Legal ยท Privacy

Privacy Policy

This policy explains how Arc handles business contact information and customer programme information used in its requirements management and verification software. Arc supports multi-tenant SaaS, on-premises and air-gapped application deployments, with bring-your-own-database available as a data-ownership configuration across each. The exact processing boundary and service providers depend on the deployment agreed with each customer. This page gives the public, high-level processing summary.

Last updated .

Privacy in short

Arc limits collection to information needed to provide, support and secure the service, respond to direct enquiries and meet legal obligations. Customer programme information stays within the agreed deployment boundary and is processed under customer instructions.

What we collect

  • Basic business contact details when someone books a demo, starts a sales conversation, or becomes an Arc customer.
  • Name, work email, company and role when someone requests a manually provisioned Arc account or worked example. The form also records a non-identifying request ID and whether the person separately chose to receive marketing communications.
  • Account, onboarding, support and deployment records needed to provide the service.
  • Customer programme information submitted to Arc, which may include requirements, architecture, interfaces, risks, verification and test records, evidence, attachments, comments, reviews, approvals and audit history.
  • AI prompts, proposed outputs, model-routing details and review decisions when AI processing and related audit history are enabled for the deployment.
  • Information from connectors or other data sources that the customer has deliberately authorised.

How we use it

  • To provide onboarding, support, deployment management and customer-requested product functionality.
  • To check for an existing Arc account, create or update a private organisation, provision the requested example and send a secure invitation.
  • To send optional marketing communications only when the person has made the separate marketing choice. Requesting an account does not require marketing consent, and that consent can be withdrawn at any time.
  • To operate connected requirements, review, verification, evidence and customer-requested integration workflows.
  • To protect the service, investigate issues and maintain the customer’s configured audit trail, including attributable approvals and AI actions.
  • To apply customer-specific feature controls, retention rules, model-routing choices and access policies.
  • To comply with law, enforce agreements, and respond to security or incident-response requests.

Our role and the customer’s role

For customer programme information, Arc generally acts as a processor and handles that information on the customer’s documented instructions. The customer determines which programme records enter Arc, who can access them, how long they are retained and which deployment or AI-processing options are enabled.

Arc acts as a controller for information used to manage direct website enquiries, account requests, sales conversations and its own business relationship with a customer. A signed customer agreement or data-processing schedule may provide more specific terms and controls.

Deployment and processors

Arc supports three application deployment models: multi-tenant SaaS, on-premises and air-gapped. Bring your own database is a data-ownership configuration available across all three, not a separate hosting model. The infrastructure, database and model-inference boundary is agreed with the customer, so the exact list of processors varies by deployment.

  • Website scheduling through Cal.com when someone books a call through this site.
  • Website form delivery through Formspark when someone submits an account, example or contact request. Formspark processes the submitted fields and request metadata on Arc’s behalf.
  • Infrastructure, networking or storage providers used for Arc-managed environments when the customer selects that deployment model.
  • Communications tools used to answer customer requests and manage onboarding.
  • Approved model or compute providers when AI processing is enabled under customer-approved deployment rules.
  • Air-gapped deployments require no external calls, keep model inference local and receive updates through an offline process.

Retention, export and deletion

Arc minimises retention where possible and applies the retention and deletion rules agreed for each customer deployment.

  • Customers are kept in separate deployment boundaries so retention and deletion rules can be applied cleanly.
  • Customers can export their programme records and, subject to their agreement and any required audit or legal retention, instruct Arc to delete customer programme information from Arc-operated services. Customers operating Arc in their own environment control export and deletion within that environment.
  • Account and example requests are retained only for as long as needed to respond, provision access, maintain the necessary account or business record, and meet applicable legal obligations. A person may ask Arc to delete a request that no longer needs to be retained.
  • Optional connectors and data sources can remain off entirely unless the customer explicitly authorises them.
  • Provider inference is transient and limited to returning the requested result under the selected deployment policy. Any prompt, output or decision history retained by Arc remains subject to the customer’s configured audit and retention rules.
  • Arc and enabled model providers never use customer content to train models.

Security and customer control

  • Arc encrypts data using AES-256 at rest and TLS 1.2 or later in transit.
  • Logical tenant isolation and granular role-based permissions control viewing, editing, reviewing, approving and administration.
  • Administrative access, data residency, audit exports, model routing and authorised data sources are scoped to the customer and selected deployment.
  • On-premises and air-gapped customers can keep inference local and disable external AI processing.

Requests and contact

Subject to applicable law and the customer relationship, people may ask to access, correct or delete their personal information, object to or restrict processing, or withdraw a marketing choice. Customer users should normally direct programme-data requests to their organisation, which controls that deployment. For website or general privacy questions, email luc@archelps.com.