Privacy Center
Privacy is a routing decision.
Arc.AI evaluates the requested data policy before dispatch. If no eligible endpoint meets it, the request fails instead of silently relaxing the requirement.
This page illustrates intended product behavior using simulated routes and data. A production deployment requires a privacy notice, named responsible entity, DPA, retention schedule, and deployment-specific subprocessor list.
“Arc.AI does not persist payloads” is not the same as end-to-end ZDR. A strict ZDR route also requires an eligible provider endpoint, compatible observability and guardrail settings, and current supporting evidence. Review the complete Zero Data Retention definition and subprocessor scope.
Data Arc.AI may process
Requests can include prompts, outputs, attachments, tool inputs, and tool results. Operational metadata can include organization, workspace, principal, key, model, endpoint, tokens, latency, cost, policy version, errors, and route attempts.
Default logging
The control plane is designed for metadata-only operational logging. Payload logging, debugging, observability, and guardrails must follow the workspace policy and contract. Arc.AI does not represent a universal retention period across every deployment.
Strict ZDR routes
A strict ZDR route must avoid persistent payload storage in the Arc.AI gateway, use an eligible provider endpoint, disable incompatible connectors, prevent training use where required, and exclude non-compliant fallbacks. Metadata retention is disclosed separately.
Endpoint evidence
Arc.AI records the endpoint region, payload and metadata retention, training policy, subprocessors, evidence source, verification date, expiry, and status. Missing, expired, or suspended evidence is not eligible for a strict ZDR route.
BYOK and provider responsibility
BYOK traffic uses the customer’s provider agreement and credentials while Arc.AI still applies configured access, budget, route, and logging policy. Provider terms and data handling continue to apply.
Requests and contractual documents
Export, deletion, logging changes, DPA requests, and subprocessor details are handled according to the applicable agreement and deployment. Contact Arc.AI with the organization, workspace, and request scope.
Retention and residency schedule
Payload, operational metadata, security events, audit records, billing records, and backups require separate documented schedules. Residency and deletion behavior are disclosed for the exact deployment rather than implied platform-wide.
Rights and requests
Privacy requests are routed through the verified contact channel and handled by the responsible entity under the applicable agreement and law.
Cross-border processing and incidents
Each supported contracting and deployment model documents its transfer mechanism, recipient categories, safeguards, incident-contact path, and contractual notice timing.