ARIA is operated by Arkmurus Limited (company number 16028039), registered in England and Wales, whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Arkmurus Limited is the data controller for account administration, service operation, security, billing, communications and its own product improvement. ARIA is a domain-specialised AI assistant for security and defence due-diligence work. See the model card for the capability statement.
Contact us about privacy, access, correction, deletion or any other data-protection right at support@imaria.io, or by post at the registered office above, marked “Data Protection”. We have not appointed a data protection officer; privacy enquiries are handled by Arkmurus Limited.
This policy covers personal data we process when you:
support@imaria.io or aria@imaria.io.For personal data about third parties that a business customer submits for due diligence or employment vetting, the customer will normally be the controller and Arkmurus Limited will act as processor under the applicable agreement (see §10). Arkmurus Limited may remain an independent controller for limited purposes required by law or necessary to protect the service, such as security logging and responding to lawful requests.
| Category | Examples | Required? |
|---|---|---|
| Account identifiers | Username, full name, email address, hashed password | Yes |
| Organisation context | Account type (individual / company), company name + country + size, sector, job title | Optional |
| Use-case context | Primary use cases, region focus, languages, volume estimate, compliance needs, free-text purpose statement | Optional |
| Conversation content | The messages you send to ARIA + ARIA's replies | Generated when you use the product |
| Document uploads | PDFs, DOCX, XLSX, images you upload for analysis | Generated when you upload |
| Communication preferences | Notification toggles (digest, flash, push, Telegram), Telegram username | Optional |
| Billing identifiers | Stripe customer ID + subscription ID once you subscribe (no card data; Stripe holds those) | Optional / generated on subscribe |
| Support and business communications | Your correspondence with us, enquiries, feedback and request history | Generated when you contact us |
| Category | Examples |
|---|---|
| Usage telemetry | Daily message counts, daily upload counts, monthly DD-run counts (the per-user quota counters in lib/billing/quotas.mjs and aria_service/intel/user_quota.py) |
| Audit-log entries | Each material claim ARIA produces with timestamp, source citations, confidence tag, source-tier breakdown: hash-chained and HMAC-signed (see model card §7) |
| Cost telemetry | Per-call LLM cost (provider, model, input/output tokens, latency), used for the monthly cap enforcement |
| Server logs | HTTP request method / path / status / IP address / user-agent for the duration the host (fly.io) retains them |
| Device storage | Strictly necessary authentication, security and preference data stored in cookies or browser storage |
| Purpose | Data | UK GDPR lawful basis |
|---|---|---|
| Register users, authenticate accounts, provide requested chat, document analysis, alerts and support | Account, organisation and use-case details; conversations; uploads; preferences; support communications | Contract (Art. 6(1)(b)) where you contract personally; otherwise our legitimate interests (Art. 6(1)(f)) in providing and administering the service to your organisation |
| Operate quotas, maintain auditability, diagnose faults, prevent fraud and secure ARIA | Usage, cost and audit telemetry; server and security logs | Legitimate interests (Art. 6(1)(f)) in reliable, secure and accountable service operation |
| Administer subscriptions, invoices, tax and financial records | Account, transaction and billing identifiers | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Send requested operational messages and service notices | Contact details and communication preferences | Contract (Art. 6(1)(b)) or legitimate interests (Art. 6(1)(f)) |
| Send optional electronic marketing | Contact details, preferences and engagement | Consent (Art. 6(1)(a)) where PECR requires it; otherwise legitimate interests where law permits. You may unsubscribe at any time. |
| Comply with binding law, court orders and regulatory requirements, and establish or defend legal claims | Relevant records | Legal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)), as applicable |
Where we rely on legitimate interests, we assess necessity and balance those interests against the person's rights. You may object as explained in §7. We do not rely on consent merely because a profile field is optional. If we ask for consent, refusing or withdrawing it will not affect processing already carried out lawfully or prevent use of unrelated service features.
Please do not submit special-category data (such as health, biometric, political-opinion or religious data) unless it is necessary, lawful and expressly supported by the relevant ARIA workflow. Criminal-offence data is subject to the additional controls in §10b.
We use suppliers and sub-processors to operate ARIA. A supplier receives only the information needed for the relevant function and is subject to appropriate contractual and security controls. The providers actually used depend on the enabled feature and current configuration:
| Processor | Purpose | What's shared |
|---|---|---|
| Approved production LLM providers, which may include Anthropic, OpenAI, Mistral, Groq or OpenRouter | AI reasoning, used only when the provider is configured, contractually approved and invoked | Conversation content, relevant document extracts and system instructions needed to answer the request. |
| Sanctions and corporate-data sources, which may include OpenSanctions and Companies House | Requested screening and registry searches; a public authority such as Companies House is not necessarily our processor | Search terms such as entity names or company numbers |
| Stripe | Subscription billing (when activated) | Email + name (for the Stripe customer object); Stripe stores card data directly. |
| Fly.io (London region where configured) | Application hosting, networking and persistent storage | Data processed or stored through the hosted service |
| Meta / WhatsApp | WhatsApp message transport when that channel is active | Your account identifiers, messages and our replies; Meta may act as an independent controller for its own purposes under its terms |
| Email providers (operator's IMAP/SMTP) | Inbound email ingestion + transactional email | Email content sent to aria@imaria.io; outbound notifications. |
We may also disclose relevant data to professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies, a purchaser or investor in a corporate transaction, or another person where you direct us or the law permits or requires it. We do not sell personal data. We do not use customer conversation content to train external providers' general-purpose models; provider handling remains governed by our applicable service agreement with that provider.
| Data type | Retention |
|---|---|
| Conversation history | Until you delete it (per-conversation delete via DELETE /api/aria/conversations/:id) or you close your account. |
| Account record | For the account term, then normally deleted or anonymised within 30 days, except records required for tax, fraud prevention, dispute resolution or legal claims. |
| Document uploads | Bound to the conversation that ingested them; deleted when that conversation is deleted. |
| Audit-log entries | For the account term. On closure, entries needed to establish, exercise or defend legal claims may be retained in pseudonymised form for up to 6 years, subject to earlier deletion where they are no longer necessary. Integrity design does not override a valid data-protection right. |
| Telemetry counters | Daily counters keyed by UTC date with TTL of 36 hours; monthly counters with 35-day TTL. |
| Server and security logs | Normally up to 30 days, unless a security incident or legal hold requires longer retention. |
| Backup snapshots | Off-host email backups retained per ARIA_BACKUP_RETENTION_DAYS (default 30 days). |
Depending on the circumstances and lawful basis, UK data-protection law gives you rights to:
/account.html). Others can be corrected via the same email.We normally respond within one month after receiving a valid request. We may ask for information needed to verify your identity and may extend the response period by up to two further months for a complex or numerous request, explaining why. Rights may be limited by law. If we process third-party data solely for a customer, we may refer the request to that customer as controller.
Our primary application infrastructure is configured in the United Kingdom. Supplier processing may involve countries outside the UK, including the United States, European Economic Area and Singapore, depending on the production provider selected for a request. Where a restricted transfer is not covered by UK adequacy regulations, Arkmurus Limited must put an applicable safeguard in place before the transfer, such as the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses, and complete any required transfer risk assessment. You may request information about the applicable safeguard at support@imaria.io.
DeepSeek is not an ARIA production sub-processor. It may be used in isolated development or evaluation environments before launch, but it must be discontinued for the live service and must not receive production customer prompts, documents, account data or other personal data.
Operational restriction: no provider may receive production personal data unless Arkmurus Limited has verified and documented appropriate contractual terms, security controls and, for a restricted transfer, a lawful transfer mechanism and any required transfer risk assessment.
Employment-vetting data is carved out of the above. Personal data in a vetting case (identity documents, career evidence and criminal-conviction information) is never sent to the general LLM chain. Vetting document classification uses an explicitly approved processor list only (currently Anthropic, United States), and the system fails closed: where no approved processor is available, no extraction takes place and the document is routed to a human instead. No vetting personal data is transmitted to any provider outside that approved list.
JWT_SECRET env var; the codebase hard-fails at boot if unset).No system is completely secure. Where a personal-data breach is notifiable, we will notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware of it. Where a breach is likely to result in a high risk to an individual's rights and freedoms, we will also notify affected individuals without undue delay, unless a lawful exception applies.
When you ask ARIA to investigate a third-party entity (a company, a director, a beneficial owner), ARIA processes that personal data under your instructions. In legal terms, you are the data controller for that processing and we act as your processor.
We will execute a Data Processing Agreement (DPA) with you on request. The DPA aligns with the UK ICO's standard processor terms and includes:
Contact support@imaria.io to request a DPA.
Where you use ARIA's employment-vetting module to screen an applicant, you are the data controller for that applicant's personal data and we act as your processor. Our processing schedule is available on request and covers roles, sub-processors, security measures, retention and deletion.
Three obligations sit with you and cannot be discharged by us:
The vetting module processes criminal-conviction and offence data (UK GDPR Art. 10) - convictions declarations, DBS/Disclosure certificates, NPCC police letters and SIA licences. This is processed only where authorised by domestic law under DPA 2018 s.10(5) and Schedule 1.
ARIA is a defence-industry tool intended for professional adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered, contact support@imaria.io and we will delete the account.
ARIA uses cookies or browser storage that are strictly necessary for authentication, security, session continuity and user-requested preferences. These technologies do not require consent where the PECR strictly-necessary exemption applies, but we still describe them here. Arkmurus Limited must not set analytics, advertising or other non-essential cookies or similar technologies before obtaining valid consent through a clear choice mechanism. If non-essential technologies are introduced, this notice and the consent control will identify their provider, purpose and duration.
ARIA generates research, screening indicators and recommendations using automated processing. Arkmurus Limited does not intend ARIA itself to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers must provide meaningful human review and must not use ARIA output as the sole basis for employment, access, credit, legal or similarly significant decisions. If this practice changes, we will identify the logic, significance, likely consequences, lawful condition and safeguards, including routes to human intervention and challenge, before carrying out that processing.
We will publish material changes here and notify registered users by email at least 30 days before they take effect. Non-material changes (clarifications, formatting) take effect on publication.