Privacy Policy
How we collect, use, and protect your personal information and business data.
1. Introduction
Arnen Inc. ("Arnen," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Go-To-Market AI platform (the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
Contact Information:
Arnen Inc.
Email: [email protected]
Data Protection Officer: [email protected]
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Company name and role
- Authentication credentials (managed by Auth0)
- Profile preferences and settings
2.2 Product and Business Data
To provide our services, we collect and process:
- Product information you provide (names, descriptions, features, pricing)
- Competitor information and market positioning data
- Sales narratives and messaging content
- Buyer personas and audience segments
- Integration data from connected services (with your consent)
2.3 Usage Data
We automatically collect:
- Log data (IP address, browser type, pages visited, timestamps)
- Device information (operating system, device identifiers)
- Feature usage patterns and analytics
- Performance metrics and error reports
2.4 Integration Data
When you connect third-party services, we may collect:
- CRM data (with explicit authorization)
- Document content from connected repositories
- Call recordings and transcripts (from Gong or similar tools)
3. How We Use Your Information
We use your information for the following purposes:
- Service Provision: To operate, maintain, and improve our GTM AI platform
- AI-Powered Features: To generate narratives, analyze competitors, and provide insights
- Personalization: To customize your experience and provide relevant recommendations
- Communication: To send service updates, security alerts, and support messages
- Analytics: To understand usage patterns and improve our services
- Legal Compliance: To comply with legal obligations and enforce our terms
4. AI Data Processing
NO TRAINING COMMITMENT
Arnen does NOT use your data to train AI models. Your product information, narratives, and business data are processed only to provide our services and are never used to train or improve foundation models. We use third-party AI providers under agreements that prohibit training on customer data.
4.1 How We Process Data with AI
Arnen uses artificial intelligence to analyze your data and generate insights. Here's how your data flows through our AI systems:
- Input Processing: Your product and market data is securely sent to our AI processing pipeline
- AI Analysis: We use Anthropic Claude to generate narratives, analyze competitors, and provide strategic insights
- Vector Storage: We create embeddings (mathematical representations) of your content for semantic search, stored in Pinecone
- Research Enrichment: We may use Exa for web research to supplement competitive intelligence
4.2 Third-Party AI Providers
| Provider | Purpose | Data Shared | Training Policy |
|---|---|---|---|
| Anthropic (Claude) | Text generation, analysis | Product info, prompts | No training on API data |
| Pinecone | Vector embeddings storage | Text embeddings (not raw text) | No model training |
| Exa | Web research, data enrichment | Search queries only | No customer data stored |
4.3 Data Processing Agreements
We maintain Data Processing Agreements (DPAs) with all AI service providers that include:
- Prohibition on using customer data for model training
- Data encryption in transit and at rest
- Immediate deletion after processing (no persistent storage)
- GDPR-compliant data handling practices
5. Third-Party Services
We use the following third-party services to operate our platform:
6. Data Retention
We retain your data for as long as necessary to provide our services and comply with legal obligations:
| Data Type | Retention Period | After Deletion |
|---|---|---|
| Account data | Duration of account + 30 days | Permanently deleted |
| Product/business data | Duration of account | Permanently deleted |
| Generated content | Duration of account | Permanently deleted |
| Usage analytics | 24 months | Anonymized aggregate data retained |
| Audit logs | 7 years (compliance) | Archived then deleted |
You can request deletion of your data at any time. See Section 7 for GDPR rights and Section 8 for CCPA rights.
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under GDPR:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw previously given consent at any time
To exercise these rights, email [email protected] or use the settings in your account dashboard. We will respond within 30 days.
Legal Basis for Processing: We process your data based on:
- Contract performance (providing our services)
- Legitimate interests (improving services, security)
- Consent (optional analytics, marketing)
- Legal obligations (compliance, tax records)
8. Your Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected, used, and disclosed
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
- Right to Correct: Request correction of inaccurate personal information
We do not sell your personal information. Arnen does not sell, rent, or trade personal information to third parties for monetary or other valuable consideration.
To exercise your rights, email [email protected] with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.
9. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: AES-256-GCM encryption for sensitive data at rest; TLS 1.3 for data in transit
- Access Control: Role-based access control (RBAC) with principle of least privilege
- Multi-Tenant Isolation: Strict data isolation between organizations using Row-Level Security (RLS)
- Infrastructure: Cloud infrastructure with SOC 2 Type II certification
- Monitoring: 24/7 security monitoring and automated threat detection
- Incident Response: Documented incident response procedures with 72-hour breach notification
10. International Transfers
Arnen is based in the United States. If you access our services from outside the US, your data will be transferred to, stored, and processed in the United States.
For transfers from the EEA, UK, or Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with appropriate safeguards
- EU-US Data Privacy Framework (where applicable)
By using our services, you consent to the transfer of your data to the United States with these protections in place.
11. Changes & Contact
11.1 Policy Updates
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification to your registered email address
- Prominent notice on our website
- In-app notification on your next login
Continued use of our services after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
11.2 Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Data Protection Officer: [email protected]
For EU/EEA residents, you also have the right to lodge a complaint with your local Data Protection Authority.