Terms of Service
Last updated: October 8, 2026
These terms are drafted in French. The English version is provided for information only; in case of discrepancy, the French version prevails (Article 21.3). French version: https://arcane-crm.com/fr/cgu/
Preamble
The Arcane CRM service (the "Service") is published by Arcane Powered, a French single-shareholder simplified joint-stock company (société par actions simplifiée unipersonnelle) with share capital of €1,000, whose registered office is at 142 rue de Rivoli, 75001 Paris, France, registered with the Paris Trade and Companies Register (RCS) under number 109 293 266 (the "Publisher"). Contact: [email protected]. Support: [email protected].
The Service is available at https://app.arcane-crm.com. The full legal notice is available at https://arcane-crm.com/legal-notice/.
Article 1 — Purpose, acceptance and applicable documents
1.1. These Terms of Service (the "Terms of Use", in French conditions générales d'utilisation or "CGU") set out the rules for access to and use of the Service by Users.
1.2. The commercial terms (Plans, prices, payment, unpaid amounts, term, contractual liability) are set out in the applicable conditions of sale, provided to the Customer before any payment (the "Conditions of Sale"). The processing of personal data on behalf of the Customer is governed by the Data Processing Agreement (the "DPA"), available on request at [email protected].
1.3. Each User accepts these Terms of Use upon first sign-in (the version and date of acceptance are recorded). The Customer undertakes to ensure that its Users comply with them and is liable for their actions within the Service.
1.4. The Service is intended for business users only. The User must be of legal age and act in a professional capacity.
Article 2 — Definitions
- Customer: a legal entity or individual acting for business purposes that subscribes to the Service for an Organization.
- User: an individual authorized by the Customer to access the Service.
- Plan: a subscription plan for the Service (Free, Starter, Growth, Scale or custom quote), whose content and limits are described on the Pricing page (https://arcane-crm.com/fr/pricing/).
- Trial: the free trial period of the Growth Plan.
- Seat: named access to the Service assigned to a User.
- Recording Hours: the meeting recording time included each month in the Plan, pooled at Organization level.
- Customer Data: data, content and files imported, synced, created or generated by the Customer or its Users in the Service, including AI Outputs.
- Workflow: an automation configured in the Service.
- Organization: the Customer's workspace in the Service. A single User may belong to several Organizations; their access rights, connections and data are separate in each.
- Account Owner: the sole User who holds the Organization (Article 4).
- Organization Admin, Member, Viewer: roles described in Article 4.
- AI Agent: the artificial intelligence feature of the Service (Article 8).
- Impactful Action: an action by the AI Agent or the User that has an effect beyond mere viewing: sending an email, creating, modifying or archiving a record, sending a document for signature, inviting or removing the Recording Bot, enabling or disabling a Workflow, hiding suggestions. Moving a deal from one pipeline stage to another by the AI Agent is an exception to the confirmation requirement (Article 8.2 bis).
- Recording Bot: an automated participant that joins a video conference to record it and enable its transcription and analysis (Article 9).
- Private Content: emails synced from a User's mailbox and meetings recorded on their behalf (media, transcript, analysis), for as long as the User has not shared them with the Organization.
- Integration: a connection between the Service and a third-party service (Google, Microsoft, Stripe, Atlassian Jira, the Customer's electronic signature provider, etc.), via OAuth or using the Customer's API key (Article 12.3).
- Participant: any person attending a recorded meeting, whether or not a User.
- Visibility Policy: the Organization setting that determines who can see Private Content (Article 5).
- Processing Region: the region (European Union or United States) applicable to the Organization for the meeting Recording Bot, determined by the country declared at sign-up (European Union for any European country in the geographic sense: any country on the European continent, EU, EEA, Switzerland, United Kingdom, etc.; United States otherwise) and changeable by the Organization Admin (Article 9.7).
- AI Output: any content produced by the AI (text, draft email, summary, transcript, chapters, suggested task, suggested field, suggested Workflow, etc.).
Article 3 — Access to the Service and User account
3.1. The User accesses the Service with a verified email address, via a sign-in link sent by email, or via "Continue with Google" or "Continue with Microsoft".
3.2. The User provides accurate information and keeps it up to date.
3.3. A Seat is personal to a named individual and may not be shared between several people.
3.4. The User keeps their sign-in credentials confidential and promptly reports any unauthorized use to the Account Owner and to the Publisher ([email protected]).
3.5. An invitation to join an Organization is sent by email by the Account Owner or an Organization Admin. It is personal, valid for 7 days and revocable.
Article 4 — Organization, roles and internal responsibilities
4.1. Account Owner. Each Organization has a single Account Owner, who holds all rights and is the only one who can: manage the Plan, Seats, payment methods and invoices; enable Recording Hours overage and set its cap (Article 9.6); export the entire Organization; delete the Organization; transfer ownership. The Account Owner receives contractual notices.
4.2. Transfer of ownership. The Account Owner may transfer their role to an existing Organization Admin, who confirms by email; the former Account Owner becomes an Organization Admin. The Account Owner may not leave the Organization without a prior transfer. If the Account Owner cannot be reached (for example after leaving the company), the Customer may request a transfer from support, upon supporting evidence (email address on the company's domain, invoice, etc.).
4.3. Organization Admin. The Organization Admin holds all rights except those reserved to the Account Owner (the Organization Admin may view billing but not change it). The Organization Admin manages in particular Users and their roles (except the Account Owner), the Organization's Integrations, objects, fields and pipeline stages, recording rules, the Processing Region, the Visibility Policy, the retention period of recordings and API keys. The Organization Admin may not enable Recording Hours overage or change its cap, which are reserved to the Account Owner (Article 9.6).
4.4. Member. The Member uses the Service within the assigned scope: "all records" or "own records" (records the Member owns). The Member may connect their own mailbox and calendar, record their meetings and create draft Workflows. The "Automator" option allows the Member to activate their own Workflows. Visibility of financial amounts may be restricted by the Organization Admin.
4.5. Viewer. The Viewer has access only to the reports and dashboards of the Organization that are opened to them. The Viewer does not access records, emails, meetings, recordings or any other data of the Service outside those reports and dashboards. The Viewer cannot modify anything, has neither meeting recording nor email or calendar connection, does not use the AI Agent or AI features and cannot create or publish Workflows.
4.6. The Customer is responsible for assigning roles and revoking access, in particular when an employee leaves (Article 18).
4.7. Customer Data belongs to the Customer (the Organization), not to the individual User, subject to the confidentiality rules for Private Content in Article 5.
Article 5 — Confidentiality of emails and meetings, and visibility by Organization Admins
5.1. Private by default. Emails synced from a User's mailbox and meetings recorded on their behalf (video, transcript, summary, analysis) are private by default: only that User has access to them. Neither other Members, nor Organization Admins, nor the Account Owner, nor the AI Agent used by another User can view them.
5.2. Voluntary sharing. The User may share an email, a thread or a meeting with the Organization. When a meeting brings together several Users of the same Organization, a single recording is made and is accessible to each of those Users.
5.3. Visibility Policy changeable by the Organization Admin. The Organization Admin may change the Organization's Visibility Policy, up to making all Users' emails and meetings visible to Organization Admins. This power is subject to the following transparency safeguards, which the Publisher implements and which the Customer cannot disable:
- an indicator permanently visible to each User, from their inbox and meetings, shows the Visibility Policy in force;
- each User is notified of any change to the Visibility Policy;
- each change is logged (author, date, old and new value).
5.4. Customer's obligations. By enabling a broadened Visibility Policy, the Customer, as employer and controller, remains solely responsible for: informing its employees and staff in advance and, where applicable, consulting employee representative bodies; having a legal basis and a legitimate purpose; complying with proportionality, the secrecy of correspondence and the right to privacy, in particular for messages identified as personal.
5.5. Users are informed, by these Terms of Use and within the Service, that the Visibility Policy may be broadened by the Organization Admin under the above conditions. Users are advised not to connect to the Service a mailbox containing personal correspondence.
Article 6 — Prohibited uses
6.1. The User shall use the Service fairly, in compliance with the law and these Terms of Use.
6.2. In particular, it is prohibited to:
- send unsolicited communications in breach of the law (spam) or bulk mailings without a legal basis;
- impersonate any person or mislead recipients as to the sender, the subject of a message or the fact that it was generated by AI where the law requires this to be disclosed;
- collect personal data unlawfully (web scraping, purchase of non-compliant lists, etc.);
- store or disseminate unlawful, defamatory, hateful, discriminatory or infringing content, or content that violates privacy;
- record a person without their knowledge, hide, circumvent or disable the Recording Bot's announcement, or record a meeting despite a Participant's stated refusal (Article 9);
- use the Service for phishing, fraud or the distribution of malware;
- attempt to gain unauthorized access to the Service, another Organization, another User's Private Content (outside a duly enabled Visibility Policy) or the Publisher's systems;
- test the Service's vulnerability without prior written consent;
- overload the Service, circumvent its technical limits, quotas or rate limits, or share a Seat;
- manipulate the AI Agent to make it produce prohibited content or circumvent its safeguards;
- use the Service to make decisions producing legal or similarly significant effects on individuals based solely on automated processing, in breach of Article 22 GDPR;
- use the Service's AI for anything other than the CRM's features (misuse: resale, use as a generic AI API, mass scripts unrelated to the CRM — Article 8.7);
- use the AI features for prohibited practices or "high-risk" uses within the meaning of Regulation (EU) 2024/1689 on artificial intelligence (for example assessing individuals for recruitment, worker management or access to credit), without the Publisher's prior written consent;
- record or process special categories of data (health, political opinions, religious beliefs, etc., Article 9 GDPR) or data relating to criminal offences without an appropriate legal basis;
- use the Service, the API or their outputs to develop a competing product or resell access to the Service.
6.3. Reporting. Anyone may report unlawful content to [email protected]. The Publisher may remove or disable access to manifestly unlawful content reported to it.
Article 7 — Emails sent from the Service and direct marketing
7.1. The User may send emails from their connected mailbox (Gmail or Outlook). The AI Agent may draft emails and replies.
7.2. Human confirmation. The AI Agent never sends an email without the User's explicit approval; the User sees the content and recipients before sending, on all Plans. On the Free Plan, the AI Agent only drafts: the User sends the email themselves. A Workflow activated by an authorized User may send emails automatically, according to its configuration (Article 11); this is not a sending decided by the AI Agent.
7.3. Liability. Any email sent from the Service, whether its text was written by the User, by the AI Agent or by a Workflow, is sent in the name of the User and the Customer, who are solely responsible for it: content, accuracy, recipients, legal basis for the contact, compliance with commitments made.
7.4. Direct marketing. The Customer is solely responsible for the compliance of its direct marketing with the GDPR, Directive 2002/58/EC and its national transposition (in France, Article L.34-5 of the Postal and Electronic Communications Code), and with the rules of the recipients' countries: informing individuals, right to object and a simple means to unsubscribe, maintaining a suppression list, prior consent where required by law.
7.5. Deliverability. To protect connected mailboxes and domain reputation, the Publisher may limit the number of emails sent per period. The Publisher does not review emails before they are sent; it may suspend the sending feature in the event of abuse, complaints or reports (Article 17).
Article 8 — Artificial intelligence
8.1. Features. Within the limits of the User's rights and the current Organization, the Service's AI may in particular: read the context (records, emails and meetings to which the User has access); draft emails; suggest and, after confirmation, create tasks or update records; move a deal from one pipeline stage to another on its own (Article 8.2 bis); prepare meeting briefs; transcribe, summarize and analyze recorded meetings; help build Workflows.
8.2. Confirmation of Impactful Actions. The AI Agent performs no Impactful Action without the User's explicit confirmation. It never permanently deletes data. Write actions performed via the AI Agent are logged in the name of the User who confirmed them. Suggestions from the analysis of a meeting (tasks, contacts) are only entered in the CRM after validation by the User; changing a deal's stage follows Article 8.2 bis.
8.2 bis. Autonomous moving of deals. By way of exception to Article 8.2, the AI Agent may move a deal on its own from one pipeline stage to another, without prior confirmation, when the CRM data (emails, meetings, tasks) justify it. Such moves are subject to the following:
- Traceability: each move is logged (author "AI Agent", User or rule on whose behalf it acts, date and time, origin and destination stages, elements that motivated the decision) and shown in the deal history and to the relevant Users;
- Undo: any User with the right to edit the deal may undo the move, which restores the previous stage; the undo is itself logged;
- Limits: the AI Agent does not delete, archive or mark a deal as won or lost without confirmation, and acts within the limits of the relevant User's rights.
8.3. Third-party content. The AI Agent treats the content of emails, documents and transcripts as data and does not execute instructions they contain. The User remains vigilant against manipulation attempts through third-party content.
8.4. Nature of AI Outputs. AI Outputs are generated automatically. They may be inaccurate, incomplete, outdated or unsuitable. The User reviews them before using them, sending them or making a decision based on them, in particular meeting summaries and transcripts, emails, amounts, dates and commitments. The Publisher guarantees neither their accuracy nor their fitness for a particular purpose.
8.5. Transparency. The Service informs the User when they are interacting with AI and when content has been generated by AI. The Customer assesses whether it must disclose to recipients that content was generated or assisted by AI.
8.6. AI provider and no training. The AI features (AI Agent, chat, summaries, tasks, drafting) rely on models provided by OpenAI, through the Publisher's accounts and the OpenAI API called without storage of responses (store: false). Only the data necessary for the requested task is transmitted (data minimization). Customer Data is not used to train AI models, either by the Publisher or by its AI provider (OpenAI does not use data from its API for training, unless explicitly opted in). OpenAI's models are operated in the United States: the transfer is governed by the European Commission's standard contractual clauses provided for in the DPA entered into with OpenAI. OpenAI may retain the data transmitted for up to 30 days in its abuse monitoring logs before deleting it. These safeguards are described in the Privacy Policy (https://arcane-crm.com/privacy/) and in the DPA.
8.7. AI quota (Free) and unlimited AI (paid Plans).
- Free Plan: AI is subject to a monthly quota, renewed each month. Its consumption is displayed in the Service as a percentage; no fixed number of actions or amount is communicated. When the quota is reached, AI features are suspended until renewal, without blocking the rest of the CRM. The AI Agent drafts; the User sends emails themselves (no automatic sending).
- Paid Plans: AI is "unlimited*" (*Normal team usage, no threshold.): it is subject to no usage limit, whether hard or soft, is not counted in tokens or credits, nor billed on usage; occasional peaks of normal usage are never limited. *The only reservation concerns misuse, i.e. using the AI for anything other than the CRM's features (for example resale, use as a generic AI API, mass scripts unrelated to the CRM). The Publisher monitors usage for this sole purpose and, in the event of misuse, applies the following procedure: alert, discussion with the Customer, then proportionate limitation.
- No AI consumption is billed as an extra, on any Plan.
Article 9 — Meeting recording, transcription and analysis
9.1. Operation. The Recording Bot joins video conferences (Google Meet, Microsoft Teams and Zoom) to record them. The recording is then transcribed and analyzed by AI (summary, chapters, decisions, open questions, suggested tasks, participants matched to contacts). The Bot is operated by a provider of the Publisher, Recall.ai.
9.2. Scheduling. According to the rules set by the Organization Admin for the Organization:
- by default, meetings in the connected calendar with at least one participant external to the Organization are recorded automatically;
- internal meetings are recorded only if the relevant User has enabled it;
- the User may, for each meeting, force or prevent recording, and invite the Bot to a one-off meeting;
- the Organization Admin may change these rules for the Organization.
When several Users of the same Organization attend the meeting, a single Bot joins it.
9.3. Announcement that cannot be disabled. The Bot joins the meeting as a visible participant, under an explicit name indicating that it is recording. It posts in the meeting chat a message stating that the meeting is being recorded. This announcement is mandatory and cannot be disabled by either the Customer or the User.
9.4. Customer's responsibility: informing Participants and obtaining their consent. The Bot's announcement does not relieve the Customer of its obligations. The Customer, as controller, and the User on whose behalf the meeting is recorded must, before any recording:
- inform all Participants, including external persons, that the meeting will be recorded, transcribed and analyzed by AI, of the purpose and of the retention period;
- determine the appropriate legal basis and obtain Participants' consent where required by law, including under the law of the country where Participants are located;
- respect a Participant's refusal, by not recording or by removing the Bot;
- comply with the internal rules of the Participants' organizations.
Recording a person without their knowledge may constitute a criminal offence (in particular under Article 226-1 of the French Criminal Code). The Customer and the User are solely responsible for compliance with these obligations; the Customer shall indemnify the Publisher against any claim in this respect.
9.5. Stopping. Any Participant may ask for the recording to be stopped; the User then removes the Bot. If removed during the meeting, the part already recorded is processed, unless deleted by the User.
9.6. Quotas and overage. Recording consumes the Organization's Recording Hours provided for by its Plan; unused hours do not roll over and the Service displays the remaining hours. The Account Owner and Organization Admins are alerted at 80% and then 100% of the quota.
- Free Plan: no overage. When the monthly quota is exhausted, no new Bot is scheduled and Bots already scheduled are cancelled with notification to the User, until the quota is renewed or the Plan is upgraded.
- Paid Plans: only the Account Owner may enable, on demand, paid overage of Recording Hours, at the rate set out in the Conditions of Sale ($1 excl. VAT per hour, billed per minute, converted at payment), by setting a cap expressed in US dollars (USD) for the Organization. When the cap is reached, recording stops immediately, including for a meeting in progress, until the quota is renewed, the cap is raised or the Plan is upgraded. Without overage enabled, the Free Plan rule applies.
9.7. Processing Region. There is no fixed default region: the Processing Region is derived from the country declared by the Organization at sign-up, selecting the closest region: European Union for a European country, understood in the geographic sense: any country on the European continent (EU, EEA, Switzerland, United Kingdom, etc.), including Turkey and the Caucasus countries, but excluding Russia; United States otherwise. The Recording Bot (Recall.ai) and transcription follow this region: in the European Union, transcription by Mistral AI (Voxtral Mini Transcribe 2 model (voxtral-mini-2602)); in the United States, transcription by xAI. The Account Owner or an Organization Admin may change the Processing Region; the change is logged and applies to subsequent recordings. For an Organization in the EU region, recording and transcription remain within the Union. However, AI analysis of transcripts and the other AI features (summaries, tasks, drafting) are performed by OpenAI, in the United States, regardless of the Processing Region (see Article 8.6 and the DPA).
9.8. Retention.
- Recordings (video and audio) and transcripts: kept for 30 days by default, adjustable by the Organization up to 6 months maximum; if the Plan provides for a lower maximum, that maximum applies. The Account Owner or an Organization Admin sets this period (for example 15 days). On expiry, the recording and its transcript are deleted automatically.
- Summaries, tasks and analyses: kept as long as the meeting exists in the Service, unless deleted.
- Deletion on request: the User who owns the meeting may delete the video or the entire meeting at any time; deletion is immediate in the Service.
- Backups: deleted data may remain for up to 30 days in technical backups, without being accessible or used, and is then erased.
- The media is deleted from the recording provider after being copied to the Service's storage.
9.9. Sensitive data. The User avoids recording meetings involving special categories of data (Article 9 GDPR) without an appropriate legal basis.
Article 10 — Electronic signature requests
10.1. On the Growth and Scale Plans (and during the Growth Trial), the User may send a PDF document for electronic signature through the Customer's account with an electronic signature provider chosen by the Customer (Youtrust or DocuSign). The Customer uses its own account and its own contract with that provider and configures the connection itself; the Publisher only provides the connector. Youtrust is connected using the Customer's own Youtrust API key, entered on a self-service basis by the Account Owner or an Organization Admin, under the rules of Article 12.3: the key remains the Customer's, is stored encrypted, is used only for the signature requests made by the Customer and may be revoked at any time. The Customer remains responsible for its Youtrust account and contract. That provider is a third-party service chosen by the Customer, not a sub-processor of the Publisher: documents and signatories' details are transmitted to it on the Customer's instructions. Electronic signature is not available on the Free and Starter Plans. These services remain governed by the terms agreed between the Customer and their provider.
10.2. The User checks the document, the signatories, the signing order and the signature level before any sending, which requires their confirmation. The document sent becomes visible to the team.
10.2 bis. The AI Agent may prepare the email sending the document to an outside reviewer (for example the Customer's lawyer); this email is sent from the User's mailbox after their approval, and the reply is handled like any synced email (Article 5 and Article 12).
10.3. The Publisher is not a party to the signed documents and does not guarantee their legal validity. The signed PDF and the audit trail provided by the provider are attached to the record.
Article 11 — Workflows (automations)
11.1. Authorized Users create Workflows, including with the help of the AI Agent. Only the Account Owner, Organization Admins and Members with the "Automator" option (for their own Workflows) may activate them.
11.2. A Workflow may act repeatedly and at scale (sending emails, modifying data, calling external services). The User checks and tests it before activating it. The actions of an active Workflow are deemed to be performed by the Customer.
11.3. The number of active Workflows is limited by the Plan; beyond that, activation is refused (Free Plan) or subject to confirmation of an additional cost (paid Plans), in accordance with the Conditions of Sale.
11.4. Outgoing HTTP calls from a Workflow are restricted for security reasons (HTTPS only, internal addresses blocked, maximum timeouts and sizes). When an Integration requires re-authorization, the Workflows that depend on it are paused and the Organization Admin is notified.
Article 12 — Third-party integrations
12.1. Email and calendar. Each User may connect their own Google (Gmail, Google Calendar) or Microsoft (Outlook, Microsoft 365 calendar) mailbox and calendar via OAuth. The permissions requested allow reading and syncing emails, sending emails, and reading and modifying the calendar (creating, modifying and deleting events from the Service), as well as checking availability and the list of calendars in order to propose time slots; the Google permissions are detailed in section 9 of the Privacy Policy. Scope: by default, only new emails exchanged with contacts already in the CRM are processed. The User may enable, and revoke at any time, two separate settings: analysis of their full mailbox history and contact suggestions from new emails; revocation immediately stops the processing, deletes unaccepted suggestions and purges within 30 days history emails not from CRM contacts, existing contacts and accepted suggestions being kept; these settings do not relieve the Customer of its duty to inform the correspondents concerned (Article 19.3). A connection is linked to the User within a given Organization: the same mailbox connected in two Organizations results in two independent syncs.
12.2. Organization integrations. The Account Owner or an Organization Admin may connect services for the Organization (in particular Stripe in read-only mode, Atlassian Jira, or the Customer's electronic signature provider, Article 10). All integrations managed by the Publisher are available on all Plans (except electronic signature, reserved to the Growth and Scale Plans, Article 10).
12.3. Connecting Integrations: OAuth or the Customer's API key. OAuth is preferred where the provider offers it. Otherwise, the Account Owner or an Organization Admin may connect an Integration directly, on a self-service basis, using an API key or other authentication secret that the Customer holds with the relevant provider, within the limits of the Integrations available on its Plan (Article 12.2 and Pricing page); this applies in particular to Youtrust (Article 10.1) and to the generic "HTTP header" connector in Workflows. For such keys:
- they are provided by the Customer and remain the Customer's;
- the Publisher stores them encrypted (AES-256-GCM, like other integration secrets) and uses them only for the connected feature, on the Customer's instructions;
- the Customer may revoke them at any time by deleting them in the Service or with the provider;
- the Customer is responsible for its account and contract with the provider, for the keys it provides and for the services it calls; the Publisher is responsible for the secure storage of these keys.
This option does not apply to AI model provider keys: on the Plans of the shared application, AI features always run through the Publisher's accounts (Article 8.6); the Customer's use of its own key for the AI Agent model is reserved to dedicated instances, on quotation.
12.4. The User only connects accounts they are authorized to use, in accordance with their organization's rules, and authorizes the Service to access the data in those accounts within the limits of the permissions granted, in order to provide the requested features.
12.5. Revocation. The User may revoke an Integration at any time from the Service or from the third-party service's settings; syncing then stops. If Google access (Gmail, Google Calendar) is revoked, processing stops immediately, unaccepted contact suggestions are deleted and emails not linked to a CRM contact are purged within 30 days; data already incorporated into the CRM (existing contacts, accepted suggestions, emails linked to a contact) remains Customer Data, subject to the retention and deletion rules of these Terms of Use (in particular Article 18).
12.6. Google data. Arcane CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This data is used only to provide and improve user-facing features of Arcane CRM; it is never used to train generalized AI models, and is neither sold nor used for advertising. Details are set out in section 9 of the Privacy Policy (https://arcane-crm.com/privacy/).
12.7. Third-party services are governed by their own terms. The Publisher is not responsible for their availability, their changes or the withdrawal of their APIs.
Article 13 — Public API, webhooks and access by third-party applications
13.1. Paid Plans only. The Arcane CRM public API and webhooks are available on the Starter, Growth and Scale Plans. They are not available on the Free Plan.
13.2. API keys. Keys are created by the Account Owner or an Organization Admin, for an Organization, with configurable rights (read or write, per object, webhooks, Workflows). A key is displayed only once; it may be rotated, have an expiry date and be revoked immediately. Creations, rotations, revocations and write calls are logged.
13.3. Rate limits. By default: Starter 120, Growth 300, Scale 600 requests per minute. Beyond that, the Service responds with a temporary refusal; the Customer may contact support for an adapted limit.
13.4. Webhooks. Webhooks are signed with a secret issued by the Publisher. The Customer verifies their signature and secures the receiving endpoint.
13.5. Customer's responsibility. The Customer keeps its keys confidential, grants the minimum necessary rights and is liable for the use of the API by its developers and contractors, and for the data it obtains and transfers by this means. Data transmitted through the API or webhooks to a system of the Customer or of a third party chosen by the Customer leaves the Publisher's scope of responsibility.
13.6. MCP server and third-party assistants. The Customer may connect third-party assistants or agents (for example MCP-compatible AI assistants) to the Service, by means of an OAuth authorization. These assistants act with the rights of the User who authorizes them, and the data they obtain is processed by their provider under the Customer's responsibility.
Article 14 — Security
14.1. The Publisher implements appropriate technical and organizational measures to protect the Service and Customer Data, described in the DPA, in particular: isolation of Organizations; encryption of communications (TLS); application-level encryption of OAuth tokens and integration secrets (AES-256-GCM); encryption of data at rest, including backups, by the hosting provider Railway (AES-256); logging of staff access (Article 14.3).
14.2. The place of processing of Customer Data depends on the Organization's Processing Region: in the EU region, meeting recording and transcription remain in the European Union (Recall.ai EU, Mistral AI); in the United States region, they are performed in the United States (Recall.ai US, xAI). In all cases, AI features are performed by OpenAI, in the United States (Article 8.6). These processing operations outside the Union are described in the DPA and the sub-processor list.
14.3. Access by the Publisher's staff. The Publisher's staff only access an Organization's Data where necessary (support requested, security, legal obligation). Any access is logged and visible to the Account Owner.
14.4. The User contributes to security (strong sign-in credentials, locking their devices, revoking unnecessary access and keys) and promptly reports any vulnerability or incident to [email protected].
14.5. In the event of a personal data breach, the Publisher informs the Customer in accordance with the DPA.
Article 15 — Content and intellectual property
15.1. The Customer remains the owner of Customer Data. The User warrants that they hold the necessary rights over the content they import or record. Data import (in particular via CSV file, available on all Plans) is carried out under the Customer's responsibility, which warrants the lawfulness of its collection and processing.
15.2. The Service, its code, interfaces, documentation and trademarks belong to the Publisher or its licensors. The Publisher grants the Customer a non-exclusive, non-transferable right of use, for the term of the subscription, for its internal needs and within the limit of the Seats subscribed.
Article 16 — Availability, evolution and limits of the Service
16.1. The Publisher endeavors to ensure the availability of the Service, without any quantified commitment, under the conditions set out in the Conditions of Sale.
16.2. The Service evolves. Some features may be offered in beta, provided "as is", and may be modified or withdrawn.
16.3. Limits and data exceeding limits. When a Plan limit is reached or reduced, the rules of the Conditions of Sale apply. In particular, at the end of the Growth Trial, data and items exceeding the Free Plan limits are frozen in read-only mode for 30 days, then archived: they are no longer accessible in the Service but remain restorable if a paid Plan is subscribed. Archives are kept for 90 days, then permanently deleted, subject to backup rotation (30 days), after notice by email (7 days before deletion).
16.4. Deleting a field. Deletion of a custom field by the Account Owner or an Organization Admin immediately and permanently erases its values in all records, after an enhanced confirmation. It is refused if a published Workflow uses that field. There is no recycle bin; the 30-day technical backups do not constitute a restoration commitment.
Article 17 — Suspension
17.1. The Publisher may suspend a User's access, a feature (for example email sending, the Recording Bot, the API or an API key) or an Organization, in the event of:
- breach of these Terms of Use, in particular the prohibited uses (Article 6) or the recording rules (Article 9);
- repeated complaints from email recipients or Participants;
- risk to the security or integrity of the Service, other Organizations or third parties (for example a compromised API key);
- misuse of the AI (Article 8.7), after the alert and discussion procedure described in Article 8.7, or circumvention of technical limits;
- non-payment, according to the schedule set out in the Conditions of Sale (read-only from the 14th day, suspension from the 30th day of delay);
- a request from an authority.
17.2. Except in an emergency, the Publisher notifies the Account Owner and grants a reasonable period to remedy the situation. The suspension is proportionate and lifted as soon as its cause has ceased.
17.3. During a suspension of the Organization, no new Bot is scheduled and Bots already scheduled are cancelled; Workflows and syncs are stopped.
Article 18 — User departure and deletion
18.1. Removal of a User. The Account Owner or an Organization Admin may remove a User's access. Upon removal:
- the Organization Admin designates a successor, to whom the records owned by the User, their Workflows (deactivated then reassigned), shared dashboards and shared meetings are transferred;
- the User's sessions, keys and access tokens (including API and MCP) are revoked immediately;
- their Google or Microsoft connections are revoked with the provider and their syncs stopped;
- their private emails and meetings, not shared with the Organization, are deleted 30 days after their departure, subject to backups (30 additional days at most);
- the operation is logged.
18.2. Deletion of the Organization. Only the Account Owner may delete the Organization, after an explicit confirmation step. The Organization is placed in pending deletion for 30 days, during which the deletion can be cancelled; syncs, Workflows and Bots are stopped and Integrations revoked. At the end of this period, the data is permanently deleted, subject to backups (30 days) and the Publisher's legal retention obligations.
18.3. Before any deletion, the Account Owner is invited to export the data.
Article 19 — Personal data
19.1. Processing carried out by the Publisher on its own behalf (User accounts, support, billing, security) is described in the Privacy Policy (https://arcane-crm.com/privacy/).
19.2. Processing carried out on behalf of the Customer (CRM contacts, emails, calendars, meeting recordings and transcripts, AI Outputs) is governed by the Data Processing Agreement (DPA), available on request at [email protected]. The list of sub-processors and third-party services ("Third parties", in French) is available at https://arcane-crm.com/fr/third-parties/.
19.3. The Customer, as controller, informs data subjects (employees, contacts, prospects, Participants) of the processing it carries out through the Service and handles their requests to exercise their rights. The Service provides tools to search for, export and delete an individual's data; the Publisher assists the Customer in accordance with the DPA.
19.4. Cookies and trackers are described in the Privacy Policy (https://arcane-crm.com/privacy/). At present, no tracker requiring consent is used.
Article 20 — Changes to the Terms of Use
20.1. The Publisher may change these Terms of Use. Material changes are notified within a reasonable period before they take effect, by email or within the Service. Changes required by law or for security reasons may apply immediately.
20.2. Use of the Service after the changes take effect constitutes acceptance. A Customer who refuses may terminate under the conditions set out in the Conditions of Sale.
Article 21 — Governing law and disputes
21.1. These Terms of Use are governed by French law.
21.2. Disputes are handled in accordance with the provisions of the Conditions of Sale on dispute resolution.
21.3. Language. These terms are drafted in French. The English version is provided for information only; in case of discrepancy, the French version (https://arcane-crm.com/fr/cgu/) prevails.
Article 22 — Contact
- General contact, reports, security and personal data: [email protected]
- Support: [email protected]
- Post: Arcane Powered, 142 rue de Rivoli, 75001 Paris, France