Privacy Policy
Welcome to Arkai! We take your privacy very seriously. This Privacy Policy explains how we, operating under the ownership of Enzo Barbon Lema ("we", "us", "our"), collect, use, store, and protect your personal information when you visit our website and use our B2B SaaS platform Arkai (the "Platform") to create and run workflows and Artificial Intelligence (AI) agents.
Our goal is to be transparent about how we handle your data so you can use Arkai with confidence.
1. Data Controller
The person responsible for processing your personal data is:
Name: Enzo Barbon Lema
Address: Camino del Molino de Gilledo, 480, Gijón, Asturias, Spain
Contact email for privacy: info@arkai.app
2. Information We Collect
We collect different types of information depending on how you interact with us:
If you only visit our website: We use Google Analytics to collect information on how visitors use our site (pages visited, time spent on the page, etc.). This helps us understand visitor interests and enhance our marketing and website. These data are generally aggregated and do not personally identify you directly, although they may include your anonymized IP address. For more details, check our Cookie Policy.
If you register and use the Arkai Platform:
Account Information: We collect the information you provide when you register or complete your profile: your email address, your name (if provided), your job title, your company's sector, your self-perceived level of AI knowledge, your language, and your country.
Billing Information: When you subscribe to a paid plan, billing information (such as credit card details) is collected and processed directly by our third-party payment provider, Stripe. We do not store full card details, though we may access limited transaction information (such as the type of plan or payment date) to manage your subscription. You can manage your payment information through your account on our platform, interacting with the Stripe interface.
Platform Usage Information: We may record how you interact with the Platform, which features you use, etc., to improve the service and provide support.
Data Processed when Using AI:
Input Data in "Conversations": When you interact with the AI or execute workflows, the data you input (texts, questions, commands) are temporarily stored in what we call "conversations" so you can view your recent history. These conversation data are private and are automatically deleted every week.
Data in Flow Configurations: If you save specific data as part of a workflow or AI agent configuration (e.g., a fixed instruction, an API key for another service, etc.), those data will remain stored as part of your flow until you decide to delete that workflow. You have control over these data.
External AI Providers: For workflows to function, we need to send your input data to external AI model providers (third parties). It's important to know that we select providers who commit to NOT using your data to train their own AI models and not storing them beyond what is strictly necessary for temporary technical logs, generally for short periods. Requests are made aiming to protect your privacy as much as possible.
3. How We Use Your Information (Purpose)
We primarily use the information we collect to:
Provide and manage the service: Create your account, allow you to build and execute AI workflows, and give you access to platform features.
Billing and payment management: Process your payments via Stripe and manage your subscription.
Improve the Platform: Analyze how the service is used (in aggregate or anonymized form whenever possible) to find areas for improvement, fix bugs, and develop new features.
Communicate with you: Send you important emails about your account, service updates, policy changes, or respond to your support requests.
Marketing (Web Visitors): Understand our website traffic to optimize our marketing campaigns (based on Analytics data).
4. Legal Basis for Processing (Why We Can Use Your Data)
We process your personal data primarily based on:
Contractual Necessity: We need to process your account, usage, and flow data to provide you with the Arkai service you have contracted.
Legitimate Interest: We have a legitimate interest in analyzing our website and platform usage (in anonymized or aggregate form if possible) to improve our services and in securing the platform. Also, to communicate with you about essential service aspects.
Consent: For the use of certain cookies (like those for Google Analytics), we rely on your consent, which you can manage through our cookie banner.
5. How We Share Your Information (Third Parties)
We do not sell your personal data. We only share your information with trusted third parties when necessary to operate and enhance Arkai:
Payment Provider: Stripe processes your payments. We share the information necessary to manage your subscription. Stripe operates under its own privacy policies.
Cloud Hosting Provider: We use Microsoft Azure to host our platform and your data. Our primary servers are located in Europe.
Web Analytics Provider: Google Analytics helps us analyze web traffic. We configure Google Analytics to respect your privacy as much as possible (e.g., IP anonymization if enabled).
AI Model Providers: As explained earlier, to execute your workflows, we send the necessary input data to external AI model providers. These providers are contractually obliged (according to our agreements with them and their policies) not to use your data for their own purposes (like training) and to maintain confidentiality.
We ensure these third parties offer sufficient guarantees to protect your information.
6. International Data Transfers
While our primary servers are in Europe (Azure), some of our providers (like Stripe, Google Analytics, and potentially some AI providers) may be located or process data outside the European Economic Area (EEA), mainly in the United States. When this occurs, we ensure there are adequate safeguards to protect your data, such as the European Commission's Standard Contractual Clauses (SCCs) or these providers' adherence to recognized frameworks like the EU-U.S. Data Privacy Framework (DPF).
7. Security of Your Data
We take the security of your data very seriously. We implement appropriate technical and organizational measures to protect your information from unauthorized access, alteration, disclosure, or destruction. We use reputable providers (like Azure) and follow standard security practices. However, no system is 100% secure, so we cannot guarantee absolute security.
8. Data Retention (How long we keep your data)
We retain your personal information only for as long as necessary for the purposes for which it was collected:
Your Account Data: As long as you maintain an active account with us. If you delete your account, we will delete your associated personal data, except those we need to retain by legal obligations (e.g., billing data during the required fiscal period).
Input/Output Data in "Conversations": Automatically deleted every week.
Data in Flow Configurations: Remain until you delete the corresponding workflow.
Google Analytics Data: Kept according to our configuration set in Google Analytics.
9. Your Data Protection Rights
Under the GDPR, you have several rights regarding your personal data:
Access: Right to know what data we have about you and to obtain a copy.
Rectification: Right to correct incorrect or incomplete data.
Erasure ("Right to be Forgotten"): Right to request that we delete your data under certain conditions.
Restriction of Processing: Right to request that we restrict the use of your data under certain conditions.
Object: Right to object to us using your data for certain purposes (like direct marketing, if applicable).
Portability: Right to receive your data in a structured format and to transfer it to another controller, when technically feasible.
You can exercise most of these rights directly from your account settings on the Arkai Platform. For any other request or if you have questions, please contact us at info@arkai.app.
You also have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe we have not handled your data adequately.
10. Cookie Policy
We use cookies and similar technologies. For more information on which cookies we use, why, and how you can manage them, please refer to our [Cookie Policy / Cookie Section].
11. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. If we make significant changes, we will notify you through the Platform or by email before the change takes effect. We encourage you to review this page periodically.
12. Contact
If you have any questions about this Privacy Policy or how we handle your data, please feel free to contact us at: info@arkai.app.