Privacy Policy
Last updated: 22 August 2026
Arvo is used by construction teams to read programmes and contracts. This policy explains what personal data we handle, why, and what you can ask us to do with it.
1. Who we are
Arvo Systems Ltd (“Arvo”, “we”) is a company registered in England and Wales, company number 17305187, with its registered office at 48 Norbury Avenue, Watford, England, WD24 4PJ. We are the data controller for the personal data described in section 3 and a data processor for the project content our customers upload.
For anything in this policy, contact hello@arvosystem.com.
2. Controller and processor, and why the difference matters
Two different relationships run through this product, and your rights differ between them.
- We are the controller for account data: the people who sign up, sign in, book a demo or receive our emails. We decide what to collect and why.
- We are a processor for the project content a customer puts into Arvo: programmes, contracts, correspondence and the personal data inside those documents, for example the names and contact details of site staff and contract administrators. The customer organisation is the controller for that material and decides how long it stays. If your details appear in a project because you work on it, your request usually belongs with that organisation, and we will help them answer it.
3. What we collect
| Data | Why | Lawful basis |
|---|---|---|
| Name, work email, organisation | Creating and securing your account, and knowing which projects you may see | Contract |
| Work email submitted to “Book a demo” | Replying to arrange a demonstration | Legitimate interests: responding to an enquiry you made |
| Project content you upload: programmes, contracts, correspondence, files | Providing the service. May contain personal data your organisation put there | Processed on your organisation’s instructions |
| Usage and audit records: sign-ins, actions taken, AI outputs and their provenance | Security, support, and showing where an AI-derived statement came from | Legitimate interests: running a service that can be audited |
| Technical data: IP address, browser, and whether a digest email was opened | Security, rate limiting, and knowing whether our own emails are useful | Legitimate interests |
We do not collect special category data deliberately. Do not put health, trade union or similar data into a project unless your organisation has a lawful basis for it.
4. AI processing, and what it does not do
Arvo sends project text to Anthropic and OpenAI to draft correspondence and summarise documents. If you record a voice note, the audio itself is sent to OpenAI to be transcribed, so what leaves Arvo in that one case is a recording of someone speaking rather than text. Two limits are worth stating plainly, because they are the questions we are actually asked:
- Your content is not used to train their models. We use these providers under their API terms, which exclude API data from model training.
- AI output is a draft, never a decision. Arvo proposes, deterministic code validates, and a human approves. Nothing is sent to a third party, and no contractual notice is issued, without a person deciding to.
5. Who processes data for us
Each of these handles data only to deliver part of the service, and this is the whole list as the product stands today rather than an architecture we intend to build. Every provider that holds personal data for us is engaged under a data processing agreement. The one exception is the weather lookup at the end of the table, which receives a place name and nothing else, and is a free public service we have no agreement with.
| Provider | What they do | Data involved |
|---|---|---|
| Supabase | The database and file storage behind Arvo, hosted in London. Almost everything described in section 3 is held here. | Every record Arvo keeps: accounts, projects, contracts and the documents you upload, programmes, correspondence, risks, site records and audit logs |
| Clerk | Authentication and sessions | Name, email, sign-in credentials, session identifiers |
| Cloudflare | Bot protection in front of sign-in, used by Clerk, and the platform PartyKit runs on | IP address and request metadata at sign-in; and, through PartyKit, the draft text and names described in that row |
| Vercel | Hosting, and cookie-free traffic and performance measurement | Requests to the app; page and performance counts with no cookies |
| Fly.io | Two supporting services, both hosted in London: one reads Microsoft Project and Powerproject files, which are binary formats the rest of Arvo cannot open, and one renders the documents you issue to a client | The programme file you upload, which the service fetches directly from storage, and the contents of any programme you issue as a client document |
| Anthropic | AI drafting and summarisation | The project text needed for the feature |
| OpenAI | AI drafting and summarisation, and transcribing voice notes | The project text needed for the feature, and the audio of any voice note you record |
| Resend | Email delivery, including daily digests and notice correspondence | Email addresses and message content |
| PartyKit | Real-time collaboration while a draft or board is open, including contractual correspondence | The text of the notice or board being edited, and the name of each person in the session, for as long as it is open |
| Optional Drive integration, only if you connect it | The specific files you choose to open with Arvo | |
| wttr.in | Weather for a project’s location, shown on the daily briefing | A place name only, sent from our servers. No personal data, no account details and not your IP address |
Some of these process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Addendum or equivalent safeguards.
6. How long we keep it
- Account data: for as long as the account is active, then up to 12 months.
- Project content: for as long as the customer organisation keeps it, and deleted on their instruction. Backups age out within 35 days.
- Demo enquiries: up to 24 months from your last contact with us.
- Security and audit logs: up to 12 months.
7. Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, and ask for it in a portable form. Email hello@arvosystem.com and we will respond within one month.
If your data reached us because your employer or a contracting party put it into a project, we will pass your request to them, since they decide what happens to it.
You can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first.
8. Security
Access is scoped to your organisation and project membership and enforced on every request. Data is encrypted in transit and at rest. Files are served through short-lived signed URLs rather than public links. We will tell affected customers and the ICO about a qualifying personal data breach within 72 hours of becoming aware of it.
9. Cookies
Arvo sets only cookies that are strictly necessary to sign you in and keep the service secure. There is no advertising and no cross-site tracking. See the Cookie Policy for the specific cookies and what each one does.
10. Changes
We may update this policy. The date at the top changes when we do, and we will tell customers before a material change takes effect.