Privacy Policy
Last updated: October 7, 2026
1. Who we are
The arcane-crm.com website and the Arcane CRM service (app.arcane-crm.com) are published by Arcane Powered, a French SASU (simplified joint-stock company) with share capital of €1,000, 142 rue de Rivoli, 75001 Paris, France, registered with the Paris Trade and Companies Register (RCS) under number 109 293 266 ("Arcane", "we", "us").
Personal data contact: Rayane Abdi, President — [email protected].
Arcane CRM is customer relationship management (CRM) software with artificial intelligence features, intended for business use only.
2. Two distinct roles
Depending on the data, Arcane acts in one of two capacities under Regulation (EU) 2016/679 (the "GDPR"):
| Arcane's role | Data concerned | Applicable document |
|---|---|---|
| Controller | Website visitors, prospects, user accounts, billing, support, security and technical logs, monitoring of AI misuse | This policy (sections 3 to 5) |
| Processor on behalf of our customers | Data that customers manage in their CRM: contacts, companies, deals, synced emails and calendars, meeting recordings, transcripts and summaries, AI-generated content | Data Processing Agreement (DPA) entered into with each customer, available on request at [email protected] or through the contact form (https://arcane-crm.com/fr/nous-contacter/); summary in section 6 |
For CRM data, the customer (the company using Arcane CRM) is the controller: it decides which data it imports, syncs or records, and data subjects should exercise their rights with the customer first (section 11).
3. Processing for which Arcane is the controller
3.1 Visitors to arcane-crm.com
| Data | IP address, browser and device type, pages viewed, date and time (technical logs of the content delivery network) |
| Purposes | Displaying the website, securing it (protection against attacks and abuse), measuring its availability |
| Legal basis | Arcane's legitimate interest in providing a safe and functional website (Art. 6(1)(f) GDPR) |
| Retention | In accordance with the provider's retention policy, available on its website (https://www.cloudflare.com/privacypolicy/) |
| Recipients / processors | Cloudflare, Inc. (website hosting and proxy) |
Cookies and trackers: as of the date of this policy, the website uses no audience measurement tool and sets no trackers. The app only uses trackers that are exempt from consent (authentication, interface preferences); the Crisp support chat is used only inside the app and sets the cookies needed for the conversation to work. No consent banner is therefore required. Any tracker requiring consent would trigger a banner.
3.2 Prospects and sales inquiries
| Data | Name, business email, company, expected number of seats, content of exchanges (support chat, "Contact us" button for a dedicated instance or an offer of 20 seats or more) |
| Purposes | Responding to inquiries, preparing a quote (dedicated instance), sales follow-up |
| Legal basis | Pre-contractual steps taken at the person's request (Art. 6(1)(b)); legitimate interest in business-to-business sales follow-up (Art. 6(1)(f)) |
| Retention | 3 years from the last contact initiated by the prospect (in line with the CNIL guidelines on sales management) |
| Recipients / processors | Arcane team; Crisp (chat) |
Arcane only sends email marketing to business contacts for offers related to their business, with an opt-out link in every message.
3.3 User accounts
| Data | First name, last name, business email, organization, role (account owner, admin, member, viewer), country declared at sign-up (which determines the recording bot region, section 7), preferences, language, Google or Microsoft sign-in identifiers, sign-in history, date and version of acceptance of the Terms of Use |
| Purposes | Creating and managing the account and the organization, authentication, providing the service and the 14-day Growth trial, sending service emails (invitations, quota alerts, end of trial, security) |
| Legal basis | Performance of the contract (Art. 6(1)(b)); for users invited by a customer, the legitimate interest of Arcane and the customer in providing the service (Art. 6(1)(f)) |
| Retention | For the life of the account. Member leaving: access revoked immediately, private emails and meetings deleted 30 days after departure. Organization deletion: 30-day cancellable waiting period, then permanent deletion. End of trial: data exceeding the Free plan limits is read-only for 30 days, then archived and kept for 90 days, then permanently deleted after notice by email. Backups: 30 additional days at most (section 5) |
| Recipients / processors | Authorized Arcane staff; Railway (hosting, EU); Cloudflare, Inc. (Cloudflare Email: sending transactional emails from arcane-crm.com) |
3.4 Subscription, billing and unpaid invoices
| Data | Identity of the account owner, company name, billing address, VAT number, plan, seats, add-ons, payment history; card or bank account details are collected directly by Stripe and are not stored by Arcane |
| Purposes | Invoicing, collecting payments, chasing unpaid invoices, bookkeeping, fraud prevention |
| Legal basis | Performance of the contract (Art. 6(1)(b)); legal accounting and tax obligations (Art. 6(1)(c)); legitimate interest in fraud prevention (Art. 6(1)(f)) |
| Retention | Accounting records: 10 years (Art. L.123-22 of the French Commercial Code). For unpaid invoices: read-only at day 14, suspension at day 30, deletion of customer data at day 120, excluding accounting records |
| Recipients / processors | Stripe (payments), which also partly acts as a separate controller, in particular for fraud prevention; our chartered accountant; tax authorities on request |
3.5 Customer support (Crisp chat)
| Data | Name, email, organization and plan (passed on by the service), content of conversations and attachments, browser technical data |
| Purposes | Answering support requests, handling incidents, improving online help |
| Legal basis | Performance of the contract for customers (Art. 6(1)(b)); legitimate interest for other persons (Art. 6(1)(f)) |
| Retention | In accordance with the provider's retention policy, available on its website (https://crisp.chat/en/privacy/) |
| Recipients / processors | Arcane support team; Crisp IM SAS (Nantes, France) |
When a member of the Arcane team needs to access an organization's data for support purposes, that access is logged and visible to the account owner.
3.6 Security, technical logs and observability
| Data | Technical identifiers (organization, user and request identifiers), performance and usage metrics, error logs, audit log (sign-ins, role changes, exports, deletions, support access). Technical traces contain no email addresses and no content from emails, meetings or records |
| Purposes | Securing the service, detecting and fixing incidents, isolating organizations, measuring availability and AI cost per organization |
| Legal basis | Arcane's legitimate interest in ensuring the security and proper operation of the service (Art. 6(1)(f)); security obligation (Art. 32 GDPR) |
| Retention | Traces: 15 days; logs: 30 days; metrics: 13 months; audit log: 1 year |
| Recipients / processors | Arcane technical team; SigNoz, Inc. (SigNoz Cloud, EU region); Railway |
3.7 Monitoring of AI misuse
| Data | AI volume and cost per organization and per task (aggregated metrics), without reading the content of requests |
| Purposes | Detecting misuse of the AI, i.e. using it for something other than the CRM's features (resale, use as a generic AI API, mass scripts unrelated to the CRM). AI on paid plans has no usage limit: monitoring only serves to trigger a procedure of alert, discussion with the customer and, where appropriate, proportionate limitation. No blocking is automatic |
| Legal basis | Arcane's legitimate interest in preventing abuse and protecting the service (Art. 6(1)(f)) |
| Retention | Same as metrics (13 months) |
| Recipients / processors | Arcane team; SigNoz Cloud |
3.8 Legal obligations and defense of rights
Arcane may retain or disclose certain data to comply with a legal obligation or a request from an authority, or to establish, exercise or defend legal claims (Art. 6(1)(c) and 6(1)(f)), for the applicable limitation period.
4. Data subjects who are not users
Arcane CRM also processes data about people who do not have an account:
- CRM contacts (our customers' clients, prospects and partners): their contact details, exchanged emails, notes and deals are stored in the customer's CRM, and the customer is responsible for them. Arcane processes them as a processor (section 6). Data imported by the customer (for example via a CSV file) is the customer's responsibility.
- Correspondents in synced emails: by default, only new emails exchanged with contacts already in the customer's CRM are processed. Each user can enable, and revoke at any time, two separate settings (called "consents" in the product): full mailbox history analysis and contact suggestions from new emails. On revocation, processing stops immediately, unaccepted suggestions are deleted at once and history emails that do not come from CRM contacts are purged within 30 days; existing contacts and accepted suggestions are kept. These settings are configuration choices made by the user on behalf of the customer; they do not amount to the correspondents' consent. Processing of correspondents' data relies on the customer's legal basis (usually its legitimate interest), and it is up to the customer to inform them. This data remains subject to the Google user data Limited Use rules (section 9).
- Participants in recorded meetings: voice, image, name and statements made during an online meeting (Google Meet, Microsoft Teams, Zoom) recorded by a customer's bot. The bot joins the meeting as a visible participant, under a name showing that it is recording, and posts an announcement message that cannot be disabled. This announcement does not replace informing participants and, where required, obtaining their consent, which is the customer's responsibility. Any participant may ask for the recording to be stopped.
These people can exercise their rights with the customer concerned, or write to [email protected]: Arcane will forward the request to the customer and help it respond (section 11).
5. Backups
Data deleted in the service may remain for up to 30 days in technical backups, without being accessible or used, and is then erased.
6. Customers' CRM data: Arcane as processor (DPA summary)
For data that customers manage in Arcane CRM, Arcane acts only on the customer's instructions, under the DPA (Art. 28 GDPR). In summary:
- Private by default: emails and meetings synced by a member are private; an organization admin can widen visibility, transparently (visible indicator, notification to members, log).
- Revoking an email setting (full history or contact suggestions): immediate stop; unaccepted suggestions deleted immediately; history emails not from CRM contacts purged within 30 days; existing contacts and accepted suggestions kept.
- Meeting recordings: videos, audio and transcripts kept for 30 days by default, adjustable by the customer up to 6 months maximum (or its plan's maximum if lower), then deleted automatically; summaries and tasks kept as long as the meeting exists, deletable at any time; media deleted from the recording provider after being copied to our storage.
- Member leaving: their private emails and meetings are deleted 30 days after departure.
- End of contract: export available to the account owner, then deletion (organization: 30 days after the request; unpaid invoices: day 120), subject to backups (30 days).
- AI: processing of the content needed for the requested feature (drafting emails that are always approved by the user before sending and then sent from their own Gmail or Outlook mailbox, summaries, tasks, logged and reversible deal moves), with data minimization and no model training (section 8).
- Sub-processors: list kept up to date (https://arcane-crm.com/fr/third-parties/); prior notice to the customer before any addition, with 30 days' notice and a right to object.
7. Processing region and hosting
- Hosting: the database, files and backups are hosted in the European Union (Railway).
- Meeting recording: the Recall.ai bot runs in the region closest to the country declared by the organization: European Union for any country on the European continent in the geographic sense (EU, EEA, Switzerland, United Kingdom, etc.), including Turkey and the Caucasus countries, excluding Russia; United States otherwise. The account owner or an organization admin can change this region; the change is logged.
- Meeting transcription: follows the organization's region: European Union → Mistral AI; United States → xAI. The account owner or an organization admin can change the region (bot and transcription).
- AI features (summaries, tasks, analysis, drafting, agent, chat): performed by OpenAI, in the United States, regardless of region (section 8).
8. Transfers outside the European Union
| Recipient | Country | Data | Safeguards |
|---|---|---|---|
| OpenAI — OpenAI Ireland Limited (Ireland) and OpenAI OpCo, LLC (United States) — AI features | United States | Excerpts strictly necessary for the task (minimization: no full record sent if an excerpt is enough), including email content when you ask for a summary or a draft | European Commission Standard Contractual Clauses (OpenAI DPA). Data sent through the API is not used to train OpenAI's models; OpenAI may keep abuse monitoring logs for up to 30 days. |
| xAI — SpaceXAI LLC (meeting transcription for organizations in the United States region) | United States | Meeting audio and transcripts of organizations in the United States region | Standard Contractual Clauses (xAI DPA) |
| Recall.ai — Hyperdoc Inc. (recording bot, United States region) | United States | Audio/video streams, display names and metadata of participants in meetings of organizations in the United States region | EU and UK Standard Contractual Clauses under Recall.ai's DPA |
| Cloudflare, Inc. (proxy, CDN and Cloudflare Email) | United States (global network) | Technical connection data (IP address, headers, requests); name, address and content of transactional emails | Cloudflare DPA: Standard Contractual Clauses and Data Privacy Framework as declared by Cloudflare |
| Railway Corporation | US company; data hosted in the EU | Possible access from the United States for operations | Railway DPA: Standard Contractual Clauses; Railway states that it complies with the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) |
| Stripe — Stripe Payments Europe, Limited (Ireland), with Stripe, LLC (United States) | EU / United States | Account owner's identity and contact details, billing and payment data | Stripe, LLC states that it complies with the EU-U.S. Data Privacy Framework; Standard Contractual Clauses (Stripe DPA) |
| SigNoz, Inc. (observability, SigNoz Cloud EU region) | US company; EU region | Technical data with no content and no email addresses | Safeguards provided under SigNoz's terms |
| Crisp IM SAS (Nantes, France) | France / EU | Support conversations | Established in the EU; any transfers by its own providers governed by Chapter V of the GDPR |
For organizations in the EU region, recording (Recall.ai, EU region) and transcription (Mistral AI) stay in the European Union. AI features (summaries, tasks, drafting) are always performed by OpenAI in the United States. Details of providers are available on the "Third parties" page (https://arcane-crm.com/fr/third-parties/). A copy of the safeguards can be obtained on request at [email protected].
9. Google user data (Gmail and Google Calendar)
When you connect your Google account, Arcane CRM requests only the following scopes:
gmail.readonly: to read your emails so they can be linked to the contacts and deals in your CRM, to show your conversation history, and to let the AI agent prepare replies. By default, only new emails exchanged with contacts already in your CRM are processed; full-history analysis and contact suggestions are enabled only if you choose them, and you can turn them off at any time.gmail.send: to send, from your mailbox, the emails you have written or approved. The AI agent never sends an email without your approval.calendar.events: to read and create events in your calendar so we can prepare your meetings, add the recording bot if you enabled it, and schedule the meetings you ask for.
Arcane CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- this data is used only to provide and improve user-facing features of Arcane CRM;
- it is never used to train or improve generalized AI models, by Arcane or by its service providers;
- it is not transferred to third parties, except to the technical service providers strictly necessary to provide the service (for example OpenAI, the AI provider that generates a summary or a draft at your request, under contract and with no training rights), to comply with applicable law, or as part of a merger or acquisition with prior notice to you;
- it is not sold, not used for advertising, and not used to determine creditworthiness or for lending purposes;
- no human reads it, unless you give explicit consent for specific messages, for security purposes (such as investigating abuse), to comply with applicable law, or when it is aggregated and anonymized for internal operations.
You can revoke Arcane CRM's access at any time from the app settings or from your Google account.
The same commitments apply to Microsoft data (Outlook, Microsoft 365 calendar).
10. Automated decision-making
Arcane makes no decision based solely on automated processing that produces legal effects or similarly significantly affects a person, within the meaning of Article 22 GDPR. AI features produce proposals (drafts, summaries, tasks) that the user reviews; automatically moving a deal in the pipeline is an internal operation in the customer's CRM, logged and reversible, and does not produce such an effect. The Terms of Use prohibit customers from using the service to make such decisions without human involvement.
11. Your rights
Under the GDPR and the French Data Protection Act, you have the following rights:
- access, rectification and erasure of your data;
- restriction of processing;
- objection, at any time, to processing based on our legitimate interest, on grounds relating to your particular situation, and unconditionally to direct marketing;
- portability of the data you provided to us, where processing is based on contract or consent;
- withdrawal of consent, where processing is based on consent;
- setting instructions regarding what happens to your data after your death.
To exercise them: [email protected], or by post: Arcane Powered, 142 rue de Rivoli, 75001 Paris, France. Proof of identity may be requested in case of reasonable doubt. We respond within one month, which may be extended by two months for complex requests.
For data in a customer's CRM (section 6), please contact that customer first; if you write to us, we will forward your request to them.
You may lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
12. Security
Arcane implements appropriate technical and organizational measures, including encryption of data in transit (TLS), isolation between organizations, encryption of integration tokens, an audit log, limited access rights and logged support access. In the event of a personal data breach, Arcane notifies the CNIL and, where applicable, the affected individuals or the customer, as required by the GDPR and the DPA.
13. Changes
This policy may change. The current version is published at https://arcane-crm.com/privacy/ (French version: https://arcane-crm.com/fr/confidentialite/); in the event of a material change, users are informed by email or in the service.