Legal
Privacy Policy
Last updated: August 28, 2026
This policy explains what data arosis collects, why we collect it, who processes it on our behalf, and the rights you have over it. It covers both your account data and the business data we publish and monitor on your behalf.
1. Who we are
arosis is operated by Tran Binh Nguyen, an individual (sole proprietor) trading as “arosis”, of An Nhon Ward, Go Vap, Ho Chi Minh City, Vietnam(“arosis”, “we”, “us”). We are the data controller for the personal data described in this policy, except where we act as a processor on your behalf (see section 4).
You can reach us about anything in this policy at success@arosis.ai.
2. Data we collect
Account data. Your name, email address, and authentication details, collected when you sign up. Authentication is handled by Clerk; we do not store your password.
Business data (your “Golden Record”). The canonical record of the business you manage in arosis: business name, address, phone number, website, opening hours, service areas, services and descriptions, categories, FAQs, images, and related content. Some of this may be personal data — for example a sole trader’s name, home-based business address, or personal phone number.
Connected-account data. When you authorize a connection, we access and store data from that provider: Google Business Profile (listing content, posts, reviews metadata), Google Analytics (aggregated traffic and referral metrics), Google Search Console (sitemap and indexing status), your website or CMS via our plugin, and directory and listing platforms. We also store the OAuth access and refresh tokens needed to maintain the connection.
Audit data. If you run a free audit, we collect the website URL you submit, your email address, the content our crawler retrieves from that public website, and the resulting scores and analysis.
Monitoring data. The prompts run against AI engines on your behalf, and the responses returned — including whether your business was mentioned, its position, and competitor names appearing alongside it.
Billing data. Subscription status, plan, and transaction records. We do not collect or store your card details — payment details are collected and held by Paddle, our Merchant of Record.
Usage and technical data. Log data, IP address, browser and device information, pages viewed, feature usage, API and MCP access logs, and error diagnostics.
3. How we use your data
- To provide the Service: publishing your business record to directories and Google Business Profile, injecting schema into your website, generating and publishing content, submitting URLs for indexing, and running monitoring.
- To generate reports, dashboards, audit results, and alerts for you.
- To operate your account, take payment through Paddle, and provide support.
- To send service and transactional email — monitoring alerts, review requests sent on your behalf, billing notices, and security notices.
- To secure, debug, maintain, and improve the Service, including aggregated and anonymized analysis that does not identify you or your customers.
- To comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your business data to train third-party AI models — see section 5.
4. Legal basis for processing (UK/EU)
- Contract — to provide the Service you have subscribed to and to take payment.
- Legitimate interests — to secure and improve the Service, prevent abuse, and communicate about your account, balanced against your rights.
- Consent — for optional marketing email and for non-essential cookies, where used. You may withdraw consent at any time.
- Legal obligation — for tax, accounting, and compliance records.
Where the business data you upload includes personal data about other people (for example, customers you ask us to email a review request), you are the controller for that data and arosis acts as your processor, processing it only on your documented instructions.
5. Sub-processors and third parties
We use the following providers to operate the Service. Your account and business data is processed by them for the purposes shown, under contracts requiring appropriate confidentiality and security:
| Provider | Purpose | Data processed |
|---|---|---|
| Clerk | Authentication and account management | Name, email, session and login data |
| Neon | Primary database hosting | All account, business, monitoring, and billing records |
| Upstash | Caching and rate limiting | Transient keys, cached results, request metadata |
| Vercel | Application hosting and delivery | Requests, IP addresses, logs |
| Paddle | Merchant of Record — payments, tax, invoicing | Name, email, billing address, payment details, transactions |
| Resend | Transactional and alert email delivery | Recipient email address, message content |
| Anthropic | AI processing — audit analysis, content generation, monitoring | Business record content, website content, prompts and responses |
| OpenAI | AI processing and engine monitoring | Prompts and responses relating to your business |
| Perplexity, xAI (Grok), Google (Gemini / AI Overviews via SerpAPI) | Multi-engine visibility monitoring | Prompts about your business and the responses returned |
| Synup | Directory syndication to partner directories — used only where directory syndication is enabled on your plan (a gated add-on, not active on all plans) | Your public business record — NAP, hours, categories, description |
| Google (Business Profile, Analytics, Search Console APIs) | Profile updates, analytics, and indexing | Connected-account data and OAuth tokens (see section 6) |
| Inngest | Background job orchestration | Job payloads containing client and record identifiers |
Directory syndication is, by design, publication: the business record you give us is distributed to public directories and is then publicly visible. Do not put anything in your Golden Record that you do not want published.
We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition (with notice to you). Our sub-processor list may change; we will update this page.
6. Google user data and Limited Use
arosis accesses Google user data through Google’s OAuth APIs when you connect Google Business Profile, Google Analytics, or Google Search Console.
arosis’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request only the scopes needed to deliver the features you have enabled — updating your Business Profile, reading analytics, and submitting sitemaps to Search Console.
- We use Google user data only to provide and improve those user-facing features.
- We do not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI or machine-learning models.
- We do not allow humans to read Google user data except with your explicit consent for specific messages, where necessary for security or to comply with law, or on aggregated and anonymized data used for internal operations.
You can revoke arosis’s access at any time from the arosis dashboard or from your Google Account permissions page. On revocation we stop using the connection and delete the stored OAuth tokens.
7. Data retention and deletion
We keep your data for as long as your account is active and you are subscribed.
On cancellation: your account moves to a read-only/inactive state and scheduled actions stop running. Your data is retained for the duration of your subscription; deleted or anonymized within 90 days of account closure or a valid deletion request — so you can reactivate without losing your history within that period. Stored OAuth tokens for connected accounts are deleted on cancellation.
On request: you can ask us to delete your data at any time by emailing success@arosis.ai. We will action verified requests within 30 days.
What we may keep: billing and tax records for the period required by law (typically 6–7 years, held by Paddle as Merchant of Record), plus security logs and aggregated anonymized statistics that cannot identify you.
What deletion does not reach: information already published on your behalf to public destinations — directories, your Google Business Profile, and your own website — is controlled by you or by those platforms. Deleting your arosis account does not remove it. We will tell you what was published where so you can remove it, or remove what we still have access to if you ask before cancelling.
8. Security
We protect your data with encryption in transit (TLS) and at rest, access controls and per-account ownership checks on every record, scoped API credentials, and infrastructure hosted with reputable providers. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant regulator where the law requires it. Report a suspected vulnerability to success@arosis.ai.
9. International transfers
arosis and its sub-processors operate internationally, and your data may be processed in the United States and other countries outside the UK and EEA. Where data is transferred out of the UK or EEA, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or an adequacy decision. Contact us for details of the safeguards applying to a specific transfer.
10. Your rights (UK & EU — GDPR)
If you are in the UK or EEA, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted (“right to be forgotten”).
- Restriction — limit how we process your data.
- Portability — receive your data in a structured, machine-readable format, or have it sent to another provider.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where processing is based on consent, without affecting prior processing.
Exercise any of these by emailing success@arosis.ai. We will verify your identity and respond within one month. You will not be charged, and we will not treat you differently for exercising a right.
You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ICO); in the EEA, your local data protection authority.
11. Your rights (California — CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to — all set out in sections 2–5 above.
- Access a copy of the specific pieces of personal information we hold.
- Delete your personal information, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information, and limit the use of sensitive personal information.
- Non-discrimination — we will not deny service, charge a different price, or provide a different quality of service because you exercised a right.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We also do not knowingly collect personal information from anyone under 16.
Submit a request by emailing success@arosis.ai with “CCPA request” in the subject line. We will verify your identity before responding and will respond within 45 days. You may use an authorized agent, with proof of authorization.
13. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact success@arosis.ai and we will delete it.
14. Changes to this policy
We may update this policy as the Service and our sub-processors change. We will update the “Last updated” date above and, for material changes, notify you by email or in the dashboard before they take effect.
15. Contact
To exercise a right, or to ask anything about this policy:
- Tran Binh Nguyen, an individual (sole proprietor) trading as “arosis”
- An Nhon Ward, Go Vap, Ho Chi Minh City, Vietnam
- success@arosis.ai
arosis has not currently appointed a data protection officer or a UK/EU representative. For any data-related request, contact success@arosis.ai. This will be revisited as the UK/EU customer base grows.