Data Processing Addendum

How Arroway processes, on a team's behalf, the content that the team and its AI assistants write into it: who is responsible for what, how the data is protected, who else touches it and where, and how it ends.

1. Parties and roles

This Data Processing Addendum ("DPA") is part of the agreement between the customer ("Customer"), the organization on whose behalf its members and their AI assistants use Arroway, and Arroway, which is operated by Alexandre Viola ("Arroway"), under the Arroway Terms of Use.

For the content that Customer's people and AI assistants write into Arroway projects, Customer is the controller and Arroway is the processor. "Content" means memories, rules, decisions, daily-log entries and hand-offs, with the names of the people who wrote them.

For account and sign-in data, service e-mails and audience measurement of the public pages, Arroway is the controller, under its Privacy Policy. This DPA does not govern those.

2. Scope of the processing

Arroway processes Content only to provide the service Customer uses, for as long as Customer's account exists and until the deletion described in Section 9 is complete.

  • Nature of the processing: storing Content; showing it to Customer's people in the panel; returning it to the AI assistants those people connect, which read only the projects their person belongs to; and e-mailing project summaries and notices to those people.
  • Categories of data: the text of Content; the name and e-mail of each author, attached to what they wrote; which AI tool each person connected and when it was last active in a project; and the record of what each read delivered to an AI, which is deleted automatically after 90 days.
  • Data subjects: Customer's members, people Customer invites, and anyone named in Content.
  • Special categories of data: Arroway is not built for them and Customer should not write them into Content. The instruction handed to every connected AI forbids writing credentials, tokens and API keys into a project, with no exception.

Arroway never keeps passwords (it has none), the conversation between a person and their AI, their files, or the assistant's own memory: it cannot reach any of them.

3. Instructions and confidentiality

Arroway processes Content only on Customer's documented instructions: this DPA, the Terms of Use, and what Customer's people do with the product's features. Arroway does not sell, rent or share Content with third parties, and does not use it to train any AI model.

If Arroway believes an instruction breaks the law, it tells Customer before acting on it. Everyone at Arroway who can reach Content is bound by confidentiality.

Your AI assistant (Claude, ChatGPT or another) receives what it reads from Arroway, because it is the one reading. What that vendor does with it is governed by that vendor's policy, not by this DPA.

4. Security measures

Arroway applies the measures below, described as the system works at the date of this DPA. A change that weakens one of them is announced to Customer by e-mail before it takes effect.

  • In transit: the panel, the public pages and the address an AI connects to answer only over HTTPS, and the connection between the application and the database is encrypted.
  • At rest: the database provider encrypts stored data with AES-256, with keys managed in AWS Key Management Service.
  • Secrets: the private address of each AI connection, every invitation and every OAuth credential are stored only as SHA-256 digests, which recognise the right value and cannot rebuild it.
  • Authentication: Arroway has no passwords. People sign in with Google or with a link sent to their e-mail.
  • Access: an AI reaches only the projects its person belongs to, and that access always derives from the person's identity, never from anything the AI says. Revoking a connection ends its access immediately.
  • Monitoring: server error monitoring is set up not to send personal data and to mask connection addresses.
  • E-mail: messages are sent with opportunistic TLS, so they are encrypted whenever the receiving mail server supports it.
  • Retention limits: the record of what each read delivered, and the measurements of first use, are deleted automatically after 90 days. Daily-log entries older than 14 days stop being sent to AIs.

5. Sub-processors

Customer gives Arroway general authorization to use the sub-processors in Annex A to process Content.

Arroway tells Customer by e-mail at least 30 days before it adds or replaces a sub-processor that processes Content. Within that period Customer may object on reasonable data-protection grounds. If the objection cannot be resolved, Customer may stop using the affected service and have its Content deleted under Section 9.

Arroway binds each sub-processor to data-protection terms that protect Content to a level no lower in substance than this DPA, and remains responsible for what a sub-processor does with Content.

Annex A, at the end of this page, is the current list. The Trust page links to it, so a change shows here on the day it takes effect.

6. International transfers

Content is stored on servers in the United States (database on Amazon Web Services, US East; application hosting on Vercel). If Customer or its members are outside the United States, their Content is transferred there. The parts of Content that travel in e-mails (Annex A) are sent through Resend's São Paulo region.

Where that transfer is subject to the GDPR, the parties incorporate the EU Standard Contractual Clauses (Module Two, controller to processor), and the UK Addendum where the UK GDPR applies. Where it is subject to the LGPD, the parties use the standard contractual clauses approved by the Brazilian data protection authority (ANPD). Sections 2, 4 and Annex A complete the annexes of those clauses.

7. Data-subject requests

Arroway helps Customer answer requests from people exercising their rights under the LGPD or the GDPR (access, correction, deletion, restriction, portability and objection).

A request that reaches Arroway first is passed to Customer without delay and is not answered on Customer's behalf, unless Customer asks. A request from Customer to Arroway at hello@arroway.app is answered within 15 days.

Inside the product, people can already revoke an AI connection, correct or archive a memory, close a project and delete their own account. There is no export button: a copy of the data is something Arroway sends on request.

Arroway also assists, within reason, with data-protection impact assessments and prior consultations that concern Content.

8. Personal data incidents

Arroway tells Customer without undue delay, and within 72 hours, after it becomes aware of an incident that affects Content. The notice says what happened, which data and roughly how many people are affected, the likely consequences, and what Arroway has done and will do about it.

Arroway keeps Customer informed as it learns more and helps Customer meet its own duty to notify the competent authority and the people affected, as the applicable law requires.

9. Return and deletion

Content stays while Customer's account exists. Closing a project or archiving a memory hides it from AI reads and keeps the history, because knowing that something was decided and later reversed is part of the record.

When a person deletes their account, their access, AI connections, e-mail, picture and personal project are removed. What they wrote in a team project stays, under their name, because it is that team's record. Customer, as controller of that team project, may instead ask in writing for the project and its Content to be deleted, and Arroway does so within 30 days.

On the end of the agreement, Arroway returns a copy of Content on request and then deletes it, unless the law requires it to keep it. Deleted Content stays in the database provider's point-in-time restore history for up to one day, and Arroway keeps no snapshots.

10. Audit and records

Arroway keeps a record of the processing it does for Customer and gives Customer the information needed to show that this DPA is being followed: the Trust page, Annex A and written answers to a security questionnaire, once a year.

Customer may audit Arroway on site, or through an independent auditor bound by confidentiality, only when the law requires it or after an incident that affected Content. Arroway is given 30 days' notice, the audit runs at Customer's cost, and it never reaches other customers' data.

11. General

If this DPA and the Terms of Use conflict on the processing of personal data, this DPA prevails. Liability under this DPA is subject to the limits in the Terms of Use.

This DPA is governed by Brazilian law, as the Terms of Use are. Where Customer is a consumer, it keeps the right to bring a case where it lives. Otherwise disputes go to the courts of the operator's domicile in Brazil.

Last updated: 2026-10-06. A material change to this DPA is announced by e-mail before it takes effect, and the date here always says when this version started to apply. For anything this page does not answer, write to hello@arroway.app.

Annex A: Sub-processors

Six providers touch data in Arroway; three of them process Content. The regions of Neon, Resend and Sentry were read from each provider's own console on 2026-10-06.

Sub-processorWhat it doesProcesses Content?What it handlesWhere
NeonManaged PostgreSQL databaseYesAll Content and account dataAWS US East 1 (N. Virginia)
VercelHosts the application; counts page views without cookies; stores profile picturesYes, in transitEvery request to the panel and the connection address; profile picturesUnited States
ResendDelivers e-mailYes, in partSign-in link, invitations, notices and project summaries: memory titles and types, counts, author names, one-line summaries of log entries and hand-offs, next stepsSão Paulo, Brazil (sending region, sa-east-1)
SentryServer error monitoringNo, set up not to send personal data and to mask connection addressesError reportsUnited States (us.sentry.io)
Google (sign-in)Identity, when the person chooses GoogleNoName, e-mail, pictureSet by Google's terms
Google AnalyticsAudience measurement on the public pages only, never in the panelNoVisitor identifier cookie, pages viewed, origin of the visitSet by Google's terms