Data processing agreement
Where data protection law treats you as a controller and us as a processor, this agreement applies to the personal data in your register. The terms below are the template; a signed copy is available on request.
Last updated 23 Sep 2026
1. Parties and roles
The customer organization (“Customer”) is the controller of personal data it enters into Archecura. Perizer LLC (“Processor”) processes that data only to provide the service under the terms of service and the Customer’s documented instructions, which are the terms, the settings the Customer configures, and any written instruction that is consistent with them.
2. Subject matter and duration
Processing of account data and register data (entities, brands, marks, documents, specimens, licenses, acknowledgements, and public USPTO records tied to them) for the duration of the Customer’s use of the service and the retention periods in the privacy policy.
3. Data subjects and categories
- Customer’s users and invited counsel: name, email, role, activity in the audit log.
- Individuals named in USPTO records the Customer imports: owner names, correspondence details, attorney names, as published by the USPTO.
- Individuals appearing in documents the Customer uploads.
The service is not designed for special categories of personal data and the Customer agrees not to enter them.
4. Processor obligations
- Process personal data only on the Customer’s documented instructions, unless required by law, in which case we inform the Customer unless the law prevents it.
- Ensure that people authorized to process the data are bound by confidentiality.
- Implement the technical and organizational measures described on the security page, and keep them current.
- Assist the Customer with data subject requests, using the export and deletion tools in the service and by email where needed.
- Notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Customer’s data.
- Delete or return all personal data at the end of the service, subject to the retention periods the law requires (invoices, seven years).
- Make available the information needed to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.
5. Subprocessors
The Customer authorizes the subprocessors listed on the subprocessors page. We give 30 days’ notice by email before adding one; the Customer may object, and if the objection cannot be resolved, may terminate and export its data. We remain responsible for our subprocessors.
6. International transfers
Data is processed in the United States. Where the Customer is in the European Economic Area, the United Kingdom, or Switzerland, the EU standard contractual clauses (module two, controller to processor), the UK addendum, and the Swiss amendments as applicable are incorporated by reference, with the Customer as data exporter and Perizer LLC as data importer.
7. Customer obligations
The Customer is responsible for having a lawful basis to process the personal data it enters, for the accuracy of its instructions, and for the people it invites to its organization.
8. Liability and precedence
The limitation of liability in the terms of service applies to this agreement. If this agreement conflicts with the terms, this agreement prevails for the processing of personal data.