Legal
Privacy Policy
What we collect, why, how long we keep it, and what you can ask us to do about it.
Last updated 7 October 2026. Written in English; where a translation exists, the English version governs.
Placeholders to complete before launch. Items marked
[…] need your legal entity details, and the sub-processor list
must be confirmed against what you actually use. If you have customers in
the EU or UK you will also need a Data Processing Addendum, which this page
references but does not replace.
Who is responsible
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller for the account and website data described below. For the content you put inside a product, you are the controller and we act as your processor. Contact: [email protected].
What we collect
Account data
Your name, work email, organisation name, password (stored only as a bcrypt hash), role, and the products you subscribe to. We need this to give you an account and bill you. Legal basis: performance of a contract.
Billing data
Subscription, invoice and payment records, plus the last four digits, brand and expiry of a card. Full card numbers never reach our servers — Stripe collects and stores them. Legal basis: performance of a contract, and our legal obligation to keep financial records.
Content you put into products
Whatever you enter or upload: contacts, deals, loads, documents, candidates, inventory records, feedback and so on. This may include personal data about your own customers, staff or applicants. We process it on your instructions to provide the product. We do not sell it, and we do not use it to train models.
Website analytics
Our analytics are cookieless and we do not store IP addresses. To count a visitor without identifying them, an IP and user-agent are combined into a one-way hash using a salt that changes every day, so the same visitor cannot be followed from one day to the next and the hash cannot be reversed to an address. We keep the page, referrer category, device class and country. Legal basis: legitimate interest in understanding whether the site works.
Security and operational logs
Sign-ins, password reset requests, administrative actions and errors. Password reset requests record the email supplied, anything the requester volunteers to prove the account is theirs, a one-way marker derived from the IP, and the browser string — because resets are handled by a person here, and the operator needs to see who is asking. Legal basis: legitimate interest in keeping accounts secure.
What we do not do
- We do not sell personal data.
- We do not run advertising trackers or third-party analytics on this site.
- We do not use your workspace content to train machine-learning models.
- We do not store full payment card numbers.
- We do not store visitor IP addresses.
Who we share it with
Sub-processors we rely on to run the service:
| Provider | Purpose | Data |
|---|---|---|
| Stripe | Payments, invoicing, card storage | Name, email, billing address, card details |
| Cloudflare | Network delivery and protection | Request metadata in transit |
| [EMAIL PROVIDER, once configured] | Transactional email | Name, email |
[Confirm this list is complete and keep it current — the GDPR requires customers to be able to see who processes their data, and often to be told before you add a new one.]
We also disclose data where the law requires it. If we receive a request for your data from an authority, we will tell you unless legally prevented from doing so.
Where it is held
Application data is held on infrastructure in [HOSTING REGION]. Stripe and Cloudflare operate internationally and may process data outside that region under their own transfer mechanisms. [If you have EU or UK customers, confirm the transfer basis — Standard Contractual Clauses or an adequacy decision.]
How long we keep it
| Data | Retention |
|---|---|
| Account and workspace content | While your account is open, then 30 days after cancellation |
| Invoices and payment records | [7 years, or your local statutory period] |
| Website analytics | Aggregated by day; no visitor-level record persists beyond the daily salt |
| Password reset requests | 12 months, then deleted |
| Security logs | 12 months |
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy. You can exercise most of these yourself:
- Access and portability — every product exports to CSV or Markdown from inside the app.
- Correction — edit your account details directly.
- Deletion — cancel and your data is removed after the 30-day window.
For anything else, email [email protected]. We will respond within 30 days. If you are unhappy with our response you can complain to your data protection authority [name the lead authority for your jurisdiction].
If you are a customer’s customer
If your data is inside an Arkenso workspace because one of our customers put it there, that customer decides what happens to it. Please contact them. If you contact us instead, we will pass your request on.
Security
Passwords are hashed with bcrypt and never stored in readable form. Sessions can be revoked, and are revoked automatically whenever a password changes. Access to each organisation’s data is scoped to that organisation. Traffic is encrypted in transit.
If we discover a breach affecting your personal data, we will notify you without undue delay and, where required, within 72 hours of becoming aware.
Children
Arkenso is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.
Changes
We will post updates here and change the date at the top. For material changes affecting your rights we will give notice by email or in the application.
See also the Terms of Service and the Refund and Cancellation Policy.