Data Processing Agreement
Last updated 18 September 2026
This agreement applies where you use Arkitype to process personal data and the UK GDPR, EU GDPR or a comparable law applies. It forms part of the terms and takes precedence over them on anything to do with personal data.
Please read this first. These terms are written in plain English and cover what Article 28 requires. They have not been reviewed by a lawyer. If your organisation needs a counter-signed agreement, or your own paper, write to legal@arkitype.srinidhibhat.com — we would rather sign yours than argue about ours.
1. Who is who
You are the controller: the personal data in your design systems, your comments and your team's accounts is yours, and you decide why it is there. Srinidhi Bhat, trading as Arkitype is the processor, acting on your instructions.
For your own account details — the address you signed up with, your billing contact — we are the controller, and the privacy notice covers that.
2. What we process, and why
- Subject matter: providing the design system builder — storing your systems, showing them to people you share with, compiling the exports you ask for.
- Duration: for as long as you have an account, plus the backup retention in §8.
- Categories of data subject: your team, and anyone you invite to a file.
- Categories of personal data: names, email addresses, profile details, and whatever personal data you choose to put into a design system or a comment.
- Special category data: none is requested, and the service is not designed to hold any.
3. Our instructions are yours
We process personal data only on your documented instructions — which, in the ordinary case, means operating the features you use. We do not sell it, we do not share it for anyone else's purposes, and we do not use it to train models. If we are ever required by law to process it some other way, we will tell you first unless the law forbids that.
4. Confidentiality
Everyone with access to your data is bound to keep it confidential. Access is limited to the people who need it to run the service, is authenticated individually rather than with a shared credential, and every administrative action is written to an append-only log before it is performed.
5. Security
We maintain the technical and organisational measures described on the trust page, which names what is in place and what is not. In summary: row-level security in the database rather than only in the application, encryption in transit and at rest, least-privilege operator access with an audit trail, and dependency scanning in continuous integration.
6. Subprocessors
You give general authorisation for the subprocessors below. We will give you 30 days' notice before a new one starts processing your data; if you object on reasonable data protection grounds you may terminate the affected service and receive a pro-rata refund.
- Supabase — Database, authentication, and file storage. The region configured for the project. Standard Contractual Clauses.
- Vercel — Application hosting and content delivery. Global edge network. Standard Contractual Clauses.
- Stripe — Payments, invoicing, and tax. United States and Ireland. Standard Contractual Clauses.
- Google Analytics — Marketing-page analytics only — never a published styleguide. United States. Standard Contractual Clauses; consent required before loading.
7. Your people's rights
We help you answer access, correction, erasure, restriction, portability and objection requests. Two of them need no help at all: any account can download everything it holds and delete itself from Settings → Account. For anything else, write to privacy@arkitype.srinidhibhat.com and we will respond within one month. If one of your data subjects contacts us directly, we forward it to you rather than answering for you.
8. Breach notification
If we confirm a personal data breach affecting your data we will tell you within 72 hours, with what we know, what we are doing, and what we recommend you do. We will not wait until we have a complete picture to make the first contact.
9. Return and deletion
You can export everything at any time, on every plan, in open formats. When you delete your account the live data goes immediately; encrypted backups age out within 30 days. On termination we delete your data within 30 days unless the law requires us to keep it, and we will say so if it does.
10. Audit
We will answer reasonable questions about our processing and provide what evidence we have — including, on Team and Enterprise, your own organisation's audit log. We do not hold a SOC 2 or ISO 27001 report; the trust page says so plainly. An on-site audit can be arranged on Enterprise terms, with reasonable notice and at your cost.
11. International transfers
Where personal data leaves the EEA or the UK it is covered by the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated here by reference. Each subprocessor's basis is listed in §6.
12. Liability and law
The limits in the terms apply to this agreement too. This agreement is governed by the law of Karnataka, India, and nothing in it limits a right a data subject has under applicable data protection law.
Signing it
Using Arkitype on a plan that includes a DPA accepts these terms without anyone signing anything. For a counter-signed copy, or to use your own template, write to legal@arkitype.srinidhibhat.com with the entity name and address for the agreement.
Questions about any of this? srinidhibhat45@gmail.com