Data Protection and Processing
Last updated: 24 August 2026
Roles
For website accounts and business inquiries, Arad generally acts as controller. For customer data processed solely to provide a contracted service, the contract may define Arad as processor and the customer as controller.
Instructions and purpose limitation
Processor activities are limited to documented instructions, service delivery, security, support and legal duties. Product-specific scope, categories, duration and purpose belong in the applicable agreement or data processing addendum.
Confidentiality and access
Personnel access is need-based and subject to confidentiality and security controls. Privileged actions should be attributable and reviewed.
Subprocessors and transfers
Hosting, email, monitoring or support providers may be used where necessary. Contractual notice, objection and transfer mechanisms apply when included in the customer agreement or required by law.
Assistance
Within the agreed scope, Arad supports reasonable requests concerning security, incidents, data-subject requests, assessments, return and deletion.
Deletion and return
At service end, customer data is returned or deleted according to contract, backup cycles and mandatory retention, unless law requires continued storage.
Contract priority
This page is an overview, not a data processing agreement. A signed contract and DPA control where their terms differ.
