Skip to content
ARXIMUS AI Runtime Authorization
Platform Security
Financial Services Transaction-level authority Defense & National Security Mission-bounded authority Critical Infrastructure Operational authority control AI Startups Runtime authority from day one
Explore Applications Where else machine authority applies
Enterprise Pricing
Request a Demo ↗
Platform Security Industries Financial Services Defense & National Security Critical Infrastructure AI Startups Explore Applications Enterprise Pricing Request a Demo
ARXIMUS PRIVACY

PRIVACY
Policy

This Privacy Policy explains how Arximus processes personal data in connection with its website, Cloud, Enterprise services and runtime security capabilities.

GDPR DATA MINIMIZATION PROCESSOR BOUNDARY ZERO RETENTION EU PROCESSING SECURITY DATA RIGHTS
PRIVACY POLICY

How Arximus protects and processes personal data.

Effective date: 2 September 2026.

This Privacy Policy explains how Arximus processes personal data in connection with its website, business relationships, Arximus Cloud, Arximus Enterprise and related security and authorization services.

01

Scope, Identity & Responsibility

This Privacy Policy applies to personal data processed by Arximus in connection with the public Arximus website, contact and access requests, customer and prospective customer relationships, account and service administration, Arximus Cloud, Arximus Enterprise and related services.

Privacy and data-protection inquiries may be submitted through the Arximus Contact page. The requester should state that the inquiry concerns privacy or data protection so it can be handled appropriately.

Arximus may act in different data-protection roles depending on the processing involved.

Arximus as controller. Arximus generally acts as controller where it determines why and how personal data is processed for its own business operations, such as website security, contact requests, access requests, customer administration, commercial relationships, billing administration, service security and compliance.

Arximus as processor or subprocessor. Where a customer transmits or otherwise makes personal data available through the Services and determines the purposes and essential means of that processing, Arximus generally processes that Customer Personal Data on the customer's documented instructions under the applicable Data Processing Agreement.

Data-protection roles are determined by the actual processing and applicable law. A contractual label does not override a role imposed by applicable data-protection law.

The Services are business-to-business services. That does not reduce the privacy rights of individuals whose personal data may be processed through a customer's use of the Services.

02

Categories of Data

Arximus distinguishes between different data classes because they have different purposes, security requirements and retention characteristics.

Business and contact data. This may include name, work email address, organization, role, business telephone number, correspondence, access-request information, procurement information, support communications and other professional contact information.

Account and administration data. This may include account identifiers, organization, project and environment membership, roles, permissions, authentication information, account-security events and administrative activity.

Customer Personal Data. Customer Personal Data means personal data contained in Customer Data that Arximus processes as processor or subprocessor on behalf of a customer.

Service Content. Service Content may include prompts, model input and output, submitted operations, tool calls, API requests, protected-function parameters, documents, retrieved context, structured payloads and other content processed through an applicable Arximus runtime path.

Configuration and authority data. This may include trusted identity context, delegation, policy configuration, Action Schemas, protected operations, approval rules, verification sources, integrations, connectors, release destinations and customer-defined security configuration.

Security Evidence. Security Evidence consists of structured records generated for authorization, verification, security, release and accountability purposes. It may include relevant identifiers, policy information, decisions, verification results, protected-operation information, release information and execution results reported by an authoritative source.

Operational Metadata. Operational Metadata may include request identifiers, timestamps, tenant, project or environment information, usage and metering information, latency, reliability, capacity, errors, technical diagnostics, security events, administrative audit information and similar service telemetry.

Not every item in these categories is personal data. Information is personal data where it relates to an identified or identifiable natural person under applicable data-protection law.

03

Sources of Personal Data

Arximus may receive personal data directly from an individual, from a customer or prospective customer, from an Authorized User, from a customer's systems or from services configured by the customer.

Where Arximus acts as controller, personal data is generally obtained directly from business contacts, prospective customers, customers, Authorized Users and other individuals who communicate with Arximus or use Arximus-controlled services.

Where Arximus acts as processor or subprocessor, Customer Personal Data is provided by or on behalf of the customer through the Services, customer applications, integrations, configured systems or other customer-directed processing paths.

Arximus may also generate technical, operational, security and usage information through the operation and protection of the Services.

Where Customer Personal Data was not obtained directly from the individual, the customer or other applicable controller remains responsible for providing any transparency information required of that controller. Arximus provides processor assistance as required by the applicable Data Processing Agreement and law.

04

Controller Purposes & Legal Bases

Where Arximus acts as controller, it processes personal data only where a lawful basis applies.

Contact, access and commercial requests. Arximus processes information to respond to inquiries, evaluate access requests, discuss potential deployments and manage prospective customer relationships. Depending on the circumstances, the legal basis may be steps requested before entering into a contract or Arximus's legitimate interest in conducting and managing business relationships.

Customer and account administration. Arximus processes business-user information to provide accounts, administer organizations and environments, authenticate users, provide support and manage the commercial relationship. The legal basis may be contract, steps related to a contract or legitimate interests in providing and administering business services.

Service and security operations. Arximus processes technical, authentication, network and security information to protect accounts, prevent abuse, detect security events, investigate suspicious activity, preserve service integrity and maintain availability. The legal basis is generally Arximus's legitimate interest in securing the Services, customers and infrastructure, together with legal obligations where applicable.

Billing, accounting and legal compliance. Arximus may process business contact, transaction and account information to administer charges, maintain accounting records, meet tax or financial requirements, respond to legal obligations and establish, exercise or defend legal claims.

Service communications. Arximus may send operational, security, account, contractual and service-related communications where necessary to administer the relationship or protect the Services.

Business communications. Arximus may communicate with business contacts about relevant Arximus services where permitted by applicable law and may rely on legitimate interests where appropriate. Consent will be obtained where consent is required. An individual may object to direct marketing at any time.

Where Arximus relies on legitimate interests, it considers the nature of the information, the purpose of the processing, the reasonable expectations of the individual and the effect of the processing on the individual's rights and freedoms.

05

Customer Personal Data

When Arximus processes Customer Personal Data as processor or subprocessor, the customer or other applicable controller determines the purposes of the underlying processing and is responsible for establishing its lawful basis.

Arximus processes that personal data on documented instructions, except where applicable law requires otherwise.

The applicable Arximus Data Processing Agreement governs processor obligations, including documented processing instructions, confidentiality, technical and organizational measures, subprocessors, international transfers, assistance with data-subject rights and data-protection impact assessments, personal-data breach obligations, deletion or return of Customer Personal Data and applicable compliance and audit rights.

A customer remains responsible for determining whether the personal data it submits to Arximus is lawful, appropriate and necessary for the customer's intended processing.

The customer is also responsible for notices, lawful bases, consents where required, human-review obligations, sector-specific requirements and other controller responsibilities associated with the customer's application or workflow.

06

Service Content & Default Zero Retention

Ordinary AI Service Content is not retained by default after the runtime processing required to provide the applicable service path.

Arximus may transiently process Service Content in memory, network buffers, short-lived runtime state or other systems technically necessary to receive, evaluate, transform, authorize, route or release the applicable request or response.

Default non-retention of ordinary Service Content does not mean that Arximus retains no information about an interaction. Security Evidence and Operational Metadata are separate data classes and may be retained according to their own purposes and retention rules.

Service Content may be retained where the customer expressly enables a retention or logging feature, where customer policy authorizes selected content capture, where limited retention is required for authorized support, investigation or incident response, where a configured feature requires retention, where the applicable Agreement establishes a retention requirement or where retention is required by applicable law.

Arximus's architecture separates ordinary Service Content from security evidence and operational telemetry so raw content does not become an uncontrolled copy of complete conversations in ordinary application logging or monitoring systems.

Enterprise deployments may establish customer-specific content-retention and forensic-capture requirements as part of the contracted deployment scope.

07

Security Evidence

Arximus generates structured Security Evidence so customers can establish what security and authorization controls were applied to protected activity.

Depending on the service configuration, Security Evidence may contain the identifiers and timing information required to associate an event with the applicable customer environment, together with relevant policy and decision information, verification and approval information, protected-operation information, integrity values, release information and any execution result reported by a customer-controlled executor or another authoritative source.

Security Evidence is separate from ordinary AI-content retention and may remain available even where the underlying Service Content was processed transiently and was not retained.

Where evidence information is capable of identifying or relating to an individual, it is treated as personal data and protected accordingly.

Arximus's evidence architecture is designed to preserve the distinction between authorization, release and reported execution and to protect historical evidence against unauthorized modification.

08

Operational Metadata & Metering

Arximus generates Operational Metadata required to operate, secure, support, measure and improve the Services.

Operational Metadata may include identifiers, timestamps, customer-environment references, usage and metering information, service and provider information, performance and reliability information, capacity information, errors, diagnostics, security events, administrative activity and other technical information required to operate, secure, support and account for the Services.

Operational Metadata is not intended to become a copy of ordinary Service Content.

Arximus may use aggregated or de-identified telemetry for capacity planning, reliability, security, operational analysis and improvement of the Services where that information does not identify a customer, identify an individual or disclose Customer Data.

09

Sensitive & Regulated Personal Data

The business-to-business nature of Arximus does not mean that Customer Personal Data is limited to ordinary business contact information.

Depending on a customer's use case, Customer Personal Data may include information relating to employees, contractors, customers, end users, patients, applicants, account holders, public-service users or other individuals.

Customer Personal Data may therefore include special categories of personal data under Article 9 GDPR, including health information, biometric information, genetic information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex-life information or sexual orientation.

Customer Personal Data may also include information subject to Article 10 GDPR or other heightened restrictions under applicable law.

Where Arximus processes such data as processor or subprocessor, the customer remains responsible for identifying an applicable lawful basis and any additional condition required for that sensitive processing.

Arximus processes the information according to the customer's documented instructions, the applicable Agreement and the security requirements applicable to the Services.

Arximus does not use Customer Personal Data to infer sensitive characteristics for advertising or unrelated profiling purposes.

Security detection or classification may identify that content appears to contain a protected or sensitive data category where doing so is necessary to apply customer-configured security controls.

10

AI, Authorization & Automated Decisions

Arximus is runtime authorization and security infrastructure. The Services can make automated technical decisions about whether a machine-requested operation satisfies configured authority and policy conditions.

These technical authorization decisions are distinct from determining the underlying purpose for which a customer uses AI or determining whether a decision about an individual should carry legal or similarly significant effects.

Where a customer configures Arximus as part of a workflow that makes or contributes to decisions concerning individuals, the customer remains responsible as controller for determining whether GDPR Article 22 or another rule concerning automated decision-making applies.

The customer is responsible for implementing any required human intervention, review, explanation, contestability or other safeguard required for the customer's use case.

Arximus does not treat an authorization decision, verification result, classification, security signal or evidence record as a substitute for professional judgment, human approval or another legal safeguard independently required for the customer's use case.

Where Arximus acts as controller for its own business processing, Arximus does not use Customer Personal Data to make solely automated decisions about individuals that produce legal or similarly significant effects unless that processing is specifically disclosed and permitted by applicable law.

The EU Artificial Intelligence Act may impose separate obligations depending on the AI system, use case and role of the parties. This Privacy Policy does not transfer a customer's obligations as an AI provider, deployer, operator, controller or other regulated actor to Arximus.

Data-protection responsibilities and AI-regulatory responsibilities are assessed separately according to applicable law and the actual processing involved.

11

Data Retention

Arximus applies different retention rules to different data classes rather than treating all service data as one category.

Ordinary Service Content. Ordinary AI Service Content is not retained by default after the transient runtime processing required to provide the applicable service path.

Optional content logs. Content retained because a customer enabled logging or another retention feature is retained according to the applicable customer configuration, Agreement and retention requirements.

Forensic capture. Selected forensic information may be retained for an investigation, incident response, support or compliance purpose according to the defined capture scope and applicable retention requirement.

Security Evidence. Security Evidence is retained according to the applicable service configuration, Agreement, security requirements, accountability requirements and applicable law.

Operational Metadata. Operational Metadata is retained for periods reasonably necessary for service operation, security, troubleshooting, capacity management, metering, billing, fraud or abuse prevention, audit requirements and legal obligations.

Account and business records. Business, account, contractual and support information is retained for the duration of the applicable relationship and thereafter where reasonably required for legal, accounting, security, dispute-resolution or contractual purposes.

Contact and access requests. Arximus retains inquiry information for as long as reasonably necessary to respond, evaluate the request, administer the resulting relationship and maintain appropriate business and security records.

Accounting and billing records. Records required by accounting, tax or other applicable law are retained for the legally required period.

Backups. Data may remain temporarily in protected backup systems until the applicable backup lifecycle expires. Backup data is not treated as normal active service data and remains subject to applicable security and retention controls.

Enterprise customers may establish customer-specific retention, evidence and regional requirements through an Order Form, Enterprise Agreement, Data Processing Agreement or other binding deployment terms.

Where no fixed retention period is stated, Arximus uses the purpose of processing, customer instruction, security requirements, contractual obligations, legal requirements, limitation periods and operational necessity to determine the applicable retention period.

12

Recipients of Personal Data

Arximus limits disclosure of personal data to recipients that have a legitimate role in the applicable processing.

Personal data may be disclosed to authorized Arximus personnel, Arximus Providers and subprocessors, professional advisers and auditors where access is necessary for the applicable purpose. Information may also be disclosed to the applicable customer and its Authorized Users or transmitted to Customer-Selected Third-Party Services where the customer has directed Arximus to do so.

Arximus may disclose personal data to a public authority or other recipient where disclosure is required or permitted by applicable law, or in connection with a legitimate corporate transaction subject to appropriate confidentiality and data-protection safeguards.

Access to personal data does not give a recipient the right to use that information for unrelated purposes.

13

Arximus Providers & Subprocessors

Arximus may use hosting, infrastructure, authentication, monitoring, communications, security, support and other service providers to support delivery of the Services.

Where such a provider processes Customer Personal Data on behalf of Arximus, it is treated as a subprocessor where applicable.

Subprocessors are subject to contractual data-protection obligations appropriate to the processing they perform.

The applicable Data Processing Agreement governs authorization, notice and objection rights for changes to subprocessors where required.

Arximus remains responsible for performing the processor obligations that Arximus assumes under the applicable Agreement, including obligations performed through an authorized subprocessor.

A current Subprocessor Register containing information relevant to Customer Personal Data is available through the Compliance & Assurance process.

14

Customer-Selected Third-Party Services

Customers may configure Arximus to communicate with third-party services selected or controlled by the customer.

Customer-Selected Third-Party Services may include AI model providers, private or self-hosted models, APIs, SaaS applications, tools, MCP servers, databases, knowledge systems, identity and approval systems, customer-controlled executors and other customer-selected security, verification or integration services.

Customer-Selected Third-Party Services are different from subprocessors selected by Arximus.

Where the customer instructs Arximus to transmit Customer Data to a Customer-Selected Third-Party Service, Arximus performs that transmission according to the configured service path and the customer's instruction.

The customer is responsible for its relationship with the Customer-Selected Third-Party Service and for determining the lawful basis, permissions, contracts, transfer mechanism and other legal requirements applicable to the customer's use of that service.

Arximus is not responsible for independent processing performed by a Customer-Selected Third-Party Service after information has been lawfully transmitted to that service according to customer instruction, except to the extent responsibility arises from Arximus's own breach of applicable law or an obligation expressly assumed under the Agreement.

15

European Processing & International Transfers

Arximus is based in Sweden and operates its standard European production environment within the European Union.

The European production infrastructure described in the Arximus Compliance & Assurance materials is located in Frankfurt, Germany.

This regional service architecture does not necessarily mean that every corporate operation, support function, subprocessor or Customer-Selected Third-Party Service used in connection with Arximus is located in Germany or elsewhere inside the European Economic Area.

Where Arximus transfers personal data from the EEA to a country outside the EEA and a GDPR transfer mechanism is required, Arximus uses an appropriate legal mechanism under Chapter V GDPR.

Where required, Arximus may rely on a European Commission adequacy decision, the European Commission Standard Contractual Clauses or another transfer mechanism permitted by applicable data-protection law. Supplementary technical, contractual or organizational safeguards are applied where appropriate to the circumstances of the transfer.

Information concerning relevant processing locations, subprocessors and transfer safeguards is available through the Arximus compliance or contractual process.

Enterprise deployment, residency, dedicated infrastructure or geographic commitments apply where expressly included in the applicable Order Form, Enterprise Agreement or other binding deployment terms.

16

Security of Personal Data

Arximus is security infrastructure and is designed under an assume-breach model in which compromise of one component should not automatically provide unrestricted access to every customer, security domain, secret or evidence system.

Arximus applies technical and organizational measures appropriate to the applicable service and deployment. These measures address identity and access management, tenant isolation, least privilege, separation of security responsibilities, privileged access, network security, cryptographic protection, secrets management, configuration integrity, evidence integrity, monitoring, availability, backup protection, secure development, recovery and incident response.

Arximus separates major security functions so normal control-plane administration, runtime authorization, protected release, customer extensions, secrets and historical evidence do not automatically share one unrestricted privilege boundary.

Specific technical and organizational measures applicable to Customer Personal Data are described in the Arximus Technical & Organizational Measures and, where applicable, the Data Processing Agreement, Security Addendum or Enterprise Agreement.

Additional security and architecture documentation may be provided under appropriate confidentiality protections. See Compliance & Assurance.

17

Personnel & Support Access

Arximus limits access to Customer Personal Data to personnel and authorized providers whose responsibilities require that access.

Access is subject to applicable authentication, authorization, confidentiality and security requirements.

Privileged production access is treated separately from ordinary employee access and is intended to be narrowly scoped to operational need.

Arximus personnel do not require routine access to ordinary customer AI Service Content merely because traffic passes through Arximus.

Where authorized support, investigation or incident response requires access to retained Customer Data, access is limited to the purpose for which it is authorized and remains subject to applicable security and confidentiality controls.

18

Security Incidents & Personal Data Breaches

Arximus maintains processes for identifying, investigating, containing, escalating and remediating security events affecting the Services.

Where Arximus becomes aware of a personal-data breach affecting Customer Personal Data processed as processor or subprocessor, Arximus will notify the applicable controller without undue delay as required by applicable law and the applicable Data Processing Agreement.

Arximus will provide information reasonably available to it and required to assist the controller in meeting applicable breach-assessment and notification obligations.

Where Arximus acts as controller, Arximus will notify the competent supervisory authority and affected individuals where notification is required by applicable data-protection law.

Customer-specific security-incident notification periods, escalation commitments or incident-assistance obligations may be established in a Data Processing Agreement, Security Addendum, Regulatory Addendum or Enterprise Agreement.

19

Data-Subject Rights

Subject to the conditions and limitations established by applicable law, individuals may have rights of access, rectification, erasure, restriction, portability and objection. An individual may object to direct marketing at any time and may withdraw consent where consent is the basis for processing.

Applicable law may also provide rights concerning certain solely automated individual decisions and the right to lodge a complaint with a competent data-protection supervisory authority.

These rights are not absolute and may be subject to legal exceptions, identity verification, competing rights, contractual requirements or mandatory retention.

Where Arximus acts as controller, a rights request may be submitted through the Arximus Contact page.

Arximus may request information reasonably necessary to verify identity and protect personal data against unauthorized disclosure.

Where the request relates to Customer Personal Data that Arximus processes only on behalf of a customer, the individual should normally submit the request to the customer or other controller responsible for that processing.

Arximus will provide reasonable assistance to the applicable controller as required by the Data Processing Agreement and applicable law.

Arximus will not independently alter or delete Customer Personal Data processed solely as processor where doing so would conflict with the controller's documented instructions, except where applicable law requires otherwise.

20

Legal & Government Requests

Arximus may disclose personal data where required by applicable law, valid legal process, a binding order or another lawful obligation.

Where reasonably possible and legally permitted, Arximus evaluates the validity and scope of a request and seeks to disclose only the information legally required.

Where a government or legal request concerns Customer Personal Data processed on behalf of a customer, Arximus will notify the applicable customer before disclosure where legally permitted and where doing so is consistent with the applicable Agreement.

Arximus may also disclose information where lawfully necessary to protect the rights, security or integrity of Arximus, its customers, individuals or the Services, or to establish, exercise or defend legal claims.

21

Website Sessions & Cookies

The Arximus website and contact processes may use first-party session or security technologies necessary to operate the site, protect forms, maintain session integrity and defend against abuse.

These technologies may process information such as a session identifier, IP address, request information, browser information or security-related metadata where technically necessary.

Strictly necessary technologies are used for operation and security rather than behavioral advertising.

Arximus does not use Customer Data or Customer Personal Data for cross-context behavioral advertising.

If Arximus introduces non-essential analytics, advertising or similar technologies that require consent or another specific notice under applicable law, Arximus will provide the required information and consent mechanism before using those technologies where required.

22

Business Users & Children

Arximus Services are offered for business, organizational, professional and institutional use. Arximus does not offer personal consumer accounts.

Individual employees, contractors, representatives and other Authorized Users may nevertheless use Arximus on behalf of a business or institution. Those individuals retain the privacy rights provided by applicable law.

Arximus Services are not directed to children for their own personal or consumer use.

A customer may nevertheless operate a lawful workflow involving personal data relating to children or minors, for example in healthcare, education, public administration or another institutional context.

Where Arximus processes such information on behalf of the customer, the customer remains responsible for determining the lawful basis, notices, authorization, safeguards and any consent or parental-authorization requirements applicable to that processing.

23

No Sale, Advertising Use or Unrelated AI Training

Arximus does not sell Customer Personal Data or ordinary Service Content.

Arximus does not use Customer Data for cross-customer behavioral advertising or advertising profiles.

Arximus will not use Customer Data to train general-purpose or unrelated AI models or to develop products for other customers unless the customer expressly agrees in writing.

Arximus may generate and use aggregated or de-identified service telemetry for purposes such as security, reliability, capacity planning, operations and service improvement where that information does not identify the customer, identify an individual or disclose Customer Data.

24

Regulated & Enterprise Deployments

Arximus may be used by organizations operating in regulated environments including financial services, healthcare, government, critical infrastructure and other sectors where personal data and consequential machine operations require heightened control.

Applicable legal obligations depend on the customer, industry, location, data, AI system, use case and role of each party.

Depending on the deployment, requirements may arise under the General Data Protection Regulation, national data-protection legislation, the EU Artificial Intelligence Act, NIS2, DORA, the European Health Data Space framework and other financial, healthcare, public-sector or sector-specific requirements applicable to the customer and its processing.

The European Health Data Space Regulation applies progressively beginning from 26 March 2027, with major obligations phased according to the Regulation. A reference to EHDS in Arximus materials does not mean that every healthcare deployment is within its scope or that every EHDS obligation is currently applicable.

Likewise, obligations under the EU Artificial Intelligence Act depend on the regulated system, classification, role and applicable implementation date.

Arximus does not represent that use of the Services automatically makes a customer's AI system, organization, deployment or processing activity compliant with any law, regulation or standard.

Customers remain responsible for the independent legal, regulatory, clinical, financial, public-sector or other professional obligations applicable to their own systems and processing.

Where required for an Enterprise or regulated deployment, Arximus and the customer may establish additional contractual requirements through a Data Processing Agreement, Security Addendum, Regulatory Addendum, Enterprise Agreement or Order Form.

25

DPIAs, Compliance Review & Audit Support

Customers remain responsible for determining whether their processing requires a data-protection impact assessment, prior consultation, regulatory filing, AI-system assessment or other customer-side compliance process.

Where Arximus acts as processor, Arximus will provide reasonable information and assistance required under the applicable Data Processing Agreement and data-protection law, taking into account the nature of processing and information available to Arximus.

Enterprise and procurement documentation available through the Arximus Compliance & Assurance process may include the Data Processing Agreement, Subprocessor Register, Technical & Organizational Measures, data-residency and transfer information, security and architecture information, incident-response and continuity information, regulatory and standards mappings and applicable independent assurance or testing information when such assurance or testing has been completed.

Security-sensitive or proprietary information may require appropriate confidentiality protections or a non-disclosure agreement.

Any binding customer audit, security-assurance, regulatory-access or inspection right is governed by the applicable Data Processing Agreement, Security Addendum, Regulatory Addendum, Enterprise Agreement or other binding contractual document.

26

Data Deletion & Service Termination

Where Arximus processes Customer Personal Data as processor, deletion or return following termination is governed by the applicable Data Processing Agreement, customer instruction and applicable law.

Data that is no longer required for an active purpose will be deleted, anonymized or otherwise removed from active processing according to the applicable retention requirement.

Deletion from active systems does not necessarily produce immediate physical erasure from every protected backup copy. Backup copies may remain until they expire through the applicable backup lifecycle.

Data retained in backups remains protected and is not treated as ordinary active data. If backup restoration reintroduces information that should otherwise have been deleted, applicable deletion controls will be reapplied where technically and legally appropriate.

Arximus may retain information where required by law, necessary to establish or defend legal claims, required for security or fraud investigation, or otherwise permitted under the applicable Agreement and data-protection law.

27

Changes to This Privacy Policy

Arximus may update this Privacy Policy to reflect changes to the Services, processing activities, law, regulatory requirements, security practices or business operations.

The current public version will be published on this page with an updated effective date.

Where a change materially affects how Arximus processes personal data as controller, Arximus will provide additional notice where required by applicable law.

Changes to this public Privacy Policy do not by themselves amend a signed Data Processing Agreement, Enterprise Agreement, Order Form, Security Addendum or Regulatory Addendum.

28

Contact & Supervisory Authority

Questions about this Privacy Policy, Arximus's controller processing or the exercise of applicable data-protection rights may be submitted through the Arximus Contact page.

Please identify the request as a privacy or data-protection request and provide enough information for Arximus to understand and appropriately verify the request.

Where the request concerns Customer Personal Data processed by Arximus on behalf of another organization, Arximus may direct the requester to the applicable customer or controller and will provide processor assistance where required.

Individuals may also have the right to lodge a complaint with a competent data-protection supervisory authority.

Arximus is based in Sweden. The Swedish supervisory authority for data protection is:

Integritetsskyddsmyndigheten (IMY)

Depending on applicable GDPR jurisdiction rules, an individual may also be entitled to contact another competent supervisory authority in the European Economic Area.

PRIVACY & ASSURANCE

Review Arximus data protection before deployment.

Request the Arximus Data Processing Agreement, Subprocessor Register, Technical & Organizational Measures, data-residency information and supporting security documentation through the compliance review process.

Compliance & Assurance ↗ Contact Arximus
ARXIMUS AI Runtime Authorization

Arximus is the authorization and enforcement layer between AI and the systems it can act on. It determines whether protected actions are authorized, enforces those decisions at runtime and preserves evidence of what happened.

Privacy Policy Terms of Service
Product Platform Security Enterprise Pricing Applications
Industries Financial Services Defense & National Security Critical Infrastructure AI Startups
Company About Compliance Contact
AI Runtime Authorization Control AI authority before execution. Request a Demo↗
© 2026 Arximus. All rights reserved. AI Security & Governance Infrastructure