ArcGabriel Privacy Policy
Version 1.4, September 2026
ArcGabriel is operated by ArcGabriel Ltd, a company registered in England and
Wales (company no. 17389329), registered office Carlile Institute Business Centre, 54 Huddersfield Road, Meltham,
Holmfirth HD9 4AE ("we"). We comply with UK GDPR and the Data Protection Act
2018, and we are registered with the Information Commissioner's Office. This
policy says what we collect, why, and your rights, briefly and honestly.
Two roles, and which one applies
For your own account we are the controller. Your name, your email, your
business details, your payment record, your sign-ins: we decide what to hold
and why, and this policy explains it.
For personal data about your customers we are your processor. A customer's
name and contact details you enter for a review request, people who appear in
photographs you upload, anyone you name in material you give us to publish,
that is your data about your people. You are the controller; we hold it and
work on it on your instructions, and on nobody else's. The terms governing that
are Schedule 1 to the [Terms of Service](/terms), which is drafted to satisfy
Article 28 of the UK GDPR, so you do not need a separate agreement from us.
The practical difference: for your own account, ask us. For your customers'
data, you decide, and the Service gives you erasure and export for every such
record without needing to ask anyone.
What we collect as controller, and why
| Data | Why (lawful basis) |
|---|---|
| Account details (name, email, business name) | To provide the Service (contract) |
| Signed agreement record (name, IP, timestamp, document hash) | To evidence the contract (contract; legal obligation) |
| Payment records | Processed by Stripe; we hold no card numbers (contract; legal obligation) |
| Files and information you upload | To do the marketing work you subscribe for (contract) |
| Connected account tokens (e.g. Meta, LinkedIn, Google) | To publish on your instruction (contract). Encrypted at rest, and revocable by you at any time |
| Activity records (sign-ins, actions, IP addresses) | Security and audit (legitimate interests) |
| Emails we send you about the Service | Operating the Service (contract). Marketing email only with consent, withdrawable any time |
| Anonymous page counts on our own website | Understanding what the site does (legitimate interests). No cookies, no cross-site tracking, no individual identification |
We do not sell personal data. We do not use your data, or your customers', to
train artificial-intelligence models, ours or anyone else's.
What we process on your behalf, as your processor
Names and contact details of your customers, a short note of the work you did
for them, and the message we draft for you to send. Photographs and files you
upload, which may show identifiable people. Text you give us to publish.
We never contact your customers ourselves. Review requests are drafted for you
to send from your own email or phone, which is why the Service asks you to
confirm, for each person, that they are your customer and that you may contact
them, and why every drafted message gives them a plain way to say no.
Please do not enter special category data: health, beliefs, and the rest of
Article 9. The Service is not built for it.
Where it lives and who touches it
The application and its database run in the European Economic Area, and the
off-box backups are stored there. These are every sub-processor we use and what
each does:
| Who | What they do | Touches your customers' data? |
|---|---|---|
| Railway | Hosts the application and the database | Yes: it is where the Service runs |
| Cloudflare | Off-box encrypted backups (R2); DNS and network protection for our sites | Yes: backups include everything |
| Stripe | Takes card payments and holds the card details; we never see them | No |
| Resend | Sends the Service's emails to you | No |
| Anthropic | Writes the marketing copy from the brief you give us | No. Only the text you provide for publication is sent, never your customer list, never your uploaded images |
| Meta (Facebook, Instagram), LinkedIn, Google | Receive what publishing and reporting requires, on your instruction | Only where you name someone in content you approve for publishing |
| Pexels | Supplies stock photographs when you ask us to find some. Receives the search words, which are built from your business description and the areas you cover | No |
| Approximated | Where you point your own domain at a website we host, routes visitors to it | No. It carries your website's visitors, not your account or your customers' records |
That is the list. Several of these companies are established outside the UK;
where personal data reaches them, the transfer relies on UK adequacy
regulations or on the International Data Transfer Addendum to the EU Standard
Contractual Clauses, with a transfer risk assessment behind it. If the list
changes we will tell you at least 30 days before it does, and this policy
changes with it.
If you subscribe from outside the UK and the EEA, including from the United
States, your account data and the data you hold about your own customers is
transferred to and processed in the UK and the EEA, under the same protections
set out above. Nothing about where we operate reduces the rights this policy
gives you.
How long we keep it
While your subscription runs, plus 90 days after cancellation so you can return
or export, then erased, except invoices and contract records kept for the
legally required period.
- Files you delete yourself are held, marked for deletion, for 90 days
(accident protection, as set out in the Terms) and then permanently erased.
You can request immediate erasure instead and we will honour it.
- Review request records are erased 12 months after they are closed, or the
moment you erase them, whichever comes first.
- Activity and security records are kept for the life of the account; when an
account is deleted the people they referred to are gone, so what remains is
an action, a time and an address.
- Backups roll: 14 days on the machine, 35 days off-box. Anything erased from
the live Service disappears from the backups as that rotation completes, and
is never restored back in.
Your rights
Access, rectification, erasure, restriction, portability, and objection: ask
at hello@arcgabriel.com and we respond within one month. Where the data is
your customers' rather than yours, the request belongs to you as controller
and the Service lets you act on it yourself immediately; if one of your
customers contacts us directly, we will not answer for you; we will tell you
promptly and let you handle it.
You also have the right to complain to the Information Commissioner's Office
(ico.org.uk). We will notify you and the ICO of any breach where the law
requires it; where a breach affects data we hold on your behalf, we will tell
you within 24 hours of becoming aware of it so that you can meet your own
72-hour duty.
If you are in the United States
We do not sell your personal information, and we do not share it for
cross-context behavioural advertising. Depending on the state you live in, you
may have the right to know what personal information we hold about you, to have
it corrected or deleted, and to receive a copy, and we will not treat you
differently for asking. Email hello@arcgabriel.com to exercise any of these.
Where the data is your customers' rather than yours, you act on it yourself in
the Service, exactly as set out above.
Cookies
The Service uses only strictly necessary cookies (your sign-in session and
onboarding state). No advertising or cross-site tracking cookies. Our public
website counts page views without a cookie and without identifying anyone.