Who we are, and what this policy covers
ArboRule operates a platform for automated workflows and automated decisions. This policy explains what personal data we collect, why we use it, who we share it with, and what you can ask us to do about it.
ArboRule is a product of Murilo Zaffalon Marra Tecnologia da Informação Ltda., a company registered in Brazil under CNPJ 36.586.187/0001-02. That company is the controller of the personal data described here, and “we” means that company throughout this policy.
The policy covers our public website at arborule.com, the product application, and the API. It does not cover the third-party services you connect to a flow. Those services have their own policies, and you choose which of them to use.
If you want to exercise a right, or if you have a question about anything below, write to us at hello@arborule.com. We answer within 30 days.
Two kinds of data, and two different roles
The distinction below decides which parts of this policy apply to you, so we state it before anything else.
We are the controller of your account data. When you create an account, visit the website, or write to us, we decide why and how we use that data. Everything in this policy applies.
We are the processor of your workspace content. The flows you build and the decisions you run can contain personal data about your own customers. We only act on your instructions there. Your own privacy policy governs that data, and our agreement with you sets our obligations. If you are the subject of a decision that one of our customers ran, contact that customer — they can answer for the decision, and we cannot.
The words used here
Personal data means any information about an identified or identifiable person.
Processing means anything done with personal data — collection, storage, use, disclosure, or deletion.
Controller means the party that decides why and how personal data is processed. Processor means the party that processes it on the controller’s instructions.
These terms carry the meaning given to them in the General Data Protection Regulation (GDPR) and in the Brazilian General Data Protection Law (LGPD, Law 13.709/2018).
What we collect
- Account data
- Your name, your email address, your password in hashed form, the name of your organization, the country you bill from, and the product you chose at sign-up.
- Workspace content
- The flows, versions, decision tables, connections, cases, and files that you and your colleagues create. This content can contain personal data about your own customers.
- Decision records
- The input, the output, and the step-by-step trace of every run your flows perform. These records exist so that you can explain a decision after the fact.
- Usage and technical data
- Your IP address, your browser type, the pages you open, the API keys you use, and the entries in your workspace audit log.
- Billing data
- Your plan, your subscription status, and your invoices. Stripe processes the payment itself and holds the card details.
- Contact and support data
- The demo requests, the support messages, and the sales conversations you send us, together with what you write in them.
We do not ask for special categories of data, such as health data or biometric data. Do not send them to our support address. What you choose to process inside your own workspace is your decision and your responsibility.
Where the data comes from
Most of it comes from you: you type it into the sign-up form, into the product, or into an email to us.
Some of it comes from your device as you use the service — your IP address, your browser type, and the pages you open.
Some of it comes from a colleague. An administrator who invites you to a workspace gives us your email address before you have used the product at all.
Some of it comes from a provider that acts for us. Stripe tells us whether a payment succeeded. Cloudflare tells us whether a sign-up looks automated. An identity provider tells us who signed in, when your organization uses single sign-on.
Why we use it
- To give you the platform, to run your flows, and to keep your decision records available to you.
- To create and administer your account, and to let your colleagues join your workspace.
- To bill you, to collect payment, and to keep the accounting records the law requires.
- To answer your questions, and to give you technical support.
- To keep the service secure: to detect abuse, to block automated sign-ups, and to investigate incidents.
- To measure how the product and the website perform, so that we can improve them.
- To tell you about changes to the service, and — where you agreed to it — to send you marketing email.
- To comply with the law, and to defend a legal claim.
Our legal basis for each use
To perform our contract with you. We need your account data to give you an account, to run your flows, and to bill you. Article 6(1)(b) GDPR; Article 7, V LGPD.
Our legitimate interests. We use technical data to keep the service secure, to prevent abuse, and to understand how the product is used. We have weighed these interests against your rights, and you can object at any time. Article 6(1)(f) GDPR; Article 7, IX LGPD.
Your consent. We rely on consent for optional analytics cookies and for marketing email. You can withdraw it at any time. Article 6(1)(a) GDPR; Article 7, I LGPD.
A legal obligation. Tax law and company law require us to keep invoices and accounting records. Article 6(1)(c) GDPR; Article 7, II LGPD.
International transfers
We host the platform in the United States, in the AWS region us-east-1. Our providers are listed in the table above, with the country each one operates in.
If you are in the European Economic Area, in the United Kingdom, or in Switzerland, your data leaves that area when you use the service. We rely on the European Commission’s Standard Contractual Clauses for those transfers, and we keep a copy of the clauses we have signed.
If you are in Brazil, we transfer your data abroad under Article 33 of the LGPD, on the basis of contractual clauses that carry the protection the law requires.
How we protect it
We encrypt data in transit with TLS, and we encrypt it at rest. We store passwords as salted hashes, never in a form we can read.
We store an API key as a SHA-256 digest. The key itself is shown to you once, at the moment you create it, and it is never written to our database — which is also why we cannot recover a lost key for you.
We encrypt the credentials you save in a connection at the application layer, so a database backup does not carry the secrets for your other systems in readable form.
Access to production is restricted to the people who need it, and every administrative action inside a workspace is written to that workspace’s audit log.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authority within the time the law allows.
How long we keep it
We keep your account data and your workspace content while your account is open.
After you close your account, we delete the workspace content within 30 days, except where you have asked us in writing to hold it longer.
We keep technical logs for 12 months, so that we can investigate an incident that is reported late.
We keep invoices and accounting records for as long as tax law requires, which is normally five years in Brazil and seven years in other countries where we operate.
We keep a record of a support conversation for two years after it ends.
Your rights
You have the rights below over your own account data. Write to hello@arborule.com to use any of them. We may ask you to confirm who you are before we act, because handing your data to the wrong person is the worse mistake.
- Access
- You can ask for a copy of the personal data we hold about you.
- Rectification
- You can ask us to correct data that is wrong or incomplete.
- Erasure
- You can ask us to delete your data, unless the law requires us to keep it.
- Restriction
- You can ask us to stop using your data while a dispute about it is open.
- Portability
- You can ask for your data in a machine-readable format, or ask us to send it to another provider.
- Objection
- You can object to processing that rests on our legitimate interests. See the next section.
- Withdrawal
- You can withdraw a consent at any time. The withdrawal does not undo what we did before it.
- Complaint
- You can complain to your data protection authority. You do not have to contact us first.
Using a right costs nothing. We will only charge a fee, or refuse, if a request is clearly excessive or repeated without reason — and we will explain which of the two we think it is.
Your right to object
Where we process your personal data on the basis of our legitimate interests, you can object to that processing at any time, on grounds that arise from your particular situation.
If you object, we stop — unless we can demonstrate compelling legitimate grounds that override your interests, or unless we need the data to establish or defend a legal claim.
If you object to direct marketing, we stop without exception, and we stop immediately.
If you are in Brazil
The LGPD applies to you, and it gives you the rights listed above. It also gives you two more.
You can ask us to confirm that we process your data at all, and you can ask which public and private bodies we have shared it with.
You can ask us to review a decision that was taken purely automatically and that affects your interests. If the decision was run by one of our customers, ask that customer: they built the policy, and they hold the record.
You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.
If you are in California
The California Consumer Privacy Act gives you the right to know what we collect, the right to delete it, the right to correct it, and the right not to be discriminated against for using those rights.
The categories we collect are listed in the section on what we collect. We collect them for the purposes listed in the section on why we use them, and we disclose them to the providers listed in the section on sharing.
We have not sold personal information in the last 12 months, and we have not shared it for cross-context behavioural advertising. We do not sell the personal information of anyone under 16.
Write to hello@arborule.com to make a request. You can name an authorised agent to act for you.
Children
The service is sold to businesses, and it is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We update this policy when the service changes, when we add a provider, or when the law changes. The effective date at the top always tells you which version you are reading.
If a change materially affects your rights, we will tell you by email before it takes effect.
How to contact us
The controller is Murilo Zaffalon Marra Tecnologia da Informação Ltda., registered in Brazil under CNPJ 36.586.187/0001-02.
Write to hello@arborule.com for anything in this policy: a question, a request, a complaint, or a report of a security problem.
Tell us which right you want to use and which email address your account uses. That is enough for us to find you.