Archesell Privacy Policy
Effective date: September 28, 2026 Last updated: September 28, 2026
This Privacy Policy explains what personal information Archesell collects and processes through its applications and websites (the “Services”), how we use and disclose it, how long we retain it, and the choices and rights available to individuals.
In short
This summary is for orientation only. The numbered sections below are what govern.
-
Archesell is business software. Our customers are organizations. We do not offer individual consumer accounts.
-
The Services work by connecting to business tools a customer already uses, such as email and calendar. A user chooses to connect those tools and can disconnect at any time.
-
We do not sell personal information and we do not use customer data for advertising.
-
We do not use customer data, or data received from Google Workspace, to train artificial-intelligence models.
-
Most of the information in a customer workspace is controlled by that customer organization. The organization decides how long it is kept and when it is deleted.
-
You can write to privacy@archesell.ai about any of this. You do not need your administrator’s permission to contact us.
1. Overview
Archesell provides business customer relationship management software with AI-assisted features, including account prioritization, relationship intelligence, activity capture, meeting summarization, and drafting assistance. The Services are offered to organizations for business use. The Services do not offer individual consumer accounts and do not support consumer Google accounts, either for sign-in or as connected data sources.
Where the Services are offered. Archesell offers the Services to organizations located in Canada and the United States. Archesell does not offer the Services to organizations established in the European Economic Area, the United Kingdom or Switzerland, and does not direct the Services to individuals located in those jurisdictions.
Our role. For Customer Platform Data processed through an organization’s workspace, the customer organization determines the purposes and means of processing and Archesell acts as its processor or service provider. Archesell may act as a controller or business for other categories of information that we process for our own purposes, such as Website Visitor Data, account and billing administration, security telemetry, marketing information, and Licensed Business Data.
Agreements with customers. Where a customer has entered into a data processing agreement or similar written agreement with Archesell, that agreement governs Archesell’s processing of Customer Platform Data and controls in the event of any conflict with this Policy.
2. Definitions
Capitalized terms used in this Policy have the meanings given below.
-
Customer Platform Data — CRM records; customer and prospect information; business communications and meeting content saved as evidence in an Archesell customer record; calendar events; user notes; activity records; and other records created or saved in the customer workspace. The customer organization controls the retention and disposition of Customer Platform Data, subject to applicable law, contract and source-specific requirements.
-
Customer Business Evidence — provider-originated content, such as an email message or a meeting transcript, that has been saved as supporting evidence on a governed customer record. It is a subset of Customer Platform Data.
-
Connected-Source Data — information accessed from services that a customer or authorized user connects to Archesell, including email, calendar, meeting and related provider data. Some Connected-Source Data is processed only in passing and is never saved as a customer record.
-
Derived Data — information computed or generated from other information, such as account-fit and prioritization values, risk indicators, relationship-coverage measures, extracted signals, summaries, briefs, commitments and drafts.
-
Licensed Business Data — professional contact and company information obtained from third-party data providers and made available in the Services.
-
User Account Data — name, work email, role, authentication information, billing contacts, subscription records, product settings and usage telemetry.
-
Website Visitor Data — device, browser, cookie and analytics information associated with visits to our websites.
-
Saved as a customer record — we use this phrase to mean that information has been written into the customer’s workspace as part of its governed business record. Information that is not saved as a customer record follows a short transient or user-scoped lifecycle instead, described in Sections 3.3 and 14.
3. Google user data
3.1 Limited Use
Archesell’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Archesell’s use of information received from Google Workspace APIs will also adhere to the Google Workspace API User Data and Developer Policy.
This section applies specifically to information Archesell receives through Google APIs. Archesell requests Google access only for user-facing features, and uses Google user data only in accordance with the permissions granted by the authorized user and the customer organization.
3.2 What we access and why
| Google scope | What Archesell accesses | Why we need it |
|---|---|---|
| gmail.readonly | Email threads, replies, headers and participants. For attachments, only each attachment’s name, type and size, so the user can open it from the original message in Gmail. We do not read, analyze or store attachment contents. | To identify customer communications, build activity history, identify explicitly stated business signals, maintain customer relationship context, and ground summaries and drafts in the customer’s own communications. |
| gmail.send | Sends a single message from the user’s account | Only after the user has reviewed that specific message and explicitly approved it for sending. Archesell does not send messages on a user’s behalf automatically. |
| calendar.events.readonly | Calendar events, attendees, and event descriptions or agendas | To identify customer meetings, resolve participants and prepare meeting context. Archesell does not use this permission to create, modify or delete calendar events. |
| meetings.space.readonly | Meeting metadata and available transcript entries, where the feature is enabled and a transcript exists | To identify customer meetings and retrieve available transcript text for activity records, summaries, commitments and follow-up assistance. Archesell reads transcript entries through the Google Meet API. Archesell does not join meetings with a recording bot and does not request Google Drive access for this purpose. |
| userinfo.email, userinfo.profile | Basic profile information such as name and work email address | For authentication and account identification. |
Archesell requests the narrowest scope that supports each feature described above, and limits the features available to a user according to the access actually granted.
3.3 How connected Google data becomes a customer record
Accessing information from Google does not by itself make that information a saved customer record. Archesell may process Connected-Source Data only in passing, to determine whether it is relevant to the customer’s business use of the Services. Information that is filtered out, or that is never associated with a customer record, remains subject to short operational retention and to the connected user’s deletion controls described in Section 3.7.
When provider-originated content is identified as a customer business interaction and saved as evidence on an Activity or another governed customer record, it becomes Customer Business Evidence and therefore Customer Platform Data. Its retention and disposition are then controlled by the customer organization, subject to applicable law, contractual requirements and the controls described in this Policy. Disconnecting or offboarding an individual user does not delete those customer records.
3.4 AI processing of Google user data
Google user data may be processed by AI systems only as necessary to provide the user-facing Archesell features that the customer or user has requested or enabled.
Archesell does not use data obtained through Google Workspace APIs to create, train, fine-tune or improve any machine-learning or artificial-intelligence model. This includes generalized, foundational, cross-customer and customer-specific models.
Where Archesell uses a third-party AI provider to deliver a feature, that provider is contractually prohibited from using Google user data to train or improve its models. Where a provider retains data for a limited period for security and abuse monitoring under our agreement with it, that retention is limited to the period set out in that agreement and the data is not used for any other purpose.
3.5 Sharing and transfer
Archesell does not sell Google user data and does not use it for advertising. We transfer Google user data only as permitted by Google’s applicable policies, and only:
-
to service providers operating under contract, as necessary to provide or secure the user-facing features the user has requested and with the user’s consent;
-
to other authorized users within the customer organization, only as described in Section 9 under “Who can read captured communications”;
-
as necessary to investigate a security issue or abuse;
-
where required by applicable law; or
-
in connection with a merger, acquisition or sale of assets, only after obtaining explicit prior consent from the affected user.
We do not transfer Google user data to data brokers or advertising platforms, and we do not use Google user data to determine credit-worthiness or for lending purposes.
3.6 Human access
Archesell restricts human access to Google user data. A person at Archesell may view Google user data only:
-
after the user gives affirmative agreement to view specific messages, files or other data;
-
where necessary for security purposes, such as investigating a bug or abuse;
-
where required by applicable law; or
-
where the data has been aggregated and anonymized and is used for internal operations, in accordance with applicable privacy requirements.
3.7 Disconnecting and deleting Google data
An authorized user may disconnect Google inside Archesell, or revoke Archesell’s access through their Google account controls. Either action ends future access through that authorization. Archesell revokes and deletes the associated stored credentials promptly.
A user may also ask us to delete Google data that is still held only for that user and has not been saved as a customer record. We delete that data — including the stored authorization credentials and any Connected-Source Data that was never saved to a customer record — from our active systems within 24 hours of the request. Routine backups expire on the schedule set out in Section 14.
This deletion path does not reach customer business records. The retention and disposition of an email exchange or meeting record that was already saved into the customer’s workspace are controlled by the customer organization. Requests about that information are handled as described in Sections 15 and 16.
4. Information we collect
The table below sets out the categories of personal information we collect, where each category comes from, and why we use it. The categories of parties we disclose information to are in Section 13. Our retention periods are in Section 14.
| Category | What it includes | Sources | Primary purposes |
|---|---|---|---|
| Customer Platform Data | CRM records, customer and prospect information, business communications and meeting content saved as evidence, calendar events, user notes, activity records | The customer organization and its authorized users; connected services the customer chooses to connect | Provide the Services under the customer’s instructions; maintain customer and activity records |
| Connected-Source Data | Email, calendar, meeting and related provider data accessed from connected services. Some is processed only in passing and never saved. | Services a customer or user connects, such as Google Workspace, Zoom and CRM systems | Identify customer communications and meetings; build activity history; prepare context for user-facing features |
| User Account Data | Name, work email, role, authentication information, billing contacts, subscription records, product settings, usage telemetry | Directly from users and customer administrators | Authenticate users; administer accounts, subscriptions and billing; support; security; product operation |
| Licensed Business Data | Professional and company information such as name, title, seniority, work email, work phone, company address, industry, size, revenue range, location, technology information, public professional-profile links | Third-party data providers, who compile it from publicly available sources and other collection and verification methods | Enrich and deduplicate business records; support account intelligence |
| Derived Data | Account-fit and prioritization values, risk indicators, relationship-coverage measures, extracted signals, summaries, briefs, commitments, drafts | Computed by Archesell from the categories above | Provide account and relationship intelligence and drafting assistance to the customer’s users |
| Website Visitor Data | Device, browser, cookie and analytics information | Our public websites. See Section 17. | Operate, secure and improve our websites |
| Email Engagement Data | Delivery events such as bounces, unsubscribe requests and link-click events, where enabled | Email sending and delivery infrastructure | Deliverability and list hygiene. Archesell does not use open-tracking pixels. |
Payment-card details are entered directly with our payment processor and are not stored by Archesell.
5. Information about people who are not users
The Services may process information about people who do not have an Archesell account, including external meeting attendees and email participants, professional contacts contained in Licensed Business Data, and contacts represented in customer CRM records. When this information comes from a customer’s connected systems or workspace, the customer is generally responsible for determining the purposes and means of that processing, and Archesell processes the information on the customer’s behalf.
Licensed Business Data may originate from publicly available sources and third-party data providers. Individuals may contact privacy@archesell.ai to exercise applicable privacy rights. Where Archesell holds information on behalf of a customer, we may refer the request to that customer and assist with the response.
6. Meeting transcripts and notes
Archesell may ingest meeting transcripts produced by connected meeting services such as Google Meet and Zoom. Archesell does not itself join meetings with a recording bot and does not record audio or video through such a bot. Archesell does not create or use voiceprints or other biometric identifiers to identify or authenticate meeting participants. Recording and transcription are controlled by the customer’s meeting-service settings and applicable participant notices. Customers are responsible for using recording and transcription in accordance with applicable law.
When a meeting transcript is saved as evidence for a customer Activity or another governed customer record, it is Customer Business Evidence and remains governed by the customer’s retention and disposition instructions. Removing or offboarding one participant does not delete a saved record of a multi-party customer meeting.
Users may also create notes by typing or by voice. If voice-note audio is collected, its retention and deletion follow the production retention configuration disclosed in the applicable product notice and in Section 14.
7. Connected CRM and other services
When a customer connects a CRM or another third-party service, Archesell may import information from that service and, where the integration supports it, write customer-approved or customer-configured updates back to that service. Information transferred to a connected service is then also subject to that service’s terms and privacy practices. Disconnecting an integration stops new access through that connection; it does not by itself delete Customer Platform Data already saved in Archesell.
8. Licensed business data
Archesell may make licensed business-to-business company and professional-contact information available within the Services. The attributes included are listed in Section 4.
Our data providers compile this information from publicly available sources and other collection and verification methods. We use Licensed Business Data to enrich and deduplicate business records and to support account intelligence. We do not use Licensed Business Data to train artificial-intelligence or machine-learning models.
Individuals may request access, correction, deletion or suppression of licensed personal information where applicable by contacting privacy@archesell.ai. Archesell will handle such requests according to applicable law and the rights and obligations governing the relevant data source.
9. Controls over connected data
Connections to third-party services are optional and are available only to eligible business users under the customer’s organization. Archesell presents the access required for a connection and limits features according to the access actually granted. Users may disconnect their own connected sources. Customers and users may also have controls to exclude particular data, or to correct information that should not have been saved as part of the customer’s business record, depending on the feature and their organization’s configuration.
If information is removed from the customer’s governed record because it was incorrectly classified or should have been excluded, it returns to the applicable transient or user-scoped lifecycle. That correction is not by itself a deletion. Access to information inside a customer workspace is governed by the customer’s workspace permissions and by Archesell’s access-control model.
Retention is not visibility. Saving communication content as Customer Business Evidence does not make that content generally visible across the customer’s organization. Access to it remains subject to the customer’s workspace permissions and to Archesell’s communication-visibility controls.
Who can read captured communications. By default, the content of a captured email or meeting — the message body and the meeting transcript — can be read only by the user who connected the source and, for a specific message or meeting, by other people from the customer organization who took part in that message or meeting. Taking part in one message does not give access to other messages in the same conversation. Other authorized users in the customer organization, including the user’s managers, can see that the interaction took place, who took part and when, together with summaries and business facts derived from it, but not the content itself. A user may choose, in their own settings, to let the people above them in their reporting line read that content, and may withdraw that choice at any time. That choice ends when the user leaves the customer organization. Customer administrators cannot make this choice for a user, and an administrator role does not by itself give access to communication content. Any exceptional access to communication content outside these rules must be permitted by applicable law, by the customer’s agreement with Archesell and by the requirements that apply to the source of the data. Such access is recorded, and the record is available to the customer organization.
10. How we use information
We use personal information to provide, operate, secure and improve the Services; maintain customer and activity records; generate account and relationship intelligence; prepare summaries, briefs and drafts; support user-approved actions; administer accounts, subscriptions and billing; communicate with users; prevent misuse; comply with law; and protect users and the Services.
We do not use Customer Platform Data or Derived Data for advertising, and we do not sell Customer Platform Data or Derived Data. We do not use them to build data products for other parties.
We may use de-identified and aggregated information about product usage and configuration to operate and improve the Services, provided that this use complies with applicable restrictions on the underlying data, does not identify a customer or an individual, and does not contain customer records or communications, or information derived from them. This de-identification and aggregation path does not apply to Google user data except to the extent expressly permitted by the Limited Use requirements described in Section 3.
11. AI processing
Archesell uses artificial-intelligence and machine-learning technologies to provide features such as summarization, extraction of explicitly stated business information, drafting assistance, account and relationship intelligence, and user-facing recommendations. AI-generated drafts that would communicate outside the customer’s organization are subject to the approval and execution controls provided by the Services. A user reviews and approves such a message before it is sent.
We may use third-party AI providers to deliver these features. Those providers process data under contractual restrictions and under the configurations selected by Archesell for the applicable service. They are prohibited from using the data to train or improve their own models.
Archesell does not use Customer Platform Data, Customer Business Evidence, Connected-Source Data or Derived Data to create, train, fine-tune or improve any machine-learning or artificial-intelligence model, including generalized, foundational, cross-customer and customer-specific models.
11.1 Adaptive features
Archesell provides features that adapt to a customer’s business context, for example by remembering business facts, user preferences, prior outcomes and patterns that are relevant to future recommendations.
This adaptation is implemented through governed data, memory, retrieval and reasoning at the time a feature runs. It does not train, fine-tune or improve any artificial-intelligence or machine-learning model.
Where adaptive information is derived from a user’s connected source and has not been saved as a customer record, Archesell uses it only to provide features to that user. Where information has been saved as part of the customer’s governed business record, Archesell may use it to provide customer-facing features within that customer’s workspace, subject to the permissions, use restrictions and other requirements applicable to the originating source.
Information from one customer’s workspace is never used to adapt or provide features for another customer, except as described in Section 10 for de-identified and aggregated information that contains no customer records or communications.
12. Automated processing and profiling
Archesell generates scores, rankings and indicators about business accounts, opportunities and relationships to help users decide where to spend their time. These outputs are decision support for the user.
They are not used to make decisions that produce legal or similarly significant effects on an individual, and they are not used for employment, credit, lending, insurance, housing or education decisions. A user may disregard or override any Archesell recommendation. Where applicable law gives you a right to opt out of profiling, contact privacy@archesell.ai.
13. How we disclose information
We may disclose personal information:
-
to service providers operating under contract for us, including hosting, AI, speech-to-text, support, analytics and payment providers;
-
to systems the customer chooses to connect;
-
to professional advisers;
-
to authorities where required by law;
-
to a successor in a corporate transaction, subject to applicable requirements and, for Google user data, to Section 3.5; and
-
to authorized users within the customer’s workspace.
We do not disclose Customer Platform Data or Derived Data to advertisers or data brokers for their own advertising or commercial purposes.
A current list of Archesell’s sub-processors is available at archesell.ai/subprocessors. Customers may subscribe to notifications of changes to that list.
14. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide contracted services, and to satisfy legal, security and operational requirements. Retention depends on the type of information and the lifecycle that applies to it.
| Data / lifecycle | Retention approach |
|---|---|
| Connected-service credentials | Revoked and deleted promptly when the connection is disconnected, the user is offboarded, or the customer service terminates. |
| Transient sync and processing data | Kept for short operational periods, minimized to what the user-facing feature requires and consistent with applicable provider requirements. |
| Attachment metadata | Kept with the email record it belongs to. Attachment contents are not stored. |
| Customer Platform Data during service | Retained under the customer’s applicable retention settings, instructions and contractual terms. |
| Customer Platform Data after customer termination | Normal access to the Services ends, and for 30 days the customer and its users can export their data or request deletion. Customer Platform Data is then deleted from active product systems, subject to legal or contractual exceptions. |
| Derived Data supporting a customer record | Retained while the customer record it supports is retained. When the underlying evidence is deleted, Archesell re-evaluates or removes the derived values that depended on it. A non-content provenance record may be retained as described in Section 15. |
| Derived Data from connected-source data never saved as a customer record | Deleted from active systems on the same 24-hour schedule as the connected-source data it was derived from. This includes user preferences and patterns learned only from that user’s connected source. |
| Routine backups | Deleted through normal backup rotation within 90 days after deletion from active product systems, unless a legal or security obligation requires otherwise. |
| Records associated with an offboarded employee | Remain with the customer under the customer’s retention instructions. Offboarding changes the user’s access; it does not by itself delete customer records. |
| Connected-source data not saved as a customer record | Authorization artifacts and connected-source data that was never saved as a customer record are deleted from active systems within 24 hours of the user’s request. This 24-hour period does not apply to Customer Platform Data or to routine backups. |
| Billing, security and legal records | May be retained separately for applicable tax, accounting, dispute-resolution, fraud-prevention, security and legal requirements. |
15. Deleting data and revoking access
Archesell distinguishes among five actions. They have different consequences.
| Action | What it does | What it does not do |
|---|---|---|
| Disconnect a connected source | Ends future access through that authorization and removes the associated credentials. | Does not delete Customer Platform Data already saved in the customer workspace. |
| Request deletion of data not saved as a customer record | Deletes that user’s transient or user-scoped connected-source data from active systems within 24 hours (Sections 3.7 and 14). | Does not delete Customer Business Evidence or other Customer Platform Data. |
| Request statutory deletion of personal information | Handled with the customer organization as controller. Archesell receives and assists with the request as processor and executes the customer’s lawful instructions. | Does not override applicable legal, contractual, security and retention requirements. |
| Remove a user seat / offboard an employee | Ends that person’s access and connected authorization. | Does not by itself delete the customer’s business records. |
| Terminate the Services | External data access stops on the termination date. The workspace enters the export and recovery period in Section 14 before active-system deletion. | Does not delete records that a legal or contractual obligation requires us to keep. |
Where Customer Business Evidence is lawfully deleted, Archesell may retain a non-content deletion or provenance record sufficient to show that the evidence existed and was deleted, and may re-evaluate Derived Data that depended on it. Such a record does not preserve the deleted communication content.
16. Privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or portability of personal information, and to object to or restrict certain processing or withdraw consent where applicable. We may need to verify your identity before completing a request.
You may submit a privacy or statutory rights request directly to Archesell at privacy@archesell.ai. You do not need an administrator’s permission to make a request. Where the requested information is Customer Platform Data that Archesell processes on behalf of your organization, we may refer or route the request to that organization as controller and assist it in responding. The customer’s involvement in determining the disposition of Customer Platform Data does not limit your ability to submit the request.
Appeals. If we decline your request, we will tell you why. You may appeal by replying to our response, or by writing to privacy@archesell.ai with the subject line “Privacy request appeal.” We will respond to an appeal within the time required by the law that applies to you, and in any case within 45 days of receiving it. If we deny your appeal, we will tell you how to complain to your state attorney general or other applicable regulator.
17. Cookies and website analytics
Our public websites use cookies and similar technologies. We group them as follows.
-
Strictly necessary — required for the site to work, including security, load balancing and remembering your cookie choices. These cannot be switched off.
-
Analytics — help us understand how visitors use our site so we can improve it. Our analytics providers are [ANALYTICS PROVIDER NAMES].
-
Marketing — [MARKETING COOKIES: describe, or replace this bullet with a statement that none are used]
We do not use cookies or similar technologies inside the product to track users across other companies’ websites.
Your choices. You can manage cookies through our cookie banner and through your browser settings. Archesell honours the Global Privacy Control (GPC) signal where applicable law requires it. Blocking strictly necessary cookies may prevent parts of the site from working.
Email engagement. Where enabled in the Services, delivery events such as bounces, unsubscribe requests and link-click events may be recorded. Archesell does not use open-tracking pixels.
18. Canada
Archesell is headquartered in British Columbia, Canada. We handle personal information in accordance with applicable Canadian private-sector privacy laws, including federal and provincial requirements that apply to our activities. Personal information may be processed outside Canada, including in the United States, where it may be subject to the laws of those jurisdictions.
Our designated Privacy Officer is responsible for Archesell’s compliance with this Policy and with applicable privacy law, and can be reached at privacy@archesell.ai or at the address in Section 24. If you are not satisfied with our response, you may also contact the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.
19. United States
Residents of US states with comprehensive privacy laws may have rights concerning access, correction, deletion, portability, opt-out choices, appeals, and disclosures about the categories, sources, purposes and recipients of personal information.
The categories of personal information we collect, where each comes from, and why we use it are set out in Section 4. The categories of parties we disclose personal information to are in Section 13. Our retention periods are in Section 14. How to make a request, and how to appeal a decision, are in Section 16.
Sale and sharing. Archesell does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined under applicable US state privacy laws.
Sensitive personal information. Archesell does not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under applicable US state privacy law.
We will not discriminate against you for exercising any of these rights.
20. Security
We maintain administrative, technical and organizational safeguards designed to protect personal information. These include encryption in transit and at rest, tenant isolation, least-privilege access controls, authorization controls for connected services, logging, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a security incident affecting personal information occurs, Archesell will notify affected customers and, where required, affected individuals and regulators, in accordance with applicable law and our contractual commitments.
21. International data transfers
Archesell and its service providers may process information in Canada, the United States and other countries. Where applicable law requires safeguards for international transfers, we use appropriate contractual or other recognized transfer mechanisms.
22. Children
The Services are business software and are not intended for children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information to Archesell, contact privacy@archesell.ai and we will delete it.
23. Changes to this Policy
We may update this Policy from time to time as our Services, integrations, legal requirements or data practices change. We will post the updated version with a new effective date, and provide additional notice of material changes where required by law or appropriate to the change. Previous versions are available on request.
24. Contact
Privacy inquiries, rights requests and complaints may be sent to privacy@archesell.ai.
Archesell Technologies Inc.
Attn: Privacy Officer
555 Burrard Street, Floor 1, Vancouver, British Columbia V7X 1M8, Canada