Arcus ("Arcus," "we," "us," or "our")
This Privacy Policy describes how Arcus collects, uses, and discloses information when you visit our website at usearcus.ai (the "Site") or engage us for consulting and engineering services (the "Services").
01Information We Collect
Information you provide directly
- Contact information — name, email address, company name, job title, and phone number when you fill out a contact form, email us, or schedule a call.
- Business communications — the contents of messages, proposals, and correspondence you send us.
- Client engagement data — information you or your organization provide to us in the course of a consulting engagement, which may include business data, technical documentation, credentials for systems you authorize us to access, and other materials necessary to perform the Services.
Information collected automatically
- Usage data — pages visited, time spent, referring URLs, and general interaction with the Site.
- Device and log data — IP address, browser type, operating system, and device identifiers.
- Cookies and similar technologies — small data files used to operate the Site and understand how it is used. See Section 8.
Sources of information
We collect information directly from you and automatically through your use of the Site. We do not purchase personal information from data brokers or enrichment services.
Aggregated and de-identified data
We may create aggregated or de-identified data (such as statistics about Site usage) that can no longer reasonably be associated with you. We may use and retain such data for any lawful purpose, and we commit to not attempting to re-identify it.
We do not knowingly collect sensitive personal information (such as government identifiers, health information, or precise geolocation) through the Site.
02How We Use Information
We use the information we collect to:
- Respond to inquiries and communicate with you;
- Provide, perform, and manage consulting engagements;
- Send administrative information such as proposals, invoices, and engagement updates;
- Operate, maintain, and improve the Site;
- Analyze usage trends to improve our offerings;
- Comply with legal obligations and enforce our agreements; and
- Protect the security and integrity of our systems and Services.
We do not sell your personal information, and we do not use client engagement data for any purpose other than performing the Services, unless separately agreed in writing.
03Client Confidentiality
Information shared with us in the course of a consulting engagement is treated as confidential and handled in accordance with the applicable services agreement, statement of work, or non-disclosure agreement between Arcus and the client. Where the terms of a client agreement conflict with this Privacy Policy, the client agreement controls with respect to that engagement's data.
05Third-Party Service Providers
We use the following third-party services, which may process personal information on our behalf:
| Provider | Purpose | Data Location | Privacy Policy |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | United States | aws.amazon.com/privacy |
| Google Analytics | Website traffic and usage analytics | United States | policies.google.com/privacy |
| Google BigQuery | Data warehousing and analysis | United States | policies.google.com/privacy |
| Supabase | Database and application backend services | United States | supabase.com/privacy |
| Anthropic (Claude) | AI-assisted processing and service delivery | United States | anthropic.com/privacy |
| Google (Gemini) | AI-assisted processing and service delivery | United States | policies.google.com/privacy |
We do not permit these providers to use your personal information for their own purposes.
AI service providers
Certain internal workflows and service deliverables involve processing information through large language model APIs provided by Anthropic and Google. We use these providers' commercial API offerings, under terms that do not permit the provider to use submitted data to train their models.
Client engagement data is processed through AI services only as necessary to perform the Services and consistent with the applicable client agreement. Clients who require that their data not be processed by AI providers may specify this in their services agreement.
06Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, including to maintain business records, comply with legal obligations, resolve disputes, and enforce agreements. Analytics data may be retained in aggregated form indefinitely. Client engagement data is retained or deleted in accordance with the applicable services agreement; absent contrary terms, we delete or return client data upon written request following the conclusion of an engagement.
07Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction, and we limit access to personal information to personnel and contractors with a business need to know. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We maintain procedures for responding to suspected data security incidents. In the event of a breach affecting your personal information, we will notify you and any applicable regulators as required by law, including California's data breach notification statute.
09Marketing Communications
If you request information from us or engage our Services, we may send you communications about our services, work, or insights we think may interest you. We will obtain your consent before sending marketing emails where required by law, and every marketing email we send includes an unsubscribe link. Opting out of marketing does not affect administrative or engagement-related communications (such as proposals, invoices, or project updates). We will not share your contact information with third parties for their marketing purposes.
10Your Privacy Rights
California residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, may provide you with rights to:
- Know what personal information we collect, use, and disclose;
- Request deletion or correction of your personal information;
- Opt out of the sale or sharing of personal information (we do not sell or share personal information as those terms are defined under the CCPA); and
- Not be discriminated against for exercising these rights.
EEA, UK, and other jurisdictions
If you are located in the European Economic Area or the United Kingdom, you may have rights under the GDPR or UK GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing include performance of a contract, legitimate interests (such as operating and improving our business), and compliance with legal obligations. You may also lodge a complaint with your local supervisory authority.
How to exercise your rights
To exercise any of these rights, contact us using the information in Section 15. To protect your information, we will verify your identity before fulfilling a request — typically by confirming control of the email address associated with the information we hold, and by requesting additional information where reasonably necessary. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authorization. We respond to verified requests within the timeframes required by applicable law (generally 30 to 45 days), and we will notify you if we need additional time or cannot fulfill a request, along with the reason.
11International Transfers
We are based in the United States, and information we collect is processed and stored in the United States, including by the service providers listed in Section 5. If you access the Site or Services from outside the U.S., you understand that your information will be transferred to and processed in the U.S., which may have different data protection laws than your jurisdiction.
12Children's Privacy
The Site and Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13Third-Party Links
The Site may contain links to third-party websites and resources. We do not control these sites and are not responsible for their privacy practices. We encourage you to review the privacy policy of any site you visit.
14Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated "Last updated" date. Material changes will be communicated by reasonable means, such as a notice on the Site.
15Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact:
Arcus
Email: support@usearcus.ai
Questions about this policy?
For anything about this Privacy Policy, or to exercise your privacy rights, write to support@usearcus.ai.