Privacy

Privacy Policy

This privacy policy explains which personal data we process when you visit the website, contact us, log in, or use the Arqlee platform.

Last updated: June 16, 2026

1. Controller

The controller responsible for data processing is the Arqlee provider named in the legal notice. You can use the contact details listed there for privacy-related requests.

2. Website Access and Server Logs

When you access our website and platform, technically necessary access data is processed so that the pages can be delivered, secured, and operated reliably.

  • IP address, date and time of access
  • requested URL, referrer URL and HTTP status
  • browser, operating system and transferred data volume
  • Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in security, error analysis and stable operation

3. Contact Form

If you contact us through the contact form, we process your information to handle the request and, where applicable, to initiate a contractual relationship.

  • Name, email address, company, role, subject and message
  • Email delivery via an email service provider
  • Legal basis: Art. 6(1)(b) GDPR for pre-contractual requests, otherwise Art. 6(1)(f) GDPR

4. Login, User Account and Platform Access

For protected platform areas, we use passwordless login via magic link and a specialized authentication provider. Authentication and session data is processed to identify users and secure customer and project access.

  • Email address, user ID, login status, session and refresh tokens
  • Customer, project and role information for access control
  • Necessary cookies for authentication and session continuity
  • Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR

5. Portfolio, Import and Analysis Data

Arqlee processes portfolio, architecture and technology data uploaded by customers or provided through integrations. Typical data includes application names, technologies, costs, lifecycle information, criticality, vendors, dependencies and architecture relationships. The professional analyses are designed to run without personal data in these datasets. Personal data may still be processed for platform access, communication, role and rights management, or where individual customer-provided fields contain application owners, contacts or email addresses.

  • Purpose: platform use, import, structuring, analysis and creation of analysis results
  • Data minimization: personal fields should be removed, pseudonymized or replaced with roles, teams, departments or neutral IDs before being provided
  • Benchmarks: anonymized, aggregated structural patterns and benchmark metrics may be derived from project and analysis results unless benchmark use is contractually excluded; these contain no personal data, company names, raw data or identifiable customer details
  • Pseudonymization: personal fields are removed or reduced before AI processing where possible
  • Legal basis: Art. 6(1)(b) GDPR for service delivery

6. AI Analysis and Model Providers

Arqlee may use external AI services for analysis, for example large commercial model providers such as Anthropic, OpenAI or Google. We do not use customer data to train our own models. For external AI providers, we use commercial API endpoints and privacy controls where available to exclude or restrict use of inputs for model training.

  • Only data required for the specific analysis purpose is transmitted
  • Special categories of personal data under Art. 9 GDPR should not be uploaded or entered into prompts
  • The concrete provider and sub-processor list is documented in the DPA
  • Legal basis: Art. 6(1)(b) GDPR; where processing is not contractually required, Art. 6(1)(f) GDPR

7. Recipients and Service Providers

We use service providers that support us with website and platform operation, authentication, email delivery, hosting, storage and AI processing. When selecting infrastructure, we prefer hosting regions in Germany where possible. Where this is not available or appropriate for the specific service, we prefer hosting within the EU. Service providers process data only for the respective purposes and under contractual requirements.

  • Hosting and infrastructure providers for frontend, backend, database and storage functionality
  • Authentication providers for login, sessions and access control
  • Email service providers for transactional emails and contact requests
  • Selected AI model providers for analysis calls
  • Additional sub-processors are listed transparently in the DPA

8. International Transfers

Some service providers or their sub-processors may process personal data outside the EU/EEA. Where this occurs, we rely on appropriate transfer mechanisms, in particular EU Standard Contractual Clauses, adequacy decisions, or additional contractual and technical safeguards.

9. Cookies and Local Storage

We currently do not use non-essential marketing or analytics cookies. Necessary cookies or similar storage technologies may be used for login, session continuity, language settings and technical security. They are required to provide the platform functionality explicitly requested by the user.

10. Retention and Deletion

We store personal data only for as long as required for the relevant purpose or by statutory retention obligations. Contact requests are deleted once fully handled unless legal or contractual reasons require further storage. Customer, project, import and analysis data is deleted according to the contract, DPA or a valid deletion request. Anonymized, non-identifiable benchmark metrics may be stored for longer; they contain no personal data, company names, raw data or identifiable customer details.

11. Your Rights

Data subjects have GDPR rights to access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, consent can be withdrawn at any time with effect for the future.

12. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

13. Security

We protect data through technical and organizational measures, including encrypted transmission, role-based access control, authentication, access restrictions and separated customer and project contexts. These measures are adapted to risk, the state of the art and product development.

14. Changes to this Privacy Policy

We update this privacy policy when our processing, service providers or legal requirements change. The version published on this page applies.

Provider details are available in the legal notice.