Head of Engineering, [email protected]

Activities relevant to the data transferred under these Clauses: Provision of the Services as described in the Agreement, comprising the creation, editing, AI-assisted generation, hosting, publication, delivery and measurement of Arcades, demos and videos, together with the related support, security, billing and account-administration activities described in this DPA.

Signature and date: The UK Addendum and EU SCCs will be considered executed upon Customer's proper acceptance of the Agreement.

Role (controller/processor): Processor in respect of Personal Data processed on the data exporter's documented instructions (Modules Two and Three); independent controller in respect of Customer Account Data and Customer Usage Data as described in Section 8 of this DPA (Module One).

‍

2. Description of the Transfer

Data Subjects: The categories of data subjects are determined and controlled by the data exporter and may include:

  • the data exporter's personnel, including employees, consultants, contractors and agents authorised to access the data exporter's Arcade workspace;
  • the data exporter's customers, end users and prospective customers;
  • viewers of Arcades, demos and videos published by the data exporter; and
  • any individual whose personal data appears in screen recordings, screenshots, audio, page data, uploaded media, prompts or other content that the data exporter captures or submits to the Services.

Categories of Personal Data: 

The personal data transferred is determined and controlled by the data exporter and may include:

  • account and identity data: name, email address, physical address, location, job title and authentication credentials;
  • captured content: screenshots, screen recordings and page data (including HTML) captured by the data exporter, which may contain any information displayed on the captured screen;
  • audio: audio recorded during a capture where the data exporter enables audio recording, and narration the data exporter records or uploads;
  • AI input and output data: uploaded media, brand assets, prompts and instructions submitted to AI Features, and the outputs generated from them;
  • viewer data: IP address, approximate location derived from IP address, device and browser information, viewing activity and interactions, information submitted through forms within a published Arcade, and organisation-level information obtained through enrichment; and
  • usage data: activity logs and Service usage data as described in Section 1.4 of this DPA.

Special Category Personal Data (if applicable): The data importer does not request, and the Services are not designed to receive, special categories of personal data, and the data exporter is instructed not to submit such data. The data exporter acknowledges that special categories of personal data may nonetheless appear incidentally within unstructured content — such as a screen recording, screenshot, page data or audio recording — that the data exporter elects to capture or submit. Where such data is transferred, the technical and organizational measures set out in Exhibit C apply, together with the blur and redaction tools the data importer makes available within the Services. The data importer does not create or derive biometric identifiers, including voiceprints or facial templates, from personal data transferred under these Clauses.

Nature of the Processing: Collection, recording, organisation, structuring, storage, retrieval, transcoding, transcription, translation, analysis by the artificial-intelligence and machine-learning services described in the AI Addendum, hosting, publication and display to viewers at the data exporter's direction, transmission to Authorized Sub-Processors, erasure and destruction — in each case as necessary to provide the Services.

Purposes of Processing: To provide, secure, support and administer the Services to the data exporter in accordance with the Agreement, this DPA and the data exporter's documented instructions, including the creation, editing, AI-assisted generation, publication and measurement of Arcades, demos and videos; and, in respect of Customer Account Data and Customer Usage Data, for the controller purposes set out in Section 8 of this DPA.

Duration of Processing and Retention (or the criteria to determine such period): For the duration of the Agreement, and thereafter until Personal Data is returned or deleted in accordance with Section 2.4 of this DPA. Copies held in automated backup, archival or disaster-recovery systems are deleted in the ordinary course of the data importer's retention cycle as described in Section 2.4, and remain subject to the confidentiality and security obligations of this DPA for so long as they are retained.
Frequency of the transfer: Continuous, for the duration of the Agreement, as initiated by the data exporter through its use of the Services. 

Recipients of Personal Data Transferred to the Data Importer: The Authorized Sub-Processors identified in Exhibit D and published at https://www.arcade.software/subprocessors, as updated from time to time in accordance with Section 3.2 of this DPA.

‍Transfers to Sub-Processors: For transfers to the Authorized Sub-Processors identified in Exhibit D, the subject matter and nature of the processing are as described in the "Function" column of Exhibit D; the duration of processing is the duration of the data importer's engagement of that sub-processor, subject to the retention limits set out in this DPA and, for AI Subprocessors, Section 2.4 of the AI Addendum.

3. Competent Supervisory Authority

‍The competent supervisory authority is determined in accordance with Clause 13 of the EU SCCs, as follows:

(a) where the data exporter is established in an EU Member State, the supervisory authority of that Member State that is responsible for ensuring the data exporter's compliance with the GDPR in respect of the data transfer;

(b) where the data exporter is not established in an EU Member State but falls within the territorial scope of the GDPR pursuant to Article 3(2) and has appointed a representative pursuant to Article 27(1), the supervisory authority of the Member State in which that representative is established; and

(c) where the data exporter is not established in an EU Member State, falls within the territorial scope of the GDPR pursuant to Article 3(2), and is not required to appoint a representative pursuant to Article 27(2), the supervisory authority of a Member State in which the data subjects whose personal data is transferred under these Clauses are located.

Where the competent supervisory authority cannot be determined under (a) to (c), the parties agree that the Irish Data Protection Commission shall act as competent supervisory authority.

For transfers subject to the UK Addendum, the competent authority is the UK Information Commissioner's Office. For transfers subject to the FADP, the competent authority is as set out in Section 5.5 of this DPA.

Exhibit C

Description of the Technical and Organizational Security Measures implemented by the Data Importer

The following includes the information required by Annex II of the EU SCCs and Appendix 2 of the UK Addendum.

‍

Technical and Organizational Security Measure

Details

Pseudonymisation and encryption of personal data

Customer data is processed in a multi-tenant environment in which the workspace is the logical tenancy boundary. Server-side authorization, database security rules, ownership checks, and role-based access controls restrict access to authorized workspace resources. Data transmitted over public networks is encrypted using TLS. Production databases and object storage use provider-managed encryption at rest. Secrets and authentication credentials are maintained in managed identity, authentication, or secret-management systems and are not stored in plaintext in application source code.

Ongoing confidentiality, integrity, availability, and resilience

Arcade maintains documented access-control, secure-development, incident-response, business-continuity, and disaster-recovery practices. Controls include least-privilege access, multi-factor authentication or single sign-on where supported, code review and change controls, production monitoring and alerting, backups, and use of cloud infrastructure designed for redundancy and resilience.

Restoring availability and access after an incident

Primary customer application data stored in Firestore is backed up every two hours and retained for ninety (90) days, with additional Point In Time Recovery support available over the previous seven days, and authentication data is backed up daily. Backup copies are encrypted and stored in a multi-region location separate from production. Restoration priorities and targets are governed by Arcade's business-continuity and disaster-recovery procedures and any applicable commitments in the Agreement.

Regular testing and evaluation of security measures

Arcade monitors security and compliance controls on an ongoing basis, including through automated compliance tooling and management review. Arcade undergoes an annual SOC 2 Type II examination and commissions an independent penetration test at least annually. Current assurance materials are made available through Arcade's Trust Center or upon request, subject to appropriate confidentiality restrictions.

User identification and authorization

Access to production systems is assigned to uniquely identified users and limited according to role and business need. Arcade uses role-based access control, least-privilege permissions, encrypted administrative connections, strong password requirements, and multi-factor authentication or single sign-on where supported. Access is approved, periodically reviewed, and revoked when no longer required.

Protection of data during transmission

Customer data transmitted over public networks is protected using HTTPS/TLS or other encrypted transport appropriate to the service. Administrative access to production systems uses encrypted channels.

Protection of data during storage

Customer data may be stored in managed services provided by Google Cloud, Amazon Web Services, ClickHouse, and Authorized Sub-Processors identified in Exhibit D. Production databases, data stores, and object storage use provider-managed encryption at rest. Access is limited by identity, role, environment, and business need.

Physical security of processing locations

Arcade does not operate its own data centers. Physical and environmental controls for hosted production infrastructure are maintained by the applicable cloud and hosting providers. Arcade personnel must protect company devices and work areas, including by using automatic screen locking and following Arcade's physical-security and acceptable-use requirements.

Event logging

Arcade records authentication, administrative, security, application, and infrastructure events appropriate to the relevant system. Logs are used for security monitoring, troubleshooting, incident response, and audit support. Access to logs is restricted, and alerts are configured for material operational or security conditions.

System configuration and secure defaults

Production environments are configured through documented engineering and change-management practices. Arcade uses peer review, environment separation, managed secret storage, restricted production access, dependency and vulnerability monitoring, and configuration controls intended to reduce unauthorized or insecure changes.

Assurance of processes and products

Arcade undergoes a SOC 2 Type II examination covering applicable trust-services criteria and obtains an independent penetration test at least annually. Reports or summaries are available through Arcade's Trust Center or upon request, subject to appropriate confidentiality restrictions.

Data minimisation

Arcade limits collection and processing to information reasonably necessary to provide, secure, support, and administer the Services, to comply with law, and to perform the controller-side activities described in the DPA. Product and engineering changes affecting data collection are subject to review, and Arcade does not use Customer Personal Data for a materially different purpose without appropriate notice, instructions, or another valid legal basis.

Data quality

Arcade applies validation, testing, monitoring, and peer review to changes affecting data collection and processing. Customers control the source content and instructions they submit to the Services and may correct or replace that information through available product functionality or by contacting Arcade.

Limited data retention

Arcade maintains retention and deletion procedures based on the type of data, the purpose for which it is processed, contractual commitments, and legal requirements. Upon termination or a valid deletion request, Customer Personal Data is returned or deleted as described in the DPA. Data in backups and disaster-recovery systems is isolated from ordinary use and expires through the applicable backup-retention cycle unless retention is required by law.

Accountability

Arcade maintains written security and privacy policies, assigns responsibility for the security program, and requires personnel to acknowledge applicable policies, complete security and privacy training, and enter into confidentiality obligations. Arcade also maintains incident-response, access-review, secure-development, and vendor-risk-management processes and conducts background checks where permitted by law and appropriate to the role.

Data portability and erasure

Arcade maintains documented procedures to respond to valid requests for access, export, return, and deletion of Customer Personal Data. Available product features and APIs support export of relevant application data in commonly used formats. Deletion procedures address primary production systems and applicable Authorized Sub-Processors; residual copies in backups expire in the ordinary course, as described in the DPA and subject to applicable law and technical feasibility.

Technical and organizational measures of sub-processors

Before authorizing a sub-processor to process Customer Personal Data, Arcade conducts security and privacy due diligence proportionate to the service and risk and enters into written data-protection terms. Arcade periodically reassesses material sub-processors based on risk and requires them to implement appropriate safeguards, support incident response and data-subject obligations, and use lawful transfer mechanisms where required.

‍

Exhibit D

Authorized sub-processors.

‍

The following entities may process Customer Personal Data on Arcade's behalf to provide the Services. The listed location identifies the principal processing location used by Arcade; processing may also occur in other locations permitted by the applicable agreement and transfer mechanism.

‍

Sub-Processor

Category

Function

Location

Google LLC

Infrastructure and AI

Cloud hosting, compute, authentication, databases, object storage, and AI model services through Google Cloud and Vertex AI, including text, image, video, speech, and translation processing.

United States

Amazon Web Services, Inc.

Infrastructure

Managed cloud infrastructure, databases, data warehousing, object storage, and serverless compute used to operate and support the Services.

United States

Cloudflare, Inc.

Infrastructure

DNS, content delivery, network security, image optimization, and distributed-denial-of-service protection.

United States

Vercel Inc.

Infrastructure

Hosting and delivery of the Arcade web application and related edge services.

United States

Algolia, Inc.

Infrastructure

Indexing and search of customer workspace content and related metadata.

United States

Hatchet Technologies, Inc.

Infrastructure

Managed workflow orchestration and task execution metadata, including workspace, requester, and job identifiers used to run background workflows.

United States

browserless.io, Inc.

Media and content

Managed browser rendering and capture of customer-selected websites to extract page content, screenshots, and design context.

United States

Hookdeck Technologies Inc.

Media and content

Webhook receipt, relay, delivery, retry, and observability for media-processing and customer event workflows.

United States

Mux, Inc.

Media and content

Video hosting, transcoding, streaming, and transcription of customer-recorded media.

United States

Liveblocks, Inc.

Media and content

Real-time collaboration features in the Arcade editor, including presence, comments, and notifications.

United States

Footage Firm, Inc. d/b/a Storyblocks

Media and content

Search and retrieval of licensed stock media based on customer or workflow search terms and associated request identifiers.

United States

OpenAI OpCo, LLC

Artificial intelligence

Text and structured-output generation and analysis of customer-provided text, files, images, and sampled video frames.

United States

Eleven Labs Inc.

Artificial intelligence

Text-to-speech, music generation, pronunciation processing, sound effects, and audio-isolation services.

United States

Anthropic PBC

Artificial intelligence

Provider of Claude models accessed through Google Vertex AI for text and multimodal model processing. Arcade does not call Anthropic's API directly for these customer-facing workflows.

United States

OpenRouter, Inc.

Artificial intelligence

Routing of requests to supported third-party language and vision models for copy generation, Brand Kit workflows, and asset analysis.

United States

Braintrust Data, Inc.

Artificial intelligence

AI observability and evaluation, including storage and analysis of prompts, outputs, traces, and evaluation datasets. Not used for Enterprise workspaces.

United States

TypeSafe AI, Inc. (Jev)

Artificial intelligence

Automated quality checking of AI-generated video plans and output based on user-provided prompts. Receives text from the user's session, such as their requests and messages, and the generated plan or a description of the generated video. Not used for Enterprise workspaces.

United States

Exa Labs, Inc.

Artificial intelligence

Web search, page-content retrieval, and research used to supply context for AI-assisted workflows.

United States

Twilio Inc. (Segment)

Data and analytics

Collection and routing of viewer analytics events from published Arcade demos and videos.

United States

ClickHouse, Inc.

Data and analytics

Storage and querying of product and viewer event data used to operate, measure, and support the Services.

United States

Google LLC (Google Analytics)

Data and analytics

Measurement of viewer engagement with published Arcade demos and videos.

United States

Metabase, Inc.

Data and analytics

Internal business intelligence and reporting over analytics datasets that may include customer account, usage, viewer, or content-derived information.

United States

Fivetran Inc.

Data and analytics

Managed data integration and replication used to move data between Arcade production and analytics systems, including datasets that may contain customer information.

United States

PostHog, Inc.

Data and analytics

Product analytics, feature flags, and experimentation for the Arcade application using account-holder identifiers and in-product usage events.

United States

Finsweet Inc. (Consent Pro)

Data and analytics

Cookie consent management on Arcade's marketing website, including serving the consent banner, recording visitor consent choices, scanning the site to detect cookies and trackers, and generating cookie policy content. Does not receive Customer Personal Data.

United States, Western Europe

Functional Software, Inc. d/b/a Sentry

Operations and monitoring

Application error reporting and performance monitoring; Customer Personal Data may appear incidentally in diagnostic records.

United States

Twilio Inc. (SendGrid)

Business operations

Transactional email delivery for product, workspace, and account notifications.

United States

Stripe, LLC

Business operations

Payment processing, subscription billing, invoicing, and related account and transaction administration.

United States

Intercom, Inc.

Business operations

Customer support messaging, ticketing, and account communications that may include customer contact details and support content.

United States

HubSpot, Inc. (including Clearbit)

Business operations

Customer relationship management, marketing and sales operations, and Clearbit enrichment of account, company, and viewer-related records.

United States

Prighter GmbH

Business operations

Intake and administration of privacy rights requests through the Prighter Privacy Rights Manager, including contact details and request content submitted by data subjects.

Austria

‍

Customer-enabled integrations. Third-party services that a Customer elects to connect to the Services may also receive Customer Personal Data at the Customer's direction. Providers separately engaged by Arcade to process Customer Personal Data are listed above.

Other providers. This exhibit lists providers that process Customer Personal Data on Arcade's instructions. It does not list providers that support Arcade's own business operations and relationship with Customer — such as CRM, sales engagement, call recording, and internal collaboration tools — for which Arcade acts as an independent controller of Customer Account Data and Customer Usage Data as described in Section 8 of the DPA.

‍

Arcade on Twitter
Arcade on LinkedIn
Product
AI VideosInteractive DemosPersonalizationIntegrationsEnterprisePricingDesktop AppChrome Extension
Solutions
For Product MarketingFor Growth MarketingFor Product ManagementFor Sales EngineeringTalk to a GTM expert
Resources
BlogKnowledge BaseChangelogShowcaseCase studiesGuidesCommunity
Company
Careers
BrandSecurityStatusLegal

Smarter Stories, Every Month.

All good, you're in!
We have a little issue, please try again later.