Data Processing Agreement
Version 1.0 · August 12, 2026This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or other written agreement between Archis Inc. DBA Ridefluencer, doing business as Ridefluencer ("Ridefluencer"), and the Business Customer identified in the applicable Order Form (together, the "Agreement"), and applies to the extent we process personal data on behalf of the Business Customer in connection with the Service. Capitalized terms not defined here have the meaning given in our Terms of Service or the Agreement.
1. Roles of the Parties
For personal data submitted to the Service by or on behalf of the Business Customer ("Customer Data"), the Business Customer is the controller (or "business" under the CCPA) and we are the processor (or "service provider"). Where the Business Customer is itself a processor acting for a further controller, it warrants that it has obtained all necessary authorizations for our processing under this DPA.
This DPA governs Customer Data only. It does not apply to data for which we are the controller under our Privacy Policy, such as data collected from website visitors, driver personal data we manage directly, or aggregated and de-identified data we use to operate and improve the Service.
2. Scope and Instructions
We will process Customer Data only: (a) to provide the Service in accordance with the Agreement; (b) in accordance with the Business Customer's documented instructions, including through its configuration of the Service; or (c) as required by applicable law, in which case we will, where legally permitted, notify the Business Customer before processing.
Schedule 1 (Details of Processing) describes the subject matter, duration, nature, and purpose of processing, the categories of data subjects, and the types of personal data processed.
3. Confidentiality
We will ensure that personnel authorized to process Customer Data are subject to a binding written confidentiality obligation.
4. Security Measures
We will implement appropriate technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, consistent with the safeguards described in our Privacy Policy. These include encryption in transit, access controls and role-based authorization, and use of reputable infrastructure providers listed in our Sub-processor List.
5. Sub-processors
The Business Customer provides general authorization for us to engage sub-processors to help provide the Service, subject to this Section. Our current Sub-processor List is available at ridefluencer.com/subprocessors. We will:
- Impose data-protection obligations on each sub-processor no less protective than those in this DPA;
- Remain liable to the Business Customer for a sub-processor's acts and omissions to the same extent we would be liable if performing the services ourselves;
- Provide notice of a new sub-processor by updating the Sub-processor List and, where the Business Customer has subscribed to notifications, by email at least 30 days before the new sub-processor begins processing Customer Data.
If the Business Customer reasonably objects to a new sub-processor on data-protection grounds within 30 days of notice, the parties will work in good faith to resolve the objection; if unresolved, the Business Customer may terminate the affected Service as its exclusive remedy.
6. Data Subject Rights
Taking into account the nature of the processing, we will provide reasonable assistance to the Business Customer, through the Service or otherwise, to respond to requests from data subjects to exercise their rights under applicable data-protection laws. If we receive such a request directly regarding Customer Data, we will direct the individual to the Business Customer and forward the request without undue delay.
7. AI Features and Validation
Where the Service uses AI Features to validate a Promotion, the Business Customer acknowledges that our AI validates whether a recommendation occurred and produces supporting proof and sentiment signals; it does not make any decision about an individual. The Business Customer is responsible for ensuring that its promotion offer and approved talking points comply with applicable law. We will provide reasonably available technical information about a given AI Feature to support the Business Customer's compliance, subject to our ability to do so without disclosing proprietary technology or trade secrets.
8. Personal Data Breach Notification
We will notify the Business Customer without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting Customer Data, and will provide reasonably available information to help the Business Customer meet its own notification obligations.
9. International Data Transfers
We operate the Service from, and store Customer Data in, the United States. Where Customer Data originates in a jurisdiction whose data-protection laws restrict cross-border transfer, the parties will rely on a valid transfer mechanism recognized under those laws.
10. Audits
We will make available to the Business Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant certifications or audit summaries if obtained. On at least 30 days' prior written notice, and no more than once per year (except following a confirmed security incident or if required by a supervisory authority), the Business Customer or its appointed auditor may audit our relevant policies and records, at the Business Customer's expense, subject to confidentiality obligations and reasonable scheduling.
11. Deletion or Return of Data
On termination or expiration of the Agreement, we will, at the Business Customer's choice, delete or return all Customer Data within 30 days, except to the extent applicable law requires continued retention. If the Business Customer does not specify a choice within 30 days of termination, we will delete Customer Data in accordance with our standard retention procedures.
12. Liability and Governing Law
Each party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Agreement, except to the extent applicable data-protection laws prohibit such limitation. This DPA is governed by the laws of the State of Delaware, without prejudice to any mandatory data-protection law requiring a different law or forum for specific provisions.
Schedule 1: Details of Processing
- Subject matter: Provision of the Ridefluencer rideshare word-of-mouth promotion platform.
- Duration: For the term of the Agreement, plus any period specified in Section 11.
- Categories of data subjects: The Business Customer's authorized users and business contacts.
- Categories of personal data: Contact and identity information (name, email, phone, business name); Account and login data; campaign configuration, promotion offers, and approved talking points; and usage and log data.
- Special categories of data: None are intentionally collected. The Business Customer must not submit special categories of personal data through the Service absent a separate written agreement.
- Nature of processing: Hosting, storage, campaign management, AI-assisted validation of promotions, and reporting.
- Purpose of processing: To provide the Service as described in the Agreement.
Questions
Questions about this DPA may be sent to info@ridefluencer.com.