Last updated June 12, 2026

Data Processing Agreement (DPA)

Aruwo™ Effective Date: June 12, 2026 Last Updated: June 12, 2026


Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Aruwo™ Inc. ("Aruwo", "Processor") and the customer ("Controller") who has accepted the General Terms of Service at aruwo.dev.

This DPA applies where Aruwo™ processes personal data on behalf of the Controller in the course of providing the Services. It supplements the General Terms of Service and prevails over them in the event of conflict with respect to data processing matters.

This DPA is intended to meet the requirements of:

  • GDPR (EU General Data Protection Regulation 2016/679)
  • UK GDPR and Data Protection Act 2018
  • Nigeria Data Protection Act (NDPA) 2023
  • South Africa's POPIA (Protection of Personal Information Act 4 of 2013)
  • Kenya's Data Protection Act 2019
  • Other applicable African data protection laws

Part 1: Roles and Scope

1.1 Roles

  • Controller: The Aruwo™ customer (the business or individual) who determines the purposes and means of processing personal data through the platform.
  • Processor: Aruwo™ Inc., which processes personal data on behalf of the Controller as directed by the Controller's use of the Services.

1.2 Scope

This DPA covers personal data that Controllers submit to or generate through the Aruwo™ platform, including:

  • End-user data of the Controller's customers stored in Supabase databases created through the platform
  • Project data, generated code, and workspace content containing personal information
  • Data submitted through forms, applications, and tools built using Aruwo™

This DPA does not cover Aruwo's processing of Controller account data (name, email, billing) — that processing is described in our Privacy Policy where Aruwo acts as an independent Data Controller.


Part 2: Processing Details

2.1 Subject Matter

Processing of personal data to provide the Aruwo™ AI-powered startup building, hosting, deployment, and domain services described in the General Terms of Service.

2.2 Duration

For the term of the Controller's subscription, and until all personal data is deleted or returned in accordance with Section 7.

2.3 Nature of Processing

  • Storage of personal data in Supabase instances
  • Transmission to AI processing services (Claude API) where Controller submits data as part of prompts
  • Transmission to deployment infrastructure (Vercel, GitHub)
  • Processing for backup, security monitoring, and platform operations

2.4 Purpose

To provide the Services as described in the General Terms of Service, solely as instructed by the Controller.

2.5 Categories of Data Subjects

  • The Controller's customers and end-users
  • The Controller's team members
  • Any individuals whose personal data the Controller submits to the platform

2.6 Types of Personal Data

The types of personal data processed depend entirely on what the Controller submits and builds. May include:

  • Names, email addresses, phone numbers
  • Location data
  • Financial and payment information (processed by Controller's payment integrations)
  • Health or other sensitive data (if the Controller builds applications in those sectors)
  • Any other personal data the Controller chooses to process through their applications

Part 3: Controller's Obligations

The Controller represents and warrants that:

3.1 It has a lawful basis for processing all personal data submitted to or processed through the platform.

3.2 It has provided required privacy notices to its end-users describing processing activities performed through Aruwo™.

3.3 It will use the Services only for lawful purposes and in accordance with the Platform Rules.

3.4 It will not submit special categories of sensitive personal data (health, biometric, financial, political opinions, etc.) to the AI Builder without implementing appropriate additional safeguards.

3.5 It will comply with applicable data protection laws in all jurisdictions where its end-users are located.


Part 4: Aruwo's Obligations as Processor

Aruwo™ agrees to:

4.1 Process only on documented instructions from the Controller. The Controller's configuration and use of the Services constitutes documented instructions.

4.2 Ensure confidentiality — all Aruwo™ personnel with access to Controller personal data are bound by confidentiality obligations.

4.3 Implement appropriate technical and organizational security measures as described in Section 6.

4.4 Engage sub-processors only as described in Section 5 and will inform the Controller of sub-processor changes.

4.5 Assist the Controller in responding to data subject requests as described in Section 8.

4.6 Notify the Controller of personal data breaches involving Controller data without undue delay and no later than 72 hours after becoming aware, as described in Section 9.

4.7 Delete or return Controller personal data upon termination as described in Section 7.

4.8 Provide information reasonably necessary for the Controller to demonstrate compliance with applicable data protection laws, including supporting audits as described in Section 10.

4.9 Not process Controller personal data for any purpose other than providing the Services, including not using it to train AI models.


Part 5: Sub-Processors

Aruwo™ uses the following sub-processors to provide the Services. The Controller grants general authorization for Aruwo™ to engage these sub-processors:

Sub-ProcessorPurposeLocationData Protection Framework
Supabase Inc.Database, authentication, file storageUS / EUSCCs, SOC 2
Anthropic PBCAI processing (Claude API)United StatesSCCs, Privacy Policy
GitHub Inc. (Microsoft)Code repository hostingUnited StatesSCCs, DPA
Vercel Inc.Application deployment and hostingUnited StatesSCCs, DPA
Stripe Inc.Payment processingUnited StatesSCCs, PCI-DSS
Flutterwave Inc.African payment processingNigeria / USNDPR compliant, PCI-DSS
Paystack Inc.African payment processingNigeriaNDPR compliant, PCI-DSS
Tucows / OpenSRSDomain registrationCanadaPIPEDA compliant
Resend Inc.Transactional emailUnited StatesSCCs

Sub-processor Changes

Aruwo™ will provide the Controller with at least 30 days' notice before adding a new sub-processor or making material changes to existing sub-processors. Notice will be given via email or in-platform notification. The Controller may object to a new sub-processor within 14 days of notice by contacting privacy@aruwo.dev. If the parties cannot resolve the objection, either party may terminate the affected Services with 30 days' notice.


Part 6: Security Measures

Aruwo™ implements the following technical and organizational security measures:

Technical Measures

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Encrypted storage of OAuth tokens and API credentials
  • Role-based access controls limiting staff access to Controller data
  • Database row-level security (RLS) isolating Controller data from other customers
  • Regular automated backups with point-in-time recovery
  • Web Application Firewall (WAF) and DDoS protection
  • Intrusion detection and monitoring

Organizational Measures

  • Staff data protection training
  • Background checks for employees with access to production systems
  • Incident response plan and designated security contact
  • Vendor security assessment for sub-processors
  • Regular security reviews

Part 7: Data Return and Deletion

7.1 Upon expiry or termination of the Controller's subscription, Aruwo™ will:

  • Allow the Controller to export project files, generated code, and database schemas for 30 days post-termination
  • Permanently delete all Controller personal data within 60 days of termination

7.2 The Controller may request deletion of specific data sets at any time by contacting privacy@aruwo.dev.

7.3 Aruwo™ may retain data beyond these periods only where required by applicable law, in which case Aruwo™ will notify the Controller of the legal basis and duration.

7.4 Upon request, Aruwo™ will provide written confirmation of deletion.


Part 8: Data Subject Rights

8.1 Where Aruwo™ receives a request from a data subject relating to Controller data (e.g. an access, deletion, or portability request directed to Aruwo™), Aruwo™ will promptly forward that request to the Controller and will not respond directly unless required by law.

8.2 Aruwo™ will provide the Controller with reasonable technical assistance (through existing platform tools or upon written request) to facilitate the Controller's response to data subject requests.

8.3 The Controller is responsible for responding to data subject requests within applicable legal deadlines.


Part 9: Data Breach Notification

9.1 Aruwo™ will notify the Controller of any personal data breach involving Controller data without undue delay, and where feasible within 72 hours of becoming aware.

9.2 Breach notifications will include, to the extent available:

  • Nature of the breach and categories of data affected
  • Estimated number of data subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9.3 The Controller is responsible for notifying relevant supervisory authorities and affected data subjects as required by applicable law.


Part 10: Audits and Compliance

10.1 Aruwo™ will, upon reasonable written request (with at least 30 days' notice), provide information necessary to demonstrate compliance with this DPA, including access to relevant audit reports (SOC 2, ISO 27001, or equivalent).

10.2 The Controller may conduct an audit of Aruwo's processing activities no more than once per calendar year, at the Controller's expense, with reasonable prior notice and subject to Aruwo's reasonable confidentiality requirements.

10.3 Aruwo™ may satisfy audit obligations by providing current third-party audit reports in lieu of direct access audits.


Part 11: International Data Transfers

11.1 Where the Services involve transfers of personal data to countries outside the Controller's jurisdiction, Aruwo™ ensures such transfers are protected by appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (for EEA/UK transfers)
  • Binding corporate rules or equivalent measures where applicable
  • Compliance with NDPR and NDPA for transfers involving Nigerian residents
  • Compliance with POPIA adequacy requirements for South African residents

11.2 Upon request, Aruwo™ will provide copies of applicable SCCs or transfer mechanism documentation.


Part 12: Liability

Each party's liability under this DPA is subject to the limitations set out in the General Terms of Service. In the event of conflict, the more protective provision for data subjects prevails.


Part 13: Governing Law

This DPA is governed by the same governing law as the General Terms of Service (Delaware, United States), except that where mandatory local law applies (e.g. GDPR for EU processing), those mandatory provisions take precedence.


Part 14: Contact and Updates

For DPA-related queries, data subject requests, or breach reports:

Email: privacy@aruwo.dev Page: aruwo.dev/legal/dpa

We will update this DPA to reflect changes in applicable law, sub-processors, or processing activities. Material changes will be communicated with 30 days' notice.


This DPA is automatically incorporated into your agreement with Aruwo™ upon acceptance of the General Terms of Service. No separate signature is required for standard use. Enterprise customers requiring a countersigned DPA may contact legal@aruwo.dev.