Data Processing Agreement (DPA)
Effective Date: August 13, 2026
Version: 1.0
Operator: ARYX LLC (aryx.pro). The contracting party named on an Order Form controls for that transaction.
1. Introduction and Structure
This Data Processing Agreement ("DPA") is entered into by and between ARYX LLC ("ARYX", "Processor") and the customer entity identified in the applicable order form or master services agreement (the "Customer", "Tenant", or "Controller"). This DPA forms part of, and is governed by, the master subscription or services agreement between the parties (the "Agreement"). Where the Agreement and this DPA conflict on the subject matter of Processing of Personal Data, this DPA controls.
This DPA governs ARYX's Processing of Personal Data on behalf of Customer in connection with the ARYX platform and its constituent applications — EnrollFlow (member enrollment; handles PHI), ARYX CRM (lead and member relationship management), ARYX Accounts (identity, SSO, org provisioning, and the subscription/billing engine), and supporting applications including AdvisorIQ and the IT Ticketing/Support tooling (collectively, the "Services").
This DPA incorporates three Annexes: Annex I (parties and details of Processing), Annex II (technical and organizational security measures), and Annex III (Subprocessors).
2. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Law.
- "Applicable Data Protection Law" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and, where the parties so agree in writing, the Health Insurance Portability and Accountability Act ("HIPAA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Special Category Data", and "Supervisory Authority" have the meanings given in the GDPR. For CCPA purposes, "Business" corresponds to Controller, "Service Provider" corresponds to Processor, and "Personal Information" is included within "Personal Data".
- "Member Data" means Personal Data relating to Customer's members, enrollees, applicants, and their dependents that is Processed through the Services, including PHI Processed in EnrollFlow.
- "PHI" means Protected Health Information as defined under HIPAA, to the extent Processed through EnrollFlow or otherwise.
- "Authorized User" means Customer's staff, agents, brokers, or administrators authorized to access the Services under Customer's tenancy.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Subprocessor" means any third party engaged by ARYX to Process Personal Data on ARYX's behalf in connection with the Services.
- "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission (Decision 2021/914) and, for the UK, the ICO's International Data Transfer Addendum.
3. Roles of the Parties
With respect to Member Data and other Personal Data Processed through the Services, Customer is the Controller (and, under CCPA, the Business) and ARYX is the Processor (and, under CCPA, the Service Provider). ARYX Processes such Personal Data solely on Customer's behalf and under Customer's documented instructions.
ARYX acts as an independent Controller only with respect to limited data it Processes for its own legitimate business purposes — for example, Authorized User account/credential administration in ARYX Accounts, billing records for ARYX's own invoicing of Customer, service telemetry, and security logging. Such independent-Controller Processing is governed by ARYX's own privacy notice and is outside the scope of the Controller-Processor relationship established by this DPA. Where financial-state and transaction records are concerned, roles are further described in ARYX's refund and settlement standards.
The parties acknowledge that ARYX is not a bank, card network, payment processor, money transmitter, or merchant of record; the Tenant holds and controls the Authorize.Net merchant account, and settlement funds flow Processor → Tenant and never through ARYX.
4. Scope, Nature, and Purpose of Processing
The subject matter, nature, purpose, and duration of Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I. In summary, ARYX Processes Personal Data to provide, secure, maintain, and support the Services — including member enrollment workflows, CRM relationship management, identity and SSO, and orchestration of subscription/billing activity. ARYX does not determine the purposes or means of Processing Member Data beyond providing the Services as instructed.
5. Categories of Data Subjects and Personal Data
Data Subjects include: Customer's members, enrollees, applicants, and their dependents; Customer's Authorized Users, staff, brokers, and agents; and other individuals whose data Customer submits to the Services.
Categories of Personal Data include: identifiers and contact data; member PII (name, date of birth, government identifiers where submitted); Special Category / health data (PHI) Processed in EnrollFlow; financial and transaction data associated with enrollment and billing; and Authorized User credentials and access logs.
Payment data handling (material to scope): Card primary account numbers ("PAN") and CVV are tokenized in-browser via Accept.js and transmitted as opaqueData; PAN and CVV never reach ARYX servers or database (PCI-DSS SAQ-A posture). ARYX Processes only the resulting payment tokens and stored payment-profile references via Authorize.Net CIM and the schedule-driven recurring charge engine. Full details are in Annex I.
6. Processor Obligations
ARYX shall:
- Process only on documented instructions. ARYX Processes Personal Data only on Customer's documented instructions (including with respect to international transfers), as set out in this DPA, the Agreement, and Customer's configuration and use of the Services, unless required to do otherwise by law — in which case ARYX shall inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest. If ARYX believes an instruction infringes Applicable Data Protection Law, it shall inform Customer without undue delay.
- Confidentiality. ARYX shall ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and Process Personal Data only as necessary to perform their duties.
- Security. ARYX shall implement and maintain the technical and organizational measures described in Annex II and in ARYX's information security program, appropriate to the risk, including multi-tenant isolation enforced in Postgres via Row-Level Security (RLS), org-scoped so that one Tenant cannot access another Tenant's data.
- Data minimization in support. ARYX personnel access Member Data only as needed to deliver, secure, or support the Services, subject to least-privilege controls and logging.
7. Subprocessing
Customer provides general written authorization for ARYX to engage Subprocessors to Process Personal Data. ARYX's current Subprocessors are listed in Annex III and maintained in the register referenced at the Subprocessor Register. As of the Effective Date these include, without limitation: Supabase (database, authentication, storage), Vercel (application hosting), Authorize.Net (payment processing), Resend (transactional email), and GoTo (SMS/voice).
ARYX shall: (a) impose data protection obligations on each Subprocessor that are no less protective than those in this DPA (flow-down), by written contract; (b) remain fully liable to Customer for each Subprocessor's performance of its obligations; and (c) give Customer at least 30 days' prior notice of any intended addition or replacement of a Subprocessor (via email and/or a subscribable change page), during which Customer may object on reasonable, documented data-protection grounds. If the parties cannot resolve a reasonable objection, Customer may, as its sole remedy, terminate the affected portion of the Services under the Agreement.
8. Assistance with Data Subject Rights
Taking into account the nature of the Processing, ARYX shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligations to respond to requests from Data Subjects exercising their rights (including access, rectification, erasure, restriction, portability, and objection) under Applicable Data Protection Law. Where a Data Subject submits such a request directly to ARYX, ARYX shall, unless legally prohibited, promptly forward it to Customer and shall not respond substantively except on Customer's documented instructions. Customer may exercise many of these rights directly through Service self-service and administrative functions.
9. Personal Data Breach Notification
ARYX shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data, and in any event within 72 hours of ARYX's confirmation of such a Breach, in accordance with ARYX's incident response commitments. Such notification shall describe, to the extent known: the nature of the Breach and categories and approximate number of affected Data Subjects and records; likely consequences; and measures taken or proposed to address the Breach and mitigate its effects. ARYX shall provide reasonable cooperation and information to assist Customer in meeting its own notification obligations to Supervisory Authorities and Data Subjects. Where HIPAA applies, breach obligations under the applicable Business Associate Agreement (see the HIPAA Business Associate Agreement) also apply and, where more stringent, control.
10. Data Protection Impact Assessments
Taking into account the nature of Processing and information available to ARYX, ARYX shall provide reasonable assistance to Customer with data protection impact assessments ("DPIA") and prior consultations with Supervisory Authorities that Customer reasonably considers required under Applicable Data Protection Law, in respect of Customer's use of the Services.
11. Deletion and Return on Termination
Upon termination or expiry of the Agreement, and at Customer's election, ARYX shall delete or return all Personal Data Processed on Customer's behalf and delete existing copies, save to the extent retention is required by law or permitted for the limited independent-Controller purposes described in Section 3 (e.g., billing records, security logs). Deletion and return timelines, formats, and retention exceptions are governed by ARYX's data ownership and retention terms. Backup copies are purged in accordance with ARYX's backup rotation cycle described therein. Note that deletion of transaction/financial records is subject to the financial-state and recordkeeping constraints in ARYX's refund and settlement standards.
12. Audits and Compliance
ARYX shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer. To satisfy audit requests, ARYX may first make available relevant certifications, third-party attestations (e.g., SOC 2 or equivalent attestations where available when available), and the security documentation referenced in Annex II. On-site or direct audits shall be limited to once per 12-month period (unless required more frequently by a Supervisory Authority or following a Personal Data Breach), on reasonable prior notice of 30 days, during business hours, subject to confidentiality, and conducted so as not to compromise the security or multi-tenant integrity of other Tenants. Customer bears its own audit costs; ARYX may charge reasonable fees for extraordinary audit support.
13. International Transfers
ARYX shall not transfer Personal Data outside the European Economic Area, the United Kingdom, or Switzerland except where an appropriate transfer mechanism under Applicable Data Protection Law is in place. Where such transfers occur (including transfers to or by Subprocessors), the parties agree that the Standard Contractual Clauses are incorporated by reference and completed as follows: Customer is "data exporter", ARYX is "data importer"; Module Two (Controller-to-Processor) applies (and Module Three (Processor-to-Processor) applies as between ARYX and its Subprocessors); the docking clause is included; and the annexes to the SCCs are populated by Annexes I–III of this DPA. For UK transfers, the ICO International Data Transfer Addendum applies. Governing-law and forum options in the SCCs are set to the laws of the United States / the courts designated on the applicable Order Form to the extent permitted. ARYX shall conduct and, on request, share a summary of applicable transfer impact assessments.
14. CCPA Service-Provider Terms
To the extent ARYX Processes Personal Information subject to the CCPA on Customer's behalf, ARYX acts as a Service Provider. ARYX shall not: (a) sell or share Personal Information (as those terms are defined under CCPA); (b) retain, use, or disclose Personal Information for any purpose other than the specific business purpose of performing the Services, or as otherwise permitted by CCPA; (c) retain, use, or disclose Personal Information outside the direct business relationship between the parties; or (d) combine Personal Information with data from other sources except as permitted by CCPA. ARYX certifies that it understands and will comply with these restrictions. ARYX shall assist Customer with consumer requests to know, delete, correct, and opt out to the extent applicable.
15. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Aggregation of liability across the Agreement, this DPA, and any applicable Business Associate Agreement shall be as stated in the Agreement's limitation-of-liability provisions. confirm interaction of the liability cap with statutory data-protection damages, which may be non-excludable.
16. Duration and Order of Precedence
This DPA is effective for as long as ARYX Processes Personal Data on Customer's behalf under the Agreement. In the event of conflict, the order of precedence is: (1) any executed Business Associate Agreement (as to PHI/HIPAA matters), (2) this DPA (as to Processing of Personal Data), (3) the Agreement. All other terms of the Agreement remain in full force.
Annex I — Parties and Details of Processing
Data Exporter / Controller: Customer, as identified in the Agreement. Contact: Customer's privacy contact per order form. Data Importer / Processor: ARYX, the notice address designated on the applicable Order Form. Contact: legal@aryx.pro.
Subject matter of Processing: Provision of the ARYX Services (EnrollFlow, ARYX CRM, ARYX Accounts, AdvisorIQ, IT Ticketing/Support).
Nature and purpose of Processing: Hosting, storage, transmission, collection, organization, retrieval, and deletion of Personal Data to deliver member enrollment, CRM, identity/SSO, subscription/billing orchestration, and support.
Duration: For the term of the Agreement plus any legally required or configured retention period (see ARYX's data ownership and retention terms).
Categories of Data Subjects: Members, enrollees, applicants, and dependents; Authorized Users, staff, brokers, and agents.
Categories of Personal Data: Identifiers and contact data; member PII; financial/transaction data and payment-profile tokens; Authorized User credentials and access/audit logs.
Special Category / health data: PHI Processed in EnrollFlow (subject to HIPAA where applicable). Frequency: ongoing, per Customer's use.
Payment data note: PAN and CVV are tokenized client-side via Accept.js (opaqueData) and are not received or stored by ARYX; ARYX Processes only Authorize.Net CIM payment-profile references and the recurring charge schedule.
Competent Supervisory Authority (for SCC purposes): to be determined by Customer's EU/UK establishment or representative.
Annex II — Technical and Organizational Security Measures
ARYX maintains measures appropriate to the risk, as further detailed in ARYX's information security program, including:
- Multi-tenant isolation: Postgres Row-Level Security (RLS), org-scoped, on Supabase, preventing cross-Tenant data access.
- Encryption: TLS in transit; encryption at rest for database and storage (Supabase/Vercel platform controls). Payment card data excluded from ARYX systems via Accept.js tokenization.
- Access control: Least-privilege, role-based access; authentication and SSO via ARYX Accounts; credential Processing minimized and protected.
- Webhook and integrity controls: Inbound Authorize.Net webhooks verified via Processor-specified signature verification (to be enforced); see ARYX's refund and settlement standards for financial-state integrity requirements.
- Logging and monitoring: Security and audit logging; monitoring for unauthorized access.
- Resilience: Backups and recovery via platform providers; documented backup rotation and deletion cycle.
- Personnel: Confidentiality obligations; security awareness; onboarding/offboarding controls.
- Subprocessor assurance: Contractual flow-down and reliance on providers' certifications.
Specific configuration values (backup retention, log retention, MFA enforcement scope, encryption key management) are documented in Annex II and ARYX's security program.
Annex III — Subprocessors
The following Subprocessors are authorized as of the Effective Date. The authoritative, maintained list is at the Subprocessor Register.
| Subprocessor | Service Provided | Data Categories | Location |
|---|---|---|---|
| Supabase | Database, Auth, Storage | All Personal Data incl. PHI | United States |
| Vercel | Application hosting | Personal Data in transit/runtime | United States |
| Authorize.Net | Payment processing (CIM) | Payment tokens, transaction data | United States |
| Resend | Transactional email | Contact identifiers, email content | United States |
| GoTo | SMS / voice | Phone numbers, message/call metadata | United States |
Questions about this document? Contact legal@aryx.pro. Related: all legal documents · Privacy Policy · Terms of Service.