At ArGen ("we," "us," or "our"), we are committed to protecting the privacy and security of personal data in compliance with the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and all other applicable data protection laws. This page outlines our comprehensive compliance framework, your rights as a data subject, and how we process your personal information lawfully, fairly, and transparently.
1. Data Controller Information
ArGen acts as the Data Controller for personal data collected through our Website and Services, except where we process data on behalf of our enterprise customers as a Data Processor (as defined in our Data Processing Agreement). The entity responsible for your personal data is:
ArGen (IsiraGlobal)
Contact Email: isiraglobal@gmail.com
Address: IsiraGlobal, Mumbai, Maharashtra, India
For matters pertaining to data protection, you may contact our Data Protection Officer (DPO) directly at the email address above. We respond to all inquiries from data subjects and supervisory authorities within the statutory timeframes.
2. Lawful Basis for Processing
Under the GDPR, we process your personal data only when we have a valid lawful basis to do so. The specific bases we rely on include:
- Consent (Article 6(1)(a)): Where you have freely given, specific, informed, and unambiguous consent for us to process your data for a particular purpose (e.g., subscribing to marketing communications or accepting non-essential cookies). You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Contractual Necessity (Article 6(1)(b)): Where processing is necessary for the performance of a contract to which you are a party, such as providing you with access to the ArGen evaluation platform, generating AI capability reports, and managing your account billing.
- Legal Obligation (Article 6(1)(c)): Where processing is necessary for compliance with a legal obligation to which we are subject, such as retaining financial records for tax purposes or responding to lawful requests from regulatory authorities.
- Legitimate Interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, provided such interests are not overridden by your rights and freedoms. This includes improving our platform's security, analyzing usage patterns to enhance user experience, and preventing fraud or abuse.
3. Data Subject Rights Under GDPR
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:
- Right of Access (Article 15): You have the right to obtain confirmation from us as to whether your personal data is being processed, and if so, access to that data along with information about the processing purposes, categories of data, recipients, retention periods, and your other rights.
- Right to Rectification (Article 16): You have the right to request the correction of inaccurate personal data concerning you. We will make corrections promptly upon verification.
- Right to Erasure ("Right to be Forgotten") (Article 17): You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent, or where you object to processing and there are no overriding legitimate grounds.
- Right to Restriction of Processing (Article 18): You have the right to restrict processing while we verify accuracy of data or the lawfulness of processing.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV) and to transmit that data to another controller without hindrance.
- Right to Object (Article 21): You have the right to object to processing based on legitimate interests, including profiling for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
4. California Privacy Rights (CCPA/CPRA)
If you are a resident of the State of California, the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant you specific rights regarding your personal information. ArGen does not sell your personal information in exchange for monetary or other valuable consideration. We share information only as necessary to provide our Services (e.g., with hosting providers and payment processors) as part of our business operations.
California residents have the following additional rights:
- Right to Know: You may request, up to twice in a 12-month period, that we disclose the categories and specific pieces of personal information we have collected, used, or disclosed about you in the preceding 12 months.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions (e.g., to complete a transaction, detect security incidents, or comply with a legal obligation).
- Right to Correct: You may request that we correct inaccurate personal information maintained about you.
- Right to Opt-Out: You have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising. We do not currently engage in such practices.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights, such as by denying services, charging different prices, or providing a different level of service.
To exercise your California privacy rights, please submit a verifiable consumer request to isiraglobal@gmail.com. We will confirm receipt within 10 business days and respond substantively within 45 calendar days.
5. International Data Transfers
As a global SaaS platform, ArGen may transfer your personal data to countries outside the European Economic Area (EEA) or the United Kingdom, including to our cloud infrastructure providers located in the United States, Singapore, and India. Where such transfers occur, we ensure that appropriate safeguards are in place in compliance with Chapter V of the GDPR and UK GDPR. Specifically, we rely on:
- Standard Contractual Clauses (SCCs): We have executed the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor and Module 3: Processor-to-Processor, as applicable) with our sub-processors, including Vercel Inc., Supabase Inc., and Google LLC.
- Data Protection Impact Assessments (DPIAs): We have conducted DPIAs for our key processing operations, particularly the AI evaluation engine, to identify and mitigate privacy risks before processing begins.
- Transfer Impact Assessments (TIAs): We have assessed the legal framework of recipient countries to ensure an essentially equivalent level of protection for your data.
6. Data Retention and Deletion
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The specific retention periods are determined based on:
- Account Data: Retained for the duration of your active account plus 90 days after account closure or termination, after which it is securely deleted or anonymized.
- Evaluation and Response Data: Retained for the duration of your subscription service agreement to provide historical benchmarking and analytics. After contract termination, this data is deleted within 90 days unless otherwise required by law.
- Financial and Billing Data: Retained for the period required by applicable tax and accounting laws (typically 7 years in most jurisdictions).
Upon expiration of the applicable retention period, your personal data is irreversibly anonymized or securely destroyed using industry-standard data sanitization methods.
7. Complaints and Supervisory Authorities
If you believe that our processing of your personal data infringes upon your rights under applicable data protection law, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first at isiraglobal@gmail.com so that we may resolve your concerns directly. If you are unsatisfied with our response, you may escalate to:
For EEA residents: Your local Data Protection Authority (DPA) in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement.
For UK residents: The Information Commissioner's Office (ICO): https://ico.org.uk
For California residents: The California Privacy Protection Agency (CPPA) or the California Attorney General's Office.