Privacy Policy
Version 1.0 · Last updated: 18 July 2026
This Privacy Policy explains how Arkavio Ltd (“Arkavio”, “we”, “us”) collects and uses personal data when you use the Arkavio website at arkavio.com and the Arkavio application (together, the “Service”). It should be read with our Cookie Policy and, for business customers, the Data Processing Agreement.
1. Who we are
Arkavio Ltd is a company incorporated in England (company number 17157509), registered office 7 The Broadway, Wembley, London HA9 8JT. We are registered with the UK Information Commissioner’s Office (ICO) as a data controller.
Contact for privacy matters: privacy@arkavio.com.
2. Our two roles — controller and processor
Arkavio handles personal data in two different capacities, and this matters for your rights:
- As a controller. For personal data about the people who run and use a customer account — account administrators and Authorised Users (e.g. their name, work email, role, billing and usage data) — and about website visitors and prospects. This Privacy Policy governs that data, and we decide how it is used.
- As a processor. When an architecture practice (our customer) uploads personal data about its own clients, contacts, and staff (including names, contact details, job titles, salary/cost data and timesheets), the practice is the controller and Arkavio is the processor acting on its instructions. That processing is governed by the DPA, not by this Policy, and data-subject requests about it should be directed to the relevant practice.
3. What personal data we collect
| Category | Examples | Our role |
|---|---|---|
| Account data | Work email (personal-email domains are blocked), name, phone, role | Controller |
| Organisation data | Practice name, registered/trading address, company & VAT numbers, RIBA/ARB numbers, financial settings, and the practice's own bank account details (account name, sort code, account number) used to receive client payments and shown on the invoices you issue | Controller |
| Billing data | Subscription status, plan, Stripe customer/subscription identifiers (card data is held by Stripe, not us) | Controller |
| Usage & device data | Pages viewed, features used, log-in events, IP address, browser/device info | Controller |
| Analytics & session replay | Product analytics events; anonymised, input-masked session recordings — only with your consent | Controller |
| In-app feedback | Feedback you actively submit through the in-app “Give feedback” widget (your message, its category, and the page you were on), stored with our analytics provider (PostHog, EU region) | Controller |
| Cookie-consent records | Your cookie choices, with a hashed (not raw) IP, retained as a compliance audit record | Controller |
| Founding Partner applications | Contact name, work email, practice name and size, motivation, marketing attribution | Controller |
| Communications | Emails and messages you send us | Controller |
| Customer-uploaded data | Your clients, contacts, projects, staff cost data, timesheets, invoices | Processor (see DPA) |
We do not intentionally collect special-category data through the Service and ask that you do not upload it. Note that staff salary/cost data, while not a special category under UK GDPR, is sensitive and is protected accordingly.
4. Lawful bases for processing (controller data)
We rely on the following UK GDPR Article 6 bases:
- Contract — to create your account, provide the Service, take payment, and provide support.
- Legitimate interests — to secure the Service, prevent abuse and fraud, understand and improve how the Service is used, and to administer the Founding Partner programme. We balance these against your rights.
- Consent — for non-essential cookies, product analytics, session replay and any marketing where consent is required. You can withdraw consent at any time (see clause 8 and the Cookie Policy).
- Legal obligation — to keep financial records and comply with tax and accounting law.
5. How we use personal data
To provide, operate, secure and support the Service; to process payments and manage subscriptions; to communicate with you about your account and service updates; to provide customer support; to understand and improve the Service (analytics, with consent where required); to administer the Founding Partner and beta programmes; and to comply with our legal obligations.
We do not sell personal data, and we do not use Customer Data to train third-party AI models.
6. Sub-processors and who we share data with
We use a small number of trusted service providers (“sub-processors”) to run the Service. The current list, with purpose, data and location, is maintained in Annex 3 of the DPA and summarised here:
- Supabase — database, authentication and file storage (hosted within the UK/EU)
- Stripe — subscription billing and payment processing (US; UK/EU safeguards in place)
- Resend — transactional email (US)
- PostHog— product analytics and session replay, consent-gated (EU region). Also stores in-app feedback you actively choose to submit through the “Give feedback” widget — that submission is sent server-side when you press send, so it does not depend on your cookie choices
- Sentry — error and performance monitoring, with personal data minimised (US)
- Vercel — application hosting and content delivery (US)
- Cloudflare — bot/abuse protection (Turnstile) on public forms
- Google Places API — address autocomplete and lookup when you enter practice or client addresses (US)
- Adobe Fonts — web font delivery
We may also disclose personal data where required by law, to enforce our terms, or in connection with a merger or acquisition (with appropriate safeguards).
7. International transfers
Some sub-processors are located outside the UK (for example, in the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and/or transfers to countries covered by UK adequacy regulations. We do not rely on the invalidated EU-US Privacy Shield.
8. Your rights
Under UK GDPR you have the right to: be informed; access your data; rectification; erasure; restrict processing; data portability; object to processing; withdraw consent; and not to be subject to solely automated decisions with legal effect (we do not carry out such decision-making).
You can export your organisation’s data directly from within Arkavio at any time (for example, invoices and timesheets to CSV, and proposals and invoices to PDF), and your data remains available for export for 30 days after your account ends. To request erasure of your account and data, or to exercise any other right relating to data for which we are the controller, contact privacy@arkavio.com. We will respond within one month (extendable for complex requests, with notice) and may need to verify your identity. Erasure is subject to data we must keep by law (for example, financial records retained for 6 years — see clause 9).
For data we process as a processor on a practice’s behalf, please direct your request to that practice; we will assist them as required by the DPA.
9. Data retention
We keep personal data only as long as necessary:
- Account and Customer Data — for as long as your account is active. After termination we make data available for export for 30 days, then delete or anonymise it (see the Terms and the DPA).
- Financial records — retained for 6 years to meet UK tax and accounting obligations.
- Cookie-consent records — retained as a compliance audit trail.
- Analytics data — retained for up to 12 months.
10. Security
We protect personal data with technical and organisational measures including row-level security (data is scoped per organisation), role-based access, encryption in transit and at rest, masked session replay, and hashing of IP addresses in consent records. See our Security overview for detail.
11. Cookies
We use strictly necessary cookies to run the Service and, only with your consent, optional cookies for analytics and session replay. We do not use advertising or cross-site tracking cookies. See the Cookie Policyand use the “Cookie settings” link in our footer to change your choices.
12. Children
The Service is a B2B product and is not directed at children. We do not knowingly collect data from anyone under 18.
13. Complaints
If you have a concern we have not resolved, you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk. We would appreciate the chance to address it first via privacy@arkavio.com.
14. Changes
We may update this Policy. We will post the updated version here with a new date and, where the change is material, notify you and seek fresh consent where required.
15. Contact
Arkavio Ltd— 7 The Broadway, Wembley, London HA9 8JT, England · info@arkavio.com