This Data Processing Addendum is part of the Arodus Terms of Service. It applies when your organization accepts the Terms, so there's nothing to sign. Admins can download a pre-signed copy from Settings → Billing.
Version 1.0, effective October 2, 2026. Questions or a negotiated version: security@arodus.com.
This Data Processing Addendum ("DPA") forms part of the Arodus Terms of Service (the "Terms") between Arodus Inc. ("Arodus") and the customer that accepts the Terms ("Customer"). Capitalized terms not defined here have the meaning given in the Terms.
1. How this DPA applies
1.1 This DPA applies when Customer accepts the Terms, including by starting a trial. No signature is required. Arodus records the date of acceptance and the versions of the Terms and this DPA that were accepted.
1.2 A copy of this DPA signed by Arodus and identifying Customer is available to Customer's administrators in the Service. That copy evidences this DPA and does not change it.
1.3 If Customer and Arodus sign a separately negotiated data processing agreement, that agreement replaces this DPA for Customer.
2. Definitions and roles
2.1 "Data Protection Laws" means all laws on the processing of personal data that apply to a party's processing of Customer Personal Data, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
2.2 "Customer Personal Data" means personal data that Arodus processes on Customer's behalf in providing the Service, as described in Annex I. "Controller," "processor," "data subject," "personal data," "processing" and "personal data breach" have the meanings given in the GDPR, and the equivalent terms in other Data Protection Laws (such as "business" and "service provider") are read accordingly.
2.3 For Customer Personal Data, Customer is the controller and Arodus is the processor. Arodus is an independent controller, and this DPA does not apply, for: (a) account, sign-in and billing data Arodus uses to run its business; (b) Contributions as described in the Terms, once anonymized and attributed only by role and verified spend band; and (c) Aggregated Data under section 15. The Privacy Policy describes that processing.
3. Processing on instructions
3.1 Arodus processes Customer Personal Data only on Customer's documented instructions. The Terms, this DPA, Customer's configuration of the Service (including the ERP connection and the line-item setting) and Customer's use of the Service are Customer's complete instructions. Additional instructions need written agreement.
3.2 Arodus will tell Customer if it believes an instruction breaks Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or changed.
3.3 Arodus processes Customer Personal Data only to the extent needed to provide the Service. Arodus reads accounts payable records, the customer's own company profile and book-close date from Customer's accounting system, sends read requests only, and stores only the fields set out in Annex I.
3.4 Customer is responsible for having a lawful basis for the processing and for giving any notices the processing requires, including to its own vendors' contact persons.
4. Confidentiality
Arodus ensures that everyone it authorizes to process Customer Personal Data is bound by confidentiality obligations and has access only as needed for their role.
5. Security
5.1 Arodus implements the technical and organizational measures in Annex II, which are designed to protect Customer Personal Data against personal data breaches and to keep each customer's data logically isolated from every other customer's.
5.2 Arodus may update those measures, provided that no update materially lowers the overall protection of Customer Personal Data.
6. Assistance
6.1 Arodus will promptly forward to Customer any request from a data subject about Customer Personal Data and will not respond to it except on Customer's instruction. Taking into account the nature of the processing, Arodus will help Customer respond, mainly through the Service's own features.
6.2 Arodus will give Customer reasonable information and help with data protection impact assessments and prior consultations with supervisory authorities, to the extent the information is available to Arodus.
7. Subprocessors
7.1 Customer gives Arodus general authorization to engage subprocessors. The subprocessors in use on the effective date are listed at arodus.com/subprocessors, which forms part of this DPA.
7.2 Arodus will give at least 30 days' notice before a new subprocessor processes Customer Personal Data, by email to Customer's workspace administrators and to any address Customer adds for notices, and by updating the list. Arodus may replace a subprocessor on shorter notice where needed to keep the Service secure or available, and will give notice as soon as it can.
7.3 Customer may object to a new subprocessor on reasonable data protection grounds by writing to security@arodus.com within the notice period. The parties will discuss the objection in good faith. If Arodus can't reasonably avoid using the subprocessor for Customer, Customer may terminate the affected part of the Service, and Arodus will refund any prepaid fees for the period after termination.
7.4 Arodus imposes on each subprocessor, by written contract, data protection obligations that protect Customer Personal Data at least as well as this DPA, and remains responsible for each subprocessor's performance of those obligations.
7.5 Arodus monitors each subprocessor that handles Customer Personal Data as a vendor in its own Arodus workspace, and reviews any event it marks Relevant under section 8.
8. Personal data breaches
8.1 Arodus will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Arodus will supplement the notice as more becomes known.
8.3 Arodus will take reasonable steps to contain and remediate the breach and will help Customer meet its own notification obligations. A notice is not an admission of fault.
9. Records you choose to share
9.1 Bill line items are processed only if a Customer administrator turns on line-item storage. When it is turned off, Arodus stops collecting line items and deletes those it stored within 30 days.
9.2 Line items, Customer's identifiable records and Customer's spend figures are processed only for Customer's workspace and are never used in network signals or shown to other customers.
10. Individuals as vendors
Where a vendor in Customer's accounting system is a natural person, Arodus processes that vendor's data only for Customer's workspace. It does not monitor them, does not add them to the shared vendor catalog, and does not use them in network signals.
11. Return and deletion
11.1 On termination of the Terms, or on Customer's written request, Arodus will delete Customer Personal Data within 30 days. Backup copies expire within a further 30 days and are not restored except to recover the Service.
11.2 Before deletion, administrators can export their vendor list and records from the Service.
11.3 Arodus may keep Customer Personal Data longer only where law requires it, and then keeps it confidential and processes it only for that purpose.
12. Audits
12.1 Arodus will make available the information reasonably needed to show compliance with this DPA. In the first instance that consists of this DPA, Annex II, a completed security questionnaire once a year, and, once issued, Arodus's SOC 2 reports.
12.2 If that information isn't enough to meet a requirement of Data Protection Laws or a supervisory authority, Customer may audit Arodus's compliance once a year, on at least 30 days' notice, during business hours, through an independent auditor bound by confidentiality, at Customer's cost, and without access to other customers' data.
13. International transfers
13.1 Arodus processes Customer Personal Data in the United States.
13.2 Where Customer Personal Data is transferred from the European Economic Area to Arodus, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs") are incorporated into this DPA as follows: Module Two applies where Customer is a controller and Module Three where Customer is a processor; Clause 7 (docking) applies; under Clause 9, Option 2 applies with the notice period in section 7.2; the option in Clause 11 does not apply; under Clause 13, the supervisory authority is the one competent for Customer; Clauses 17 and 18 select the law and courts of Ireland; Annexes I to III of the SCCs are completed by Annexes I to III of this DPA.
13.3 For transfers from the United Kingdom, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0) applies, with Tables 1 to 3 completed by this DPA and either party able to end it as allowed in Table 4.
13.4 For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and Swiss data subjects able to bring claims in Switzerland.
13.5 If the SCCs and this DPA conflict, the SCCs control.
14. US state privacy laws
14.1 Arodus is a service provider (or processor) to Customer for Customer Personal Data under the CCPA and other US state privacy laws.
14.2 Arodus will not: (a) sell or share Customer Personal Data, as those terms are defined in the CCPA; (b) retain, use or disclose it for any purpose other than the business purposes in Annex I, or outside the direct business relationship with Customer; or (c) combine it with personal data Arodus receives from others, except as the CCPA permits a service provider to.
14.3 Arodus will comply with the CCPA as it applies to service providers, give the same level of privacy protection it requires, and notify Customer if it can no longer meet these obligations. Customer may then take reasonable steps to stop and remediate unauthorized use.
15. Aggregated Data
15.1 Arodus may create data that is aggregated and deidentified so that it does not identify Customer, any individual or any household, and can't reasonably be linked to them ("Aggregated Data"). Aggregated Data includes the relative spend trends and network signals described in the Terms, published only where enough buyers contribute that no single account can be identified.
15.2 Arodus will take reasonable measures to keep Aggregated Data deidentified, publicly commits not to reidentify it, and contractually requires any recipient to do the same. Aggregated Data is not Customer Personal Data.
16. Liability and general terms
16.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. Nothing in this DPA limits a data subject's rights under the SCCs.
16.2 If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls.
16.3 This DPA lasts as long as Arodus processes Customer Personal Data. Arodus may update it on 30 days' notice to workspace administrators. An update may not reduce the protection of Customer Personal Data except where Data Protection Laws require the change.
16.4 This DPA is governed by the law that governs the Terms, except where the SCCs or Data Protection Laws require otherwise.
Annex I: Details of processing
| Item | Detail |
|---|---|
| Data exporter | Customer, as identified at acceptance of the Terms. Role: controller (or processor for its own customers) |
| Data importer | Arodus Inc., Delaware, United States. Contact: security@arodus.com. Role: processor |
| Subject matter and nature | Reading accounts payable records from Customer's accounting system through a connection Customer authorizes; matching vendors to a vendor catalog; computing spend; monitoring vendors for events; showing the results to Customer's users |
| Purpose | Providing the Service under the Terms |
| Duration | The term of the Terms, plus the deletion periods in section 11 |
| Frequency | Continuous; Customer's accounting data syncs daily |
| Data subjects | Customer's authorized users; contact persons at Customer's vendors; vendors who are natural persons (sole proprietors and freelancers); individuals named in bill line items, if Customer turns line-item storage on |
| Categories of personal data | Users: name, work email, role. Vendor contact persons: name, email address, phone number and street address, used for matching and not stored. Vendors who are natural persons: name, city, state and country, website and email domain, and the bills, payments and credits Customer recorded with them. Line items, if turned on: description, amount, item or account, quantity |
| Data Arodus does not store | Vendor account numbers held with the vendor, tax identifiers, the bank or card account a payment came from, free-text memos, and Customer's own street address, phone and contact email after account setup |
| Sensitive data | None intended. Customer should not record special categories of data in vendor or line-item fields |
| Retention | As in section 11. Working copies kept to re-run a sync hold only the stored fields and expire after 30 days |
Annex II: Technical and organizational measures
| Measure | What Arodus does |
|---|---|
| Encryption | TLS 1.2 or higher in transit; AES-256 at rest; keys managed in AWS KMS; connection credentials held in encrypted secrets management and never logged in plaintext. |
| Tenant isolation | Every customer's data is logically separated through a per-tenant routing table and checked on every request. Responses are built from allowlisted fields only. |
| Read-only accounting access | Arodus sends read requests only. Every request to an accounting system is checked in code against a fixed list of permitted records before it is sent, and a build-time check blocks code that requests anything else. On NetSuite, the integration role also restricts access. |
| Data minimization | A field allowlist governs what is stored from each accounting record, including copies kept to re-run a sync. Contact email addresses are reduced to their domain at the point of reading. |
| Access control | Production access is need-to-know, granted individually, protected by multi-factor authentication and reviewed regularly. |
| Logging and monitoring | Infrastructure and application logging and alerting. Personal data, account numbers and bank details are kept out of URLs, logs and third-party telemetry. |
| Secure development | Code review on every change, dependency and vulnerability scanning, and separate development and production environments. |
| Resilience | Managed database backups with retention of 30 days or less; infrastructure in AWS us-east-1. |
| Vendor management | Every subprocessor is under written contract and monitored as a vendor in Arodus's own workspace. |
| Incident response | A documented process that meets the 72-hour customer notice in section 8. |
| Assurance | SOC 2 is on Arodus's compliance roadmap, Type I first, then Type II. Arodus will share each report once it's issued. |
Annex III: Subprocessors
The current list, with what each subprocessor does, the Customer Personal Data it handles and its location, is published at arodus.com/subprocessors and forms this Annex.
Version history
| Version | Effective | Change |
|---|---|---|
| 1.0 | October 2, 2026 | First published version. |