Skip to content
Legal · Processing

Data Processing Addendum

Last updated August 8, 2026Version 1.0

1. Definitions and Roles

This Data Processing Addendum (“DPA”) forms part of the Samva Terms of Service between Arya Labs, Inc. (“Arya Labs”) and the customer (“Customer”). It applies when Arya Labs processes Personal Data on Customer’s behalf through the Services.

“Personal Data,” “Process,” “Processing,” “Controller,” “Processor,” and “Data Subject” have the meanings given by applicable Data Protection Laws. Customer is the Controller or Processor responsible for its instructions and Customer Content. Arya Labs is the Processor or Subprocessor for that Customer Content, except when it processes information as an independent Controller for account administration, billing, security, abuse prevention, service improvement, or legal compliance.

2. Processing Instructions

Customer instructs Arya Labs to process Personal Data to provide, secure, support, monitor, and improve the Services; send and track messages at Customer’s direction; provide delivery, bounce, complaint, unsubscribe, and suppression features; prevent abuse; and comply with documented Customer instructions and applicable law.

The subject matter is hosted email communications and related account operations. The duration is the term of the Services plus the period reasonably required for deletion, backup expiry, security, legal compliance, suppression, and dispute resolution.

Personal Data may include names, email addresses, phone numbers where supplied, identifiers, IP addresses, user agents, URLs, message content, attachments, engagement events, delivery events, preferences, suppression records, and other information Customer submits. Data Subjects may include Customer personnel, recipients, contacts, prospects, and other individuals represented in Customer Content.

3. Arya Labs Obligations

  • Process Personal Data only for the purposes described in this DPA, the Terms, and Customer’s documented instructions.
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
  • Maintain appropriate technical and organizational measures appropriate to the risk.
  • Assist Customer with reasonable requests concerning Data Subject rights, security, impact assessments, and regulator inquiries.
  • Notify Customer promptly after confirming a Personal Data Breach affecting Customer Content, subject to law and investigation needs.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Customer Obligations

Customer is responsible for the legality, accuracy, source, and retention of Customer Content; its notices and permissions; its instructions; recipient rights; configuration of engagement tracking; and its use of exported or delivered data.

Customer will not submit payment-card data, protected health information, special-category personal data, children’s data, or other regulated data unless Arya Labs has separately approved that processing in writing.

5. Subprocessors

Customer gives Arya Labs general authorization to use the subprocessors listed at /legal/subprocessors. Arya Labs will require subprocessors to provide data-protection obligations appropriate to the services they provide and will remain responsible for its contractual obligations under this DPA.

Arya Labs will provide at least 14 days’ advance notice of a new or replacement subprocessor by updating the subprocessor list or using another reasonable notice channel. Customer may object in writing on reasonable data-protection grounds. If Arya Labs cannot reasonably address the objection, either party may stop the affected processing or terminate the affected Service on reasonable notice.

6. International Transfers

Arya Labs may process Personal Data in the United States and other countries where it or its subprocessors operate. The parties will use an applicable lawful transfer mechanism where required by Data Protection Laws. Where Standard Contractual Clauses are legally required and applicable, the parties will incorporate the relevant controller-to-processor or processor-to-processor clauses and complete the required annex information through this DPA or a supplemental document.

7. Security and Incidents

Arya Labs maintains measures appropriate to the Services, including access controls, tenant isolation, encryption in transit, credential and key protections, logging, and operational safeguards. Arya Labs does not guarantee that security incidents will never occur.

Arya Labs will provide prompt notice after confirming a Personal Data Breach affecting Customer Content, with available information about the nature and scope of the incident, affected categories, likely consequences, and mitigation steps. Customer is responsible for determining whether and how to notify Data Subjects or regulators.

8. Audits and Information

Customer may request reasonable information about Arya Labs’ processing and security measures. Any audit must be reasonable in scope, protect confidentiality, avoid disruption, and occur no more than once annually unless a Personal Data Breach or regulator requires otherwise. Customer bears its audit costs.

9. Return and Deletion

At the end of the Services, Arya Labs will delete or return Customer Content according to the Terms, the applicable account controls, and Customer’s lawful instructions, unless retention is required or permitted for legal compliance, billing, security, abuse prevention, suppression, backups, or dispute resolution.

10. Precedence

If this DPA conflicts with the Terms concerning processing of Personal Data, this DPA controls. The Terms control all other matters. No provision of this DPA requires Arya Labs to process prohibited or unapproved regulated data.