Legal

Privacy Policy

How Arqis collects, uses and protects personal data across the website, demonstration environments and the platform.

Last updated 9 September 2026
01

Controller and contact

Arqis is the controller for personal data collected through this website and our own business operations. Where we process transaction data inside a customer workspace, the customer is the controller and Arqis is a processor acting on their instructions under a data processing agreement. Contact: team@arqis.ai.

02

What we collect

03

Why we use it

We use personal data to respond to enquiries, run working sessions, provide and secure the platform, produce and version determinations, meet our own legal and sanctions screening obligations, and improve the service. We do not sell personal data, and we do not use customer content to train foundation models.

04

Legal bases

Where GDPR or comparable law applies we rely on: performance of a contract, for providing the platform; legitimate interests, for security, service improvement and business-to-business communication; legal obligation, for sanctions, export control and record-keeping; and consent, where required for optional analytics or marketing, which you can withdraw at any time.

05

Sub-processors and model providers

We use third-party infrastructure and foundation model providers to operate the service. Model providers process the documents submitted for reading and drafting under contractual terms that prohibit training on that content. A current list of sub-processors is available on request and is maintained for customers under their data processing agreement.

06

International transfers

We operate from Singapore, the United States and, for some customers, EU and UK regions. Transfers out of the EEA or UK are made under Standard Contractual Clauses or an equivalent transfer mechanism. Customers who require regional data residency can specify it in their agreement.

07

Retention

Enquiry and correspondence data is retained for up to twenty-four months from last contact. Workspace data is retained for the term of the customer agreement and deleted or returned on termination, except where retention is required by law. Audit logs are retained for the period the customer specifies, since a determination has to remain reproducible after the fact.

08

Security

Access is scoped to the workspace and role, authentication is enforced, data is encrypted in transit and at rest, and every action against a determination is logged. Confidential positions on live transactions are treated as sensitive by default rather than by classification.

09

Your rights

Subject to local law you may request access to your personal data, correction, deletion, restriction or objection to processing, and portability. Where Arqis acts as a processor we will refer the request to the relevant customer. Requests go to team@arqis.ai and are answered within thirty days. You may also complain to your local supervisory authority.

10

Cookies

The site uses essential cookies for session handling and, where you consent, analytics cookies that tell us which pages are read. No advertising or cross-site tracking cookies are used. You can clear or block cookies in your browser; essential cookies are needed for forms to work.

11

Children

The service is intended for business use and is not directed at anyone under 18. We do not knowingly collect data from children.

12

Changes

We will post any update here and change the date above. Material changes affecting customer data are notified directly before they take effect.

This policy is a starting framework, not filed legal advice. Controller entity details, sub-processor list and retention periods should be confirmed by counsel before publication.