Arrk.io Privacy Policy
Effective Date: Aug 27, 2025
1. Introduction
The Arrk, Inc. ("Arrk," "Company," "we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website www.arrk.io and use our SaaS technology services (collectively, the "Services"). By using our Services, you consent to the data practices described in this Privacy Policy.
2. Information We Collect
Personal Information: We may collect personal information that you voluntarily provide, including:
- Name, email address, phone number, and business contact information
- Account credentials and authentication information
- Payment and billing information
- Business and professional information related to insurance activities
- Communications and correspondence with us
Automatically Collected Information: We automatically collect certain information when you use our Services:
- IP address, browser type, operating system, and device information
- Usage data, including pages visited, time spent, and click patterns
- Cookies and similar tracking technologies
- Log files and server data
3. How We Use Your Information
We use collected information for the following purposes:
- Providing, operating, and maintaining our Services
- Processing transactions and managing your account
- Communicating with you about our Services, updates, and support
- Improving our Services and developing new features
- Ensuring compliance with legal and regulatory requirements
- Detecting, preventing, and addressing fraud and security issues
- Marketing and promotional communications (with your consent)
4. Information Sharing and Disclosure
We may share your information in the following circumstances:
- Service Providers: With third-party vendors who assist in operating our Services
- Business Partners: With insurance carriers and intermediaries as necessary to provide Services
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with mergers, acquisitions, or asset sales
- Consent: With your explicit consent for specific purposes
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit and at rest
- Access controls and authentication protocols
- Regular security assessments and monitoring
- Employee training on data protection practices
Note: However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your personal information only as long as necessary to:
- Provide our Services to you
- Comply with legal and regulatory obligations
- Resolve disputes and enforce our agreements
- Maintain business records for legitimate purposes
Account Termination: Upon termination of your account, we will delete or anonymize your personal information within a reasonable timeframe, unless retention is required by law.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access - Request access to your personal information
- Correction - Request correction of inaccurate information
- Deletion - Request deletion of your personal information
- Portability - Request transfer of your information to another service
- Objection - Object to certain processing activities
- Opt-out - Unsubscribe from marketing communications
To exercise these rights: Contact us at privacy@arrk.io
8. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Remember your preferences and settings
- Analyze usage patterns and improve our Services
- Provide personalized content and features
- Ensure security and prevent fraud
Cookie Control: You can control cookie settings through your browser preferences, though disabling cookies may affect functionality.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
- Cross-border data processing with appropriate safeguards
- Compliance with applicable data protection laws
- International operations with proper protection measures
10. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will take steps to delete it promptly.
11. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.
12. California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA), including:
- Right to Know: What personal information is collected and how it is used
- Right to Delete: Request deletion of personal information
- Right to Opt-out: Opt-out of the sale of personal information
- Right to Non-discrimination: No discrimination for exercising privacy rights
Important: We do not sell personal information as defined by the CCPA.
13. European Privacy Rights
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including those outlined in Section 7 above. Our lawful basis for processing includes:
- Contractual necessity for providing our Services
- Legitimate interests in operating and improving our business
- Legal compliance with applicable regulations
- Consent where explicitly provided
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes by posting the updated policy on our website and updating the effective date. Your continued use of our Services after such changes constitutes acceptance of the updated Privacy Policy.
15. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
The Arrk, Inc.2624 North Division St. #1090
Spokane, WA 99207
United States
Phone: +1 (713) 606-6210
Email: privacy@arrk.io
General Email: info@arrk.io
16. Data Protection Officer
For privacy-related inquiries or to exercise your data protection rights, you may contact our Data Protection Officer at privacy@arrk.io.
17. Biometric Information
If we collect biometric information (such as fingerprints or facial recognition data), we will:
- Obtain your written consent before collection
- Inform you of the purpose and duration of collection and use
- Not sell, lease, trade, or otherwise profit from biometric information
- Store biometric information for no more than 3 years or until the purpose is satisfied
- Use reasonable care to protect biometric information from disclosure
18. Automated Decision Making
We may use automated decision-making processes, including profiling, for:
- Risk Assessment: Fraud prevention and security measures
- Personalization: Service recommendations and customization
- Compliance: Regulatory monitoring and reporting
Your Rights: You have the right to request human review of automated decisions that significantly affect you.
19. Cross-Border Data Processing
We may process your personal information in the United States and other countries where we or our service providers operate. We implement appropriate safeguards including:
- Contractual Clauses: Standard contractual clauses approved by regulatory authorities
- Adequacy Decisions: Adequacy decisions by relevant data protection authorities
- Corporate Rules: Binding corporate rules where applicable
- Explicit Consent: Your explicit consent for specific transfers
20. Data Breach Response
In the event of a data breach affecting your personal information, we will:
- Notify relevant authorities within 72 hours where required by law
- Inform affected individuals without undue delay when required
- Provide clear information about the nature of the breach and steps being taken
- Offer appropriate remedial measures including identity monitoring services where applicable
21. Vendor and Third-Party Management
We carefully vet all service providers and require them to:
- Security Measures: Implement appropriate technical and organizational security measures
- Purpose Limitation: Process personal information only for specified purposes
- Retention Control: Not retain personal information longer than necessary
- Incident Reporting: Notify us immediately of any security incidents
22. Employee Access and Training
We limit employee access to personal information based on job requirements and provide:
- Regular privacy and security training
- Background checks for employees with access to sensitive information
- Confidentiality agreements and non-disclosure obligations
- Monitoring and logging of access to personal information systems
23. Records Management
We maintain detailed records of our data processing activities including:
- Data Categories: Categories of personal information processed
- Processing Purposes: Purposes of processing and legal basis
- Retention Schedules: Data retention schedules and deletion procedures
- International Transfers: International transfers and safeguards implemented
Security Measures: Technical and organizational security measures are documented and regularly updated
24. Regulatory Cooperation
We cooperate fully with data protection authorities and will:
- Respond promptly to official inquiries and investigations
- Provide requested documentation and access to systems
- Implement corrective measures as directed by regulators
- Participate in regulatory proceedings and compliance reviews
25. Insurance Industry Specific Provisions
Given our role in the insurance technology sector:
- Underwriting & Claims: We may process information necessary for underwriting and claims processing
- Regulatory Compliance: We comply with insurance regulatory requirements for data handling
- Information Sharing: We may share information with insurance carriers and intermediaries as necessary
- Insurance Coverage: We maintain appropriate professional indemnity and cyber liability insurance