1. Who we are and what this policy covers
Arga Core Inc., a Wyoming corporation, operates the Arga Core website and the applicable Arga-branded services identified in your agreement. In this policy, Arga Core, we, us, and our refer to Arga Core Inc. Our legal and privacy contact is legal@argacore.com. Our business mailing address is 30 N Gould St, Ste R, Sheridan, WY 82801. Our team works across Wyoming, California, and Utah. Our hosted infrastructure is located in Utah, United States.
This policy covers personal information we handle for our own website, communications, service administration, and business purposes. A product-specific notice or signed agreement may provide additional information for a particular service. Third-party services linked from our website have their own policies. This policy is not a representation that every feature or client is generally available: our portfolio includes Beta and release-candidate products.
2. Our role and customer-controlled information
For website enquiries, our business contacts, recruitment communications, and service administration that we determine, Arga Core acts as the responsible business or controller, as those terms apply under relevant law. For personal information processed solely on a customer's instructions within a hosted service, we may act as a processor or service provider. The customer's notice and the applicable Data Processing Addendum govern that instructed processing.
Customers retain ownership and control of their product content and may export it at any time while it is retained. Customer content is encrypted, and Arga Core has no access to it in readable form. We can carry out an authorized deletion of encrypted records without reading their contents. This customer-content commitment is distinct from the contact messages, account administration, billing records, and security metadata we must receive or process to communicate and operate services.
If your employer or another organization provides your account, contact that organization for requests concerning its records and instructions. We assist it as required by the applicable agreement and law. For self-hosted products, the customer controls its own installation, users, hosting, and retention; we do not automatically receive the data stored there. Support access, synchronization, optional cloud functions, or telemetry, if enabled, must be evaluated separately.
3. Categories and sources of personal information
The categories we receive depend on how you interact with us and which service you use. The public website does not itself operate an account system, payment checkout, voice-recording feature, or file-upload feature. Do not submit passwords, vault contents, government identifiers, financial account details, medical information, or other unnecessary sensitive information through the general contact form.
Information may come directly from you, from an organization administering your access, from authorized integrations you enable, or from service operation. We do not assume a right to collect every category merely because it is listed below.
| Category | Examples and source | When relevant |
|---|---|---|
| Contact and enquiry information | Name, email address, enquiry topic, optional product selection, message, and correspondence you provide | Website contact, support, product enquiries, and general applications |
| Connection and request information | IP address, requested URL, time, browser/client headers, response status, and security-related request metadata | Website hosting, troubleshooting, access logs, and abuse protection |
| Account and administrative information | User/contact identifiers, organization details, access permissions, authentication and service-administration records | Only for an applicable account or service |
| Customer-directed content | Documents, messages, task records, freight or accounting records, signing records, or audio/transcripts supplied for enabled service functions | Only within the chosen product and agreed processing scope |
| Commercial and billing records | Orders, subscription details, invoices, transaction references, and billing contacts | Where a paid offering and its billing arrangement apply |
| Recruitment information | Background, skills, experience, and CV/portfolio links voluntarily included in a general application | Careers enquiries; no employment decision is made by submitting the form |
4. Contact form, email delivery, and operational logs
When you use the contact form, the website sends your name, email, topic, optional product, and message to our server, which submits them to the configured SMTP service and destination mailbox. Your email address is included as the Reply-To address. SMTP acceptance is not a guarantee of inbox placement. Mailbox storage, mail relay records, backups, and their retention depend on the actual email deployment.
The website's explicit contact-event logs contain an event result and request identifier, rather than the submitted message body. The form uses transient, in-memory request limits to reduce abuse. Separate web-server access logs can contain connection and request information, including IP addresses and URLs. Do not place sensitive personal information in URL query strings; URLs may appear in access logs, browser history, referrers, or diagnostic systems.
The application contact flow does not create a local database of enquiries. That does not mean submitted messages are immediately deleted: delivered email and operational records may remain in mail and server systems under the retention practices described below.
5. Why we use information
We use information in ways appropriate to the interaction and applicable service, including to answer enquiries, provide and administer requested services, communicate important service information, support customers, evaluate voluntary general applications, protect systems, investigate misuse, maintain necessary business records, and meet legal obligations.
Product improvement and diagnostics must be limited to the applicable notice, customer agreement, and lawful permissions. We do not treat a support message or general application as automatic consent to unrelated marketing. Where we send optional marketing, we provide a way to unsubscribe and comply with the applicable consent or opt-out rules.
6. Legal bases where European or similar law applies
Where a law requires a legal basis, the basis depends on the purpose: contract or pre-contract steps for a requested service; legitimate interests for proportionate business communications, system protection, and administration; consent where required for optional communications or functions; and legal obligations for required records or disclosures. We consider the rights and reasonable expectations of individuals when relying on legitimate interests.
You may ask us about the basis for a particular use. You may withdraw consent for future processing without affecting earlier lawful processing. Customer-directed processing uses the customer's applicable legal basis and documented instructions; entering into a DPA does not itself supply consent or make the customer's collection lawful.
8. How information is disclosed
Administrative information, contact correspondence, and necessary service metadata may be available to authorized personnel and providers needed for hosting, email delivery, security, support, and, where applicable, payment or customer-enabled integrations. This does not grant access to readable encrypted customer content. Hosted infrastructure is in Utah, United States; any service-specific provider and transfer details are provided through the applicable notice, agreement, or authorized subprocessor register.
We may disclose information on your direction, to the organization administering your account, to comply with valid legal process, to protect rights or safety, or in a business transaction subject to appropriate safeguards and notices. Requests from authorities are evaluated for legal validity and scope. We seek to limit disclosure to what is required and provide notice where permitted.
The public website does not sell or share personal information for targeted advertising. Customer content is not made available for unrelated advertising. Any separately enabled integration or covered data use must comply with the disclosures, consent, opt-out methods, and provider restrictions applicable to it; a service-provider disclosure is not automatically outside a state's legal definitions.
9. AI, document processing, and voice functions
Some products involve AI-assisted tasks, document inspection/revision, speech, or voice workflows. Processing is determined by the product, enabled features, model choice, and deployment. Do not assume every AI function is offline, that all content remains on your device, or that every provider uses the same retention practices. A product notice or customer schedule must identify external providers and relevant data use before content is sent to them.
For customer-directed personal information, model training, fine-tuning, provider retention, and any use for a provider's own purposes require an expressly agreed and lawful arrangement; they are not silently authorized by the general contact form or this policy. The customer must have the rights and permissions needed for submitted documents, recordings, or third-party information.
Audio and transcriptions may contain sensitive information. Voice audio is not described here as biometric identification merely because it is audio; processing that creates or uses a voiceprint for identification requires a separate assessment and any legally required notice and consent. Automated outputs can be inaccurate and should be checked before consequential use.
10. Retention, deletion, and backups
We retain information for the purpose that justified it and any necessary legal, dispute, security, or business-record requirement. Criteria include the nature of the record, the duration of the relationship, statutory obligations, the sensitivity of the information, and whether an equivalent purpose can be met with less identifying data. A deletion request is subject to applicable exceptions and does not require the removal of information another controller must lawfully retain.
Encrypted customer content is retained for up to five years, subject to earlier customer deletion or a verified deletion request. Customers may export their retained content at any time. The five-year maximum is not a minimum period and does not justify delaying an earlier deletion right. Content is removed through the applicable service's deletion process when its retention period expires, unless a specific legal obligation requires narrowly limited continued retention.
Customers may delete content through the available product controls or request deletion at legal@argacore.com. The process addresses active copies and associated encrypted recovery copies. Backup expiry and any unavoidable recovery-cycle delay are described in the service schedule or explained in response to the request; no instantaneous physical erasure of every backup is promised. Recovery copies remain protected, are not used for unrelated purposes, and must not be restored into ordinary use without applying the relevant deletion instruction.
Contact and recruitment correspondence, account administration, billing records, and operational logs are separate from encrypted product content. They are retained only for their necessary purpose and applicable legal, security, or recordkeeping requirements, using the criteria above. The five-year customer-content limit is not a blanket retention rule for all company records. Server log rotation depends on time and volume rather than one guaranteed deletion age.
11. Security and your responsibilities
Customer product content is encrypted and remains under customer control; Arga Core does not access its readable contents. Website and administrative processing use measures appropriate to their risks, including HTTPS, encrypted SMTP transport, form validation, abuse controls, and controlled runtime configuration. Customer-content protection does not mean that an email enquiry or an administrative record is unreadable to the personnel handling it. We do not claim a particular encryption algorithm, independently verified zero-knowledge architecture, or audit certification through this policy.
No service can promise absolute security. Protect your credentials, use available stronger authentication, limit information submitted to what is necessary, and contact legal@argacore.com promptly if you believe personal information has been exposed. Contractual incident duties for customer data are addressed in the DPA and any applicable service agreement.
12. Requests, choices, and rights
Depending on applicable law, you may have rights to learn about processing, access information, correct inaccuracies, request deletion, obtain a portable copy, restrict processing, object to certain uses, withdraw consent, opt out of covered sale/sharing or targeted advertising, or challenge certain legally significant automated decisions. Rights differ by jurisdiction and may have exceptions; this notice does not reduce any mandatory right.
Send a request to legal@argacore.com, describe your relationship to us and the right requested, and identify the relevant product or record where possible. You do not need to create a new account to ask. We may request proportionate verification or evidence of an authorized agent's authority. Do not email passwords or unnecessary government-ID copies. We use verification material for verification and necessary security records, not unrelated purposes.
We respond within the applicable legal timeframe and explain any permitted extension or refusal. Where GDPR applies, the ordinary response period is one month, subject to the law's extension provisions. Where CCPA applies, relevant access, correction, and deletion requests generally have a 45-day response period with a permitted extension. Applicable appeal rights and complaint options will be explained where required. We do not unlawfully discriminate for exercising privacy rights.
13. California, Utah, and other regional rights
State privacy laws apply based on their definitions, thresholds, exemptions, and the particular processing, not merely because a business has people in a state. Where Arga Core is a covered business under California law, this policy's categories, purposes, sources, and recipient descriptions serve as the basis for the required collection notice, supplemented by product-specific notices and any required look-back disclosures. Covered consumers may request access, correction, deletion, and portability and may have rights to opt out of sale/sharing and limit specified sensitive-information uses.
Where Utah or another applicable state law provides rights, we process covered requests and legally required opt-outs according to that law. Not all state laws offer the same correction, appeal, sensitive-data, or profiling rights. If a law requires additional submission methods or a separate notice or link, Arga Core must implement those before conducting the covered activity. Operations in Wyoming, California, and Utah do not establish an automatic exemption from rights elsewhere.
14. International processing and complaints
Arga Core is a U.S. company and its hosted infrastructure is located in Utah, United States. A customer self-hosted installation or customer-enabled third-party integration may have a different location. Any additional provider or remote-access location must be addressed in the applicable notice and processing schedule. If a restricted transfer is subject to European, UK, Swiss, or other rules, the responsible parties must establish an applicable mechanism and any required assessment or supplementary measures. We do not claim an unverified certification or automatically executed transfer clauses.
You can contact legal@argacore.com with a concern. Where applicable, you may also complain to your competent supervisory authority or regulator without first exhausting our process. Any legally required representative or additional data-protection contact will be identified in the applicable product or regional notice.
15. Children and age-sensitive information
Our website and business-oriented communications are not directed to children under 13. Do not knowingly submit a child's personal information through the general enquiry form. If we learn that information was collected in circumstances requiring parental permission without that permission, we will take appropriate steps under the applicable law.
A product intended to serve minors requires an appropriate product-specific age policy, notices, consent mechanisms, and safeguards before that use is enabled. Customer organizations remain responsible for lawful instructions concerning minors' records; an organization's instruction alone does not override child-protection law.
16. Changes and contact
This policy is effective October 6, 2026. We will provide notice of material changes as required by law and obtain new consent where required, rather than treating a website update as retroactive permission for incompatible uses. Earlier versions are retained for recordkeeping.
Privacy and legal requests: Arga Core Inc., legal@argacore.com, 30 N Gould St, Ste R, Sheridan, WY 82801, United States.
Contact Arga Core Inc.
Wyoming corporation · Wyoming, California, and Utah.
Legal and privacy enquiries: legal@argacore.com
30 N Gould St, Ste R, Sheridan, WY 82801