← Artica · Legal

Data Processing Addendum

The terms under which Artica processes personal data in your content on your behalf, under GDPR, UK GDPR and US state laws.

CONTENTS
  1. Acceptance
  2. Definitions
  3. Scope and roles
  4. Instructions
  5. Confidentiality
  6. Security
  7. Subprocessors
  8. Assistance
  9. Personal data breaches
  10. Audits
  11. Deletion and return
  12. International transfers
  13. US state privacy laws
  14. Liability and precedence
  15. Annex I: Processing details
  16. Annex II: Security measures
  17. Annex III: Subprocessors
Effective 1 October 2026Last updated 1 October 2026

Acceptance

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Hosam Hassan LLC, a Wyoming limited liability company, 30 N Gould St. #48472, Sheridan, WY 82801, USA (“Artica”). You accept it by creating an account or using the Service; no signature is needed. If you need a countersigned copy for your records, email hello@artica.tools and we will send one with the same terms.

Definitions

  • Data Protection Laws: all laws on personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
  • Customer Personal Data: personal data in content the Customer brings to the Service (tickets, help center articles, documents, captures and screenshots), processed by Artica on the Customer’s behalf.
  • Subprocessor: a third party Artica engages to process Customer Personal Data.
  • SCCs: the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.
  • UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0).
  • Terms such as controller, processor, data subject, personal data breach and processing have the meanings given in the GDPR.

Scope and roles

  • For Customer Personal Data, the Customer is the controller (or a processor acting for its own controller) and Artica is the processor (or subprocessor).
  • For account, usage, analytics and support data about the Customer’s users, Artica is an independent controller, under its Privacy Policy. This DPA doesn’t cover that data.
  • The subject matter, nature, purposes, categories of data and data subjects, and duration are in Annex I.
  • The Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data, including having a lawful basis and giving the notices its data subjects need.

Instructions

Artica processes Customer Personal Data only on the Customer’s documented instructions, which are: these terms and this DPA, the Customer’s use and configuration of the Service (for example choosing a tool, a date range, or whether to remove personal data), and any other written instructions Artica agrees to. Artica will tell the Customer if it believes an instruction breaches Data Protection Laws, and is not required to follow it. Artica may also process Customer Personal Data where the law requires; in that case it will tell the Customer first unless the law forbids it.

Confidentiality

Only people who need access to provide the Service may access Customer Personal Data. Today that is Artica’s operator, who is bound by confidentiality. Artica does not look at Customer content except as needed to provide the Service, to give support the Customer asks for, to keep the Service secure, or as the law requires.

Security

Artica implements the technical and organisational measures in Annex II, taking into account the state of the art, the cost, and the nature and risks of the processing. Artica may update those measures as long as the overall level of protection doesn’t decrease.

Subprocessors

  • The Customer gives Artica general authorisation to use the Subprocessors listed on the subprocessors page (Annex III).
  • Artica imposes data protection obligations on each Subprocessor that are no less protective than this DPA, to the extent applicable to its service, and remains responsible for their performance.
  • Before adding or replacing a Subprocessor, Artica updates the subprocessors page. Customers who ask to be notified (by emailing hello@artica.tools) get an email at least 14 days before the new Subprocessor processes their Customer Personal Data.
  • The Customer may object on reasonable data protection grounds within that period. The parties will discuss it in good faith; if they can’t resolve it, the Customer may stop using the affected tool or close its account, and Artica will refund any prepaid, unused fees for it.

Assistance

  • Data subject requests: if Artica receives a request from a data subject about Customer Personal Data, it will pass it to the Customer without responding itself (except to say it has been passed on). Taking into account the nature of the processing, Artica will help the Customer respond, for example by finding and deleting stored content. Much of the Service stores no Customer Personal Data (see Annex I), so there is often nothing to retrieve.
  • Impact assessments and consultations: Artica will give reasonable help with data protection impact assessments and prior consultations with supervisory authorities, using the information in this DPA and its documentation first.

Personal data breaches

Artica will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, aiming to do so within 72 hours, by email to the address on the Customer’s account. The notice will describe, as far as known, the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. Artica will provide further information as it becomes available, take reasonable steps to contain and remedy the breach, and help the Customer meet its own notification obligations. Notifying the Customer is not an admission of fault.

Audits

Artica will make available the information reasonably needed to demonstrate compliance with this DPA and Article 28 GDPR. The Customer agrees to rely first on this DPA, the security page, Artica’s written answers to a reasonable security questionnaire (no more than once a year, unless after a breach), and the certifications of Artica’s Subprocessors. If that is not enough, or a supervisory authority requires it, the Customer may conduct an audit, at its own cost, with at least 30 days’ notice, during business hours, no more than once a year, by an auditor bound by confidentiality, in a way that doesn’t disrupt the Service or expose other customers’ data. Artica isn’t required to give access to its Subprocessors’ premises or systems.

Deletion and return

  • Most tools don’t store Customer Personal Data at all: they process it in memory for the length of the job (see Annex I).
  • Stored content (Article generator captures, screenshots and articles; Topic finder results; uploaded files until analysed) is deleted when the Customer asks, and in any case within 30 days after the account is closed. The Customer can export articles and copy results before then; Artica will help on request.
  • Residual copies in database backups expire within about 6 hours, and in Subprocessors’ logs and retention (including Anthropic’s, see AI use) on their own schedules. Artica will not restore or use them except to recover the Service.
  • Artica may keep Customer Personal Data where the law requires, protected under this DPA.

International transfers

Artica processes Customer Personal Data in the United States and in the other locations listed on the subprocessors page. Artica is not certified under the EU-US Data Privacy Framework. Where Customer Personal Data subject to the GDPR, UK GDPR or Swiss law is transferred to Artica in a country without an adequacy decision, the parties agree:

EU transfers

  • The SCCs are incorporated into this DPA by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. The Customer is the data exporter and Artica the data importer.
  • Clause 7 (docking) applies. Clause 9: option 2 (general written authorisation), with the notice period in Subprocessors. Clause 11: the optional language does not apply. Clause 13: the supervisory authority is the one competent for the Customer under Article 3(1) GDPR, or, if the Customer is outside the EU without a representative, the authority of the member state where the data subjects concerned are. Clause 17: Irish law. Clause 18: the courts of Ireland.
  • Annex I.A of the SCCs: the parties are the Customer (exporter, contact: the account email) and Artica (importer, contact: hello@artica.tools). Annex I.B is Annex I below; Annex II is Annex II; Annex III is Annex III.

UK transfers

The UK Addendum is incorporated: Table 1 is completed with the parties above; Table 2 refers to the SCCs modules and options above; Table 3 refers to the Annexes of this DPA; and in Table 4 either party may end the UK Addendum as allowed by its Section 19.

Swiss transfers

The SCCs apply with these changes: references to the GDPR include the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and “member state” includes Switzerland so that Swiss data subjects can enforce their rights there.

If the SCCs conflict with this DPA, the SCCs prevail.

US state privacy laws

Where the CCPA or a similar US state law applies, Artica is the Customer’s service provider or processor. Artica will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than providing the Service to the Customer (or as the law otherwise permits a service provider); retain, use or disclose it outside the direct business relationship with the Customer; or combine it with personal data from other sources, except as the law permits. Artica will comply with these laws, provide the same level of privacy protection they require, and tell the Customer if it can no longer meet its obligations. The Customer may take reasonable steps to stop unauthorised use. Artica certifies that it understands these restrictions.

Liability and precedence

Each party’s liability under this DPA is subject to the limits in the Terms of Service, except where Data Protection Laws or the SCCs don’t allow it. If this DPA conflicts with the Terms of Service on the processing of Customer Personal Data, this DPA prevails; the SCCs prevail over both. This DPA lasts as long as Artica processes Customer Personal Data.

Annex I: Processing details

Data subjects: the Customer’s end customers and contacts who appear in its tickets and screenshots; the Customer’s agents and staff; any other person named in content the Customer brings.

Categories of data: whatever the content contains, typically names, email addresses, phone numbers, company names, account and order numbers, addresses, message text and signatures, and in screenshots anything visible on the recorded screen. No special categories are intended (the Customer agrees not to bring them on purpose; see the Acceptable Use Policy).

Frequency: continuous, whenever the Customer uses a tool.

ToolNature and purposeStored?Duration
Ticket exporterReading tickets from the Customer’s Zendesk, optionally scrubbing personal data (patterns on Vercel; a name model on Modal once switched on, not yet active), and passing them to the Customer’s browser to build a fileNo. In memory only; counts are keptThe length of each request
Article exporterReading help center articles and images (public link or connection) and passing them to the Customer’s browser to build a zipNo. In memory only; counts are keptThe length of each request
Topic finderScrubbing tickets, summarising each into an anonymous question with AI, grouping and naming topicsUploaded files until the analysis starts; then only results (AI-written topics and questions, ticket IDs, counts)Files: until analysed, at most about two days. Results: until deletion
Article generatorReceiving redacted screenshots and step text from the extension, drafting an article with AI, editing, exporting to the Customer’s ZendeskYes: screenshots, steps and articles. Pattern redaction only; names on screen are not blurredUntil the Customer asks for deletion or closes its account
Format fixerReading one article, checking it in the browser, and for the AI fix sending its scrubbed text to AI; saving to Zendesk on requestNo. In memory only; counts are keptThe length of each request

Annex II: Security measures

  • Encryption in transit: TLS 1.2 or 1.3 only, with HSTS, for all traffic to artica.tools and between Artica and its Subprocessors.
  • Encryption at rest: the database and file storage are encrypted at rest by the providers. Zendesk OAuth tokens are additionally encrypted by Artica with AES-256-GCM. Keys pasted for an Article exporter export are sealed with AES-256-GCM into a session of at most 4 hours and never stored.
  • Data minimisation: most tools never store content. Personal data is scrubbed before AI processing in Topic finder and Format fixer, and pattern-redacted in the browser before upload in Article generator. Only the fields a task needs are sent to AI.
  • Isolation: every record and file is scoped to a workspace and checked on every request; files are served only to the owning workspace from a private bucket.
  • Access control: production access is limited to Artica’s operator. The admin view is read-only for customer accounts, shows masked email addresses, and never shows content. Account changes are made with audited scripts.
  • Secrets: production secrets are stored as sensitive environment variables in the hosting provider and never committed to source control.
  • Service authentication: calls between Artica’s servers and its processing service, and incoming webhooks, are authenticated with shared secrets or signatures checked in constant time, with strict payload schemas.
  • Logging: content is not logged; logs are kept briefly (Vercel runtime logs about an hour).
  • Backups and recovery: the database supports point-in-time restore for about 6 hours.
  • Incident response: as in Personal data breaches and the security page.
  • Subprocessors: chosen for their security practices; see Annex III.

Annex III: Subprocessors

The current list, with each Subprocessor’s purpose, the data it receives and its location, is on the subprocessors page, which forms part of this DPA.

Questions about this DPA, or a countersigned copy: hello@artica.tools.

TermsPrivacyDPASubprocessorsSecurityCookiesAIAcceptable usehello@artica.tools
© 2026 Hosam Hassan LLC · Artica