Legal

Privacy Policy

What we collect, why, how long we keep it, and what you can ask us to do about it.

Last updated 7 October 2026. Written in English; where a translation exists, the English version governs.

Placeholders to complete before launch. Items marked […] need your legal entity details, and the sub-processor list must be confirmed against what you actually use. If you have customers in the EU or UK you will also need a Data Processing Addendum, which this page references but does not replace.

Who is responsible

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller for the account and website data described below. For the content you put inside a product, you are the controller and we act as your processor. Contact: [email protected].

What we collect

Account data

Your name, work email, organisation name, password (stored only as a bcrypt hash), role, and the products you subscribe to. We need this to give you an account and bill you. Legal basis: performance of a contract.

Billing data

Subscription, invoice and payment records, plus the last four digits, brand and expiry of a card. Full card numbers never reach our servers — Stripe collects and stores them. Legal basis: performance of a contract, and our legal obligation to keep financial records.

Content you put into products

Whatever you enter or upload: contacts, deals, loads, documents, candidates, inventory records, feedback and so on. This may include personal data about your own customers, staff or applicants. We process it on your instructions to provide the product. We do not sell it, and we do not use it to train models.

Website analytics

Our analytics are cookieless and we do not store IP addresses. To count a visitor without identifying them, an IP and user-agent are combined into a one-way hash using a salt that changes every day, so the same visitor cannot be followed from one day to the next and the hash cannot be reversed to an address. We keep the page, referrer category, device class and country. Legal basis: legitimate interest in understanding whether the site works.

Security and operational logs

Sign-ins, password reset requests, administrative actions and errors. Password reset requests record the email supplied, anything the requester volunteers to prove the account is theirs, a one-way marker derived from the IP, and the browser string — because resets are handled by a person here, and the operator needs to see who is asking. Legal basis: legitimate interest in keeping accounts secure.

What we do not do

  • We do not sell personal data.
  • We do not run advertising trackers or third-party analytics on this site.
  • We do not use your workspace content to train machine-learning models.
  • We do not store full payment card numbers.
  • We do not store visitor IP addresses.

Who we share it with

Sub-processors we rely on to run the service:

ProviderPurposeData
StripePayments, invoicing, card storageName, email, billing address, card details
CloudflareNetwork delivery and protectionRequest metadata in transit
[EMAIL PROVIDER, once configured]Transactional emailName, email

[Confirm this list is complete and keep it current — the GDPR requires customers to be able to see who processes their data, and often to be told before you add a new one.]

We also disclose data where the law requires it. If we receive a request for your data from an authority, we will tell you unless legally prevented from doing so.

Where it is held

Application data is held on infrastructure in [HOSTING REGION]. Stripe and Cloudflare operate internationally and may process data outside that region under their own transfer mechanisms. [If you have EU or UK customers, confirm the transfer basis — Standard Contractual Clauses or an adequacy decision.]

How long we keep it

DataRetention
Account and workspace contentWhile your account is open, then 30 days after cancellation
Invoices and payment records[7 years, or your local statutory period]
Website analyticsAggregated by day; no visitor-level record persists beyond the daily salt
Password reset requests12 months, then deleted
Security logs12 months

Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy. You can exercise most of these yourself:

  • Access and portability — every product exports to CSV or Markdown from inside the app.
  • Correction — edit your account details directly.
  • Deletion — cancel and your data is removed after the 30-day window.

For anything else, email [email protected]. We will respond within 30 days. If you are unhappy with our response you can complain to your data protection authority [name the lead authority for your jurisdiction].

If you are a customer’s customer

If your data is inside an Arkenso workspace because one of our customers put it there, that customer decides what happens to it. Please contact them. If you contact us instead, we will pass your request on.

Security

Passwords are hashed with bcrypt and never stored in readable form. Sessions can be revoked, and are revoked automatically whenever a password changes. Access to each organisation’s data is scoped to that organisation. Traffic is encrypted in transit.

If we discover a breach affecting your personal data, we will notify you without undue delay and, where required, within 72 hours of becoming aware.

Children

Arkenso is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.

Changes

We will post updates here and change the date at the top. For material changes affecting your rights we will give notice by email or in the application.


See also the Terms of Service and the Refund and Cancellation Policy.