This Privacy Policy explains how ArcSeven Ltd (“ArcSeven”, “we”, “us”, or “our”) collects, uses, stores, and shares personal data when you visit arcledger.co.uk, use the ArcLedger service (the “Service”), request access, or otherwise deal with us. ArcLedger is operated by ArcSeven Ltd. Related brands and sites include ArcSeven Labs and Arcnet.
ICO registration reference: ZC178598
Privacy: privacy@arcsevenlabs.co.uk
Legal: legal@arcsevenlabs.co.uk
1. Who we are
ArcSeven Ltd provides ArcLedger, a multi-tenant UK finance and asset application for organisations of all kinds (with deep tooling for tech resale and the VAT margin scheme). We design the Service to process and store personal data primarily in the United Kingdom.
- Privacy: privacy@arcsevenlabs.co.uk
- Legal: legal@arcsevenlabs.co.uk
- Web: arcsevenlabs.co.uk
2. Personal data we collect
2.1 Information you provide
- Access applications: company name, contact name, email address, and any notes you submit.
- Account and invite data: name, email, role, account status, and credentials (passwords stored as cryptographic hashes) when an organisation invite is accepted.
- Support and correspondence: messages you send us.
- Organisation content: business records entered into ArcLedger by authorised users (for example expenses, invoices, clients, bank connection metadata, receipts, exports, and settings). That content may include personal data about your staff, customers, or suppliers.
- AI feature inputs (where the AI module is enabled for your organisation): receipt images or PDFs you choose to scan, plus related context we send to produce a draft expense (for example organisation category names). Receipts may contain personal data such as names, addresses, card tails, or purchase details.
- Billing data (if paid plans apply): purchase history, amounts, payment status, and payment-provider session identifiers. Card details are collected by the payment provider; we do not store full card numbers.
2.2 Information collected automatically
- Technical logs such as IP address, browser type, device information, timestamps, and similar hosting/security logs.
- Authentication and security events (sign-in attempts, session tokens, audit logs within the Service).
We do not intentionally collect special category data. Do not upload such data unless your organisation has a lawful basis and has configured the Service accordingly.
3. How we use personal data
We use personal data to:
- review and respond to access applications;
- create and administer organisations, users, and invites;
- provide, maintain, secure, and improve the Service;
- where enabled by your organisation, run optional AI-assisted features (for example optical character recognition and structuring of receipt text into draft expense fields);
- send service emails (for example invites and transactional notices);
- process fees and prevent fraud where billing applies;
- prevent abuse, investigate incidents, and enforce our Terms;
- comply with legal obligations; and
- establish, exercise, or defend legal claims.
We will never sell, rent, or share your personal data with third parties for marketing purposes.
4. Legal bases (UK GDPR)
Depending on the activity, we rely on:
- Contract: to provide the Service you or your organisation have requested;
- Legitimate interests: security, product improvement, fraud prevention, and corresponding with applicants, balanced against your rights (you may object; see section 11);
- Legal obligation: where we must retain or disclose data; and
- Consent: where required (for example optional marketing, if we ever offer it, which you may withdraw). Submitting an access application is treated as initiating a business enquiry.
5. Organisation data and multi-tenancy
ArcLedger is a shared-database multi-tenant system. Organisation data is segregated by organisation identifiers and access controls. You must only upload data you are lawfully entitled to process. You are responsible for configuring user roles and permissions within your organisation appropriately.
6. Sharing and processors
We may share personal data with:
- infrastructure and service providers who process data on our instructions (for example UK hosting, databases, networking, and email delivery);
- artificial intelligence and document-processing providers (currently Mistral AI), where your organisation uses optional AI features — for example to read a receipt image/PDF and suggest expense fields. Those providers process the content you submit for that request under their terms and our instructions as applicable;
- payment processors (for example Stripe), where you purchase paid services;
- professional advisers (legal, accounting, insurers) under confidentiality;
- authorities where required by law or to protect rights, safety, or security; and
- a buyer or successor in connection with a corporate transaction, subject to appropriate safeguards.
We require processors to protect personal data under written terms consistent with UK GDPR. A current subprocessor list is available on request at privacy@arcsevenlabs.co.uk. Bank or Open Banking integrations, where enabled, may involve third-party providers under their own terms; review those before connecting accounts.
7. International transfers
We design the Service to process and store personal data primarily in the United Kingdom. Some subprocessors (notably payment providers and AI / document-processing providers) may process personal data outside the UK, including in the EEA or other countries. Where personal data is transferred outside the UK, we use appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement / Addendum, Standard Contractual Clauses, or equivalent mechanisms. Details are available on request at privacy@arcsevenlabs.co.uk.
8. AI-assisted features
Some organisations may have an optional AI module enabled by the platform (for example “scan receipt” on expenses). When a user runs that feature:
- the uploaded receipt file (image or PDF) is transmitted to our AI provider to extract text;
- extracted text and limited organisation context (such as category labels) may be sent for structuring into suggested expense fields;
- suggested fields are returned to the user to review, edit, or discard before any expense is saved in ArcLedger;
- we record an audit entry that a scan occurred (for example filename and confidence summary), not a full copy of the receipt contents in that log; and
- ArcSeven does not use Customer Content from AI scans to train our own general-purpose models. AI providers may process request data under their own product terms — review those terms and your organisation’s risk appetite before enabling or using the feature.
Your organisation decides whether the AI module is used and which users may upload receipts. Do not scan documents containing special category data or information you are not entitled to process. If you prefer not to use AI, leave the module unused; core bookkeeping features do not require it.
9. Retention
We keep personal data only as long as necessary:
- Access applications and enquiry correspondence: up to 2 years if no client relationship follows; if we enter a relationship, relevant communications may be retained for the duration of that relationship plus up to 6 years for UK business record-keeping.
- Account data: for the life of the account and a reasonable period afterwards (typically up to 6 years where needed for legal claims or tax records).
- Security and audit logs: for operational and security purposes; typically up to 12 months unless a longer period is required for dispute resolution or legal compliance.
- Billing records: up to 7 years for accounting and tax purposes, where applicable.
- Organisation content: largely follows your organisation’s use of the Service and any deletion we can fulfil; backups may persist for a limited period after deletion.
- AI request payloads: receipt files and text sent for a scan are processed to fulfil that request. We do not keep a separate long-term store of AI request bodies beyond normal Service logs and audit metadata. Providers may retain technical logs under their own retention policies.
10. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit, hashed credentials, access controls, and monitoring. No method of transmission or storage is completely secure; you use the Service at your own residual risk of breach despite those measures. Use strong passwords and protect invite links.
11. Your rights
Under UK data protection law you have rights including:
- access to your personal data;
- rectification of inaccurate data;
- erasure in certain circumstances;
- restriction of processing;
- data portability where applicable;
- objection to processing based on legitimate interests; and
- withdrawal of consent where processing is based on consent.
To exercise your rights, email privacy@arcsevenlabs.co.uk. We may need to verify your identity. Where we act as processor for your organisation, contact your organisation’s administrator first for requests about organisation content.
You may lodge a complaint with the Information Commissioner’s Office (ico.org.uk). Our ICO registration reference is ZC178598. We encourage you to contact us first so we can try to resolve your concern.
12. Cookies and similar technologies
The Service stores your session token in browser local storage to keep you signed in, and may store theme preference locally. These are strictly necessary for the Service you request and do not require consent under UK PECR.
If you complete a payment, the payment provider may set cookies on its checkout pages under its own policy. We do not use Google Analytics, advertising trackers, or other non-essential analytics cookies on the ArcLedger marketing site or app. If we introduce non-essential cookies in future, we will update this policy and obtain consent where required before placing them.
13. Children
The Service is intended for business users aged 18 or over and is not directed at children. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will delete it.
14. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you. Optional AI features suggest draft expense fields for a human user to accept or reject; they do not by themselves approve payments, file taxes, or make credit or employment decisions. Security and abuse controls may automatically restrict access based on usage or risk patterns (including rate limits on AI scans).
15. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and adjust the “Last updated” date. Material changes may also be notified by email or in-product notice where appropriate. Continued use of the Service after changes take effect constitutes acceptance of the revised policy where permitted by law.
16. Governing law
This policy is governed by the laws of England and Wales, without prejudice to mandatory consumer protections in your country of residence where applicable.
17. Contact
Privacy: privacy@arcsevenlabs.co.uk
Legal: legal@arcsevenlabs.co.uk