Legal
Privacy policy
This policy describes which personal data we process when operating this website and the ARKTOS platform — and which data we process solely on behalf of our customers.
Last updated: 22 August 2026
This is a non-binding reading version. Only the German original is legally binding; in case of any discrepancy, the German version prevails.
1. Controller
- Controller
- Consilion GmbH
- Address
- Jungenhofener Weg 10, 96114 Hirschaid, Germany
- Represented by
- Florian Steinfelder, Managing Director
- Email for privacy enquiries
- admin@crm-arktos.com
No data protection officer has been appointed; the statutory conditions of Art. 37 GDPR and § 38 BDSG are not met. Please direct privacy enquiries to the address above.
2. Two roles — please read first
ARKTOS processes personal data in two separate roles. Which role applies determines who you address your rights to.
As a controller within the meaning of Art. 4 (7) GDPR we process the data arising from visits to this website, from access requests, and from operating the user accounts of our customers' staff. This policy governs that processing, and your rights are exercised against us.
As a processor within the meaning of Art. 4 (8) GDPR we process everything a customer places into their workspace or has collected there — in particular company and contact data, meeting notes, documents and analyses. There the customer alone is the controller. The basis is a data processing agreement under Art. 28 GDPR. If you are recorded as a contact person of a company in such a workspace, please address your rights to the customer who recorded you. On request we will name the controller to you, insofar as we can do so without breaching other obligations.
3. Visiting this website
When you access this website, our hosting provider processes technically necessary connection data: IP address, time of the request, the address requested, HTTP status code, volume of data transferred, referrer and user agent. This data is required to deliver the page and to detect attacks.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and uninterrupted operation of the service.
No analytics, tracking or advertising services run on this website. There are no counting pixels, no external session recorders and no advertising cookies. The fonts used are embedded when the application is built and served from our own server at runtime; no connection to a font provider is made when the page loads.
5. Access requests
If you request access via the form on this website, we process your name, your business email address, your company name, the number of workspaces and seats you want, your indication of the intended use, and your optional message.
To limit abusive requests we additionally store a cryptographic hash of your IP address. The IP address itself is not stored, and it cannot be recovered from the hash.
The legal basis is Art. 6 (1) (b) GDPR for handling your request and Art. 6 (1) (f) GDPR for abuse prevention. If no contract results, we delete the request at the latest six months after the last communication, unless a statutory retention obligation applies.
6. User accounts and contract performance
To use the platform we create an account per person. For this we process name, business email address, a password hash, the role in the respective workspace, sign-in times and — where enabled — the two-factor authentication configuration.
Security-relevant and change-relevant events are recorded in a change log that cannot subsequently be altered or deleted. A log that can be cleaned up would be worthless as evidence. When an account is deleted, we replace its identifier in that log with a pseudonym rather than removing the entry.
The legal basis is Art. 6 (1) (b) GDPR for performing the contract and Art. 6 (1) (f) GDPR for the logging; our legitimate interest is the traceability of security-relevant events.
7. Processing on behalf of our customers
The actual content of the platform is processed solely on the documented instructions of the respective customer. This includes in particular company data with addresses and management details, contact persons with their function and business contact data, meeting notes, uploaded documents, voice recordings and their transcripts, and the analyses derived from all of these.
We conclude a data processing agreement under Art. 28 GDPR with our customers. It governs the subject matter, duration, nature and purpose of the processing, the categories of data subjects, the technical and organisational measures, and the sub-processors used.
We do not use this content for our own purposes. In particular we do not analyse it to improve our own products, and we do not pass it to third parties beyond what is necessary to provide the service or required by law.
8. Use of artificial intelligence
Core functions of the platform rely on language models: enriching company profiles, scoring against the criteria the customer has configured, analysing meeting notes and documents, and drafting outreach.
Content is transmitted to the respective model provider for this. Depending on the operation it may contain personal data — for example the names of directors and contact persons, business contact data, addresses, full-text meeting notes or complete uploaded documents.
The platform's scores relate to companies, not to natural persons. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning a data subject or similarly significantly affects them. All results are proposals; the decision is taken by a human at the customer.
For four services — Anthropic, Firecrawl, RocketReach and Inven — the platform uses only access keys supplied by the customer themselves. That traffic runs under the customer's contractual relationship with the provider, not ours.
9. Recipients and sub-processors
We use the following service providers. With providers that process personal data on our behalf we conclude agreements under Art. 28 GDPR. We provide customers with a current version of this overview on request.
| Provider | Purpose | Processing location |
|---|---|---|
| Vercel Inc. | Hosting and application runtime | Ireland (Dublin region), company domiciled in the USA |
| Supabase Inc. | Database, authentication, file storage | Ireland (AWS eu-west-1), company domiciled in the USA |
| Anthropic PBC | Language model for enrichment, scoring and drafting | USA |
| Resend Inc. | Delivery of system and outreach email | USA |
| Inngest Inc. | Orchestration of background processing | USA |
| Firecrawl / Mendable | Retrieval of publicly accessible company websites | USA |
| Jina AI | Secondary page retrieval and web search | Singapore / USA |
| RocketReach LLC | Business contact discovery (on request only) | USA |
| Inven | Company search for sourcing (no personal data) | EU |
| OpenAI | Transcription of voice recordings, where enabled | USA |
| OpenStreetMap Foundation | Conversion of company addresses into coordinates | EU / United Kingdom |
10. Transfers to third countries
Some of the providers listed are domiciled in the United States or process data there. Where no adequacy decision of the European Commission applies to a provider, we base the transfer on the standard contractual clauses under Art. 46 (2) (c) GDPR together with supplementary measures.
Despite these safeguards it cannot be excluded that authorities in the recipient country access the data, or that the level of protection there falls short of the Union's in individual cases. On request we will provide the safeguards relevant to a given provider.
11. Retention periods
We retain personal data only for as long as it is necessary for the respective purpose or required by statutory retention obligations. The following periods are implemented technically and run automatically.
| Data | Period |
|---|---|
| Workspace backups | 14 days from creation, then deleted automatically |
| Raw responses from contact discovery | 90 days from retrieval |
| Cached website content | 180 days from retrieval |
| Voice recordings | 90 days from recording; transcript and analysis are retained |
| Access requests without a resulting contract | at the latest 6 months after the last communication |
| Account and contract data | for the term of the contract, then until statutory retention periods expire |
| Change log | immutable; identifiers are pseudonymised when an account is deleted |
| Content in a customer's workspace | on the customer's instruction, at the latest on termination of the contract |
12. Security of processing
We take technical and organisational measures under Art. 32 GDPR. These include in particular:
- Transport encryption with enforced HTTPS and HSTS; in production the application refuses to start if an unencrypted base address is configured.
- A TLS-secured connection to the database.
- Encryption at rest of stored provider access keys using AES-256-GCM, with key rotation supported.
- Strict tenant separation: every workspace is isolated at the database level by row-level security.
- Role-based permissions and optional two-factor authentication.
- Non-public files are served exclusively through authenticated routes and time-limited signed URLs.
- A change log that cannot be altered after the fact.
- Daily backups of every workspace with a defined retention period.
13. Your rights
You have the following rights against the respective controller. Please note the split of roles in section 2: for content inside a customer workspace, the customer is your point of contact.
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on a legitimate interest (Art. 21 GDPR)
- Withdrawal of a given consent with effect for the future (Art. 7 (3) GDPR)
14. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.
You may equally contact the supervisory authority of your habitual residence or place of work.
15. Changes to this policy
We update this policy when our processing or the legal situation changes. The version available on this page at the time applies; the date of the last change is stated above.