Effective Date: August 26, 2026

Arncur Privacy Policy


1. Scope and Information Collection

This Enterprise Privacy Policy outlines how Arncur (“we”, “our”, “us”) collects, processes, and protects corporate and personal data when clients (“Client”, “you”) access our AI-driven brand governance and regulatory compliance SaaS platform (the “Service”). We collect:

  • Account & Administrative Data: Names, corporate emails, role-based credentials, and billing information necessary for account provisioning.
  • Enterprise Content: Proprietary brand architecture, structural nomenclature, and compliance documents uploaded to the Service.
  • Telemetry & Cookies: Session tokens, API logs, IP addresses, and essential system cookies required for authentication and platform security. A detailed breakdown is available in our Cookie Policy dashboard.

2. AI Processing & Automated Decision-Making

Arncur utilizes artificial intelligence to provide structural recommendations and compliance flags. We strictly adhere to enterprise AI safety standards:

  • No Public Model Training: Client Data is processed in isolated environments and is strictly prohibited from being used to train, fine-tune, or augment public or shared generative AI models.
  • Human Oversight: Our Service provides automated insights intended to assist, not replace, human governance. Our models do not make legally binding automated decisions (per Article 22 of the GDPR) without Client configuration and human-in-the-loop validation.

3. Sub-Processors & Data Sharing

Arncur engages vetted third-party sub-processors (e.g., cloud hosting, secure infrastructure) to deliver the Service. These entities operate under strict Data Processing Agreements (DPAs). Arncur maintains a dynamic Sub-Processor Schedule within the Client dashboard. We provide thirty (30) days’ advance notice to registered administrators before authorizing any new sub-processor, granting Clients the right to object.

4. Cross-Border Transfers & Compliance

While Arncur operates from Lagos, Nigeria, our cloud infrastructure may necessitate global data routing. All international transfers of personal data are protected by Standard Contractual Clauses (SCCs) and comply with the Nigeria Data Protection Act (NDPA) and the General Data Protection Regulation (GDPR). We ensure all processing jurisdictions maintain adequate data protection safeguards.

5. Security & Incident Response SLAs

We deploy AES-256 encryption at rest, TLS 1.3 in transit, and mandatory Role-Based Access Controls (RBAC). In the event of a confirmed data breach impacting Client Data, Arncur commits to notifying the Client’s designated Data Protection Officer (DPO) or administrative contact without undue delay, and strictly within seventy-two (72) hours of confirmation, providing all required forensics and mitigation steps.

6. Data Retention & Deletion

Client Data is retained only for the duration of an active Master Subscription Agreement or to comply with legal obligations. Upon contract termination or verified request, all enterprise assets and associated personal data are permanently purged from our active databases within thirty (30) days.

7. Privacy Rights

Authorized users maintain full rights to access, correct, port, restrict, or delete their personal data. Enterprise administrators may execute these Data Subject Requests (DSRs) directly through the platform’s compliance portal.

8. Contact & Data Protection Officer (DPO)

Arncur has appointed a dedicated Data Protection Officer to oversee compliance. For privacy inquiries, DSRs, or audit requests, please contact:

  • Arncur Data Protection Office
  • Email: legal@arncur.com
  • Location: Lagos, Nigeria
  • Website: https://arncur.com/