Legal

Privacy Policy

Effective date: 29 July 2026. Last updated: 29 July 2026. Operator and controller: Arkmurus Limited.
Important privacy information This notice explains how Arkmurus Limited handles personal data through ARIA. It is not a substitute for a customer-specific data processing agreement where Arkmurus Limited processes personal data on a customer's documented instructions.

1. Who we are

ARIA is operated by Arkmurus Limited (company number 16028039), registered in England and Wales, whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Arkmurus Limited is the data controller for account administration, service operation, security, billing, communications and its own product improvement. ARIA is a domain-specialised AI assistant for security and defence due-diligence work. See the model card for the capability statement.

Contact us about privacy, access, correction, deletion or any other data-protection right at support@imaria.io, or by post at the registered office above, marked “Data Protection”. We have not appointed a data protection officer; privacy enquiries are handled by Arkmurus Limited.

2. What this policy covers

This policy covers personal data we process when you:

  • Sign up for or use the ARIA web product, WhatsApp interface, or the (forthcoming) public API.
  • Submit a registration request that requires admin approval.
  • Send us an email at an address we operate, including support@imaria.io or aria@imaria.io.
  • Receive a daily intelligence briefing or watchlist alert from us.

For personal data about third parties that a business customer submits for due diligence or employment vetting, the customer will normally be the controller and Arkmurus Limited will act as processor under the applicable agreement (see §10). Arkmurus Limited may remain an independent controller for limited purposes required by law or necessary to protect the service, such as security logging and responding to lawful requests.

3. What personal data we collect

From you, directly

CategoryExamplesRequired?
Account identifiersUsername, full name, email address, hashed passwordYes
Organisation contextAccount type (individual / company), company name + country + size, sector, job titleOptional
Use-case contextPrimary use cases, region focus, languages, volume estimate, compliance needs, free-text purpose statementOptional
Conversation contentThe messages you send to ARIA + ARIA's repliesGenerated when you use the product
Document uploadsPDFs, DOCX, XLSX, images you upload for analysisGenerated when you upload
Communication preferencesNotification toggles (digest, flash, push, Telegram), Telegram usernameOptional
Billing identifiersStripe customer ID + subscription ID once you subscribe (no card data; Stripe holds those)Optional / generated on subscribe
Support and business communicationsYour correspondence with us, enquiries, feedback and request historyGenerated when you contact us

Automatically

CategoryExamples
Usage telemetryDaily message counts, daily upload counts, monthly DD-run counts (the per-user quota counters in lib/billing/quotas.mjs and aria_service/intel/user_quota.py)
Audit-log entriesEach material claim ARIA produces with timestamp, source citations, confidence tag, source-tier breakdown: hash-chained and HMAC-signed (see model card §7)
Cost telemetryPer-call LLM cost (provider, model, input/output tokens, latency), used for the monthly cap enforcement
Server logsHTTP request method / path / status / IP address / user-agent for the duration the host (fly.io) retains them
Device storageStrictly necessary authentication, security and preference data stored in cookies or browser storage

4. Why we process this data (legal bases)

PurposeDataUK GDPR lawful basis
Register users, authenticate accounts, provide requested chat, document analysis, alerts and supportAccount, organisation and use-case details; conversations; uploads; preferences; support communicationsContract (Art. 6(1)(b)) where you contract personally; otherwise our legitimate interests (Art. 6(1)(f)) in providing and administering the service to your organisation
Operate quotas, maintain auditability, diagnose faults, prevent fraud and secure ARIAUsage, cost and audit telemetry; server and security logsLegitimate interests (Art. 6(1)(f)) in reliable, secure and accountable service operation
Administer subscriptions, invoices, tax and financial recordsAccount, transaction and billing identifiersContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Send requested operational messages and service noticesContact details and communication preferencesContract (Art. 6(1)(b)) or legitimate interests (Art. 6(1)(f))
Send optional electronic marketingContact details, preferences and engagementConsent (Art. 6(1)(a)) where PECR requires it; otherwise legitimate interests where law permits. You may unsubscribe at any time.
Comply with binding law, court orders and regulatory requirements, and establish or defend legal claimsRelevant recordsLegal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)), as applicable

Where we rely on legitimate interests, we assess necessity and balance those interests against the person's rights. You may object as explained in §7. We do not rely on consent merely because a profile field is optional. If we ask for consent, refusing or withdrawing it will not affect processing already carried out lawfully or prevent use of unrelated service features.

Please do not submit special-category data (such as health, biometric, political-opinion or religious data) unless it is necessary, lawful and expressly supported by the relevant ARIA workflow. Criminal-offence data is subject to the additional controls in §10b.

5. Who we share data with

We use suppliers and sub-processors to operate ARIA. A supplier receives only the information needed for the relevant function and is subject to appropriate contractual and security controls. The providers actually used depend on the enabled feature and current configuration:

ProcessorPurposeWhat's shared
Approved production LLM providers, which may include Anthropic, OpenAI, Mistral, Groq or OpenRouterAI reasoning, used only when the provider is configured, contractually approved and invokedConversation content, relevant document extracts and system instructions needed to answer the request.
Sanctions and corporate-data sources, which may include OpenSanctions and Companies HouseRequested screening and registry searches; a public authority such as Companies House is not necessarily our processorSearch terms such as entity names or company numbers
StripeSubscription billing (when activated)Email + name (for the Stripe customer object); Stripe stores card data directly.
Fly.io (London region where configured)Application hosting, networking and persistent storageData processed or stored through the hosted service
Meta / WhatsAppWhatsApp message transport when that channel is activeYour account identifiers, messages and our replies; Meta may act as an independent controller for its own purposes under its terms
Email providers (operator's IMAP/SMTP)Inbound email ingestion + transactional emailEmail content sent to aria@imaria.io; outbound notifications.

We may also disclose relevant data to professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies, a purchaser or investor in a corporate transaction, or another person where you direct us or the law permits or requires it. We do not sell personal data. We do not use customer conversation content to train external providers' general-purpose models; provider handling remains governed by our applicable service agreement with that provider.

6. How long we keep data

Data typeRetention
Conversation historyUntil you delete it (per-conversation delete via DELETE /api/aria/conversations/:id) or you close your account.
Account recordFor the account term, then normally deleted or anonymised within 30 days, except records required for tax, fraud prevention, dispute resolution or legal claims.
Document uploadsBound to the conversation that ingested them; deleted when that conversation is deleted.
Audit-log entriesFor the account term. On closure, entries needed to establish, exercise or defend legal claims may be retained in pseudonymised form for up to 6 years, subject to earlier deletion where they are no longer necessary. Integrity design does not override a valid data-protection right.
Telemetry countersDaily counters keyed by UTC date with TTL of 36 hours; monthly counters with 35-day TTL.
Server and security logsNormally up to 30 days, unless a security incident or legal hold requires longer retention.
Backup snapshotsOff-host email backups retained per ARIA_BACKUP_RETENTION_DAYS (default 30 days).

7. Your rights

Depending on the circumstances and lawful basis, UK data-protection law gives you rights to:

  • Access your personal data: request a copy via support@imaria.io.
  • Rectify inaccurate data: most fields are editable in the account page (/account.html). Others can be corrected via the same email.
  • Erasure in applicable circumstances. This right is not absolute; we may retain information where lawfully required or needed for legal claims.
  • Restriction of processing in applicable circumstances.
  • Portability: receive data you provided in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract.
  • Object: you have the right to object at any time to direct marketing and, on grounds relating to your situation, to processing based on legitimate interests.
  • Withdraw consent: for any processing based on consent.
  • Lodge a complaint: with the UK ICO (ico.org.uk) or your local supervisory authority.

We normally respond within one month after receiving a valid request. We may ask for information needed to verify your identity and may extend the response period by up to two further months for a complex or numerous request, explaining why. Rights may be limited by law. If we process third-party data solely for a customer, we may refer the request to that customer as controller.

8. International transfers

Our primary application infrastructure is configured in the United Kingdom. Supplier processing may involve countries outside the UK, including the United States, European Economic Area and Singapore, depending on the production provider selected for a request. Where a restricted transfer is not covered by UK adequacy regulations, Arkmurus Limited must put an applicable safeguard in place before the transfer, such as the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses, and complete any required transfer risk assessment. You may request information about the applicable safeguard at support@imaria.io.

DeepSeek is not an ARIA production sub-processor. It may be used in isolated development or evaluation environments before launch, but it must be discontinued for the live service and must not receive production customer prompts, documents, account data or other personal data.

Operational restriction: no provider may receive production personal data unless Arkmurus Limited has verified and documented appropriate contractual terms, security controls and, for a restricted transfer, a lawful transfer mechanism and any required transfer risk assessment.

Employment-vetting data is carved out of the above. Personal data in a vetting case (identity documents, career evidence and criminal-conviction information) is never sent to the general LLM chain. Vetting document classification uses an explicitly approved processor list only (currently Anthropic, United States), and the system fails closed: where no approved processor is available, no extraction takes place and the document is routed to a human instead. No vetting personal data is transmitted to any provider outside that approved list.

9. Security

  • Passwords are hashed with PBKDF2-SHA-512 (100,000 iterations), so we never see your plaintext password.
  • Authentication uses HMAC-SHA-256 signed JWTs; the signing secret is mandatory in production (JWT_SECRET env var; the codebase hard-fails at boot if unset).
  • Audit-log entries are HMAC-SHA-256 signed; the production fingerprint is published in the model card.
  • API endpoints are bearer-token protected; tokens are constant-time compared.
  • 2FA (TOTP) is available on every account.
  • We monitor for sustained authentication failures + signal-bridge misconfiguration via boot self-checks (R-F45) and surface them at /api/status.

No system is completely secure. Where a personal-data breach is notifiable, we will notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware of it. Where a breach is likely to result in a high risk to an individual's rights and freedoms, we will also notify affected individuals without undue delay, unless a lawful exception applies.

10. Counterparty data (you-as-controller)

When you ask ARIA to investigate a third-party entity (a company, a director, a beneficial owner), ARIA processes that personal data under your instructions. In legal terms, you are the data controller for that processing and we act as your processor.

We will execute a Data Processing Agreement (DPA) with you on request. The DPA aligns with the UK ICO's standard processor terms and includes:

  • Specific processing purposes (DD, sanctions screening, programme research);
  • Sub-processor list (the third parties listed in §5);
  • Notification obligations on breach;
  • Audit rights;
  • Return-or-delete obligations on contract end.

Contact support@imaria.io to request a DPA.

10a. Employment vetting (you-as-controller)

Where you use ARIA's employment-vetting module to screen an applicant, you are the data controller for that applicant's personal data and we act as your processor. Our processing schedule is available on request and covers roles, sub-processors, security measures, retention and deletion.

Three obligations sit with you and cannot be discharged by us:

  • issuing the applicant's privacy notice (Arts. 13-14) when you invite them to submit information;
  • selecting the DPA 2018 Schedule 1 condition for criminal-offence data and issuing the Appropriate Policy Document it requires - our system will refuse to hold conviction data until both are recorded;
  • making the employment decision itself, and answering any challenge to it.

10b. Criminal-conviction and offence data

The vetting module processes criminal-conviction and offence data (UK GDPR Art. 10) - convictions declarations, DBS/Disclosure certificates, NPCC police letters and SIA licences. This is processed only where authorised by domestic law under DPA 2018 s.10(5) and Schedule 1.

  • Enforced, not assumed: the system refuses to store conviction data for a customer until that customer has recorded which Schedule 1 condition they rely on and the Appropriate Policy Document that condition requires (Sch. 1 Pt 4 para 5), including a review date that has not passed.
  • Consent is not used and is not offered. In an employment relationship consent is not freely given (Art. 4(11), Art. 7(4)), so it is not an available lawful basis in this module. A signed screening authorisation evidences that the screening was authorised; it is not the lawful basis.
  • No automated decisions. Screening findings come from a deterministic rule engine, and every employment decision is recorded against a named human. Nothing in the module can issue a decision about a person.
  • Erasure. Vetting documents are encrypted with a per-case key; disposal destroys that key, rendering the retained copies irrecoverable.
  • Retention. 12 months for unsuccessful applications; 7 years from the end of employment for successful ones.

11. Children

ARIA is a defence-industry tool intended for professional adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered, contact support@imaria.io and we will delete the account.

12. Cookies and browser storage

ARIA uses cookies or browser storage that are strictly necessary for authentication, security, session continuity and user-requested preferences. These technologies do not require consent where the PECR strictly-necessary exemption applies, but we still describe them here. Arkmurus Limited must not set analytics, advertising or other non-essential cookies or similar technologies before obtaining valid consent through a clear choice mechanism. If non-essential technologies are introduced, this notice and the consent control will identify their provider, purpose and duration.

13. Automated processing and AI

ARIA generates research, screening indicators and recommendations using automated processing. Arkmurus Limited does not intend ARIA itself to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers must provide meaningful human review and must not use ARIA output as the sole basis for employment, access, credit, legal or similarly significant decisions. If this practice changes, we will identify the logic, significance, likely consequences, lawful condition and safeguards, including routes to human intervention and challenge, before carrying out that processing.

14. Changes to this policy

We will publish material changes here and notify registered users by email at least 30 days before they take effect. Non-material changes (clarifications, formatting) take effect on publication.

Companion documents: Terms of service · Model card · Service status

Operator and controller: Arkmurus Limited · Company no. 16028039 · Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom · Privacy contact: support@imaria.io