Effective Date: May 6, 2026. Last Updated: May 6, 2026.
This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service and/or Master Services Agreement (the "Agreement") between ArGen ("Processor," "we," "us," or "our") and the customer entity identified in the applicable ordering document ("Controller" or "you"). This DPA governs the processing of personal data by ArGen on behalf of the Controller in connection with the provision of the ArGen AI performance evaluation platform and related services.
Unless otherwise defined in this DPA, capitalized terms shall have the meanings given to them in the Agreement. The following terms shall have the meanings set out below:
This DPA applies exclusively to the processing of Personal Data for which the Controller is a Data Controller and ArGen is a Data Processor. The Controller retains full control over the Personal Data and remains responsible for determining the purposes and means of processing. The Controller warrants that it has obtained all necessary consents, provided all required notices, and has the lawful authority to disclose the Personal Data to ArGen for the processing activities described in the Agreement.
ArGen shall process Personal Data solely on behalf of the Controller and in accordance with the documented instructions of the Controller, except where required otherwise by applicable law. The subject matter, nature, duration, purpose, and categories of Personal Data processed under this DPA are described in Schedule 1 (Details of Processing Activities), which is incorporated herein by reference. ArGen shall immediately inform the Controller if, in its opinion, an instruction violates applicable Data Protection Legislation.
ArGen shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures shall reflect the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. Our current security measures include:
The Controller provides general authorization for ArGen to engage Sub-processors to assist in providing the Services. ArGen maintains an up-to-date list of authorized Sub-processors, which currently includes:
ArGen shall notify the Controller at least 30 days before authorizing any new Sub-processor by updating the list above and sending a notification to the Controller's primary administrative email address. The Controller may object to the engagement of a new Sub-processor on reasonable grounds relating to data protection. If an objection is not resolved within 30 days, the Controller may terminate the applicable portion of the Services without penalty.
ArGen shall enter into a written agreement with each Sub-processor containing data protection obligations that are no less protective than those set forth in this DPA. ArGen shall remain fully liable to the Controller for the acts and omissions of its Sub-processors as if they were its own.
ArGen shall maintain a data breach response plan and shall notify the Controller without undue delay, and in any event no later than 48 hours after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by ArGen on behalf of the Controller (a "Data Breach"). The notification shall include, to the extent available:
ArGen shall cooperate fully with the Controller in investigating the Data Breach and shall not make any public communication regarding the Data Breach without the Controller's prior written consent, except where required by law.
ArGen shall provide reasonable assistance to the Controller in enabling the Controller to respond to requests from Data Subjects seeking to exercise their rights under Data Protection Legislation (including rights of access, rectification, erasure, restriction, portability, and objection). If a Data Subject makes a request directly to ArGen, ArGen shall promptly forward such request to the Controller within 5 business days and shall not respond to the Data Subject on the Controller's behalf without prior written authorization.
To facilitate the Controller's compliance with its obligations, ArGen shall provide the Controller with self-service tools within the ArGen platform through which the Controller can access, correct, export, or delete Personal Data of its users. Where the requested action cannot be performed through self-service tools, ArGen shall respond to the Controller's written instruction within 30 calendar days.
Upon termination or expiry of the Agreement, ArGen shall, at the Controller's option, either delete or return all Personal Data (including all copies and backups thereof) processed on behalf of the Controller, unless applicable law requires ArGen to retain some or all of the Personal Data. If return or deletion is not feasible due to technical limitations, ArGen shall implement measures to block further processing of the Personal Data and ensure its confidentiality.
ArGen shall certify in writing to the Controller that it has fully complied with its deletion or return obligations within 90 days of the termination of the Agreement. This DPA shall survive termination of the Agreement for so long as ArGen continues to process or retain any Personal Data on behalf of the Controller.
Upon 30 days' prior written notice and no more than once per calendar year (unless a Data Breach has occurred), the Controller may audit ArGen's compliance with this DPA by:
Any on-site audit shall be conducted during normal business hours, subject to reasonable security protocols, and at the Controller's sole expense. ArGen shall cooperate with such audit and provide access to relevant records and personnel as reasonably required. If the audit reveals a non-compliance by ArGen, ArGen shall remedy such non-compliance at its own cost within 30 calendar days of written notice.
This DPA shall be governed by and construed in accordance with the laws of India, without regard to its conflict of laws principles. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions set forth in the Agreement. To the extent that this DPA incorporates the Standard Contractual Clauses (SCCs), the SCCs shall prevail in the event of any conflict with other terms of this DPA.
Subject Matter: AI-based evaluation and scoring of employee workflows using AI tools. Processing includes collection of user prompts, AI responses, evaluation scores, analytics, and user profile data.
Duration: The duration of the Agreement plus 90 days post-termination for orderly deletion.
Nature and Purpose: Provision of the ArGen AI evaluation platform, including scoring, reporting, benchmarking, and coaching services to assess enterprise AI adoption and effectiveness.
Categories of Data Subjects: Authorized users (employees, contractors, and agents) of the Controller who participate in ArGen evaluations.
Categories of Personal Data: Name, email address, job title, department, company name, evaluation responses and scores, AI interaction logs, and account activity metadata.
Special Categories of Data (Sensitive Data): The Controller shall not disclose or transfer any special categories of personal data (health information, biometric data, political opinions, etc.) to ArGen for processing. ArGen's platform is not designed to process sensitive data categories.