Data Processing Agreement (DPA)
1. Purpose
This Data Processing Agreement, hereinafter the “DPA”, governs the processing carried out by ACHALAI on behalf of the Client when the Client uses the Platform to process personal data.
The DPA supplements the Terms and forms part of the contractual relationship when the Client incorporates personal data subject to processing on its own account.
2. Parties
- Data Controller (or Processor for its group): The Client that contracts, uses, or evaluates ACHALAI.
- Data Processor: Diego Damián Freire (ACHALAI), an individual with legal domicile at Av. Medrano 1940, Autonomous City of Buenos Aires, Republic of Argentina.
3. Regulatory Framework
This DPA is interpreted in accordance with:
- Argentine Personal Data Protection Law No. 25.326 and Regulatory Decree No. 1558/2001;
- Dispositions and guidelines issued by the AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA (AAIP);
- Where applicable to European data subjects or processing operations falling within its territorial scope, Regulation (EU) 2016/679 (GDPR).
4. Instructions from the Controller
4.1. ACHALAI shall process Personal Data exclusively on documented instructions from the Client, including with respect to transfers, unless required to do so by applicable law.
4.2. Accessing, configuring, uploading, and managing data through the Platform constitutes the documented instructions of the Client.
5. Instructions Contrary to Law
If ACHALAI reasonably considers that an instruction may infringe applicable legislation, it may:
- inform the Client;
- request clarification;
- temporarily suspend the execution of said instruction when reasonably necessary.
This provision does not make ACHALAI the legal advisor of the Client.
6. Purpose and Nature of Processing
Operations may include:
- receipt;
- recording;
- hosting;
- storage;
- organization;
- structuring;
- consultation;
- updating;
- calculation;
- comparison;
- generation of indicators;
- generation of reports;
- visualization;
- export;
- deletion.
The processing has the purpose of enabling the Client to use the contracted organizational features.
7. Duration
Processing shall continue for the duration of the SaaS agreement plus the data export and secure deletion period set forth herein.
8. Categories of Data Subjects
Employees, contractors, candidates, board members, consultants, and other human occupants whose data is administered by the Client through the Platform.
9. Categories of Data
According to the configuration chosen by the Client, they may include:
Identification
- first name;
- last name;
- internal identifier;
- photograph.
Contact
- email;
- telephone;
- work location.
Organizational Information
- area;
- position;
- job title;
- supervisor;
- structure;
- location;
- seniority;
- hierarchical relationships.
Contractual Information
- engagement modality;
- status;
- tenure;
- information associated with the organizational relationship.
Compensation
- salary;
- remuneration;
- currency;
- variable pay;
- benefits;
- related costs.
Development
- performance;
- potential;
- objectives;
- succession;
- criticality;
- development information.
10. Specially Protected Data
ACHALAI does not require the processing of sensitive data or special categories as a standard matter.
The Client must not incorporate this type of information unless there is prior agreement and assessment when necessary.
If the Client decides to incorporate it without prior notice, it shall be responsible for determining the legitimacy of the processing and for the additional measures required.
11. Obligations of ACHALAI
ACHALAI agrees to:
- process data strictly in accordance with the Client's instructions;
- maintain strict professional confidentiality regarding all personal data;
- implement and maintain reasonable technical and organizational security measures;
- assist the Client in responding to data subject rights requests;
- notify security incidents without undue delay;
- make available information reasonably necessary to demonstrate compliance with this DPA;
- delete or return personal data upon termination of the SaaS service.
12. Confidentiality
Individuals authorized to access Personal Data shall:
- be subject to binding confidentiality obligations;
- access data solely when strictly necessary;
- use the information exclusively for authorized purposes.
Technical and administrative access is governed by the principle of least privilege.
13. Security
ACHALAI will maintain reasonable measures intended to protect:
- confidentiality;
- integrity;
- availability;
- access control.
Measures shall be proportional to the risk and may evolve with the Platform.
When the Client reasonably requests it, ACHALAI may provide information regarding current technical and organizational measures, subject to confidentiality and without disclosing information that may compromise security.
No public statement on security that does not reflect an actual technical implementation shall be considered part of the DPA.
14. Subprocessors
The Client grants general written authorization for ACHALAI to engage subprocessors necessary to deliver the SaaS service.
ACHALAI shall:
- select providers with appropriate technical and organizational security standards;
- impose on each subprocessor, via written contract, data protection obligations substantially equivalent to those set forth in this DPA;
- remain contractually liable to the Client for the performance of its subprocessors' obligations to the extent required by applicable law;
- notify material changes to the list of subprocessors.
15. Authorized Subprocessors
The subprocessors authorized at the date of this DPA are:
- Supabase Inc.: Database hosting, authentication, and encrypted data storage;
- Vercel Inc.: Frontend hosting, edge caching, and serverless compute;
- Resend Inc.: Transactional email delivery;
- Web3Forms: Demo form forwarding;
- Google LLC: Google Workspace and Google Analytics 4 (opt-in);
- GitHub Inc.: Code repository management.
The complete list is maintained in the Register of Subprocessors.
16. New Subprocessors and Objection Right
ACHALAI will notify the Client of any intended addition or replacement of a subprocessor with at least ten (10) calendar days' prior notice.
The Client may object to the appointment on reasonable data protection grounds. If the parties cannot resolve the objection, either party may terminate the affected service.
17. International Transfers
ACHALAI will not carry out international transfers of Personal Data on behalf of the Client without applying the safeguards that correspond under applicable regulations.
When Argentine legislation is applicable and the destination country is not recognized as providing an adequate level of protection, mechanisms recognized by the AAIP will be utilized when applicable, including model contractual clauses or other valid safeguards.
When the GDPR is applicable, onward transfers from an adequate jurisdiction to third countries shall be carried out in accordance with its Chapter V.
18. Artificial Intelligence
The use of Artificial Intelligence tools to develop ACHALAI does not authorize the processing of Client Data through said development tools.
If a product functionality requires sending Client Data to an external AI provider:
1. the provider will be evaluated;
2. it will be incorporated as a subprocessor when legally appropriate;
3. relevant contractual safeguards will be applied;
4. the Client will be informed when legally required.
19. Prohibition of General Model Training
ACHALAI will not use Client Data to train general proprietary or third-party AI models unless there is express contractual authorization from the Client and compliance with applicable regulations.
The normal provision of the Platform does not constitute such authorization.
20. Data Subject Rights
ACHALAI will promptly notify the Client if it receives a data subject request directly from an employee or occupant of the Client.
Taking into account the nature of the processing, ACHALAI will provide reasonable technical assistance to enable the Client to fulfill its obligation to respond to data subject access, rectification, deletion, or portability requests.
21. Security and Incidents
ACHALAI shall notify the Client without undue delay after becoming confirmed of a security breach affecting Personal Data processed on behalf of the Client.
The initial notification may contain information available at that time and be supplemented subsequently.
Where feasible, it shall include:
- nature of the incident;
- affected categories;
- known scope;
- reasonably foreseeable consequences;
- measures adopted;
- mitigation measures.
The notification shall not constitute an admission of liability.
22. Impact Assessments
When reasonably necessary and required by applicable regulations, ACHALAI will provide the Client with available information necessary to collaborate with:
- Data Protection Impact Assessments (DPIAs);
- Prior consultations with supervisory authorities;
- Security risk assessments.
The responsibility of determining whether a Data Protection Impact Assessment is legally mandatory corresponds to the Client in its role as Data Controller.
23. Audits
ACHALAI shall make available information reasonably necessary to demonstrate compliance with this DPA.
Ordinary audits shall:
- be notified with reasonable advance notice;
- be limited to processing related to the Client;
- be conducted preferably through documentation or remote assessment;
- protect confidential information of other Clients;
- not compromise the security of the Platform;
- be carried out during reasonable business hours.
Except in cases of significant incidents, regulatory requests, or founded material breach, audits shall not be conducted more than once per year.
Reasonable costs of special audits requested exclusively by the Client may be borne by the Client, unless they reveal a material breach attributable to ACHALAI.
24. Government Requests
If ACHALAI receives a binding request from a judicial or governmental authority to disclose personal data of the Client, ACHALAI will notify the Client promptly before disclosure, unless legally prohibited.
25. Client Obligations
The Client agrees and undertakes to:
a. have a sufficient and valid legal basis for processing;
b. adequately inform data subjects through appropriate privacy notices;
c. issue lawful and compliant instructions;
d. correctly configure permissions, access roles, and organizational profiles;
e. limit access to authorized personnel;
f. maintain security over administrative credentials and user accounts;
g. respond to data subject requests submitted by its occupants.
26. Export
Upon termination of the service, the Client has a period of 30 calendar days to export its Client Data in standard formats (CSV, XLSX, JSON).
27. Deletion and Return
Upon completion of the service and expiration of the export period, ACHALAI, at the documented choice of the Client, shall return or delete the Personal Data processed on its behalf and delete existing copies, unless a legal obligation requires their retention.
Unless a legal obligation or different agreement applies, deletion from active production systems shall be completed within the following 60 calendar days.
When reasonably requested by the Client, ACHALAI shall provide written confirmation of deletion, subject to technical backup cycles and statutory retention obligations.
28. Backups
Backup copies may retain certain data during additional technical rotation cycles.
During that period:
- they will not be used for new purposes;
- they will remain subject to the corresponding security obligations;
- they will be deleted or overwritten in accordance with their normal cycle.
29. Liability
Economic liability arising from this DPA is subject to the aggregate liability cap set forth in the Terms of Service, unless:
- a mandatory statutory rule provides otherwise;
- the parties have expressly agreed to another limit in writing.
The DPA does not in itself create an independent economic limit cumulative to that provided in the Terms.
30. GDPR
Where the GDPR applies, this DPA shall be interpreted consistently with its Article 28 and other applicable mandatory provisions.
If a mandatory GDPR obligation conflicts with a provision of this DPA, the mandatory provision shall prevail exclusively with respect to the affected processing.
31. Argentine Law
Where processing is governed by Argentine law, this DPA constitutes the written data processing agreement required by Article 25 of Law No. 25.326.
32. Term
This DPA enters into force upon access to the Platform or formalization of the Service Order and remains effective until all Client personal data is completely deleted or returned.
33. Contact
Data protection communications:
info@achalai.com
ANNEX A — DETAILS OF PROCESSING
Controller: Client.
Processor: ACHALAI.
Purpose: provision of the contracted organizational features.
Duration: term of the service plus technical and statutory retention periods.
Data Subjects: employees, contractors, collaborators, and other data subjects lawfully incorporated.
Operations: hosting, storage, organization, calculation, consultation, visualization, export, and deletion.
Frequency: continuous during use of the Platform.
Sensitive Data: not required as a standard matter.