Skip to content

Ramus / Legal

Data Processing Agreement

Our responsibilities when we process personal data on your behalf.

Effective upon valid incorporation or execution
On this page

This Data Processing Agreement ("DPA") supplements the Ramus Terms of Service or other agreement governing the Services between On A Lark LLC ("Ramus") and the customer accepting that agreement ("Customer"). It applies to personal data processed by Ramus on Customer's behalf ("Customer Personal Data"). It takes effect with the agreement that incorporates it, or upon separate execution. Capitalized terms not defined here have the meanings in that agreement (the "Agreement").

1. Definitions and roles

"Data Protection Law" means privacy and data-protection laws applicable to the processing, including, where applicable, the EU General Data Protection Regulation ("EU GDPR"), UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection ("FADP"), and California Consumer Privacy Act as amended ("CCPA"). Controller, processor, personal data, processing, data subject, and personal data breach have their meanings under applicable Data Protection Law. A "Subprocessor" is a provider Ramus engages to process Customer Personal Data on Customer's behalf.

Customer is a controller or a processor acting with its controller's authority; Ramus acts as processor or subprocessor, respectively. Processing Ramus independently determines for account administration or its own legal obligations is addressed by the Privacy Policy and applicable law.

2. Instructions and permitted processing

Each party will comply with its applicable legal duties. Ramus will process Customer Personal Data only on documented instructions contained in the Agreement, this DPA, Customer's use of supported features, and other agreed written instructions. These authorize only the requested Services and troubleshooting, together with required return, deletion, or legal preservation. The restrictions on sale and reuse of Customer Content in section 3 of the Ramus Terms of Service are incorporated into this DPA.

If law requires other processing, Ramus will notify Customer before that processing unless prohibited by law. Ramus will promptly inform Customer if it considers an instruction unlawful and may suspend the affected processing pending clarification. Customer is responsible for lawful instructions, required notices and permissions, and authority to disclose Customer Personal Data. Sensitive Data prohibited by the Agreement must not be submitted. Receipt contrary to that prohibition does not displace Ramus's applicable duties.

3. Confidentiality and security

Ramus will bind authorized persons to confidentiality and maintain technical and organizational measures appropriate to the processing risks. These include authenticated, need-to-know access and removal of unnecessary permissions; encryption in transit over public networks; appropriate storage, provider, and customer-separation controls; and protection against unauthorized access, alteration, or disclosure. Security changes must not materially reduce overall protection.

Ramus will minimize troubleshooting copies and provider disclosures, apply the agreed retention and deletion rules, and discard temporary environments when their purpose ends. It will review security-relevant changes, address vulnerabilities according to risk, maintain incident-response and appropriate recovery procedures, and periodically assess its measures and provider safeguards. It will provide accurate implementation details needed for Customer's assessment. Recovery must respect lawful deletion.

Ramus will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Available information will include the nature and likely consequences, affected data and persons where known, mitigation steps, and a contact. Information may be supplied in phases without undue delay. Ramus will investigate, mitigate, and reasonably assist Customer with required notifications; notice does not admit fault.

4. Subprocessors

Customer generally authorizes the providers identified as Subprocessors in the Ramus Subprocessor List, subject to this section. Ramus will enter into written terms imposing data-protection obligations substantively equivalent to those required here for the delegated processing before a Subprocessor receives Customer Personal Data. Ramus remains responsible for its Subprocessors' performance as required by applicable law and this DPA.

Ramus will provide Customer at least 10 days' advance written notice of an addition or replacement, with sufficient information to assess the processing. Customer may object during that period on reasonable data-protection grounds. The parties will seek a reasonable solution; Ramus will not start the objected-to processing while the objection is unresolved. If no solution is available, either party may end the affected Service, and Ramus will refund any prepaid fees for the unused affected period. Mandatory remedies remain available.

5. Requests and cooperation

Ramus will promptly forward requests concerning Customer Personal Data to Customer where lawful and will not respond on Customer's behalf except on instructions or as required by law. Taking account of the processing and information available, Ramus will provide timely assistance with data-subject rights, security obligations, breach notifications, impact assessments, and regulatory consultation. Customer may contact [email protected]. Reasonable exceptional assistance costs may be agreed in advance where lawful, but required assistance will not be withheld pending agreement.

If legally compelled to disclose Customer Personal Data, Ramus will notify Customer where permitted and disclose only what is required. It will assess the request's legality and seek appropriate protection or challenge where there are reasonable grounds, including as required by applicable transfer clauses.

6. Compliance information and audits

Ramus will make available information necessary to demonstrate compliance with this DPA and allow and contribute to audits and inspections by Customer or an independent auditor it mandates. The parties will use reasonable notice, confidentiality, scope, scheduling, and security arrangements. Existing documentation may be used first where sufficient, but does not replace an audit required by law. Arrangements must not obstruct urgent, regulatory, or otherwise legally required reviews. Customer ordinarily bears its audit costs; Ramus bears remediation costs for its own noncompliance.

7. Return and deletion

During the Services, retention follows the Agreement and lawful instructions. When processing ends, Ramus will, at Customer's choice, return available Customer Personal Data in a reasonably usable form or delete it, and delete remaining copies unless law requires retention. Customer should request return before account closure; Ramus is not required to recreate lawfully expired data. Ramus-controlled data, including associated copies and backups, will be deleted within 30 days after account closure, subject to legally required preservation.

Within that period Ramus will instruct relevant Subprocessors to delete the affected data and take available deletion actions. Any residual Subprocessor retention must be lawful, protected, limited to the permitted purpose, and consistent with this DPA and applicable transfer clauses. Provider terms do not excuse a mandatory deletion duty. Ramus will confirm completion on reasonable request. Required preserved data remains subject to protection and use restrictions until deleted.

8. International transfers and regional duties

Processing locations are identified in the Subprocessor List and applicable transfer particulars. Restricted international transfers require a lawful mechanism and any necessary supplementary measures. Ramus will cooperate with required transfer assessments. An affected transfer may not begin until required particulars are complete and a lawful mechanism is in place.

Where the CCPA applies, Ramus acts as service provider or contractor, as appropriate, and will provide the same level of privacy protection required by that law. It will not sell or share Customer Personal Data, retain/use/disclose it outside the direct business relationship or specified service purposes, or combine it with other-source personal information, except as the CCPA permits and the Agreement authorizes. Ramus certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to verify compliant use and stop or remediate unauthorized use. Ramus will notify Customer if it can no longer comply.

9. Liability and precedence

The Agreement's liability provisions apply to the extent permitted by Data Protection Law and the applicable transfer clauses. Nothing limits rights or liabilities under those clauses in a manner they prohibit, affects data-subject rights, or restricts a regulator's powers. Applicable transfer clauses prevail over conflicting provisions; this DPA otherwise prevails for processing matters within its scope. Its protections continue while Ramus or its Subprocessors retain Customer Personal Data.

On A Lark LLC · Ramus

Back to top