Legal
Privacy Policy
Archron Inc operates archron.app and the Archron platform. This policy explains what we collect, why, and what we do not do with it.
Last updated: August 2, 2026
The short version. We do not train AI models on your data. We do not send your business data to any AI provider. Business records stay in your own connected system: Archron holds structure, rules, and evidence, not a copy of your CRM.
1. Two different roles
Most privacy policies describe one relationship. Archron has two, and the distinction decides which rules apply to your data.
- As a controller. When you visit archron.app or submit an application, we decide what is collected and why. That is the personal data described in section 2.
- As a processor. When your organization connects a business system such as Salesforce or HubSpot, any personal data inside that system belongs to you. We act on your instructions, for the purposes you define, under your agreement with us. We do not use it for our own purposes.
2. What we collect as a controller
Information you give us
When you contact sales we collect what the form asks for: company name, first and last name, email address, optional phone number, and anything you write in the message field. We use it to reply to your enquiry and, if you become a customer, to set up your deployment. Creating an account is separate: that happens on the Archron platform rather than on this site.
Information collected automatically
Our site uses privacy-preserving analytics that do not set cookies or build a persistent profile of you. Our servers and hosting provider process standard technical data such as IP address and request metadata for security and reliability.
Cookies
The marketing site sets no advertising or tracking cookies of its own. The contact sales form is provided by HubSpot, and its script is loaded only at the moment you open that form. If you never open it, no HubSpot cookies are set. When you do open it, HubSpot may set cookies to associate your submission with your contact record. You can block or clear these in your browser.
3. Data inside your connected systems
When Archron governs an action, it needs enough context to verify that action and enough evidence to prove what happened. It does not need a copy of your database, and it does not keep one.
- Business records are not stored by Archron. They remain in your connected system. There is nothing to migrate and no second copy of your records to secure.
- Evidence is minimized. We retain the before and after values of the fields an operation actually wrote, not whole records. The one deliberate exception is a pre-delete snapshot, retained so a delete can be undone.
- Schema and rules, not content. We cache the structure of your system, such as objects, fields, and automation relationships, so agents cannot guess past your constraints.
- Credentials are references only. OAuth token material is held in AWS Secrets Manager. Our database stores a reference to it, never the token itself.
4. AI and your data
Archron is infrastructure, not a model. This is the clearest statement we can make:
- Archron does not use customer data to train machine learning models.
- Archron does not send your business data to any AI provider. The agent connects on your side, under your own agreement with that provider, and Archron governs the actions it proposes. Using Archron adds no new AI vendor to your data footprint.
- Schema, business rules, and audit records are used only to operate and verify your own deployment. They are not pooled, aggregated, or reused across customers.
5. Legal bases
Where the GDPR applies, we rely on: performance of a contract or steps taken at your request, to evaluate your application and deliver the service; legitimate interests, to secure our systems, prevent abuse, and communicate with business contacts; consent, where you have opted in to marketing communications, which you can withdraw at any time; and legal obligations, such as tax and accounting records.
6. Who we share data with
We do not sell personal data. We share it only with the service providers below, each bound by contract to process it on our instructions.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, secrets storage | United States (us-east-1) |
| HubSpot | Application form and CRM for our own sales contacts | United States |
| Vercel | Marketing site hosting and analytics | United States |
| Stripe | Billing. Card data is handled entirely by Stripe and never touches Archron systems | United States |
Systems you connect, such as Salesforce or HubSpot, are reached using your own OAuth grants. They are your vendors, under your agreements, not our subprocessors.
7. Where data is held
All Archron infrastructure and data reside in AWS in the United States (us-east-1). We do not currently offer an EU-resident data option, and we state that rather than implying otherwise. If you are in the EEA or UK, transfers rely on appropriate safeguards including Standard Contractual Clauses where required.
8. How long we keep it
- Application and contact data: kept while we are in contact and for a reasonable period afterwards, then deleted or anonymized.
- Audit and evidence records: retained for the life of your organization's account, because their purpose is to prove what happened. Integrity checkpoints are anchored to write-once storage with a seven-year retention period.
- Billing records: retained as required by tax and accounting law, including after account deletion.
9. Your rights
Subject to local law you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent to marketing at any time. Email support@archron.app and we will respond within the period required by applicable law.
Customers additionally have product-level controls: an owner can export organization data at any time, and can request organization-wide erasure. Erasure runs on a thirty-day cancellable grace window and closes with a sealed certificate recording what was deleted and what was retained.
One honest boundary: we can erase an entire organization, but we cannot yet redact a single individual's values from within retained evidence records. That tooling is planned. If you need it before then, contact us and we will discuss the options.
10. Security
Data is encrypted in transit and at rest. Access to production is limited and recorded. Our controls are described in detail on the security page. If we confirm a personal data breach affecting you, we will notify you without undue delay and within 72 hours, consistent with GDPR Article 33.
11. Children
Archron is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes
We will update this page when our practices change and revise the date above. Material changes affecting customers will be communicated directly.
13. Contact
Privacy and general enquiries: support@archron.app. Security reports: security@archron.app.
Archron Inc
131 Continental Dr, Suite 305
Newark, DE 19713
United States