ArkSystems

How we handle your data

Before an engagement starts, you should know exactly what we get access to, what we do with it, which tools it passes through, and what happens when the work ends. This page sets that out. If your firm has requirements of its own, tell us before we begin — it changes how we build, and that is a normal thing to specify.

The principles

Four commitments that hold across every engagement.

It stays in your systems. What we build operates on accounts you own. ArkSystems does not run a platform that holds your records, and there is nothing of yours to retrieve or migrate if you stop working with us.

We take the least access that does the job. Read-only where reading is enough. Scoped to the workflow, not the organization. If a step needs broader access, we ask for it specifically and say why.

Every tool in the path is named before it is connected. You see the list — hosting, models, storage, anything the information passes through — in writing, before anything is switched on. Nothing gets added mid-engagement without telling you.

You set the boundary between automatic and reviewed. Which steps run without a person, and which stop for one, is your decision. We build to it and we record what the system did at each step, so the record exists whether or not anyone asks for it.

What we access, stage by stage

The 20-minute call. Nothing. You describe the problem, we ask questions. No access, no documents, no credentials.

Discovery and the workshop. Conversations, process walkthroughs, and figures about how the work runs — volumes, timings, who does what. Where we need to see a real example, we ask for a redacted one, and we work from screen-shares in preference to copies. We do not need your client records to establish where the cost sits.

Implementation. Access to the systems the work touches, granted through your own administration and using accounts issued to us — never shared passwords, and never credentials sent by email. Access is scoped to what the build requires and no more.

Testing. Synthetic or redacted data wherever the test can be run with it. Where a test genuinely requires live records, we agree that specifically, in advance, and limit it to what the test needs.

Once it’s running. The system touches whatever the workflow touches — and that is defined in writing before it’s built, not discovered afterwards.

Access, and how it ends

Access is issued by you, through your own systems, so you can see it and remove it without asking us.

Multi-factor authentication is used on every account that reaches client information.

When an engagement ends, access ends. We ask you to remove our accounts and we confirm removal on our side within five business days. If you want that earlier, or immediately, say so — it is your access to withdraw at any point and you do not need a reason.

AI models specifically

This is the part clients ask about most, so it is stated plainly.

Which providers. There is no fixed list, because the answer is partly yours. Which models a build uses depends on what the work needs and on what your firm will accept — some practices have already approved a provider, some rule one out, some require processing to stay in a particular region. We propose what fits, you decide, and the providers and tiers are named in your engagement documents before anything is connected.

What each provider does with your inputs. Providers differ, and their terms change. Before anything is connected, we tell you which providers your build uses, which tier, and what their terms say about how inputs are handled — including whether they are used for model training. You decide with that in front of you rather than afterwards.

Retention at the provider. Providers may retain inputs briefly for abuse monitoring under their own terms. Those terms are named to you rather than summarized by us, so you can read them yourself.

What we keep out of models. We design so that information a model does not need to do the job does not reach it. Where a step can run on a reference rather than the underlying record, it runs on the reference.

Where the processing happens. Most major model providers process in the United States. If your firm requires processing to stay in Canada, tell us before the design is fixed — it constrains which providers can be used and it is far cheaper to know at the start than to rebuild.

Where information is processed

ArkSystems’ own operations run on:

Provider Purpose Region
Google Workspace Documents, forms, and our client and prospect records United States
Namecheap (Private Email) Our email — every message sent to or from our address United States
Netlify Website hosting United States
Cal.com Call booking United States

AI providers are not on this list, deliberately. They are chosen per engagement rather than fixed in advance, for the reasons above, and every provider inside a delivered system is named — with its tier and its region — in that engagement’s documents before anything is connected.

What we keep after the work ends

We do not keep your operational data. Not during the engagement beyond what the work requires, and not after it.

Anything you give us to examine, test with or build against is working material, not a record. It is deleted within 90 days of the engagement closing, and nothing of yours remains on our systems once the work is done. The system we built runs on your accounts, holding your data, where it always was.

What we do keep is the paperwork of the engagement:

  • Contracts, proposals, statements of work, requirements documents, the workshop document and invoices — kept for the length of the relationship and for six years after the end of the tax year they relate to, because Canadian tax law requires business records to be retained for that period
  • Credentials and access — removed at close, as above

You can ask us to delete your business data earlier than the schedule above, and we will confirm in writing when it is done.

If something goes wrong

If a security incident affects your information, we tell you — promptly, with what we know at the time, rather than after an internal investigation concludes. We work with you to establish what was affected, and we support whatever notification your own obligations require.

We do not claim that no incident can occur. What we commit to is that you hear about it from us, early.

What stays your responsibility

You remain responsible for your clients’ information and for your own professional and regulatory obligations. We build to the boundaries you set; we do not determine what those boundaries should be, and nothing on this page is advice about your obligations.

If your professional body, your insurer or a client contract imposes requirements on how information is handled or where it is processed, tell us at the start. Requirements are a design input. Discovered late, they are a rebuild.

Questions

If your firm has a security questionnaire, a vendor assessment or a data-processing agreement, send it before we start rather than after. We would rather answer it properly than discover halfway through that we cannot.

hello@arksystems.ca

ArkSystems is operated by FoodyGuru Inc..

Personal information collected through this website is covered separately, on our Privacy Policy.