Privacy Policy — Arbitex Data Protection Practices
Last updated: March 6, 2026
Draft — for reference and review only. Non-binding until attorney-reviewed and approved.
1. Your Data Protection Commitments
Before we describe what data we collect and how we use it, here are the three commitments that define our relationship with your data. These are not aspirations — they are enforced at the infrastructure level and are core to the Arbitex service contract.
2. Information We Collect
Account data. Name, email, organization name, and billing information. For SSO users, we receive the attributes your identity provider shares during authentication.
Usage data. API request counts, model provider selections, routing mode usage, policy evaluation outcomes, dashboard activity, and session metadata (IP address, browser type, timestamps).
AI traffic metadata. Per-request metadata: timestamp, source identity, destination model/provider, request and response size, latency, policy results, and DLP inspection outcomes. We do not store prompt or response content in our SaaS control plane by default (see Section 4).
Support data. Communications and diagnostic data you share with our support team.
3. How We Use Your Information
- Service operation. Route requests, enforce policies, generate audit logs, deliver the Arbitex Gateway.
- Security. Detect and prevent unauthorized access, fraud, and abuse.
- Compliance. Fulfill legal obligations and support your compliance requirements across regulatory frameworks.
- Service improvement. Analyze aggregate, de-identified usage patterns. We never use customer AI traffic content for model training or analytics.
- Billing and communication. Calculate usage, process payments, send service-related notices. No marketing communications without explicit opt-in.
4. Data Processing and Storage
Processing roles. Arbitex is the data processor. The customer is the data controller. A Data Processing Agreement (DPA) governs this relationship and is available on request.
Encryption at rest. AES authenticated encryption for secrets at rest. Key Vault integration for production key management. Customer-managed keys via BYOK available on Enterprise plans.
Encryption in transit. TLS 1.3 minimum. HSTS enforced. mTLS available for Hybrid Outpost data plane to control plane communication.
5. AI Traffic Data
Content handling. Prompts and responses are inspected in real time for DLP enforcement. Content is encrypted at rest; access requires an explicit IAM grant that is itself audit-logged.
Customer ownership. All prompt content, response content, and policy configurations are owned by the customer. Arbitex claims no rights to customer AI traffic data.
No training use. Customer data is never used to train models — ours or any third party's. This is the default and only mode.
Zero provider retention. Arbitex enforces zero-retention agreements with all upstream AI providers.
6. DLP and Content Inspection
The Arbitex Gateway operates a 3-tier DLP pipeline:
- Tier 1: Regex patterns. 80+ pattern detectors, with checksum validation on regulated identifiers, for credit card numbers, government IDs, and financial account numbers.
- Tier 2: Secret detection. 39 credential patterns for API keys, tokens, and connection strings.
- Tier 3: Neural entity recognition. 40 recognizers with GPU-accelerated contextual validation.
- Compliance bundles. 12 frameworks (PCI-DSS, HIPAA, GDPR, GLBA, SOX, CCPA, BSA/AML, SEC Reg FD, FERPA, EU AI Act, NIST AI RMF, ISO/IEC 42001).
All three tiers inspect both request (prompt) and response content. Inspection results are logged in the audit trail but the inspected content itself follows the retention policy configured by the customer.
7. Audit Logs
Every policy evaluation, routing decision, and administrative action produces an tamper-proof audit log entry. Logs are immutable and tamper-evident.
| Plan | Retention |
|---|---|
| Team | 30 days |
| SMB | 90 days |
| Enterprise | 1 year+ (configurable) |
SOC 2 compliance reports generated on demand.
8. Data Residency
- US-East (default). Data processed and stored in the US-East region.
- EU-West (on request). For customers with GDPR or data sovereignty requirements.
- Hybrid Outpost (Enterprise). Data plane runs in the customer's VPC. Prompts and responses never leave customer infrastructure.
Data does not cross region boundaries without explicit customer configuration.
9. Sub-processors
Arbitex maintains a quarterly-updated list of sub-processors. Customers receive at least 30 days advance notice before a new sub-processor is engaged. Customers may object to a new sub-processor; if the objection cannot be resolved, the customer may terminate the affected service without penalty.
10. Data Retention and Deletion
Customer data is retained for the duration of the active subscription. Upon termination, all customer data — including account data, usage data, AI traffic metadata, and audit logs — is permanently deleted within 30 days. Customers may request earlier deletion or a data export at any time during the subscription term.
11. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data, as well as the right to restrict or object to certain processing activities. To exercise any of these rights, contact us at [email protected].
12. Security Measures
- Audit controls. Security, Availability, and Confidentiality controls with on-demand compliance reporting.
- Encryption. AES authenticated encryption at rest, TLS 1.3 in transit, BYOK on Enterprise.
- Access controls. RBAC, MFA, SSO, SCIM 2.0, WebAuthn/FIDO2.
- Infrastructure. WAF, DDoS protection, secrets in HashiCorp Vault.
- Incident response. P0 acknowledged promptly. Breach notification within 24 hours.
- External validation. Annual penetration testing. Contact: [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated at least 30 days in advance via email to the account owner and via a notice in the Arbitex dashboard. Continued use of the service after the effective date constitutes acceptance of the revised policy.
14. Contact
Privacy: [email protected]
Security: [email protected]
Arbitex, Inc.
[Address to be provided by legal counsel]