Skip to content

R4AI LLC · R4ACO

Data Processing Addendum

Additional data-processing terms for ACO workspace operators.

Effective September 26, 2026 · Version 2026-09-26.1

1. Scope and documented instructions

This Data Processing Addendum is incorporated into the R4ACO Terms for Workspace Operators to the extent R4AI LLC processes personal data on their behalf. The Operator is the controller and R4AI the processor for provider-directed workspace operations; each acts independently for processing whose purposes it independently determines. Applicable law and actual activities control the classification.

Processing consists of hosting, organizing, validating, storing, retrieving, exporting and transmitting customer/staff contact information, addresses, submissions, retailer credentials and enabled checkout data, order/shipment information, fee records and operational communications. Data subjects are the Operator’s customers, staff and authorized users. Processing continues during the service relationship and applicable deletion/retention period.

Instructions are the contract and lawful documented configuration or support instructions. R4AI will process only as instructed unless law requires otherwise, inform the Operator of a required departure where permitted and flag instructions reasonably believed unlawful. The Operator must have authority and an appropriate legal basis to supply the data and instructions.

2. Confidentiality, security and assistance

R4AI will restrict access to authorized personnel under appropriate confidentiality duties, maintain reasonable technical and organizational safeguards appropriate to the data and processing risks, and assist the Operator, taking account of available information and processing nature, with rights requests, security obligations, impact assessments and required consultations.

R4AI will notify the Operator without undue delay after becoming aware of a personal-data breach affecting its processing and provide reasonably available details and updates for required notifications and mitigation. Notice does not require completion of an investigation or an admission of fault. Each party retains its own legal notice duties.

The Operator must secure accounts, connected services and downloaded files, restrict access, provide accurate notices and promptly inform R4AI of incidents or rights requests requiring platform action. Neither this agreement nor encryption changes the prohibition on post-authorization CVV retention.

3. Subprocessors and transfers

The Operator generally authorizes the infrastructure subprocessors described in the Privacy Policy, currently Vercel, Neon, AWS and Resend, and configured delivery services such as Discord and Apple/Expo to the extent they process on R4AI’s behalf. Stripe and services directly selected by the Operator may act under separate relationships; their roles depend on the relevant activity.

R4AI will impose applicable data-protection obligations on subprocessors and remains responsible for their performance of delegated processor duties as required by law. R4AI will provide notice of a material subprocessor change through the service or the registered contact with a reasonable opportunity to object on data-protection grounds before processing by the new subprocessor. The parties will seek a reasonable resolution; if none is available, the affected service may be ended with a refund of prepaid unused fees.

Restricted international transfers require an appropriate lawful mechanism before processing. This addendum is not a substitute for EU standard contractual clauses, a UK addendum or another mandatory transfer instrument. Contact ben@r4ai.net before submitting data that requires additional safeguards.

4. Return, deletion and accountability

At the Operator’s request or the end of processing, R4AI will provide reasonable assistance returning permitted records and deleting or anonymizing personal data unless lawful retention is required. Retained data remains protected and limited to that purpose. Backup deletion follows the applicable cycle with controls to prevent deleted information returning to active processing.

R4AI will make available information reasonably necessary to demonstrate compliance and allow and cooperate with reasonable assessments, including an independent audit where required by law, subject to confidentiality, proportionate notice and protection of other customers and system security. Contractual limitations may not prevent a legally required audit or regulator access.

This addendum prevails over conflicting general terms for the processor obligations it covers. The general liability provisions apply only to the extent lawful and do not restrict data subjects’ or regulators’ mandatory rights. Contact R4AI LLC at ben@r4ai.net for processing, audit or subprocessor requests.

Contact ben@r4ai.net.