ArcGabriel Privacy Policy

Version 1.4, September 2026

ArcGabriel is operated by ArcGabriel Ltd, a company registered in England and

Wales (company no. 17389329), registered office Carlile Institute Business Centre, 54 Huddersfield Road, Meltham,

Holmfirth HD9 4AE ("we"). We comply with UK GDPR and the Data Protection Act

2018, and we are registered with the Information Commissioner's Office. This

policy says what we collect, why, and your rights, briefly and honestly.

Two roles, and which one applies

For your own account we are the controller. Your name, your email, your

business details, your payment record, your sign-ins: we decide what to hold

and why, and this policy explains it.

For personal data about your customers we are your processor. A customer's

name and contact details you enter for a review request, people who appear in

photographs you upload, anyone you name in material you give us to publish,

that is your data about your people. You are the controller; we hold it and

work on it on your instructions, and on nobody else's. The terms governing that

are Schedule 1 to the [Terms of Service](/terms), which is drafted to satisfy

Article 28 of the UK GDPR, so you do not need a separate agreement from us.

The practical difference: for your own account, ask us. For your customers'

data, you decide, and the Service gives you erasure and export for every such

record without needing to ask anyone.

What we collect as controller, and why

DataWhy (lawful basis)
Account details (name, email, business name)To provide the Service (contract)
Signed agreement record (name, IP, timestamp, document hash)To evidence the contract (contract; legal obligation)
Payment recordsProcessed by Stripe; we hold no card numbers (contract; legal obligation)
Files and information you uploadTo do the marketing work you subscribe for (contract)
Connected account tokens (e.g. Meta, LinkedIn, Google)To publish on your instruction (contract). Encrypted at rest, and revocable by you at any time
Activity records (sign-ins, actions, IP addresses)Security and audit (legitimate interests)
Emails we send you about the ServiceOperating the Service (contract). Marketing email only with consent, withdrawable any time
Anonymous page counts on our own websiteUnderstanding what the site does (legitimate interests). No cookies, no cross-site tracking, no individual identification

We do not sell personal data. We do not use your data, or your customers', to

train artificial-intelligence models, ours or anyone else's.

What we process on your behalf, as your processor

Names and contact details of your customers, a short note of the work you did

for them, and the message we draft for you to send. Photographs and files you

upload, which may show identifiable people. Text you give us to publish.

We never contact your customers ourselves. Review requests are drafted for you

to send from your own email or phone, which is why the Service asks you to

confirm, for each person, that they are your customer and that you may contact

them, and why every drafted message gives them a plain way to say no.

Please do not enter special category data: health, beliefs, and the rest of

Article 9. The Service is not built for it.

Where it lives and who touches it

The application and its database run in the European Economic Area, and the

off-box backups are stored there. These are every sub-processor we use and what

each does:

WhoWhat they doTouches your customers' data?
RailwayHosts the application and the databaseYes: it is where the Service runs
CloudflareOff-box encrypted backups (R2); DNS and network protection for our sitesYes: backups include everything
StripeTakes card payments and holds the card details; we never see themNo
ResendSends the Service's emails to youNo
AnthropicWrites the marketing copy from the brief you give usNo. Only the text you provide for publication is sent, never your customer list, never your uploaded images
Meta (Facebook, Instagram), LinkedIn, GoogleReceive what publishing and reporting requires, on your instructionOnly where you name someone in content you approve for publishing
PexelsSupplies stock photographs when you ask us to find some. Receives the search words, which are built from your business description and the areas you coverNo
ApproximatedWhere you point your own domain at a website we host, routes visitors to itNo. It carries your website's visitors, not your account or your customers' records

That is the list. Several of these companies are established outside the UK;

where personal data reaches them, the transfer relies on UK adequacy

regulations or on the International Data Transfer Addendum to the EU Standard

Contractual Clauses, with a transfer risk assessment behind it. If the list

changes we will tell you at least 30 days before it does, and this policy

changes with it.

If you subscribe from outside the UK and the EEA, including from the United

States, your account data and the data you hold about your own customers is

transferred to and processed in the UK and the EEA, under the same protections

set out above. Nothing about where we operate reduces the rights this policy

gives you.

How long we keep it

While your subscription runs, plus 90 days after cancellation so you can return

or export, then erased, except invoices and contract records kept for the

legally required period.

(accident protection, as set out in the Terms) and then permanently erased.

You can request immediate erasure instead and we will honour it.

moment you erase them, whichever comes first.

account is deleted the people they referred to are gone, so what remains is

an action, a time and an address.

the live Service disappears from the backups as that rotation completes, and

is never restored back in.

Your rights

Access, rectification, erasure, restriction, portability, and objection: ask

at hello@arcgabriel.com and we respond within one month. Where the data is

your customers' rather than yours, the request belongs to you as controller

and the Service lets you act on it yourself immediately; if one of your

customers contacts us directly, we will not answer for you; we will tell you

promptly and let you handle it.

You also have the right to complain to the Information Commissioner's Office

(ico.org.uk). We will notify you and the ICO of any breach where the law

requires it; where a breach affects data we hold on your behalf, we will tell

you within 24 hours of becoming aware of it so that you can meet your own

72-hour duty.

If you are in the United States

We do not sell your personal information, and we do not share it for

cross-context behavioural advertising. Depending on the state you live in, you

may have the right to know what personal information we hold about you, to have

it corrected or deleted, and to receive a copy, and we will not treat you

differently for asking. Email hello@arcgabriel.com to exercise any of these.

Where the data is your customers' rather than yours, you act on it yourself in

the Service, exactly as set out above.

Cookies

The Service uses only strictly necessary cookies (your sign-in session and

onboarding state). No advertising or cross-site tracking cookies. Our public

website counts page views without a cookie and without identifying anyone.