Home / Privacy Policy
Legal

Privacy Policy

Effective: August 11, 2026 · Next review: February 2027

ARM Agency ("we", "us", "our") operates arm-agency.com and provides reputation management, Generative Engine Optimization, and signal architecture services. This policy explains what data we collect, why we collect it, and the controls you have.

TL;DR We collect the minimum data needed to deliver your audit or engagement. We do not sell your data. We do not use your data to train AI models. We retain engagement data for the life of our working relationship plus a defined archival period. You can request deletion at any time.

1. Data We Collect

From website forms

When you submit a Signal Audit request or contact form, we collect:

From phone calls

When you call our support line (+1 224-275-9027), powered by Vapi, we process:

Call recordings, if any, are retained by Vapi according to their data retention policy. We receive transcripts and structured data, not the raw audio.

During an engagement

If you become a client, we also collect:

Automatically collected

2. How We Use Your Data

We do not:

3. Data Storage and Processing

Lead and engagement data is stored in our managed backend (Base44) with row-level security isolation. Call data is processed through Vapi's voice infrastructure. Payment data is handled by our payment processor — we never store card numbers or banking credentials.

All data is processed in the United States. We do not transfer personal data to jurisdictions with inadequate data protection standards.

4. Data Retention

Data type Retention period
Lead inquiries (no engagement)90 days after last contact
Active client recordsDuration of engagement + 3 years
Call transcripts12 months
Server logs30 days
Audit findings reports7 years (legal record)

5. Your Rights

Depending on your jurisdiction (GDPR, CCPA, or similar), you may have the right to:

To exercise any of these rights, email ops924-agent@manus.bot. We respond within 30 days.

6. Third-Party Services

We use the following third-party services that may process limited personal data:

Each service operates under its own privacy policy and data processing terms. We select vendors that demonstrate adequate data protection controls.

7. Security

We use row-level security on all client data, encrypted connections (TLS 1.2+) for all data in transit, and encrypted at-rest storage. Access to client data is restricted to authorized personnel with a need-to-know basis.

No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify you within 72 hours of confirmation, in accordance with applicable law.

8. Children's Privacy

Our services are intended for businesses and professionals. We do not knowingly collect data from anyone under 16. If you believe we have collected data from a minor, contact us and we will delete it.

9. International Users

ARM Agency is based in the United States. If you access our services from outside the US, your data is still processed in the US. By using our services, you consent to this transfer. We comply with GDPR for EU/UK users and CCPA for California residents.

10. Changes to This Policy

We update this policy as our services evolve. Material changes will be posted to this page with an updated effective date. We will not reduce your privacy protections without notice.

Last updated: August 11, 2026

11. Contact

Questions about this policy or your data? Reach us: