Arkus AI AB, organisation number 559239-8811, with its registered office at Hagaesplanaden 1, 113 68 Stockholm, Sweden (“Arkus,” “we,” “our,” or “us”), provides the Arkus AI Agent Builder and related services for building, deploying and operating customer-created agents, applications and workflows (“Customer Agents”).
We are committed to protecting the privacy and security of personal data and complying with applicable privacy laws, including:
- EU General Data Protection Regulation (GDPR)
- UK GDPR
- Other applicable international privacy laws.
This Privacy Policy explains how Arkus Processes Personal Data when you visit arkus.ai, create or administer an Arkus account, communicate with us, purchase Services, or use the Arkus platform, APIs and integrations.
It also explains the distinction between Personal Data for which Arkus acts as Controller and Customer Personal Data that Arkus Processes on a Customer’s behalf.
1. Who is responsible for your Personal Data?
- Arkus is the Controller of Personal Data used to operate our website and business, administer accounts, process billing, provide support, secure the Services and communicate with customers.
- When a Customer submits or collects Personal Data through an agent, application or workflow, the Customer generally determines why and how that Personal Data is Processed. In that situation, the Customer is the Controller—or a Processor acting for another Controller—and Arkus is its Processor or Subprocessor.
- Arkus’s Processing of Customer Personal Data is governed by our Data Processing Agreement (“DPA”), which applies automatically where required.
- If you use an agent or application created by an Arkus Customer, contact that Customer first about its privacy practices or to exercise your rights. Arkus will assist the Customer as required by the DPA.
2. Personal Data we collect
Depending on how you interact with Arkus, we may collect:
2.1 Account and contact data
- name, business contact details and organisation;
- username, account identifiers and authentication information;
- role, workspace membership and permissions; and
- communication preferences.
2.2 Billing and transaction data
- subscription, plan, invoice, tax and transaction information; and
- limited payment information received from our payment provider.
Arkus does not store full payment-card details. Payments are processed by approved payment providers identified in our Subprocessor List.
2.3 Customer Data
When using the Services, Customers may submit or generate:
- prompts, messages and instructions;
- code, files, images and other uploaded content;
- agent, application and workflow configurations;
- integration information; and
- AI-generated outputs and execution results.
The Arkus AI Agent Builder does not itself collect health or other sensitive or special-category Personal Data directly from end users. Customer Agents may process such data where configured by the Customer, subject to the requirements in Section 5.
2.4 Usage, device and log data
- IP address, browser, operating system and device information;
- timestamps, pages viewed and feature interactions;
- agent executions, deployment events and performance measurements;
- error, diagnostic and security logs; and
- cookie and similar-technology identifiers, subject to your choices.
2.5 Support and communications
- support requests, feedback and correspondence; and
- information you provide during troubleshooting or a security investigation.
2.6 Information from integrations
If you connect a third-party service, we receive the information necessary to authenticate, configure and operate that integration, according to your instructions and permissions.
3. How and why we use Personal Data
Where Arkus acts as Controller, we use Personal Data for the following purposes and legal bases:
3.1 Performing a contract or taking requested pre-contract steps
- creating and administering accounts;
- providing purchased or requested Services;
- processing subscriptions, payments and Credits;
- providing support; and
- communicating service and account information.
3.2 Legitimate interests
Where our interests are not overridden by your rights, we Process Personal Data to:
- protect accounts, users and the Services;
- prevent fraud, abuse and policy violations;
- monitor reliability and diagnose errors;
- understand feature usage and improve user experience;
- maintain business records and manage customer relationships; and
- establish, exercise or defend legal claims.
Where required, we conduct and document a legitimate-interests assessment.
3.3 Consent
We rely on consent where required for:
- non-essential cookies and similar technologies;
- certain marketing communications; and
- optional Processing for which we ask your permission.
You may withdraw consent at any time without affecting Processing that occurred before withdrawal.
3.4 Legal obligations
We Process Personal Data where necessary to comply with tax, accounting, sanctions, law-enforcement and other legal obligations.
4. AI models and Customer Data
4.1 Default model service
The default model service offered by Arkus uses OpenAI models hosted through Microsoft Azure OpenAI Service. Arkus deploys these models exclusively using EU Regional or EU Data Zone deployment types. Under this configuration, prompts and outputs are processed within the applicable European region or data zone, and data stored at rest remains within the designated European geography.
Microsoft hosts and operates the models within its Azure environment. The service does not interact with OpenAI-operated services, including ChatGPT or the OpenAI API, and Customer prompts and outputs are not made available to OpenAI.
Microsoft processes prompts and outputs to provide model inference, content filtering and abuse monitoring. Where flagged content requires human review, access is restricted to authorised Microsoft personnel located in the EEA. Relevant Microsoft entities and Processing locations are identified in our Subprocessor List.
Customer prompts and outputs are not used to train, retrain or improve OpenAI’s or Microsoft’s foundation models, in accordance with Microsoft’s applicable data-privacy commitments and service terms. For more information, see Microsoft’s Data, privacy and security documentation for models sold by Azure.
4.2 No model training by Arkus
Arkus does not use Customer Data, prompts, files, application data or AI-generated outputs to train, retrain or fine-tune any Arkus or shared third-party AI model.
Arkus may use Usage Data and aggregated or de-identified information to secure, operate, analyse and improve the Services, provided that it does not identify a Customer or individual and is not used to train an AI model.
4.3 Customer-selected model providers
Customers may connect or select other AI providers, including Anthropic or Google Gemini. The Customer controls the provider selection, configuration and data transmitted to that provider. Customers may use available anonymisation, pseudonymisation, redaction or data-minimisation measures before transmission.
When a Customer uses a Customer-connected provider:
- Arkus transmits data according to the Customer’s configuration;
- the provider’s own contractual and privacy terms may apply; and
- the provider’s retention, training, location, security and human-review practices may differ from Azure OpenAI.
Processing of PHI or other regulated or sensitive data remains subject to Section 5. End users should contact the Customer operating the relevant agent to identify the model provider used.
5. Personal, health and sensitive data
- The Arkus AI Agent Builder does not itself collect health data or other sensitive or special-category Personal Data directly from end users. A Customer Agent may collect, receive, store or otherwise Process such data where the Customer configures the Customer Agent to do so.
- PHI or other data requiring additional sector-specific safeguards or contractual terms must not be submitted without Arkus’s prior written approval.
- The Customer operating the Customer Agent determines the purposes, data fields, collection methods and Processing operations and is responsible for establishing an appropriate legal basis and, where applicable, a condition under Article 9 GDPR or equivalent law; providing required notices; obtaining any required consent or authorisation; conducting required impact assessments; and complying with applicable healthcare, clinical-research, medical-device and other sector-specific requirements.
- The Customer controls whether Personal Data processed by its Customer Agent is transmitted to an AI model or Third-Party Component. Arkus makes such transmissions only in accordance with the Customer’s configuration, provider selection and instructions.
- Customers may use available anonymisation, pseudonymisation, redaction or data-minimisation measures before data is transmitted to an AI model or Third-Party Component. Pseudonymised data remains Personal Data where it can be attributed to an individual using additional information; data is anonymous only where individuals are not identifiable by means reasonably likely to be used.
- Arkus-selected providers that Process Customer Personal Data on Arkus’s behalf are identified in our Subprocessor List. A provider independently connected by a Customer may process data directly under the Customer’s agreement with that provider.
- Arkus does not use Customer Data, including personal or health data processed through a Customer Agent, to train, retrain or fine-tune any Arkus or shared third-party AI model.
- Availability of the Services for a use case does not mean that a Customer Agent is clinically validated, certified or legally compliant.
6. Cookies and analytics
- We use cookies and similar technologies for authentication, security, preferences, analytics and, where applicable, marketing.
- Strictly necessary technologies are used to operate and secure the website and Services. Non-essential technologies are used only where permitted by law and subject to your consent choices.
- We use PostHog for product analytics and may associate analytics events with an account identifier or email address where lawfully permitted.
- Our cookie banner identifies the technologies used, their providers, purposes and retention periods. You can accept, reject or manage non-essential technologies through the banner or the permanent “Cookie settings” control.
7. Sharing and Subprocessors
We may disclose Personal Data:
- To service providers and Subprocessors that provide cloud hosting, AI models, analytics, authentication, communications, support, payment processing and security services. Our current Subprocessor List identifies relevant providers, purposes and Processing locations.
- To Customer-Connected Providers where a Customer instructs us to operate an integration or model connection.
- To professional advisers such as lawyers, accountants, auditors and insurers where reasonably necessary and subject to confidentiality.
- For legal and safety purposes where disclosure is required by law or reasonably necessary to protect rights, safety, security, users or the Services.
- In a corporate transaction such as a merger, financing, acquisition or sale of assets, subject to appropriate confidentiality and data-protection safeguards.
Arkus does not sell Personal Data or share it for cross-context behavioural advertising.
8. International transfers
- Arkus’s primary hosting environment for Customer Personal Data is located in the European Union.
- Some service providers or Customer-Connected Providers may Process data outside the EEA, United Kingdom or Switzerland.
- For Restricted Transfers made by Arkus, we use an appropriate transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK Addendum or another legally recognised safeguard.
- The DPA contains the contractual transfer provisions applicable to Customer Personal Data.
- You may contact us to request information about the safeguards relevant to a particular transfer.
9. Data retention
We retain Personal Data only for as long as necessary for the applicable purpose, taking account of the type of data, contractual commitments, security needs and legal obligations.
- Customer Personal Data: retained for the subscription term and deleted or rendered inaccessible from active systems within 30 calendar days after termination or expiry, subject to the DPA, Customer configuration and legal-retention exceptions.
- Account and workspace data: retained while the account is active and for a limited period after closure to complete deletion, prevent fraud, resolve disputes and meet legal obligations.
- Prompts, outputs and execution data: retained according to Customer settings, applicable product functionality and the DPA. Customer-Connected Providers may apply their own retention periods.
- Security and diagnostic logs: retained for periods reasonably necessary to investigate incidents, maintain reliability and prevent abuse.
- Billing, tax and transaction records: retained for the period required by applicable accounting and tax law.
- Support communications: retained for as long as reasonably necessary to resolve the request and maintain an appropriate support and dispute record.
- Consent records: retained for as long as necessary to demonstrate consent and compliance.
- Backups: deleted or overwritten according to Arkus’s backup cycle. Until then, backed-up Personal Data remains protected and is restored only for disaster recovery, security or legal compliance.
Where retention ends, we delete, anonymise or render the data inaccessible.
10. Security
Arkus applies technical and organisational safeguards, including authentication controls, encryption in transit and at rest, logical data separation, restricted production access, monitoring, backup and incident response. The DPA describes the measures applicable to Customer Personal Data.
Customers are responsible for protecting credentials and configuring authorised users, deployed-agent access, sharing permissions, integrations, agents and flows appropriately. No online service can guarantee absolute security.
Report suspected security issues to legal@arkus.ai with the subject “Security.”
11. Your rights
Depending on where you live, you may have some or all of the rights listed below (subject to legal limits):
- Right of Access/Portability: Request disclosure of personal information collected, used, or disclosed.
- Right of Deletion: Request deletion of personal information, subject to exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Withdraw Consent: Withdraw consent for certain processing activities.
- Opt-out of sales, sharing, or targeted advertising: Opt out of the sale or sharing of personal information.
To exercise a right regarding data for which Arkus is Controller, email legal@arkus.ai with the subject “Privacy Request.” We may verify your identity and will normally respond within one month, subject to lawful extensions or exceptions.
If your request concerns an agent or application operated by an Arkus Customer, contact that Customer first. Where Arkus acts as Processor, we will assist the Customer as required by the DPA.
12. Automated decisions
Arkus does not use Personal Data for automated decisions about account holders that produce legal or similarly significant effects without appropriate notice and safeguards.
Customers may build agents that support or automate decisions. The Customer determines the purpose and configuration of such Processing and is responsible for assessing legal requirements, providing notices, enabling human review and protecting affected individuals.
13. Children
The Services are not intended for individuals under 18. We do not knowingly collect Personal Data directly from children through Arkus accounts. If you believe a child has provided Personal Data to Arkus in violation of this policy, contact us so we can investigate and take appropriate action.
Customers must not use the Services to Process children’s data unless permitted by the Agreement, applicable law and any written approval required by Arkus.
14. Third-party websites and services
The Services may link to or integrate with third-party services. Their privacy practices are governed by their own policies. Arkus is not responsible for a third party’s independent Processing, particularly where Customer selects and contracts with that third party directly.
15. Changes to this Privacy Policy
We may update this Privacy Policy to reflect legal, technical or business changes. Where required, we will provide additional notice by email, through the Services or on our website before a material change takes effect.
Previous versions should be made available through a legal-policy archive or on request.
16. Contact
If you have questions, concerns, or wish to exercise your privacy rights, please contact us.
Arkus AI AB
Organisation number: 559239-8811
Hagaesplanaden 1
113 68 Stockholm
Sweden
Email: legal@arkus.ai
Website: arkus.ai
We aim to respond to verified data-subject requests within thirty (30) days, or longer where permitted under applicable law, in which case we will notify you of the delay and reason. If you believe your inquiry has not been satisfactorily resolved, you may lodge a complaint with your local supervisory authority.
