Legal

Privacy policy

In effect from 30 July 2026.

1. Who we are

Arc is provided by Arc. For questions about this policy or to exercise any right in section 13, write to hello@archq.co.uk.

2. Our two roles

This distinction determines who is answerable for what, so it comes first.

  • We are the controller for the data we hold about you as our customer: your account, your use of the Service, and your billing.
  • We are a processor for the content you put into Arc. Conversations, decisions and your clients’ contact details are yours; you decide what goes in and why. We act on your instructions under the Data Processing Agreement.

This matters in practice: your client’s personal data is in Arc because you put it there. You are accountable to them for that, and we support you in meeting it.

3. Your clients

Arc sends a client link so your client can review and confirm decisions. To do that we process their name, email address and their responses. We do not market to them, sell their data, or use it for anything beyond delivering the confirmation loop you started. They never need an account and are never asked to pay.

4. What we collect

  • Account data — name, email address, hashed password, and the company you belong to.
  • Project content — the conversations and notes you import, the decisions drawn from them, images you attach as evidence, and your clients’ names, email addresses, telephone numbers and responses.
  • Operational data — sign-in sessions, security and audit logs, and the volume of automated processing your account uses, which is how plan limits are applied.
  • Billing data — subscription status and invoice history. Card details are entered with Stripe and never reach us.
  • Analytics — how the interface is used, and only if you consent. See section 15.

We do not ask for special category data and the Service is not designed to hold it.

5. Why we process it, and on what basis

  • To provide the Service — performance of our contract with you.
  • To secure it — detecting abuse, keeping audit logs, preventing unauthorised access. Legitimate interests: running a service our customers can rely on.
  • To bill you — performance of our contract, and our legal obligation to keep accounting records.
  • To support you — performance of our contract.
  • To improve the Service through analytics — your consent, withdrawable at any time.
  • To send service messages you need in order to use Arc — performance of our contract. Marketing email, if we ever send it, is consent-based and separately withdrawable.

6. Automated processing

When you import a conversation, its text is sent to our AI sub-processor to extract the decisions it contains. Two things follow, and both are deliberate:

  • Your content is not used to train AI models.
  • Nothing is decided about anyone automatically. Extraction produces a draft that you review, edit and approve before it reaches your client. There is no automated decision-making producing legal or similarly significant effects.

Nothing is sent for processing unless you import it. Reviewing, confirming, exporting and printing involve no AI processing at all.

7. Who processes it

We keep the list of third parties deliberately short. Each is bound by data protection terms no less protective than our own, and we remain responsible for them.

  • Amazon Web ServicesHosting, database and file storage. Processes in United Kingdom.
  • AnthropicReads the conversations you import in order to extract decisions. Processes in United States.
  • ResendDelivers the emails Arc sends on your behalf. Processes in European Union.
  • StripeSubscription billing. Card details are entered with Stripe and never reach Arc. Processes in European Union and United States.
  • AmplitudeProduct analytics, only where you have consented. Processes in European Union.

We give at least 30 days’ notice before adding or replacing a sub-processor. We do not sell personal data, and we do not share it for advertising.

We may disclose data where the law requires it. Where we are lawfully able, we will tell you first.

8. Where it is held

Your data is stored in the United Kingdom. Where a sub-processor in section 7 processes it elsewhere, that transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under UK adequacy regulations where they apply.

9. How long we keep it

  • While your account is open — account and project data are kept so the Service works.
  • Operational logs — up to 12 months.
  • Billing records — six years, as UK tax law requires.
  • Backups — deleted data persists in backups until they expire on their ordinary cycle, within 35 days.

10. Closing your account

Closing your account removes your sign-in, your personal details and your integrations.

The shared project record is retained. It was created jointly by you and your client, it is the evidence of what you both agreed, and either of you may need to rely on it — including in a dispute after your working relationship ends. Deleting it on the request of one party would remove the other party’s evidence, which is the opposite of what the Service is for.

We rely on legitimate interests for that retention: establishing, exercising or defending legal claims. You can object, and we will consider each objection on its facts — the balance changes if, for example, a record concerns a project that never proceeded. Export the record before you close your account, or ask us afterwards and we will provide it.

11. Security

Encryption in transit and at rest; passwords hashed and never readable by the application; integration keys sealed with authenticated encryption; the database unreachable from the public internet; access scoped to your company and checked on every read and write; administrative access to customer data written to an append-only audit log. More detail on the security page.

12. Breach notification

If a personal data breach affects data we hold for you, we will tell you without undue delay and within 72 hours of becoming aware, with what we know and what we are doing. Where we are the controller and the breach is likely to be a high risk to individuals, we notify them and the ICO as the law requires.

13. Your rights

Where we are the controller, you may ask for access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. Where consent is the basis, you may withdraw it at any time without affecting what was done beforehand.

Write to hello@archq.co.uk. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

Where we are the processor — that is, for the content you imported — the request belongs to the customer whose account holds it. If you are someone’s client and want your data corrected or removed, ask the business that invited you; we will help them act on it.

14. Complaints

Raise it with us first at hello@archq.co.uk. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk), the UK supervisory authority.

15. Cookies and analytics

Arc sets a session cookie to keep you signed in, and stores your analytics choice on your device. Both are strictly necessary and need no consent.

Product analytics is optional and off until you accept it. We ask once, declining is one click, and nothing analytics-related loads unless you accept. Where you do accept, session recording excludes the record itself — the decisions, names and client details on your pages are never captured. To change your mind, clear the choice in your browser and the prompt reappears.

16. Children

Arc is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

17. Changes

We may update this policy. Material changes are notified by email or in the Service at least 30 days before they take effect. The date at the top of this page always states the version in force.