This DPA forms part of the agreement governing a customer’s use of Armalo Vibe Cloud. Version July 22, 2026.
Agreement includes the Terms, MSA, order form, or other written service agreement. Customer Personal Data is personal data Armalo processes for Customer. The DPA uses Controller, Processor, Subprocessor, Data Subject, Processing, Personal Data Breach, GDPR, UK GDPR, SCC, EU-US DPF, and Security Measures in their applicable legal meanings.
Customer is Controller and Armalo is Processor for Customer Personal Data. If Customer is a Processor, Customer appoints Armalo as subprocessor and represents that the Controller authorized that appointment. Customer controls purposes and essential means, ensures lawful instructions, and provides notices and legal bases. Armalo remains an independent Controller for account administration, billing, service security, fraud prevention, and its own legal duties.
Armalo processes Customer Personal Data to provide the Services from submission or access through the Agreement term. Processing may continue for return, deletion, backup expiry, law, or documented instructions. The ordinary active-system deletion period is 30 days. Processing is EU-primary: Hetzner in Germany and Finland, Cloudflare at the edge, and E2B sandbox execution in EU or optional US regions.
Processing supports collaborative workspaces, authentication, authorization, storage, synchronization, agents, code operations, builds, tests, previews, customer-selected providers and integrations, logs, audits, support, recovery, security, metering, backups, return, and deletion. Customer Personal Data is not used to train general-purpose AI models by default; any training use requires affirmative opt-in and documented terms.
Data subjects can include Customer personnel, authorized users, workspace members, clients, prospects, contractors, and people whose data appears in submitted code, files, messages, databases, or integrations. Data can include identity and contact information, authorization metadata, messages, prompts, code, files, repository and deployment metadata, technical identifiers, integration records, agent inputs and outputs, and support content. Special-category or highly regulated data requires written authorization and agreed safeguards.
Armalo processes only documented instructions, applies confidentiality and GDPR Article 32 security, binds subprocessors to materially equivalent protections, assists with rights and GDPR Articles 32–36, notifies breaches, maintains required records, supports lawful audits, and returns or deletes data. Where lawful, Armalo notifies Customer of required government processing and challenges unlawful or overbroad requests where reasonable.
Customer gives general written authorization for subprocessors. Armalo publishes the current schedule and provides at least 30 days’ notice before additions or replacements that process Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties seek a configuration change, alternate provider, or commercial solution; if none exists, Customer may terminate the affected Service before processing begins. Urgent security, legal, or provider-failure changes are notified as soon as practical.
See security controls and subprocessors →Transfers outside the EEA, UK, or Switzerland use a lawful mechanism. Armalo may rely on adequacy, eligible EU-US DPF coverage, or SCCs. SCC Module Two applies to Controller-to-Processor transfers and Module Three when Customer is a Processor. The UK Addendum and Swiss adaptations apply where required. Transfer impact assessments and supplementary measures are used where necessary. <!-- LEGAL-REVIEW: Select the SCC governing-law Member State and courts; default candidate Ireland, finalize with counsel before customer use. -->
Controls include unique identities, workspace-scoped RBAC, least privilege, session controls, logical tenant separation, E2B sandbox boundaries, authorization before execution, scoped credentials, encryption in transit and at rest, encrypted credential storage, secret exclusion from logs, Hetzner EU hosting, Cloudflare edge security, monitoring, secure development, encrypted backups, recovery, documented retention, deletion, and credential revocation. Armalo does not represent that Armalo Inc. holds a corporate SOC 2 report unless confirmed in writing.
See security controls and subprocessors →Customer responds to rights requests as Controller. Armalo provides reasonable assistance through search, export, correction, deletion, restriction, and workspace controls. Requests identify the Data Subject, workspace, category, and action. Armalo verifies scope and authority and acts in time for Customer to meet applicable deadlines.
Armalo notifies Customer without undue delay and no later than 72 hours after awareness of a breach affecting Customer Personal Data. Notice can be phased and includes known nature, affected subjects and records, consequences, measures, containment, remediation, and a contact. Armalo contains, investigates, mitigates, remediates, preserves evidence, and assists Customer with required notices.
Armalo provides information reasonably needed to demonstrate compliance. Routine requests can use current assurance reports, provider certifications, security documentation, penetration-test summaries, questionnaires, and equivalent evidence. Customer may conduct one remote audit per year on 30 days’ notice, plus for-cause audits after a material breach, credible noncompliance, or regulator requirement. Audits protect other customers, privilege, vulnerabilities, and trade secrets.
At termination or written request, Customer chooses return or deletion. Standard exports are available before service access ends. After export or instruction, Armalo deletes Customer Personal Data from active systems within 30 days, including workspace content, indexes, artifacts, sandbox data, and credentials. Encrypted backups expire no later than 60 days after deletion begins. Lawful holds remain protected and purpose-limited.
Liability under this DPA follows the Agreement’s exclusions and limitations. Unless a signed Agreement says otherwise, the Terms cap applies: fees paid or payable during the 12 months before the event. Liability that cannot lawfully be limited and Data Subject rights under the SCCs remain unaffected.
This DPA controls Agreement conflicts about Customer Personal Data. SCCs control conflicts within their scope. A signed order form may add stronger protections but cannot reduce mandatory Data Subject rights. Electronic signatures and counterparts are permitted.
The Customer legal entity and authorized representative are identified in the Agreement, order form, or electronic acceptance record. Armalo’s legal name is Armalo Inc.; the authorized representative is Ryan Fong, Founder, or another duly authorized representative. Address, signature, title, and date are recorded in the applicable contracting flow.
Contact legal for an order-form-linked DPA and signature workflow.
Contact legal