How Arqis collects, uses and protects personal data across the website, demonstration environments and the platform.
Arqis is the controller for personal data collected through this website and our own business operations. Where we process transaction data inside a customer workspace, the customer is the controller and Arqis is a processor acting on their instructions under a data processing agreement. Contact: team@arqis.ai.
We use personal data to respond to enquiries, run working sessions, provide and secure the platform, produce and version determinations, meet our own legal and sanctions screening obligations, and improve the service. We do not sell personal data, and we do not use customer content to train foundation models.
Where GDPR or comparable law applies we rely on: performance of a contract, for providing the platform; legitimate interests, for security, service improvement and business-to-business communication; legal obligation, for sanctions, export control and record-keeping; and consent, where required for optional analytics or marketing, which you can withdraw at any time.
We use third-party infrastructure and foundation model providers to operate the service. Model providers process the documents submitted for reading and drafting under contractual terms that prohibit training on that content. A current list of sub-processors is available on request and is maintained for customers under their data processing agreement.
We operate from Singapore, the United States and, for some customers, EU and UK regions. Transfers out of the EEA or UK are made under Standard Contractual Clauses or an equivalent transfer mechanism. Customers who require regional data residency can specify it in their agreement.
Enquiry and correspondence data is retained for up to twenty-four months from last contact. Workspace data is retained for the term of the customer agreement and deleted or returned on termination, except where retention is required by law. Audit logs are retained for the period the customer specifies, since a determination has to remain reproducible after the fact.
Access is scoped to the workspace and role, authentication is enforced, data is encrypted in transit and at rest, and every action against a determination is logged. Confidential positions on live transactions are treated as sensitive by default rather than by classification.
Subject to local law you may request access to your personal data, correction, deletion, restriction or objection to processing, and portability. Where Arqis acts as a processor we will refer the request to the relevant customer. Requests go to team@arqis.ai and are answered within thirty days. You may also complain to your local supervisory authority.
The site uses essential cookies for session handling and, where you consent, analytics cookies that tell us which pages are read. No advertising or cross-site tracking cookies are used. You can clear or block cookies in your browser; essential cookies are needed for forms to work.
The service is intended for business use and is not directed at anyone under 18. We do not knowingly collect data from children.
We will post any update here and change the date above. Material changes affecting customer data are notified directly before they take effect.