Privacy Policy
1. Scope of This Policy
This Privacy Policy explains how Archon AI Inc. ("Company," "we," "us," or "our") collects, uses, and protects information in connection with our software platform (the "Service").
Two categories of data are addressed differently in this policy:
- Account and Business Contact Data — information about our business customers and their administrators/Authorized Users that we collect directly (e.g., for account setup, billing, and support). This policy governs that data directly.
- Customer Data — the data, content, and records that our business customers ("Customers") and their employees upload to or generate within the Service.
Company processes this data on behalf of our Customers, acting as a service provider/processor. If you are an employee of one of our business Customers and have questions about how your data is used within the Service, please contact your employer's administrator. Customer's own privacy notices and policies govern its collection of employee data; our handling of that data on Customer's behalf is governed by our agreement with that Customer (including any data processing terms) rather than by this policy.
2. Information We Collect
2.1 Information You Provide
- Account registration information (name, work email, company name, job title)
- Login credentials (passwords are stored using industry-standard hashing; we do not store plaintext passwords)
- Billing and payment information (processed via our payment processor; we do not store full payment card numbers)
- Support requests and correspondence
2.2 Information Collected Automatically
- Usage data (pages visited, features used, timestamps, actions taken within the Service)
- Device and log data (IP address, browser type, operating system)
- Cookies and similar technologies used for authentication/session management and basic analytics
2.3 Customer Data Processed on Behalf of Customers
Data, content, configurations, and records that Customers and their Authorized Users input or generate within the Service. We process this data only as instructed by the Customer and as necessary to provide the Service.
3. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service
- Authenticate users and manage account roles/permissions
- Send notifications or alerts through channels Customer configures, where applicable
- Process billing and manage subscriptions
- Provide customer support
- Monitor, secure, and improve the Service, including diagnosing technical issues
- Comply with legal obligations
We do not use Customer Data to train general-purpose models or for any purpose unrelated to providing the Service, except as the Customer separately authorizes in writing.
4. Third-Party Service Providers
We use third-party service providers to operate the Service, including:
- Cloud hosting and database providers, to store and process data
- Integration and notification providers, where Customer elects to connect a third-party service for certain functionality. That third party's own privacy practices govern its handling of any data it receives.
- Payment processors, to handle billing
We require service providers who process data on our behalf to maintain appropriate confidentiality and security protections. We do not sell personal information to third parties.
5. Data Retention
- Account data is retained for as long as the account is active and for a reasonable period afterward for legal, billing, and recordkeeping purposes.
- Customer Data is retained for the duration of the applicable subscription and made available for export for a defined period following termination, as described in the Terms of Service or applicable order form, after which it may be deleted.
- We may retain limited information longer where required by law or for legitimate business purposes such as dispute resolution.
6. Data Security
We use administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, or disclosure, including encryption in transit, access controls, and authentication safeguards for stored credentials. No system can be guaranteed 100% secure, and we cannot guarantee the absolute security of information.
7. Your Rights and Choices
Depending on your role:
- Authorized Users of a business Customer should direct requests about their personal data (access, correction, deletion) to their employer's administrator, who can submit such requests to us.
- Business Customer administrators can manage user account information directly within the Service's settings pages, or contact us for assistance.
- We will respond to verified requests consistent with our contractual obligations to the relevant Customer and applicable law.
8. Children's Privacy
The Service is intended for business use by employees of our Customers and is not directed to individuals under 18. We do not knowingly collect personal information from children.
9. Data Location and Transfers
We currently operate the Service and store data within the United States. If this changes, we will update this Policy accordingly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last Updated" date and, for material changes, will provide reasonable notice to Customer administrators.
11. Contact Us
Questions about this Privacy Policy can be directed to:
legal@getarchon.ai
Archon AI Inc.