Legal · Arca Labs
Privacy Policy.
How Arca Labs Ltd collects, uses and protects personal data when you visit our website, email us, or interact with the Arca platform. Written to comply with UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
01Who we are
This website (arcalabs.io) is operated by Arca Labs Ltd, a company registered in England and Wales under company number 17120412, with its registered office at 45 Whittington Chase, Kingsmead, Milton Keynes, Buckinghamshire, MK4 4HL.
Arca Labs Ltd is the data controller responsible for the personal data described in this policy and is registered with the UK Information Commissioner's Office under registration number ZC128488. References to "we", "us" or "our" mean Arca Labs Ltd. References to "you" or "your" mean any visitor to our website or individual who corresponds with us.
02Personal data we collect
We collect personal data in the following ways:
Information you give us directly
- Contact enquiries. If you email us, we receive your name, email address and the content of your message.
- Partnership / operator enquiries. Where you approach us about licensing the Arca platform we may collect your business name, role, contact details and information about your proposed operator skin.
- Correspondence. Any information you choose to include in messages, calls or meetings with us.
Information collected automatically
- Device and browser data. IP address (truncated where possible), browser type and version, operating system, screen resolution and referring URL.
- Usage data. Pages visited, time spent, interactions with features, and similar analytics signals — collected via PostHog EU (see Cookies Policy) only where you have consented to optional analytics cookies.
- Log data. Server logs (including IP address, timestamps, request paths and error information) collected for security, debugging and abuse-prevention purposes.
Information from third parties
- Email service provider. When you email us, our email provider (Microsoft 365) processes message metadata and content.
- Analytics provider. PostHog EU receives anonymised product-analytics events, subject to your cookie consent.
03How we use your data
We use personal data for the following purposes:
- Responding to enquiries
- To reply to messages you send us and to manage ongoing correspondence about the Arca platform, operator partnerships or general enquiries.
- Operating our website
- To serve, secure and maintain
arcalabs.io, including protecting against abuse, fraud and service disruption. - Analytics and improvement
- To understand how visitors use our website and to improve content, UX and the Arca product. Performed via PostHog EU only with your consent.
- Legal and compliance
- To comply with our legal obligations (tax, accounting, anti-money-laundering, responding to lawful requests from authorities).
- Operator due-diligence
- Where you approach us about licensing Arca, to assess fit, conduct basic due-diligence and negotiate commercial terms.
04Lawful bases for processing
Under UK GDPR we must have a lawful basis for each processing activity. We rely on the following:
- Consent (Art. 6(1)(a)). For optional analytics cookies and for any direct marketing emails you opt into. Consent can be withdrawn at any time — see Your rights.
- Contract (Art. 6(1)(b)). To take steps at your request before entering a licensing agreement, and to perform our obligations under any resulting agreement.
- Legitimate interests (Art. 6(1)(f)). For responding to unsolicited enquiries, securing our website, maintaining business records and pursuing partnership opportunities where our interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)). Where processing is required by UK law (e.g. tax records, statutory disclosures).
05Who we share data with
We do not sell personal data. We share it only with trusted service providers and where required by law:
| Recipient | Purpose | Location |
|---|---|---|
| PostHog EU | Product analytics (consent-based) | Frankfurt, Germany (EU) |
| Microsoft 365 | Business email | UK & EU |
| Leaseweb NL | Website hosting & CDN | EU |
| Professional advisers | Legal, accounting, insurance | UK / EU |
| Authorities | Where required by law (e.g. HMRC, ICO, court orders) | UK |
Each processor is bound by a written data-processing agreement requiring appropriate security, confidentiality and processing limits.
06International data transfers
Where personal data is transferred outside the United Kingdom or European Economic Area, we rely on one of the following safeguards:
- Adequacy decisions made by the UK Government or European Commission for the destination country.
- UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses with the UK Addendum, where adequacy is not in place.
- Your explicit consent where neither of the above applies and the transfer is genuinely necessary.
Our primary analytics provider, PostHog EU, hosts data in the European Union (Frankfurt), keeping product-analytics data within EU jurisdiction.
07How long we keep data
We retain personal data only for as long as we have a lawful purpose to do so:
- Contact correspondence
- Retained for up to 3 years after the last contact, unless an active partnership discussion requires longer.
- Commercial agreements
- Retained for 7 years after termination, to meet contractual, tax and accounting obligations.
- Analytics data
- PostHog EU events are retained for 12 months after collection, then aggregated and deleted.
- Server logs
- Retained for up to 90 days, then deleted or aggregated.
- Marketing consent records
- Retained for the duration of consent plus 24 months, as evidence of compliance.
08Your rights
Under UK GDPR you have the following rights in relation to your personal data:
- Right of access. A copy of the personal data we hold about you.
- Right to rectification. Correction of inaccurate or incomplete data.
- Right to erasure. Deletion of data in specified circumstances ("right to be forgotten").
- Right to restriction. Limiting how we process your data while a query is resolved.
- Right to data portability. A machine-readable copy of data you provided to us.
- Right to object. To processing based on legitimate interests or for direct marketing.
- Right to withdraw consent. Where we rely on consent (e.g. analytics cookies, marketing emails). Withdrawal does not affect the lawfulness of processing before withdrawal.
- Rights relating to automated decisions. We do not currently carry out automated decision-making that produces legal effects.
09Cookies and tracking
We use strictly necessary cookies to operate the site and optional analytics cookies (via PostHog EU) only where you have given consent. No advertising, marketing or cross-site tracking cookies are used.
Full details — including what each cookie does, how long it lasts, and how to change your choices — are in our Cookies Policy.
10Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or disclosure. These include TLS encryption in transit, access controls, principle-of-least-privilege, vendor due-diligence, and regular review of our security practices.
No system can be guaranteed 100% secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and, where the risk is high, notify affected individuals without undue delay.
11Children's data
Arca Labs Ltd's website and platform are intended for business and professional audiences. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
12Changes to this policy
We may update this policy to reflect changes in our practices or legal obligations. Material changes will be highlighted at the top of this page for at least 30 days before they take effect. The "Effective" date above tells you the current version.
13Contact & complaints
For any question, request or concern about privacy at Arca, contact:
- privacy@arcalabs.io
- Post
- Privacy, Arca Labs Ltd, 45 Whittington Chase, Kingsmead, Milton Keynes, Buckinghamshire, MK4 4HL
If you are unhappy with how we have handled your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO):
- ICO
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk · 0303 123 1113
We appreciate the chance to address your concerns first, before you approach the ICO.