Privacy
How Conclave handles personal data. Last revised 11 September 2026.
Who is responsible
Conclave is run by ArcSystemsTechnology, a practice of ArcGabriel Ltd, which is the controller of the personal data described here. Questions and requests go to Philip Martin at the address given on your engagement letter.
What is held, and why
Conclave holds the name, role and email address of each person a client names to use their room, so that they can be invited and signed in. It holds the name, band, tier and progress of the system being built, and the dated update lines the practice posts, so the room can show them. When a document is signed in the room it holds the exact text signed, a hash of it, the time, the signer's verified email address, the IP address and browser the signature came from, and the session it was made in, as evidence of the agreement. When a payment is made it holds the identifiers Stripe issues and the state of the payment, never card or bank details, which are entered on Stripe's own pages.
All of this is held to perform the agreement between the client and the practice, and to keep the evidence that the agreement was made.
Sign-in
There are no passwords. Sign-in is by a link emailed to an invited address; the link works once and lasts fifteen minutes. A request to sign in an address that has not been invited sends nothing and records nothing about the request beyond a count used to limit abuse. Sessions are kept in a signed cookie for up to thirty days.
Your copies
If you ask for your signed documents by email, each is sent to your registered address as a file with its record of signing, and Conclave keeps the message identifier and the delivery state the provider reports, never the message. You can ask again from the documents page, and you can say no; the archive in the room is the same either way.
Who else handles it
Conclave runs on Railway, sends email through Resend, takes payment through Stripe, and reads build status from GitHub. A nightly copy of the store is encrypted before it leaves the server and kept in Cloudflare R2 for thirty days, so that a failure of the server does not lose the record; Cloudflare holds only the encrypted bytes. Each processes data only to provide that service. No data is sold and nothing is used for advertising.
The audit ledger
Conclave keeps a record that actions happened: an invitation sent, a sign-in, a document signed, an update approved. The ledger records the kind of event and an identifier, never the content, and it is not personal data, which is why it survives an erasure.
How long
A person's record is kept while their client's service runs. Signed documents are kept as the record of the agreement for as long as the law and the agreement require. Spent sign-in links and rate-limit counts are swept within hours. An erased record can remain in an encrypted backup copy for up to thirty days after the erasure, and then it is gone from there too.
Your rights
You may ask for a copy of what is held about you, ask for it to be corrected, and ask for it to be erased. Any signed-in person can erase their own account and record in two clicks at /account/erase; the client's room and the signed documents remain, because they are the practice's record of the agreement. For anything else, write to the address on your engagement letter. You may also complain to the Information Commissioner's Office.