Legal

Privacy Policy

Last updated 3 August 2026

Your trust is the product. This policy explains, in plain terms, what Black Arcscend collects, why, who we share it with, and the control you keep over it.

01Who we are — and when we are the controller or processor

Black Arcscend is an AI-native business growth platform operated by Black Arcscend Inc. (corporation no. 1770448-8, incorporated under the Canada Business Corporations Act, formerly Black ARC Global Inc.), at 3199 Lake Shore Blvd W, Suite 710B, Etobicoke, Ontario M8V 1K8, Canada.

We are the controller of account, website, billing, security, support, and our own business data. When a customer places its contacts, prospects, meeting participants, communications, or connected-account data in the platform and instructs us what to do with it, the customer is normally the controller and we act as its processor or service provider. Customers remain responsible for their notices, permissions, and lawful instructions.

02Scope

This policy covers our public site, applications, support, AI generation, Business and Social Intelligence, content planning and approval-gated publishing, audience and outreach tools, Meeting Intelligence, Lead Agent, connected services, and voice or messaging features when enabled. A third-party service you connect has its own privacy notice and is responsible for its independent handling of data.

03Information we collect

  • Account, workspace, and billing — name, business name, email, mobile number, password hash or sign-in token, role, subscription, invoices, and transaction status. Stripe, not Black Arcscend, holds full payment-card data.
  • Business intelligence and content — business profile, objectives, offers, approved brand context, intake answers, plans, prompts, uploaded logos/photos/video/audio, generated material, edits, approvals, publishing receipts, and performance signals.
  • Audience, communications, and lead work — contacts, consent and suppression status, campaigns, recipients, delivery events, first-party or permitted prospect evidence, qualification/readiness recommendations, owner decisions, and execution receipts.
  • Meeting Intelligence — attendee and meeting details, recordings, transcripts, notes, summaries, commitments, comments, approved memory, derivative work, conference-import metadata, sharing/access receipts, and retention settings.
  • Connected-service data — OAuth permissions, encrypted access tokens, selected Facebook Pages, linked Instagram professional accounts, handles and identifiers, approved posts, YouTube/channel identifiers, push tokens, and other data you direct an enabled integration to process.
  • Social and market intelligence — permitted public or customer-authorized evidence, website observations, competitor sources, owned-post media identifiers and permitted Instagram comments. We do not infer sensitive traits to target people.
  • Support, security, and operations — messages to us, request and audit records, login and operational events, IP address and browser/device information available to infrastructure providers, abuse-prevention signals, errors, and incident records.

04Cookies and consent-aware Visitor Intelligence

Essential cookies and local storage keep you signed in, preserve security and language choices, and remember your privacy choice. They are required for the service. We activate our first-party Visitor Intelligence only after analytics consent.

After consent, we use opaque visitor/session identifiers and a small allowlist of product events and intent scores. That system does not store raw page URLs, query strings, referrers, IP addresses, user-agent strings, email addresses, or cross-site/device fingerprints in its behavioural record. We retain consent grant, denial, and withdrawal receipts. You can change your choice through the privacy controls; withdrawal stops future non-essential collection.

05How and why we use information

  • Authenticate users, operate workspaces, bill subscriptions, provide support, and keep the platform reliable and secure.
  • Turn approved business context into intelligence, plans, content, meeting outputs, audience work, and owner-reviewed recommendations.
  • Publish or send only when the product shows an approval or execution gate and an authorized user completes it.
  • Sync enabled integrations, deliver notifications, reconcile removals, maintain suppression choices, and produce audit or execution receipts.
  • Measure consented product use, diagnose failures, prevent abuse, improve quality, and meet legal, tax, accounting, and regulatory duties.

06AI processing, human control, and model training

OpenAI is our primary provider for generation, images, embeddings, and transcription. Anthropic is a standby text-generation fallback. Retell AI and ElevenLabs process call or synthetic-voice data only when those optional voice features are activated. We send only the prompt, approved business context, or submitted media needed for the requested task.

We configure business/API services so submitted data is not used to train public models by default. Providers may keep limited security or abuse-monitoring records under their own enterprise/API terms. AI can be wrong. Scores, classifications, and drafts are decision support: they do not by themselves make legal or similarly significant decisions about a person. The owner reviews consequential actions, and publishing, sending, applying, or external execution requires the applicable approval gate.

07Facebook and Instagram connections

A customer may connect Facebook Pages and linked Instagram professional accounts through Meta OAuth. Depending on the enabled workflow, the app requests: pages_show_list, pages_read_engagement, pages_manage_posts, business_management, instagram_basic, instagram_content_publish, and instagram_manage_comments, plus Meta's basic public profile information where supplied. We use them to identify authorized assets, publish approved content, read permitted engagement, and power the owned-comment listening described below. We do not receive the customer's Meta password.

Page and Instagram identifiers, handles, permission status, and access tokens are stored; tokens are encrypted at rest with AES-256-GCM and are not exposed back to the browser. Disconnecting in Analytics deletes the stored connection/token and stops future access. You should also revoke the app in Meta's settings. To request deletion of historical Meta-derived records, email hello@blackarcscend.com from the account email with the connected Page or Instagram handle. Meta independently handles data under its own privacy notice.

08Social Listening and owned Instagram comments

When a customer activates an approved Social Listening connection, we fetch a bounded set of comments on media owned by that connected Instagram professional account. We store the comment and media identifiers, permalink, text, timestamp, and analysis needed to identify patterns. The ingestion contract rejects direct contact data and does not retain the commenter's username, profile, follower count, demographics, or inferred protected traits.

Raw owned-comment evidence has a 30-day active-use expiry. Expired evidence is excluded from current analysis, and provider removals are reconciled as removed/stale. Minimal audit identifiers or deletion tombstones may remain where needed to prevent re-ingestion, prove deletion, secure the service, or meet legal duties.

09Meetings, audience work, communications, and Lead Agent

Meeting Intelligence processes recordings and transcripts supplied through an enabled capture or conference workflow and converts them into evidence-linked notes, commitments, approved memory, and owner-selected business work. Meeting sharing is access-controlled and recorded. Meeting data must not be treated as marketing consent: recipients and permissions are reviewed separately before any outreach.

Audience and Lead Agent workflows may organize first-party or otherwise permitted contacts and prospect evidence, consent/suppression state, recommendations, draft communications, and execution receipts. They must not use sensitive or protected traits for targeting. Drafting is not sending: external actions remain approval-gated, and customers must have a lawful basis to contact each recipient.

10Optional calls, SMS, recordings, and push notifications

Typed intake is the primary path. If voice or messaging is enabled, calls occur only after the user initiates or expressly schedules them, identify the AI assistant, and announce recording before capture. Call audio, transcript, phone number, consent, status, and provider receipts may then be processed. SMS recipients can reply STOP; consent can also be withdrawn in product settings or by emailing us. Message/data rates may apply.

Push notifications use a device token and platform type. You can disable them in device settings. Customers may not use our tools to cold-call, send unlawful messages, conceal AI identity, or record someone without the notices and consent required in that person's location.

11Service providers and other disclosures

These providers process data to run the service. A conditional provider receives data only when its feature is enabled. Connected social platforms are not our subprocessors; they act under the customer's account and their own terms. We do not sell personal information or share it for cross-context behavioural advertising.

ProviderPurposeData
Supabase Pte. Ltd.Database, authentication & file storageAccount, workspace, encrypted-token, content, audience, meeting and intelligence data
Vercel Inc.Application hosting, delivery, functions & operational logsRequests, IP address, device/browser data and data processed by server functions
OpenAI, L.L.C.Primary AI generation, embeddings, images & transcriptionPrompts, approved business context, submitted media and generated outputs
Anthropic, PBCStandby AI fallback when the primary AI path cannot completeOnly the prompt and business context needed for the failed generation request
Stripe, Inc. and applicable local affiliateSubscription billing & paymentsName, email, billing details (full card data is held by Stripe, never by us)
Resend, Inc.Transactional, notification and owner-approved email deliverySender/recipient email, message content and delivery/suppression events
Google LLCGoogle sign-in, Firebase push delivery, YouTube data and enabled Google integrationsIdentity token, device push token, channel/video identifiers and enabled integration data
Cloudflare, Inc.Abuse prevention and media/object storage when those features are enabledRequest/security signals and uploaded media objects
Twilio Inc. (feature-conditional)Telephone connectivity & SMS when voice/messaging is activatedPhone number and call/message metadata
Retell AI, Inc. (feature-conditional)AI voice-agent orchestration when voice calls are activatedPhone number, call audio, transcript and call status
ElevenLabs, Inc. (feature-conditional)Synthetic voice generation when the branded voice is activatedText/audio needed to produce the voice output

We may also disclose the minimum necessary data in a corporate transaction subject to appropriate protection, to professional advisers under confidentiality, to prevent serious harm or abuse, or in response to a valid binding legal demand under section 17.

12Customer responsibilities for other people's data

If you upload, record, analyze, publish, or contact information about another person, you represent that you are authorized and have delivered any required notice, obtained any required consent, honoured opt-outs and suppression lists, and limited our instructions to a lawful business purpose. Do not place unnecessary health, financial, government-identifier, precise-location, children's, or protected-trait data in the service.

14Retention, deletion, and backups

  • Account and workspace data remains while the account is active and as needed for the service. A verified account-deletion request starts our controlled deletion process; some workspace deletion flows include a disclosed 72-hour recovery period.
  • Meeting data follows workspace controls: the current default transcript policy is 365 days and the default recording policy is 7 days, but an authorized owner may configure supported periods. Provider recordings are scheduled for deletion after successful ingestion where that workflow supports it.
  • Owned Instagram comment evidence has the 30-day active-use expiry described above.
  • Billing, consent, suppression, security, audit, execution, deletion-proof, dispute, and legal-hold records may remain longer where necessary. Backups and operational logs expire on provider-controlled cycles and are not restored to active use except for recovery or security.

To delete an entire account, email hello@blackarcscend.comfrom its verified address. We verify authority and confirm scope before deletion. Deletion cannot remove data another controller independently holds, including a connected platform or a customer's own copy.

15Your rights and choices

Subject to local law, you may ask to access and receive a copy of personal information, correct it, delete it, restrict or object to processing, withdraw consent, or receive portable data. You may opt out of marketing, SMS, optional analytics, recording, and connected integrations through the relevant control or by contacting us. You will not be discriminated against for exercising a privacy right.

Email hello@blackarcscend.com. We verify identity and authority, search the systems we control, and respond within the applicable legal timeline. If we process your data solely for a customer, we may refer the request to that customer. Canadian residents may complain to the Office of the Privacy Commissioner of Canada; UK/EEA residents may complain to their supervisory authority; applicable US residents may appeal a denied request where law provides that right.

16International processing

We are based in Canada and use providers that may process data in Canada, the United States, the EEA/UK, and other locations where they or their approved subprocessors operate. The laws of those places may differ from yours. Where required, we use contractual safeguards such as data-processing terms and Standard Contractual Clauses, conduct transfer assessments, and apply supplementary technical and organizational measures.

17Security, incidents, and government requests

Safeguards include encryption in transit, encrypted connected-account tokens, tenant and row-level authorization, role-based and least-privilege access, secrets management, audit receipts, and incident containment. No system is perfectly secure. We investigate incidents and notify affected parties and regulators when legally required.

Government and public-authority demands go to the Privacy Officer. We verify the requester, agency, jurisdiction, and binding authority; obtain legal review; reject or challenge informal, unlawful, overbroad, or conflicting demands where appropriate; disclose only the minimum necessary through a secure channel; and notify the customer unless prohibited or doing so would create a demonstrable risk. Requests, approvals, legal holds, disclosures, and provider coordination are recorded in a restricted register. In the 12 months before this policy date, we made zero national-security disclosures.

18Children

Black Arcscendis a business service for adults and is not directed to anyone under 18. We do not knowingly collect children's personal information. Contact us if you believe a child supplied it so we can investigate and delete it where appropriate.

19Changes to this policy

We update this policy when the product, providers, or law changes. We will revise the date above and provide a prominent in-app or email notice before a material change takes effect where required. Prior versions may be requested from the Privacy Officer.

20Privacy Officer

Contact Privacy Officer, Black Arcscend at hello@blackarcscend.com or by mail at 3199 Lake Shore Blvd W, Suite 710B, Etobicoke, Ontario M8V 1K8, Canada. Include the account email, your jurisdiction, the right or concern involved, and enough detail to locate the relevant data—never send passwords, full payment-card numbers, or sensitive ID documents by ordinary email.