Data Processing Agreement
Last updated: October 2, 2026 · Effective October 2, 2026 · Kikzeny Cartagena LLC d/b/a ARI
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Kikzeny Cartagena LLC (“Processor,” “we,” “us”) and the Customer (“Controller,” “you”) and applies to the extent we process personal data on your behalf in connection with the Service. Capitalized terms not defined here have the meaning given in the Terms of Service or applicable data protection law (GDPR, CCPA/CPRA, or other).
1. Roles of the Parties
- You (Customer) are the Controller (or “Business” under CCPA) of the personal data contained in your Contacts/leads uploaded to ARI.
- We (Company) are the Processor (or “Service Provider” under CCPA), processing that personal data solely on your documented instructions, as set out in the Terms of Service and this DPA.
2. Subject Matter & Duration
We process personal data on your behalf for the duration of your subscription to the Service, for the purpose of providing CRM, campaign automation, calling, and texting functionality.
3. Nature & Purpose of Processing
Processing includes: storage, organization, retrieval, transmission, and deletion of Contact records (names, phone numbers, emails, addresses, notes, call/message logs) as needed to operate the Service features you configure.
4. Categories of Data Subjects
Individuals whose contact information you upload or generate through the Service - typically your leads, clients, prospects, or other business contacts.
5. Categories of Personal Data
- Contact details (name, phone, email, address)
- Communication content and metadata (call recordings, transcripts, SMS content, timestamps)
- Engagement data (opens, clicks, replies, campaign status)
- Any additional fields you choose to store in custom CRM fields
6. Processor Obligations
We agree to:
- Process personal data only on your documented instructions, including with regard to international transfers, unless required otherwise by law
- Ensure personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 9)
- Assist you, where reasonably possible, in responding to data subject requests (access, deletion, correction, portability)
- Notify you without undue delay after becoming aware of a personal data breach affecting your data
- Delete or return all personal data at the end of the subscription, at your choice, except where retention is required by law
- Make available information reasonably necessary to demonstrate compliance with this DPA
7. Subprocessors
You authorize us to engage subprocessors to provide the Service, including:
- Clerk (authentication)
- Supabase (database and storage)
- Stripe (payment processing)
- Vercel (hosting and infrastructure)
- Twilio (SMS, when you send messages)
- Resend (email delivery, when configured)
- Slybroadcast (ringless voicemail, when you send drops)
- Google Calendar (when you connect OAuth from Settings)
- Dotloop (when you connect OAuth from Settings)
- Anthropic and/or OpenAI (AI drafting features, when configured)
- ElevenLabs (AI voice synthesis, when configured)
We will maintain a current list of subprocessors available upon request and will notify you of material changes, giving you an opportunity to object on reasonable grounds.
8. International Data Transfers
If personal data is transferred outside the country of origin (e.g., from the EEA/UK to the United States), we will rely on an appropriate transfer mechanism, such as Standard Contractual Clauses (SCCs), to the extent required by applicable law.
9. Security Measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit
- Access controls limiting data access to authorized personnel
- Authentication requirements for account access
- Regular review of security practices
No system is completely secure, and we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a personal data breach affecting Customer Data, we will notify you without undue delay and provide reasonably available information to help you meet your own notification obligations under applicable law.
11. Audits
Upon reasonable request, and no more than once per year (unless required by a regulator or following a breach), we will provide information reasonably necessary to demonstrate compliance with this DPA, which may include responding to a written audit questionnaire in lieu of an on-site audit.
12. Deletion / Return of Data
Upon termination of the Service, we will, at your election, delete or return all personal data within a commercially reasonable period, except to the extent retention is required by law.
13. CCPA/CPRA Terms (if applicable)
To the extent California residents' personal information is processed:
- We will process personal information only for the limited and specified purpose of providing the Service
- We will not sell or share personal information, or retain, use, or disclose it outside the direct business relationship with you
- We certify that we understand these restrictions and will comply with them
14. Liability
Liability under this DPA is subject to the limitation of liability provisions in the underlying Terms of Service.
15. Precedence
In the event of a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA controls.
Questions about this policy? Contact hello@myari.io.
Related: Privacy policy · Terms of Service
