By accessing, using, or signing up for EveryArrow's services, you agree to be bound by these Terms of Service.
These Terms constitute a legally binding agreement between you ("Customer" or "you") and EveryArrow, Inc. ("EveryArrow", "we", "us", or "our"). If you do not agree to these Terms, you may not access or use our Services.
By creating an account, placing an order, or using our Services in any way, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service.
This Agreement consists of 30 sections (0-29) plus comprehensive Data Processing Addendum and supporting annexes.
Last Updated: This Terms of Service was last updated to reflect current legal requirements and service offerings.
The following definitions apply throughout this Agreement. Unless otherwise specified, these terms have the meanings set forth below.
Unless stated otherwise: (i) "including" means "including without limitation"; (ii) "or" is inclusive; (iii) references to laws include amendments and successor laws; (iv) headings are for convenience only; (v) "written" includes email (except for notices explicitly requiring courier/hand delivery in §27); (vi) times are in Eastern Time unless stated otherwise; and (vii) conflicts are resolved by §28 (Order of Precedence).
As between the parties, Customer owns all right, title, and interest in Customer Data, which is Customer's Confidential Information.
Customer grants EveryArrow a non-exclusive, worldwide license to host, copy, transmit, and ProcessCustomer Data solely to provide, maintain, secure, and support the Services and toprevent or address service errors or security incidents.
The Services are designed for minimal retention and do not persist Customer Data content beyond transient Processing, except that errored rows and associated diagnosticsmay be temporarily retained within Customer-controlled storage or an EveryArrow-managed diagnostics bufferfor troubleshooting and replay, for the retention period applicable to Customer's license tieras stated in the Documentation or Order (defaults referenced in §4.3), after which such data is purged per the DPA.
EveryArrow may collect and use aggregated, de-identified service usage data and telemetry to operate, secure, and improve the Services and to publish benchmarks, provided no Customer or natural person is identified.Enterprise customers may opt out of such usage analytics as specified in the Order, in which case EveryArrow will disable collection beyond what is strictly necessary to operate and secure the Services.
"Confidential Information" means non-public information disclosed by one party ("Discloser") to the other ("Recipient") that is designated confidential or would reasonably be understood as confidential, including Customer Data, product roadmaps, security documentation, pricing, and technical information; exclusions apply for information that is public, already known, independently developed, or rightfully received.
Recipient will protect Discloser's Confidential Information using at least the same degree of care it uses for its ownof like kind and no less than reasonable care, and will use it only to perform under this Agreement.
Recipient may disclose to employees, contractors, sub-processors/subcontractors, and advisors with a need-to-know, under written confidentiality obligationsno less protective; Recipient remains responsible for their compliance.
If legally compelled, Recipient will (where permitted) give prompt notice andlimit disclosure to the minimum required.
On request or termination, return or destroy Confidential Information (archival copies may remain under this Section). Obligations survive until the information is no longer confidential;trade secrets survive so long as they remain trade secrets.
For Personal Data, Customer is Controller/Business and EveryArrow isProcessor/Service Provider. The Data Processing Addendum (Exhibit A)(including SCCs/UK Addendum where applicable) is incorporated.
EveryArrow Processes Personal Data solely on Customer's documented instructions in this Agreement/DPA/Order and will flag unlawful instructions (where permitted).
Customer authorizes listed Sub-processors and replacements withadvance notice; Customer may object on reasonable data-protection grounds. If unresolved, Customer may suspend/terminate the affected Service with apro-rata refund of prepaid, unused fees for that portion. EveryArrow flows downno-less-protective obligations and remains responsible.
Upon a confirmed Security Incident involving Customer Personal Data, EveryArrow willnotify without undue delay and share available details to support legal obligations and mitigation.
On termination or request, delete (and, at Customer's option, return) Personal Datawithin 30 days, except where law requires retention (then delete after).
EveryArrow acts as a Service Provider/Processor, does not sell/sharePersonal Information, and does not retain/use/disclose it beyond providing the Services (or as permitted by law), nor combine it except as allowed for Service Provider purposes.
Customer shall not submit or cause the Cloud Services to Processregulated data, including without limitation:
EveryArrow does not support BAAs, PCI attestation, or equivalent regulated-data commitments for the Cloud Services.
For troubleshooting/replay, non-regulated errored rows and diagnostics may be retained either (i) in Customer-controlled storage, or (ii) in an EveryArrow-managed diagnostics buffer, encrypted in transit/at rest and purged per §4.3 and the DPA.
Defaults: Standard up to 7 days (configurable down to 0);Enterprise configurable up to 30 days (customer-managed bucket option). After the period, errored rows/diagnostics are automatically purged.(No regulated data retention occurs in Cloud.)
Regulated data may be Processed only under EveryArrow's Self-Hosted offering, governed by the Self-Hosted License and, if Customer requests Remote Support or specific compliance commitments, the applicable Riders (e.g., HIPAA BAA Support Rider, PCI Addendum). These exceptions do not apply to the Cloud Services.
Customer will not route regulated data into the Cloud Services or attempt to mask it as non-regulated. EveryArrow may implement detection and fail-closed safeguards to prevent prohibited ingestion.
EveryArrow implements and maintains appropriate technical and organizational measures designed to protect the Services and Customer Data against unauthorized access, use, alteration, or disclosure, including encryption in transit and at rest, access controls and role-based access, secure development and change management, vulnerability management, monitoring and audit logging, and business continuity and disaster recovery programs consistent with industry-standard practices.
Customer Data is protected with TLS 1.2+ in transit and is encrypted at rest where persisted by the Services (including diagnostics buffers). Keys are managed using a managed key service with access controls and periodic rotation consistent with industry practice.
Handling and notice align with §3.4 (notification without undue delay for confirmed Security Incidents involving Customer Personal Data).
Additional information about EveryArrow's security program may be found on its Security & Compliance page (which EveryArrow may update from time to time). These materials are provided for transparency and do not modify contractual obligations.
Monthly Uptime Percentage target: 99.9%. Measured per UTC calendar month and, for multi-region deployments, per Customer's selected region.
"Downtime" means any continuous five (5) minutes or moreof material unavailability of core APIs or inability to enqueue or process jobs due to the Services, excluding SLA Exclusions. Intermittent errors under five minutes aggregate only if same root cause and exceed five minutes within a 15-minute interval.
Scheduled/Emergency Maintenance; force majeure/Internet issues outside EveryArrow's edge; Customer systems/misuse; third-party source/destination failures; Beta/Preview features; Customer's breach.
If uptime < 99.9%: 5% (≥99.0%),10% (≥98.0%), 25% (<98.0%) of one month's fee for the affected Service/region; cap 50%;sole remedy for SLA failures.
Open a P1 ticket during the incident (or promptly after) and submit a credit request within30 days after month-end; validation via logs/monitoring/RCA.
Standard window: Saturdays 02:00–06:00 local with 48h notice; emergency as needed. Maintenance is excluded from SLA.
Material reductions don't apply mid-term; effective upon renewal unless agreed otherwise.
Support via email/portal. Business Hours means 6:00 a.m.–12:00 a.m. (midnight) Eastern Time, Monday–Friday, excluding U.S. holidays. Unless stated otherwise for a plan, targets apply only during Business Hours.
Pooled or Dedicated Support with enhanced SLAs may be offered as described on the Pricing & Support page and/or the Order. If purchased, the Order governs and may supersede §7.2.
Customer will provide qualified contacts and diagnostics; non-reproducible issues may be downgraded. Support excludes professional services, third-party product defects, and unsupported configurations.
Material reductions don't apply mid-term; effective upon renewal.
Each party has full power and authority to enter into this Agreement.
During an Order Term for a paid plan, the core, GA Services willmaterially conform to the Documentation. Customer's sole and exclusive remedyfor breach is, at EveryArrow's option: (a) re-performance, or (b) termination of the affected Service with apro-rata refund of prepaid, unused fees for the remaining Term for that Service.
§8.2 does not apply to Free/trial use; Beta/Preview/experimental features; Third-Party Services; issues caused by Customer data/configuration/environment; use not per Documentation; or features/limits not included in Customer's purchased plan.
EXCEPT AS IN §8.2, THE SERVICES, DOCUMENTATION, SDKS/CLIS, COMMUNITY CONNECTORS, AND ANY FREE/BETA OFFERINGS ARE PROVIDED"AS IS" AND "AS AVAILABLE." ALL OTHER WARRANTIES (EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE) AREDISCLAIMED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE,NON-INFRINGEMENT, TITLE, SATISFACTORY QUALITY,ACCURACY, AND QUIET ENJOYMENT.
No warranty of uninterrupted, timely, secure, or error-free operation or of meeting Customer requirements, producing particular results, or ensuring legal/regulatory compliance. Customer is responsible for validating outputs/mappings/transformations.
Third-Party Services are used under their terms and without warranties by EveryArrow. Open-source components are licensed under their own licenses and provided "AS IS."The Services are not designed for hazardous/mission-critical environments; Customer assumes all risk of such uses.
Professional services and any support SLA targets apply only if purchased (SOW or Order). Unless an SOW expressly warrants otherwise, pro services are AS IS; remedy is re-performance or refund of fees for the non-conforming portion. The remedies in this Section are sole and exclusive.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FORINDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
EXCEPT FOR AMOUNTS THAT CANNOT BE LIMITED BY LAW, EACH PARTY'S AGGREGATE LIABILITYARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO EVERYARROW FOR THE SERVICES GIVING RISE TO THE CLAIM IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY. SERVICE CREDITS (IF ANY) ARE SET-OFFSAND APPLY AGAINST THIS CAP.
THE FOREGOING LIMITATIONS APPLY TO ALL THEORIES OF LIABILITY, INCLUDING CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, AND OTHERWISE, AND APPLY EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
EveryArrow will defend Customer against any third-party claim alleging that theServices, as provided by EveryArrow and used by Customer in accordance with the Documentation,infringe a third party's intellectual property right, and will pay damages and costs finally awarded (or a settlement EveryArrow approves),provided Customer:
If a claim arises, EveryArrow may, at its option and expense:
EveryArrow has no obligation for claims to the extent arising from: (1) Customer Data; (2) combinations with products, data, or services not provided by EveryArrow; (3) use of the Services not in accordance with the Documentation; (4) Customer's continued use after notice of the alleged infringement; or (5) use of a non-current version where the current version would avoid the claim.
Customer will defend EveryArrow against any third-party claim arising from: (a) Customer Data (including allegations that Customer Data or its Processing violates law or third-party rights); or (b) Customer's use of the Services in violation of law or this Agreement (including AUP), and will pay damages and costs finally awarded (or settlements Customer approves), subject to EveryArrow's compliance with notice, control, and cooperation obligations comparable to those in §10.1.
This Section states the parties' sole and exclusive remedies for the claims described in §§10.1–10.2.
This Agreement begins on the Effective Date and continues until terminated as provided herein. Each Order has the Term stated in the Order and auto-renews for successive one-yearperiods (or the then-current Term) at then-current rates unless either party gives written notice of non-renewal at least 30 days before the end of the then-current Term.
EveryArrow may suspend the Services (in whole or part) immediately with notice if:
Suspension is narrow as practicable and lifted when the condition is cured.
Either party may terminate this Agreement or an affected Order upon 30 days' written notice if the other partymaterially breaches and fails to cure within that period. EveryArrow may terminate immediately forillegal conduct, fraud, IP infringement risk not reasonably mitigable, or repeated violations of §4 or the AUP.
Not permitted during an Order Term unless expressly stated in the Order (enterprise add-on only).
Upon termination/expiry of an Order:
Sections 2 (Confidentiality), 3 (Privacy & DPA), 4 (Prohibited Data), 6.4 (Credits, solely as offsets), 7.6–7.7, 8 (Warranties/Disclaimers), 9 (Liability), 10 (Indemnity), 11.5–11.6 (Effect; Survival), and payment obligations survive termination.
Customer grants EveryArrow a worldwide, royalty-free, non-exclusive license to use Customer'sname and logos ("Marks") to identify Customer as a customer on EveryArrow websites, slide decks, and customer lists, subject to Customer's reasonable brand guidelines (if provided). Customer may revoke this permissionat any time by written notice; EveryArrow will cease new uses and remove or update reasonable online references within a commercially reasonable time (archival/printed materials may persist until exhausted).
EveryArrow may request Customer's participation in case studies, testimonials, reference calls, speaking opportunities, or press releases. Any such activities are voluntary and require Customer's prior written approval (email sufficient) for factual accuracy of any public statements or quotes.
Use of Marks will not suggest endorsement of a specific product or claim beyond Customer's status as a customer. EveryArrow will follow Customer's brand guidelines (if provided).
Rights under §12.1 survive for already-created materials and customer lists; upon revocation, EveryArrow will stop new uses.
EveryArrow may modify the Services from time to time (including adding, changing, or removing features) to improve performance, security, or usability, or to address legal, safety, or third-party requirements. EveryArrow will not materially reduce core functionality of the Services purchased under an active Order without providing a commercially reasonable workaround or, if none is feasible, a pro-rata refund of prepaid, unused fees for the affected portion of the Services.
For non-critical feature or connector removals, EveryArrow will provide at least 90 days' notice where practicable. Emergency removals (e.g., security, legal, or upstream breakage) may occur without prior notice; EveryArrow will communicate promptly thereafter.
Many connectors and features depend on third-party APIs or services. EveryArrow is not responsible for changes or outages in third-party services. If an upstream change degrades or breaks functionality, EveryArrow may modify, limit, or remove the affected capability and will use commercially reasonable efforts to mitigate impact.
EveryArrow may update policies and Documentation (including Acceptable Use, Support Policy, and Security & Compliance pages) from time to time. Material adverse changes will not apply to Customer during an active Order Term unless required by law or to address security risks; otherwise they take effect at renewal.
Features identified as Beta/Preview/Experimental may be changed, suspended, or discontinued at any time, are provided AS IS, outside the SLA and support targets, and are not for production use unless stated otherwise.
Customer's sole and exclusive remedies for changes under this Section are the workaround or pro-rata refund described above (if applicable).
Customer acknowledges that the Services (including any clients, agents, SDKs, plug-ins, or container images) may require updates, patches, or configuration changes. EveryArrow may automatically deliver and/or require installation of updates to maintain security, performance, or compliance. Where an update is designated required, Customer will install (or allow installation of) such update within the timeframe stated in the notice or, if none, within a commercially reasonable period.
If a required update is not applied within the applicable timeframe, EveryArrow may degrade, throttle, or suspend the affected functionality until the update is completed. EveryArrow will provide reasonable notice (where practicable) and instructions for remediation.
For critical security issues, EveryArrow may enforce immediate updates or apply temporary mitigations (including disabling affected features) without advance notice. EveryArrow will communicate remediation steps promptly thereafter.
EveryArrow maintains a Version Support Policy (which may be updated from time to time) identifying Supported Versions of clients/agents/SDKs and Supported Environments (e.g., operating systems, browsers, runtimes). Functionality may be limited or unavailable on Unsupported Versions or Environments.
Certain features depend on third-party components or APIs. If a third-party change affects compatibility, EveryArrow may require Customer to update configurations or software and may modify, limit, or remove the affected capability as reasonably necessary (see §13.3).
For Self-Hosted software licensed under separate terms, Customer will implement required updates designated as security or compliance updates within the timeframe stated by EveryArrow. If Customer declines a required update, EveryArrow may suspend related support obligations and disclaim responsibility for issues attributable to the missing update.
Update notices may be provided in-product, via email to the admin contact, status page, or Documentation. Documentation will describe significant update impacts and any migration steps where applicable.
Customer will not disable, bypass, or interfere with update checks, signature verification, or telemetry necessary to verify required version compliance.
Features or services labeled Beta, Preview, Early Access, or similar are provided AS IS, outside the SLA and support targets, and not recommended for production.
Beta features may change, break, or be withdrawn at any time. If a Beta graduates to GA, continued use may require migration or re-configuration per the Documentation.
Customer should not process regulated data (§4) in Beta features. EveryArrow may collect enhanced telemetry on Beta usage to evaluate performance and improve functionality, aggregated and de-identified where feasible.
For Beta features, Customer grants EveryArrow a worldwide, perpetual, irrevocable license to use Feedback (ideas, suggestions, bug reports) to develop and improve products, without obligation to Customer.
Customer may submit Feedback about the Services. EveryArrow may freely use Feedback without restriction or compensation.
EveryArrow may generate and use Aggregated/De-identified insights (e.g., performance metrics, error rates) to operate, secure, and improve the Services and to publish benchmarks, provided no Customer or natural person is identified (Enterprise opt-out per §1).
Except for the license in §16.1, this Agreement does not assign Customer's IP. Enhancements to the Services, including those arising from Feedback, are EveryArrow IP.
Each party will comply with all applicable export control, economic sanctions, and anti-corruption/anti-bribery laws, including the U.S. Export Administration Regulations (EAR), OFAC sanctions, and the U.S. Foreign Corrupt Practices Act (FCPA) and UK Bribery Act.
Customer represents and warrants that neither Customer nor its Authorized Users are:
Customer will not export, re-export, transfer, or use the Services in violation of such laws.
Customer will not offer, promise, authorize, give, or accept anything of value to/from any Government Official or third party to obtain or retain business or any improper advantage in connection with the Services. Facilitation payments are prohibited.
Customer will not request that EveryArrow participate in any boycott not sanctioned by the U.S. and will comply with applicable anti-money-laundering laws. Customer will promptly notify EveryArrow if it or any Authorized User becomes a Restricted Party or is charged with a corruption offense.
Upon reasonable request, Customer will certify compliance with this Section and cooperate with EveryArrow regarding export/sanctions diligence relevant to Customer's use.
EveryArrow may suspend or terminate access to the Services immediately, without liability, where it reasonably believes Customer's use violates this Section or would cause EveryArrow to be in breach of applicable export, sanctions, or anti-corruption laws.
This Agreement is governed by the laws of the State of Delaware, U.S.A., without regard to conflict-of-laws rules and excluding the U.N. Convention on Contracts for the International Sale of Goods.
Before initiating arbitration, a party must provide written notice of the dispute and the parties will negotiate in good faith for 30 days.
Any dispute, claim, or controversy arising out of or relating to this Agreement will be resolved by final and binding arbitration administered by JAMS under its Streamlined Arbitration Rules then in effect. Proceedings will be conducted remotely by default (video/teleconference). If an in-person hearing is required, it will take place in Wilmington, Delaware. The arbitration will be conducted in English before a single arbitrator. Judgment on the award may be entered in any court of competent jurisdiction.
All claims must be brought on an individual basis only and not as a plaintiff or class member in any purported class, collective, or representative proceeding. The arbitrator may award relief only in favor of the individual party seeking relief.
Either party may seek temporary, preliminary, or injunctive relief in any court of competent jurisdiction at any time to protect Confidential Information or intellectual property rights, without posting bond.
Each party will bear its own attorneys' fees and costs, and the arbitrator's fees will be allocated as provided by the JAMS Rules, unless the arbitrator awards otherwise under applicable law.
If the class-action waiver in §18.4 is found unenforceable for a particular claim, then that claim (and only that claim) must be litigated in court, and the remainder will proceed in arbitration.
Services, plan tiers, quantities, and pricing are set out in an Order (or online checkout). Orders are non-cancellable and non-refundable except as expressly provided in this Agreement.
Unless paid by card at checkout, fees are invoiced in advance and due net 30 days from invoice date. Late amounts accrue the lesser of 1.5% per month or the maximum rate allowed by law and may trigger suspension under §11.2.
Payments are due without setoff or deduction.
Usage in excess of plan limits, add-on features, or professional services will be billed at the then-current or Order rates.
Fees are exclusive of Taxes (sales, VAT, GST, withholdings, duties). Customer is responsible for all Taxes associated with its purchases, excluding taxes based on EveryArrow's net income. If withholding is required by law, fees are grossed-up so EveryArrow receives the amount it would have received absent withholding. Provide valid exemption certificates if applicable.
Customer will comply with EveryArrow's Acceptable Use Policy ("AUP") as updated from time to time (material adverse changes apply at renewal per §13.4).
Customer is responsible for:
This section defines intellectual property rights and restrictions on the use of EveryArrow's proprietary materials.
All items and materials included in or made available through the Services (including but not limited to EveryArrow's technology, software, services, processes, proprietary methods, data, know-how, and information), other than Customer Data, are the exclusive property of EveryArrow and its licensors. Nothing in the Agreement grants Customer any intellectual property rights in or to such materials or items.
Customer agrees not to copy, modify, create a derivative work of, reverse engineer, decompile or otherwise attempt to extract the source code of the Services or any part thereof, unless this is expressly permitted or required by law, or unless a signed Order or Development License specifically grants Customer that right.
A standard production-use license permits Customer to configure, build, deploy, back up, and operate delivered software, but does not permit source modification or derivative development. Customer may purchase a separate Development License or engage EveryArrow to perform modifications under an Order. No Development License is required for modifications performed by EveryArrow.
EveryArrow may engage subcontractors and service providers to deliver the Services while maintaining responsibility for service delivery.
EveryArrow may from time to time engage third parties to assist it in providing the Services.
EveryArrow's use of subcontractors will not affect EveryArrow's obligations or Customer's rights under the Agreement.
This section applies when Customer is a U.S. Government entity or when the Services are used in connection with U.S. Government contracts.
This clause applies only if Customer is an agency of the U.S. Government, or Customer is acting on behalf of the U.S. Government under a U.S. Government contract.
Customer acknowledges and agrees that the Services are "commercial items" as defined in 48 C.F.R. 2.101, consisting of "commercial computer software" and "commercial computer software documentation" as such terms are used in 48 C.F.R. 12.212.
Consistent with 48 C.F.R. 12.212 and 48 C.F.R. 227.7202-1 through 227.7202-4, all U.S. Government end users acquire the Services with only those rights set forth in the Agreement.
EveryArrow may assign these Terms, but you may not assign your rights without our prior written consent.
Neither party may assign this Agreement, in whole or part, without the other party's prior written consent, except either party may assign without consent to an Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets, provided the assignee is not a direct competitor of the non-assigning party and assumes all obligations. Any prohibited assignment is void. This Agreement binds and benefits permitted successors and assigns.
Neither party will be liable for delays or failures due to circumstances beyond their reasonable control.
Neither party is liable for delay or failure to perform due to events beyond its reasonable control (e.g., acts of God, labor disputes, Internet/utility failures, denial-of-service attacks, war, terrorism, government action) excluding payment obligations. The impacted party will use commercially reasonable efforts to mitigate and resume performance.
This section governs how official notices and communications must be delivered between parties.
Notices must be in writing and deemed given when: (a) delivered by hand; (b) received by nationally recognized overnight courier; or (c) sent by email to the addresses set in the Order (legal notices to the legal contact). EveryArrow may also provide operational notices (e.g., maintenance, updates) via in-product, status page, or admin email.
This section establishes the hierarchy of documents in case of conflicts.
In case of conflict: (1) the Order (including plan-specific terms), then (2) this Agreement, then (3) the DPA and any applicable Riders for their subject matter, then (4) Documentation/policies. Handwritten or typed terms on POs or vendor portals that conflict with the foregoing have no effect unless expressly agreed in writing by EveryArrow.
This section contains final provisions regarding the agreement, amendments, and legal enforceability.
This Agreement (including Orders, Exhibits, and incorporated policies) is the entire agreement and supersedes all prior and contemporaneous understandings on its subject.
Any amendment must be in writing and executed by both parties, except that EveryArrow may update policies per §13.
Failure to enforce a provision is not a waiver. A waiver must be in writing and signed, and applies only to the specific instance.
If any provision is unenforceable, it will be modified to the minimum extent necessary to be enforceable, and the remainder will remain in effect.
The parties are independent contractors. There are no third-party beneficiaries to this Agreement.
This Agreement may be executed in counterparts and via electronic signatures, each deemed an original.
This DPA forms part of the Agreement between Customerand EveryArrow, Inc. ("EveryArrow") and applies where EveryArrow ProcessesPersonal Data on Customer's behalf. Capitalized terms not defined here have the meanings in the Agreement.
1.1 Roles.
For Personal Data under the Agreement, Customer is Controller/Business and EveryArrow is Processor/Service Provider.
1.2 Scope.
EveryArrow will Process Personal Data solely to provide, maintain, secure, and support the Services as described in the Agreement and this DPA ("Permitted Purpose").
1.3 Instructions.
Customer's documented instructions are in the Agreement, this DPA, and the Order(s). Where permitted by law, EveryArrow will notify Customer if, in its opinion, an instruction violates Applicable Data Protection Law.
2.1 Confidentiality.
EveryArrow ensures persons authorized to Process Personal Data are bound by confidentiality obligations.
2.2 Need-to-know.
Access is limited to personnel with a legitimate need to fulfill the Permitted Purpose.
3.1 TOMs.
EveryArrow implements and maintains appropriate technical and organizational measures ("TOMs") designed to protect Personal Data, as described in Clause 5 (Security) of the Agreement.
3.2 Evolution.
TOMs may evolve; protections will not be materially diminished during an active Order Term.
4.1 Notice.
Upon confirming a Security Incident involving Customer Personal Data, EveryArrow will notify Customer without undue delay and share available information to support Customer's legal obligations and mitigation.
4.2 Mitigation.
EveryArrow will take reasonable steps to contain, investigate, and remediate the Security Incident.
5.1 Data Subject Requests.
Taking into account the nature of Processing, EveryArrow will provide reasonable assistance (e.g., via tools/APIs) for Customer to fulfill data subject requests.
5.2 DPIAs & Consultations.
Upon written request, EveryArrow will provide available security information (e.g., summaries of TOMs) reasonably required for Customer's DPIAs or supervisory consultations, without disclosing confidential information or trade secrets.
6.1 Reports.
Upon request, EveryArrow will make available summary security information sufficient to demonstrate compliance with this DPA (e.g., security whitepaper or responses to a reasonable questionnaire).
6.2 Targeted Review.
If required by law/regulator and reports are insufficient, Customer may conduct a targeted on-site/remote review once every 12 months, on 30 days' notice, during business hours, minimizing disruption, and subject to confidentiality. Findings will be shared with EveryArrow.
6.3 Limits.
Audits/requests must not require disclosure of other customers' data, source code, or sensitive vendor/pricing terms.
7.1 Current Subprocessor.
As of the Effective Date, EveryArrow engages:
• Amazon Web Services, Inc. (and Affiliates) - cloud infrastructure and related services (e.g., EC2/EKS, S3, RDS, CloudWatch, KMS, SES) supporting delivery of the Services.
7.2 Changes.
EveryArrow will maintain a Subprocessor List (e.g., at /legal/subprocessors) and provide advance notice of material changes (email to admin contacts or via that page). Customer may object on reasonable data-protection grounds; if unresolved, Customer may suspend the affected Processing or terminate the affected Service for a pro-rata refund of prepaid, unused fees for that portion.
7.3 Flow-down.
EveryArrow will impose no-less-protective data protection obligations on subprocessors and remains responsible for their performance.
8.1 Transfer Tools.
Where required (EEA/UK/CH), the parties incorporate by reference: (i) the EU Standard Contractual Clauses (SCCs) (2021/914, Module 2 C→P), (ii) the UK International Data Transfer Addendum, and (iii) the Swiss Addendum (as applicable).
8.2 Annex Mapping.
The SCC annexes are populated by Appendix/Annex I–II of this DPA; Customer is the data exporter and EveryArrow the data importer. For the SCCs, governing law/forum is Ireland (or as required by the SCC text).
8.3 Precedence.
If this DPA conflicts with the SCCs/UK/Swiss addenda, the transfer instruments control.
9.1 During Term.
Customer may use provided tools/APIs to export Personal Data.
9.2 End of Term.
Upon termination or written request, EveryArrow will delete (and, at Customer's written request, return) Personal Data within 30 days, unless retention is required by law; then delete promptly after. Deletion is by secure erasure of active systems and scheduled purge of backups per standard cycles.
10.1 Service Provider.
EveryArrow acts as a Service Provider/Processor and will not: (a) sell or share Personal Information; (b) combine Personal Information with other data except as allowed for service-provider purposes; or (c) retain/use/disclose Personal Information except to provide the Services or as permitted by law.
10.2 Requests.
EveryArrow will promptly notify Customer of any consumer request it receives and will not respond directly except to refer the request to Customer, unless required by law.
11.1 Notice & Minimization.
If legally compelled to disclose Personal Data, EveryArrow will (to the extent lawful) notify Customer and limit disclosure to the minimum required.
12.1 Liability.
Each party's liability under this DPA is subject to the limitations in the Agreement.
12.2 Precedence.
For data protection, this DPA controls over the Agreement; for international transfers, the SCCs/UK/Swiss instruments control over this DPA.
"Applicable Data Protection Law" means laws governing Personal Data applicable to the Processing (e.g., GDPR/UK GDPR, CCPA/CPRA). "Personal Data," "Process," etc., have the meanings in such laws. Other capitalized terms follow the Agreement.
This Annex provides the details of data processing activities as required by GDPR Article 28 and Standard Contractual Clauses.
The subject matter of the processing is the provision of EveryArrow's Servicesas described in the Agreement, including data integration, analysis, transformation, and related cloud-based services.
Processing will occur for the duration of the Agreement and any applicable data retention period as specified in the Agreement or as required by law, but not exceeding seven (7) years after Agreement termination.
Nature: Processing of Personal Data as a processor on behalf of Customer
Purpose:
Personal Data may relate to the following categories of data subjects:
The Services may process the following categories of Personal Data (as determined and submitted by Customer):
Generally: EveryArrow does not intend to process Special Categories of Personal Data (sensitive data under GDPR Article 9) unless specifically agreed in writing.
If processed: Customer is responsible for ensuring appropriate legal basis and additional safeguards for any Special Categories of Personal Data.
EveryArrow may perform the following processing operations:
This Annex describes the technical and organizational security measures implemented by EveryArrow to protect Personal Data.
Encryption:
Pseudonymisation: Available upon request for applicable use cases
Access Controls:
Personnel Security:
Data Integrity:
System Integrity:
High Availability:
Backup and Recovery:
Security Testing:
Continuous Monitoring:
Governance:
Vendor Management:
EveryArrow leverages Amazon Web Services (AWS) data centers which provide:
EveryArrow maintains relevant security certifications and regularly updates these technical and organizational measures to address evolving threats and regulatory requirements. Current certification status is available at everyarrow.io/security.
This Annex lists the subprocessors engaged by EveryArrow that may process Personal Data on behalf of Customer.
| Subprocessor | Purpose | Location | Data Categories |
|---|---|---|---|
| Amazon Web Services, Inc. and AWS Affiliates | Cloud infrastructure, hosting, storage, compute, networking, database services, security services | Primary: United States Global AWS regions as configured | All Customer Data processed through the Services |
| Subprocessor | Purpose | Location | Data Categories |
|---|---|---|---|
| Support Vendors (as applicable) | Technical support, customer success, professional services | United States, European Union | Limited to support case data, configuration information |
| Security Providers (as applicable) | Security monitoring, threat detection, incident response | United States | Security logs, metadata, threat indicators |
Third-Party Integrations: When Customer configures integrations with third-party services (e.g., Salesforce, HubSpot, database systems), those services may act as subprocessors for the specific data Customer chooses to process through such integrations.
Customer Control: Customer maintains full control over which integration subprocessors are engaged and what data is processed through each integration.
Dynamic List: The integrations and related subprocessors used for a Customer are identified in the accepted Order and its supporting documentation.
All subprocessors are required to:
Addition of Subprocessors: EveryArrow may add new subprocessors with appropriate safeguards in place. Material changes will be communicated through service notifications.
Customer Objection: If Customer has reasonable grounds to object to a new subprocessor based on data protection concerns, Customer may raise such concerns, and EveryArrow will work in good faith to address them.
Updated List: The current subprocessor list is maintained ateveryarrow.io/subprocessors and updated as changes occur.
For subprocessors processing Personal Data outside the European Economic Area:
This list reflects subprocessors as of the Agreement effective date. For the most current information on subprocessors and data processing locations, visit everyarrow.io/subprocessors or contactprivacy@everyarrow.io.
By using our Services, you confirm that:
If you do not agree with any part of these Terms, you must immediately discontinue use of our Services.
If you have any questions about these Terms of Service or need clarification on any provisions, please don't hesitate to contact our legal team. We're here to help ensure you understand your rights and obligations.
Our legal team is available to answer questions about this document and help clarify any provisions that may affect your use of our services.
EveryArrow, Inc. • Legal Department •legal@everyarrow.io