Impressum
Last updated: September 30, 2026
This privacy policy explains how Arqh AG processes personal data when you visit www.arqh.ai, contact us, apply for a job, or do business with us. It follows the Swiss Federal Act on Data Protection (nDSG) and, where applicable, the EU and UK General Data Protection Regulation (GDPR).
1. Who is responsible
Arqh AG, Gussstrasse 26, 8180 Bülach, Switzerland
Contact for data protection: security@arqh.ch
2. EU/EEA & UK GDPR Representatives (Article 27)
If you are located in the EU or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:
EU Representative
Euverify Limited (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road
Cork, T23 AT2P, Ireland
Email: gdpr@euverify.com
UK Representative
Euverify Ltd (UK)
3rd Floor, 86-90 Paul Street
London, EC2A 4NE, United Kingdom
Email: gdpr@euverify.com
To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal at:
Euverify secure GDPR request portal
This link allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to ensure timely response and compliance.
3. What data we process and why
Website visits
When you visit www.arqh.ai, our hosting provider processes technical data (IP address, browser, pages visited, time) to deliver the website securely. To display fonts, your browser requests font files from Google Fonts (fonts.gstatic.com), sending your IP address and technical request data to Google LLC in the USA. We measure visits anonymously with PostHog and Framer Analytics, without cookies; PostHog discards IP addresses. Legal basis: our legitimate interest in running and improving the website (GDPR Art. 6(1)(f)). Details: see our Cookie Policy at www.arqh.ai/cookies.
Demo requests and contact
When you use the demo or contact form, we process your name, company, email address and message to answer you and arrange a demo. Legal basis: steps prior to a contract and our legitimate interest in answering requests (Art. 6(1)(b) and (f)).
Business contacts and sales
We store contact details of business contacts and prospects (name, business email and phone, job title, company, interaction history) in our CRM to manage customer relationships and contact potential business customers. Legal basis: legitimate interest in B2B communication (Art. 6(1)(f)). You can object at any time and we will stop contacting you. If we did not receive your data from you, it comes from your employer, a colleague who introduced us, your company’s public website or a business networking platform such as LinkedIn.
Customers
For customers we process contact and contract data to provide our services, support and invoicing. Legal basis: contract and legal obligations (Art. 6(1)(b) and (c)).
Platform users
If you use our platform as an employee of one of our customers, we process your account data (name, business email, employer, login and permission data), usage and security logs, and support correspondence to provide the platform, secure it and support you. Legal basis: contract with your employer and our legitimate interest in a secure service (Art. 6(1)(b) and (f)).
Job applicants
If you apply, we process your application documents and interview notes to assess your application. Legal basis: steps prior to an employment contract (Art. 6(1)(b)); consent if you agree to stay in our talent pool (Art. 6(1)(a)).
4. Data we process on behalf of our customers
When our customers use our platform, we process the related personal data as a processor on the customer’s instructions. The customer is the controller for this data; please contact the respective company for questions about it. Details are governed by our Data Processing Agreement with each customer. We do not use this data to train AI models.
5. Who receives your data
We use carefully selected service providers who process data on our behalf under data processing agreements, in these categories: website hosting and analytics, cloud hosting and infrastructure, email and collaboration tools, CRM, software and AI service providers, telephony, bookkeeping and payroll, and employer-of-record services. Google LLC (USA) receives technical request data when your browser loads Google Fonts. We do not sell personal data. We disclose data to authorities only where required by law.
6. Transfers abroad
Some providers are located in, or can access data from, countries without an adequate level of data protection, in particular the USA. In these cases we use the EU Standard Contractual Clauses (with the Swiss addendum) or equivalent safeguards. You can request a copy of these safeguards from us.
7. How long we keep data
Website log data: short term, as set by our hosting provider. Platform security and usage logs: 12 months. Platform account data: contract term of your employer, deleted within 30 days of its end. Demo and contact requests: up to 24 months after the last contact. Business contacts and prospects: 24 months after the last contact, or immediately if you object. Customer and contract data: contract duration plus 12 months; accounting records 10 years (Swiss Code of Obligations Art. 958f). Applications: 3 months after the decision, or up to 24 months with your consent.
8. Your rights
You have the right to access, rectify and delete your data, to restrict or object to processing, to data portability, and to withdraw consent at any time with effect for the future. You can also object to direct marketing at any time, and you have the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects. To exercise your rights, email security@arqh.ch or, if you are in the EU/EEA or UK, contact our representative (section 2). We may need to verify your identity and respond within one month.
You can lodge a complaint with a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch), in the EU/EEA the authority of your country of residence, in the UK the Information Commissioner’s Office (ICO).
9. Security
We protect personal data with technical and organisational measures, including encryption, multi-factor authentication, role-based access and logging. Our information security management system is aligned with ISO/IEC 27001.
10. Changes
We may update this policy. The current version is always published at www.arqh.ai/privacy with its date. We inform customers and platform users by email about material changes.