ARMN Data Processing Addendum

Effective Date: September 22, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement governing access to or use of ARMN, including the ARMN Terms of Service, an order form, master services agreement, or other written agreement between the parties (collectively, the “Agreement”).

This DPA is entered into between:

Semper Explorans LLC d/b/a ARMN
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: hi@us.armn.ai
(“ARMN,” “Processor,” “Service Provider,” “we,” or “us”)

and the customer or organization that has entered into the Agreement for use of the Services (“Customer,” “Controller,” or “Business”).

This DPA applies when ARMN processes Customer Personal Data on behalf of Customer in connection with the Services.

1.Definitions

For purposes of this DPA:

“Applicable Data Protection Law” means any privacy or data-protection law applicable to ARMN's processing of Customer Personal Data under the Agreement, including, where applicable, the California Consumer Privacy Act of 2018 as amended (“CCPA”), the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018, and applicable U.S. state comprehensive privacy laws.

“Customer Data” means information, content, records, documents, CRM information, prompts, conversations, files, and other data submitted to, synchronized with, generated within, or otherwise processed through the Services on Customer's behalf.

“Customer Personal Data” means Personal Data contained in Customer Data that ARMN processes on behalf of Customer.

“Data Subject,” “Controller,” “Processor,” “Processing,” “Personal Data,” “Personal Information,” “Business,” “Service Provider,” “Contractor,” “Sell,” and “Share” have the meanings given to them under Applicable Data Protection Law.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by ARMN.

“Services” means ARMN's AI-powered business command center and related features, integrations, infrastructure, and services provided under the Agreement.

“Subprocessor” means a third party engaged by ARMN to process Customer Personal Data on ARMN's behalf in connection with providing the Services.

2.Scope and Roles of the Parties

2.1 Customer as Controller

As between Customer and ARMN, Customer determines the purposes for which Customer Personal Data is processed through the Services.

Customer acts as the Controller or Business with respect to Customer Personal Data unless Customer is itself processing Personal Data on behalf of another controller, in which case Customer may act as a Processor and ARMN as its Subprocessor.

2.2 ARMN as Processor

ARMN acts as a Processor or Service Provider with respect to Customer Personal Data processed on Customer's behalf.

ARMN will process Customer Personal Data only:

  1. to provide the Services;
  2. in accordance with the Agreement, this DPA, Customer's use and configuration of the Services, and Customer's documented instructions;
  3. as reasonably necessary to protect the security and integrity of the Services; or
  4. where required by applicable law.

If applicable law requires ARMN to process Customer Personal Data other than on Customer's documented instructions, ARMN will notify Customer of that requirement before processing unless applicable law prohibits ARMN from doing so.

2.3 ARMN as Independent Controller

This DPA does not apply to Personal Data for which ARMN determines the purposes and means of processing independently from Customer.

For example, ARMN may act as a controller with respect to its own account administration, billing, subscription management, security, business operations, service communications, and similar information as described in the ARMN Privacy Policy.

3.Details of Processing

The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex I.

Customer's configuration and use of the Services constitute documented instructions to ARMN to process Customer Personal Data as necessary to provide the functionality requested by Customer.

Customer may provide additional lawful instructions through its authorized use of the Services or by written communication to ARMN.

ARMN is not required to comply with instructions that:

  • violate Applicable Data Protection Law;
  • fall outside the scope of the Services or Agreement;
  • materially alter the Services;
  • require ARMN to violate another legal or contractual obligation; or
  • require development of functionality not included in the Services.

If ARMN reasonably believes a Customer instruction violates Applicable Data Protection Law, ARMN may suspend the affected processing and notify Customer.

4.Customer Responsibilities

Customer is responsible for the lawfulness of Customer Personal Data and Customer's instructions to ARMN.

Customer represents and warrants that:

  1. Customer has all rights, authorizations, consents, notices, and lawful bases necessary to collect, use, disclose, and instruct ARMN to process Customer Personal Data;
  2. Customer's instructions and use of the Services comply with Applicable Data Protection Law;
  3. Customer has provided any privacy notices required to individuals whose Personal Data is included in Customer Data;
  4. Customer is authorized to connect any CRM, workspace, database, account, or other third-party service connected to ARMN;
  5. Customer will only permit authorized users to access Customer Personal Data through the Services;
  6. Customer will not instruct ARMN to Sell or Share Customer Personal Data in violation of Applicable Data Protection Law; and
  7. Customer will not use the Services to circumvent privacy, security, employment, financial-services, consumer-protection, or other applicable legal requirements.

Customer remains responsible for determining whether the Services are appropriate for Customer's particular processing activities.

5.Restricted and Regulated Data

Customer acknowledges that ARMN is a general business SaaS platform and is not designed as a specialized regulated-data platform unless ARMN expressly agrees otherwise in writing.

Unless expressly agreed by ARMN in writing, Customer will not intentionally use the Services to process:

  • protected health information requiring a Business Associate Agreement under HIPAA;
  • full payment-card account numbers, CVV/CVC security codes, or other cardholder data for which ARMN would be required to act as a PCI DSS service provider;
  • biometric identifiers used for unique identification;
  • information collected directly from children through ARMN accounts; or
  • other information subject to specialized regulatory requirements that ARMN has not expressly agreed to support.

Customer Personal Data may nevertheless contain sensitive information because Customer controls the information contained in its CRM, uploaded documents, communications, and business records.

Customer is responsible for determining whether it may lawfully process and instruct ARMN to process such information.

6.Prohibited High-Impact Processing

Customer will not use ARMN to make solely automated decisions concerning an individual that produce legal or similarly significant effects relating to:

  • employment or hiring;
  • lending or credit;
  • housing;
  • insurance eligibility;
  • education admissions;
  • healthcare eligibility; or
  • similar legally significant determinations.

ARMN may provide general business information and recommendations, but the Services are not designed to determine an individual's eligibility, selection, approval, rejection, or access in these areas.

7.Confidentiality

ARMN will ensure that persons authorized by ARMN to process Customer Personal Data are subject to appropriate confidentiality obligations.

ARMN will limit access to Customer Personal Data to personnel and service providers who require access for purposes of providing, maintaining, securing, supporting, or improving the reliability of the Services or otherwise fulfilling ARMN's obligations under the Agreement.

8.Security

ARMN will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

ARMN's current principal technical and organizational measures are described in Annex II.

Customer acknowledges that security measures may evolve as technologies, risks, and the Services change. ARMN may modify its security measures provided that ARMN does not materially decrease the overall security of the Services during the term of the Agreement.

No security system can guarantee complete protection against all threats.

9.Personal Data Breaches

ARMN will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data.

To the extent reasonably available, ARMN's notice will include information necessary for Customer to understand:

  • the nature of the Personal Data Breach;
  • the categories of Customer Personal Data affected;
  • the known or reasonably anticipated consequences;
  • measures taken or proposed by ARMN to contain, investigate, or remediate the incident; and
  • information reasonably available to assist Customer with applicable notification obligations.

Information may be provided in phases as ARMN's investigation develops.

ARMN's notification of a Personal Data Breach does not constitute an admission of fault, liability, or violation of law.

Customer is responsible for determining whether notification to regulators, Data Subjects, customers, or other third parties is legally required, except to the extent Applicable Data Protection Law imposes a direct notification obligation on ARMN.

10.Data Subject Requests

Taking into account the nature of the processing, ARMN will provide reasonable assistance to Customer in responding to verified requests from Data Subjects to exercise rights under Applicable Data Protection Law.

Where reasonably available, ARMN may satisfy this obligation by making functionality available through the Services or providing information or assistance to Customer.

If ARMN receives a request directly from a Data Subject relating to Customer Personal Data for which Customer is the Controller, ARMN may direct the Data Subject to Customer unless ARMN is legally prohibited from doing so.

ARMN will not independently respond to such a request on Customer's behalf unless instructed by Customer or required by law.

Customer is responsible for:

  • verifying the identity and authority of the requesting individual;
  • determining whether the requested right applies;
  • determining whether an exception applies; and
  • communicating with the Data Subject.

To the extent permitted by law, ARMN may charge reasonable fees for substantial assistance that requires materially disproportionate engineering or operational work, except where the assistance is required because of ARMN's breach of this DPA or Applicable Data Protection Law.

11.Regulatory Assistance and Data Protection Assessments

Taking into account the nature of the processing and information available to ARMN, ARMN will provide reasonable assistance to Customer with obligations applicable to Customer relating to:

  • security of processing;
  • Personal Data Breach assessments;
  • legally required breach notifications;
  • data protection impact assessments;
  • privacy or risk assessments; and
  • prior consultation with a supervisory authority,

to the extent the relevant obligation relates to ARMN's processing of Customer Personal Data.

Customer remains responsible for determining whether any assessment, notification, or regulatory consultation is required.

12.Subprocessors

12.1 General Authorization

Customer provides ARMN with general written authorization to engage Subprocessors to process Customer Personal Data in connection with the Services.

ARMN's current Subprocessors are identified in Annex III.

12.2 Subprocessor Obligations

ARMN will enter into a written agreement with each Subprocessor that imposes data-protection obligations appropriate to the services performed and requiring protection of Customer Personal Data consistent with ARMN's obligations under this DPA where required by Applicable Data Protection Law.

ARMN remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

12.3 Changes to Subprocessors

ARMN may add or replace Subprocessors as the Services evolve.

Where required by Applicable Data Protection Law, ARMN will provide Customer with reasonable advance notice of a new Subprocessor that will materially process Customer Personal Data.

Notice may be provided by email, through the Services, through an online Subprocessor list, or another reasonable electronic method.

Unless a different period is required by law, ARMN will endeavor to provide at least 15 days' notice before a new material Subprocessor begins processing Customer Personal Data.

12.4 Customer Objections

Customer may object to a new Subprocessor during the applicable notice period only on reasonable, documented grounds relating to the protection of Customer Personal Data.

ARMN and Customer will work in good faith to address the objection.

ARMN may, at its discretion:

  • provide additional information regarding the Subprocessor;
  • implement reasonable additional safeguards;
  • make a commercially reasonable alternative available; or
  • discontinue the affected Subprocessor or processing activity.

If ARMN cannot reasonably resolve a valid objection, Customer may terminate the portion of the Services that requires the disputed Subprocessor.

An objection does not give Customer a right to receive Services without paying amounts already accrued or otherwise due under the Agreement.

13.Artificial Intelligence Providers

Certain Subprocessors provide artificial-intelligence inference, embedding, or retrieval infrastructure.

ARMN will not authorize or opt in to the use of Customer Personal Data for training third-party general-purpose AI models.

ARMN will maintain commercially available no-training settings or contractual protections for AI providers used to process Customer Personal Data where ARMN has represented that such protections apply.

This restriction does not prohibit an AI provider from processing information as necessary to provide its contracted services, maintain security, detect abuse, comply with law, or perform other processing permitted under its applicable agreement with ARMN.

ARMN may replace AI providers in accordance with Section 12.

14.Return and Deletion of Customer Personal Data

During the term of the Agreement, Customer may request deletion of Customer Personal Data by contacting hi@us.armn.ai, subject to technical feasibility, applicable law, and the Agreement.

Following termination or expiration of the Services, Customer may instruct ARMN to delete or, where reasonably supported by the Services, return Customer Personal Data.

Where Applicable Data Protection Law requires ARMN to honor a deletion or return instruction within a particular period, ARMN will comply within the period required by that law.

If Customer does not provide a specific instruction, ARMN will delete or de-identify Customer Personal Data from active systems in accordance with ARMN's then-current retention practices, generally no later than 12 months after closure of the applicable account or workspace.

ARMN may retain information beyond that period where reasonably necessary to:

  • comply with applicable law;
  • maintain tax, billing, or accounting records;
  • prevent or investigate fraud or security incidents;
  • establish, exercise, or defend legal claims; or
  • comply with another lawful retention obligation.

Customer Personal Data stored in backups may remain until the relevant backup is overwritten or expires through ARMN's ordinary backup lifecycle, provided that any retained backup data remains protected under this DPA and is not restored for ordinary business use except as necessary for disaster recovery or security purposes.

Upon deletion, ARMN may retain aggregated or de-identified information that no longer reasonably identifies a Data Subject.

15.CRM Connections

Where Customer connects a supported CRM, Customer instructs ARMN to access and process information made available through the permissions granted by Customer.

At launch, ARMN's supported production CRM integration is HighLevel / GoHighLevel.

Customer authorizes ARMN to:

  • retrieve information permitted by the CRM connection;
  • synchronize supported CRM records into Customer's ARMN workspace;
  • analyze those records as part of the Services; and
  • perform supported CRM write operations that an authorized Customer user expressly approves.

ARMN will not independently authorize an external CRM write.

Disconnecting a CRM terminates ARMN's ongoing authorization to access or act through the disconnected credentials.

Previously synchronized Customer Personal Data may remain within ARMN and will be handled under the retention and deletion provisions of this DPA.

16.Audits and Demonstration of Compliance

ARMN will make available information reasonably necessary to demonstrate compliance with ARMN's obligations under Applicable Data Protection Law relating to its processing of Customer Personal Data.

The parties agree that, where legally permissible, compliance inquiries should ordinarily be satisfied first through:

  • this DPA;
  • ARMN's Privacy Policy;
  • security documentation;
  • written responses to reasonable questionnaires;
  • relevant policies or technical descriptions; and
  • other documentation reasonably available to ARMN.

If this information is insufficient to satisfy a legally required audit right, Customer may request an audit relating specifically to ARMN's processing of Customer Personal Data.

Unless prohibited by Applicable Data Protection Law or a competent regulator:

  1. an audit may occur no more than once in any twelve-month period, unless a Personal Data Breach or documented compliance concern reasonably justifies an additional audit;
  2. Customer must provide reasonable advance written notice;
  3. audits must occur during normal business hours;
  4. audits must be conducted in a manner that minimizes disruption to ARMN;
  5. any third-party auditor must be independent, appropriately qualified, not a direct competitor of ARMN, and bound by confidentiality obligations;
  6. an audit may not provide Customer or its auditor access to information concerning other ARMN customers, trade secrets unrelated to Customer's processing, credentials, source code, penetration-testing secrets, or information whose disclosure would compromise ARMN's security; and
  7. Customer will bear its audit costs and ARMN's reasonable costs of supporting a Customer-requested audit, except where the audit identifies a material breach of this DPA by ARMN.

Nothing in this Section limits audit or inspection rights that cannot lawfully be limited under Applicable Data Protection Law.

17.U.S. Service Provider and Processor Terms

Where a U.S. state privacy law applies and Customer is a Business or Controller and ARMN is a Service Provider, Contractor, or Processor, the following terms apply.

17.1 Specific Business Purposes

Customer discloses Customer Personal Data to ARMN for the limited and specified purposes of:

  • hosting and storing Customer Data;
  • maintaining Customer's ARMN workspace;
  • authenticating and supporting authorized users;
  • synchronizing permitted information from connected services;
  • providing AI-assisted analysis and responses requested by Customer;
  • retrieving relevant Customer content and business context;
  • generating embeddings and other retrieval representations;
  • generating recommendations and proposed actions;
  • executing CRM actions expressly authorized by Customer;
  • maintaining action, approval, execution, and audit records;
  • securing, monitoring, troubleshooting, and maintaining the Services;
  • providing Customer support; and
  • otherwise performing the Services requested by Customer under the Agreement.

17.2 Restrictions

ARMN will not:

  • Sell Customer Personal Data;
  • Share Customer Personal Data for cross-context behavioral advertising;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship between ARMN and Customer except as permitted by Applicable Data Protection Law;
  • retain, use, or disclose Customer Personal Data for purposes materially outside the business purposes specified in this DPA except as permitted by Applicable Data Protection Law; or
  • combine Customer Personal Data with Personal Data received from or on behalf of another person or collected from ARMN's own interactions with a consumer except where the combination is permitted by Applicable Data Protection Law and reasonably necessary to provide the Services.

ARMN will provide the level of privacy protection for Customer Personal Data required of a Service Provider, Contractor, or Processor under Applicable Data Protection Law.

17.3 Compliance

ARMN will notify Customer if ARMN determines that it can no longer meet a material obligation applicable to ARMN as a Service Provider, Contractor, or Processor under Applicable Data Protection Law.

Customer may take reasonable and appropriate steps required by Applicable Data Protection Law to help ensure that ARMN processes Customer Personal Data consistently with Customer's applicable obligations.

If Customer reasonably identifies unauthorized processing of Customer Personal Data by ARMN, ARMN will cooperate with reasonable steps to stop and remediate that processing.

17.4 Consumer Requests

ARMN will provide reasonable assistance required under Applicable Data Protection Law with verified requests to know, access, delete, correct, or obtain Customer Personal Data processed by ARMN on Customer's behalf.

18.International Data Transfers

18.1 General

Customer acknowledges that ARMN is established in the United States and that Customer Personal Data may be processed in the United States and other countries where authorized Subprocessors operate.

Where Applicable Data Protection Law requires a particular transfer mechanism, the parties will use the mechanism described in this Section.

18.2 European Economic Area

Where Customer Personal Data subject to the EU GDPR is transferred to ARMN in a country that has not been recognized by the European Commission as providing an adequate level of protection and another lawful transfer mechanism does not apply, the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of June 4, 2021 (“EU SCCs”) are incorporated into this DPA by reference.

The following selections apply:

  • Module Two (Controller to Processor) applies where Customer is a Controller and ARMN is a Processor.
  • Module Three (Processor to Processor) applies where Customer acts as a Processor and ARMN acts as Customer's Subprocessor.
  • Clause 9 uses Option 2 — General Written Authorization.
  • The notice period under Clause 9 is the Subprocessor notice period stated in Section 12 of this DPA.
  • The optional language in Clause 11 is not included.
  • For Clause 17, the parties select the laws of Ireland to the extent permitted by the EU SCCs.
  • For Clause 18, the parties select the courts of Ireland.
  • Annex I, Annex II, and Annex III of this DPA complete the corresponding annex information required by the EU SCCs.

If there is a conflict between the EU SCCs and another provision of this DPA or the Agreement concerning a Restricted Transfer, the EU SCCs control to the extent of that conflict.

18.3 United Kingdom

For a Restricted Transfer subject to UK data-protection law for which an appropriate safeguard is required, the parties incorporate the United Kingdom International Data Transfer Addendum to the EU Commission Standard Contractual Clauses.

The parties agree to be bound by:

“Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.”

The information contained in this DPA and its Annexes will be used to complete the applicable tables and appendix information to the extent permitted.

18.4 Switzerland

Where the Swiss Federal Act on Data Protection applies to a Restricted Transfer, the EU SCCs will apply with the modifications necessary for them to operate under Swiss law, including references to the competent Swiss supervisory authority where required.

18.5 Transfer Assessments

Each party will provide reasonable cooperation to the other, as required by Applicable Data Protection Law, in connection with a legally required transfer impact assessment or transfer risk assessment concerning ARMN's processing.

19.Liability

Each party's liability arising out of or relating to this DPA is subject to the exclusions, limitations, disclaimers, and liability caps contained in the Agreement.

This DPA does not create a separate or additional liability cap.

Any claims arising under this DPA and the Agreement will be aggregated for purposes of applying the Agreement's applicable liability limitations.

Nothing in this Section limits liability to the extent that Applicable Data Protection Law prohibits such limitation.

20.Order of Precedence

If there is a conflict concerning processing of Customer Personal Data:

  1. applicable mandatory provisions of the EU SCCs or UK Addendum control where they apply;
  2. this DPA controls over conflicting provisions of the Agreement concerning data protection; and
  3. the Agreement otherwise remains in effect.

Except as modified by this DPA, the Agreement remains unchanged.

21.Duration

This DPA remains in effect for as long as ARMN processes Customer Personal Data on Customer's behalf.

Provisions that by their nature are intended to survive termination, including confidentiality, deletion, audit cooperation, transfer obligations, and liability provisions, will survive for so long as ARMN retains Customer Personal Data to which those provisions apply.

22.Contact

Questions or notices regarding this DPA may be sent to:

Semper Explorans LLC d/b/a ARMN
30 N Gould St Ste R
Sheridan, WY 82801
United States

Email: hi@us.armn.ai
Phone: +1 904-341-4202

ANNEX I

Details of Processing

A. Subject Matter

Processing of Customer Personal Data as necessary to provide ARMN's AI-powered business command center and related CRM, knowledge retrieval, analysis, recommendation, action, governance, and workspace functionality.

B. Duration

For the duration of the Agreement and thereafter only for the retention, deletion, backup, security, legal, or other purposes permitted by this DPA and Applicable Data Protection Law.

C. Nature and Purpose of Processing

ARMN may perform operations including:

  • collection and receipt;
  • storage and hosting;
  • organization and structuring;
  • synchronization;
  • retrieval and search;
  • analysis;
  • AI inference;
  • creation of embeddings and retrieval representations;
  • use in workspace-specific contextual memory;
  • generation of responses, recommendations, plans, and proposed actions;
  • execution of Customer-authorized CRM actions;
  • recording approvals and execution outcomes;
  • maintenance of audit and history records;
  • troubleshooting and error handling;
  • security monitoring;
  • deletion and de-identification; and
  • other processing reasonably necessary to provide Customer-requested functionality.

D. Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer's users;
  • employees;
  • contractors;
  • owners;
  • administrators;
  • customers;
  • clients;
  • prospects and leads;
  • CRM contacts;
  • business partners;
  • vendors;
  • individuals referenced in Customer communications or uploaded documents; and
  • other individuals whose Personal Data Customer lawfully submits to the Services.

E. Categories of Customer Personal Data

Depending on Customer's use of ARMN, Customer Personal Data may include:

  • names;
  • email addresses;
  • telephone numbers;
  • business and professional information;
  • CRM identifiers;
  • contact and lead information;
  • opportunity and pipeline information;
  • appointment and calendar information;
  • conversation and communication content;
  • customer relationship history;
  • documents and information contained within uploaded files;
  • user prompts and conversations;
  • voice-to-text transcripts;
  • business context;
  • Customer-generated notes;
  • CRM synchronization records;
  • approval and action records;
  • audit information;
  • IP addresses and technical identifiers where contained in Customer Data;
  • derived retrieval representations and embeddings; and
  • other Personal Data submitted by Customer through supported functionality.

F. Sensitive Data

ARMN does not require Customer to provide sensitive Personal Data as a general condition of using the Services.

Sensitive information may nevertheless appear in Customer-controlled CRM data, documents, conversations, or other Customer Data.

Customer is responsible for determining whether such processing is lawful and appropriate.

ANNEX II

Technical and Organizational Measures

ARMN maintains technical and organizational measures designed to protect Customer Personal Data appropriate to the nature of the Services and processing.

Current measures include:

1. Tenant Isolation

ARMN uses a multi-tenant architecture with workspace-level isolation.

Database row-level security is configured on a default-deny basis, and privileged operations are subject to server-side authorization.

Frontend visibility is not treated as authorization.

2. CRM Credential Protection

CRM access and refresh tokens are encrypted at rest using AES-256-GCM.

Encryption keys are maintained as runtime secrets and are not stored alongside encrypted credentials in the application database.

CRM credentials are not intentionally returned to the browser.

3. Server-Side Credential Handling

AI provider credentials, service-role credentials, CRM credentials, and similar secrets are maintained server-side and are not intentionally embedded in frontend application code.

CRM and AI-provider calls requiring protected credentials are performed through server-side systems.

4. Logging and Redaction

ARMN applies a redaction boundary before information reaches ordinary application logs.

ARMN is designed not to log:

  • authorization headers;
  • authentication cookies;
  • session values;
  • OAuth access or refresh tokens;
  • identity tokens;
  • API keys;
  • private keys;
  • signatures; or
  • service-role credentials.

Prompts, model responses, transcripts, document contents, CRM payloads, and attachments are not intentionally written in full to ordinary operational logs.

Operational logs may retain information necessary for troubleshooting and security, including:

  • request and correlation identifiers;
  • organization and user identifiers;
  • operation names;
  • provider and model identifiers;
  • latency;
  • response status;
  • error classifications;
  • action identifiers; and
  • execution identifiers.

5. Authorization and Execution Controls

Privileged application functions are subject to server-side authorization.

CRM writes require an authorized Customer instruction or approval.

Execution paths use governance and idempotency controls designed to prevent unintended duplicate execution.

6. Rate and Abuse Controls

ARMN uses per-workspace usage controls, quotas, rate protections, and provider protections intended to reduce abuse and excessive or unauthorized service consumption.

7. Audit Records

ARMN maintains durable records for consequential actions and relevant permission or governance activity.

Records may include the action prepared, user authorization or disposition, execution activity, and result.

8. Private File Access

Private files use controlled access mechanisms.

Where signed file-access URLs are used, they are time limited.

Uploads use controlled upload mechanisms with server-side file-type and file-size enforcement.

9. CRM Disconnect

Disconnecting a supported CRM causes the applicable stored connection credential to be deleted or revoked as appropriate and prevents continued use of that credential.

Previously synchronized data remains governed by this DPA's retention and deletion provisions.

10. AI Data Controls

ARMN uses commercial AI-provider services and does not authorize or opt in to third-party general-purpose model training using Customer Personal Data.

ARMN maintains applicable no-training configurations for AI providers where such settings are used as part of ARMN's service configuration.

ANNEX III

Authorized Subprocessors

ARMN currently uses the following Subprocessors that may process Customer Personal Data in connection with the Services.

Supabase

Purpose: Managed database infrastructure, authentication, and file storage.
Data potentially processed: Stored application data and Customer Data necessary to provide the Services.

Cloudflare

Purpose: Application delivery, edge runtime, network, and security infrastructure.
Data potentially processed: Customer Personal Data transmitted during request handling.

Anthropic

Purpose: Large-language-model inference.
Data potentially processed: Relevant prompts, business context, conversation content, document excerpts, and CRM evidence necessary to respond to Customer requests.

ARMN uses Anthropic's commercial API and does not authorize Customer Personal Data to be used for training Anthropic's general-purpose models.

Voyage AI

Purpose: Embeddings and retrieval functionality.
Data potentially processed: Relevant text from Customer business context and uploaded documents used to generate retrieval representations.

ARMN maintains its AI-provider configuration so Customer content is not authorized for model training.

PostHog

Purpose: Product usage analytics, AI usage measurement, and error monitoring.
Hosting configuration: United States.
Data potentially processed: Event metadata, user/workspace identifiers, usage information, and redacted error details.

ARMN does not currently enable PostHog session replay, screen recording, or heatmap functionality.


Services Connected at Customer Direction

For clarity, a service Customer independently chooses and authorizes as its source or destination system is not necessarily an ARMN Subprocessor solely because ARMN integrates with it.

At launch, HighLevel / GoHighLevel is ARMN's supported CRM integration. Customer independently authorizes ARMN's access to its HighLevel account through HighLevel's OAuth authorization process.

Stripe and Google may process information relating to billing or authentication where applicable, but their processing of ARMN's own account-management or billing data is not necessarily processing of Customer Personal Data on Customer's behalf under this DPA.