ARKTOS.
About ARKTOS

Legal

Privacy policy

This policy describes which personal data we process when operating this website and the ARKTOS platform — and which data we process solely on behalf of our customers.

Last updated: 22 August 2026

This is a non-binding reading version. Only the German original is legally binding; in case of any discrepancy, the German version prevails.

1. Controller

Controller
Consilion GmbH
Address
Jungenhofener Weg 10, 96114 Hirschaid, Germany
Represented by
Florian Steinfelder, Managing Director
Email for privacy enquiries
admin@crm-arktos.com

No data protection officer has been appointed; the statutory conditions of Art. 37 GDPR and § 38 BDSG are not met. Please direct privacy enquiries to the address above.

2. Two roles — please read first

ARKTOS processes personal data in two separate roles. Which role applies determines who you address your rights to.

As a controller within the meaning of Art. 4 (7) GDPR we process the data arising from visits to this website, from access requests, and from operating the user accounts of our customers' staff. This policy governs that processing, and your rights are exercised against us.

As a processor within the meaning of Art. 4 (8) GDPR we process everything a customer places into their workspace or has collected there — in particular company and contact data, meeting notes, documents and analyses. There the customer alone is the controller. The basis is a data processing agreement under Art. 28 GDPR. If you are recorded as a contact person of a company in such a workspace, please address your rights to the customer who recorded you. On request we will name the controller to you, insofar as we can do so without breaching other obligations.

3. Visiting this website

When you access this website, our hosting provider processes technically necessary connection data: IP address, time of the request, the address requested, HTTP status code, volume of data transferred, referrer and user agent. This data is required to deliver the page and to detect attacks.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and uninterrupted operation of the service.

No analytics, tracking or advertising services run on this website. There are no counting pixels, no external session recorders and no advertising cookies. The fonts used are embedded when the application is built and served from our own server at runtime; no connection to a font provider is made when the page loads.

4. Cookies

We use strictly necessary cookies only. They serve to sign you in and to maintain your session in the authenticated area. Without them, signing in is technically impossible.

The legal basis for storage is § 25 (2) no. 2 TDDDG; no consent is required for this, and for the same reason we display no consent banner. The subsequent processing is based on Art. 6 (1) (b) GDPR.

5. Access requests

If you request access via the form on this website, we process your name, your business email address, your company name, the number of workspaces and seats you want, your indication of the intended use, and your optional message.

To limit abusive requests we additionally store a cryptographic hash of your IP address. The IP address itself is not stored, and it cannot be recovered from the hash.

The legal basis is Art. 6 (1) (b) GDPR for handling your request and Art. 6 (1) (f) GDPR for abuse prevention. If no contract results, we delete the request at the latest six months after the last communication, unless a statutory retention obligation applies.

6. User accounts and contract performance

To use the platform we create an account per person. For this we process name, business email address, a password hash, the role in the respective workspace, sign-in times and — where enabled — the two-factor authentication configuration.

Security-relevant and change-relevant events are recorded in a change log that cannot subsequently be altered or deleted. A log that can be cleaned up would be worthless as evidence. When an account is deleted, we replace its identifier in that log with a pseudonym rather than removing the entry.

The legal basis is Art. 6 (1) (b) GDPR for performing the contract and Art. 6 (1) (f) GDPR for the logging; our legitimate interest is the traceability of security-relevant events.

7. Processing on behalf of our customers

The actual content of the platform is processed solely on the documented instructions of the respective customer. This includes in particular company data with addresses and management details, contact persons with their function and business contact data, meeting notes, uploaded documents, voice recordings and their transcripts, and the analyses derived from all of these.

We conclude a data processing agreement under Art. 28 GDPR with our customers. It governs the subject matter, duration, nature and purpose of the processing, the categories of data subjects, the technical and organisational measures, and the sub-processors used.

We do not use this content for our own purposes. In particular we do not analyse it to improve our own products, and we do not pass it to third parties beyond what is necessary to provide the service or required by law.

8. Use of artificial intelligence

Core functions of the platform rely on language models: enriching company profiles, scoring against the criteria the customer has configured, analysing meeting notes and documents, and drafting outreach.

Content is transmitted to the respective model provider for this. Depending on the operation it may contain personal data — for example the names of directors and contact persons, business contact data, addresses, full-text meeting notes or complete uploaded documents.

The platform's scores relate to companies, not to natural persons. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning a data subject or similarly significantly affects them. All results are proposals; the decision is taken by a human at the customer.

For four services — Anthropic, Firecrawl, RocketReach and Inven — the platform uses only access keys supplied by the customer themselves. That traffic runs under the customer's contractual relationship with the provider, not ours.

9. Recipients and sub-processors

We use the following service providers. With providers that process personal data on our behalf we conclude agreements under Art. 28 GDPR. We provide customers with a current version of this overview on request.

ProviderPurposeProcessing location
Vercel Inc.Hosting and application runtimeIreland (Dublin region), company domiciled in the USA
Supabase Inc.Database, authentication, file storageIreland (AWS eu-west-1), company domiciled in the USA
Anthropic PBCLanguage model for enrichment, scoring and draftingUSA
Resend Inc.Delivery of system and outreach emailUSA
Inngest Inc.Orchestration of background processingUSA
Firecrawl / MendableRetrieval of publicly accessible company websitesUSA
Jina AISecondary page retrieval and web searchSingapore / USA
RocketReach LLCBusiness contact discovery (on request only)USA
InvenCompany search for sourcing (no personal data)EU
OpenAITranscription of voice recordings, where enabledUSA
OpenStreetMap FoundationConversion of company addresses into coordinatesEU / United Kingdom

10. Transfers to third countries

Some of the providers listed are domiciled in the United States or process data there. Where no adequacy decision of the European Commission applies to a provider, we base the transfer on the standard contractual clauses under Art. 46 (2) (c) GDPR together with supplementary measures.

Despite these safeguards it cannot be excluded that authorities in the recipient country access the data, or that the level of protection there falls short of the Union's in individual cases. On request we will provide the safeguards relevant to a given provider.

11. Retention periods

We retain personal data only for as long as it is necessary for the respective purpose or required by statutory retention obligations. The following periods are implemented technically and run automatically.

DataPeriod
Workspace backups14 days from creation, then deleted automatically
Raw responses from contact discovery90 days from retrieval
Cached website content180 days from retrieval
Voice recordings90 days from recording; transcript and analysis are retained
Access requests without a resulting contractat the latest 6 months after the last communication
Account and contract datafor the term of the contract, then until statutory retention periods expire
Change logimmutable; identifiers are pseudonymised when an account is deleted
Content in a customer's workspaceon the customer's instruction, at the latest on termination of the contract

12. Security of processing

We take technical and organisational measures under Art. 32 GDPR. These include in particular:

  • Transport encryption with enforced HTTPS and HSTS; in production the application refuses to start if an unencrypted base address is configured.
  • A TLS-secured connection to the database.
  • Encryption at rest of stored provider access keys using AES-256-GCM, with key rotation supported.
  • Strict tenant separation: every workspace is isolated at the database level by row-level security.
  • Role-based permissions and optional two-factor authentication.
  • Non-public files are served exclusively through authenticated routes and time-limited signed URLs.
  • A change log that cannot be altered after the fact.
  • Daily backups of every workspace with a defined retention period.

13. Your rights

You have the following rights against the respective controller. Please note the split of roles in section 2: for content inside a customer workspace, the customer is your point of contact.

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)
  • Withdrawal of a given consent with effect for the future (Art. 7 (3) GDPR)

14. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

You may equally contact the supervisory authority of your habitual residence or place of work.

15. Changes to this policy

We update this policy when our processing or the legal situation changes. The version available on this page at the time applies; the date of the last change is stated above.