Privacy Policy
This policy explains how ARCTICK handles personal information when organisations and their authorised users use the ARCTICK maintenance management service and website.
Information we process
- Account information such as names, work email addresses, roles, company membership and authentication identifiers.
- Company, site, asset and maintenance information entered by customer organisations.
- Engineer assignments, maintenance answers, readings, notes, reports, photographs and electronic signatures.
- Technical, authentication, security and audit information required to operate and protect the service.
- Contact form and support correspondence.
How we use information
We process information to provide and secure ARCTICK, authenticate users, apply access controls, store and synchronise maintenance records, generate reports, provide support, investigate faults or misuse and meet legal obligations.
Controller and processor roles
For ARCTICK's own account administration, security and business operations, ARCTICK generally acts as controller. For maintenance information processed on behalf of a customer organisation, ARCTICK will normally act as processor and the customer remains controller.
Hosting and storage
ARCTICK uses Supabase for authentication, database services and file storage. The primary ARCTICK Supabase project is hosted in the West EU (Ireland) region. ARCTICK also uses Cloudflare for website delivery, DNS and security services.
We do not claim that all personal data is processed exclusively in Ireland or the United Kingdom. Some service providers may process limited information in other countries. Where required, appropriate safeguards are used for international transfers.
Security
ARCTICK uses authentication, role-based permissions, database row-level security, encrypted network connections and restricted access controls. Customers and users must also protect their devices and login credentials.
Retention
Account and service information is retained while needed to provide the service and for reasonable security, support, legal and accounting purposes. Customer maintenance information is retained according to the customer relationship and applicable instructions. Some backup copies may remain for a limited period before being overwritten or securely deleted.
Your rights
Depending on the circumstances, individuals may have rights under UK data protection law including access, correction, erasure, restriction, objection and portability. Requests relating to data controlled by an employer or customer organisation should normally be directed to that organisation first. Requests relating to ARCTICK can be sent to support@arctick.co.uk.
Individuals may also complain to the UK Information Commissioner's Office.
Terms & Conditions
ARCTICK is intended for business and professional use. The service allows authorised users to manage sites, assets, maintenance templates, recurring maintenance, engineer visits, photos, signatures and reports.
Customers are responsible for the accuracy of information entered into ARCTICK, deciding which users may access their account, ensuring engineers are properly trained and competent, and complying with applicable legal, safety, inspection and manufacturer requirements.
ARCTICK supports maintenance administration and record keeping. It does not replace competent engineering judgement, statutory inspections, manufacturer instructions or a customer's legal and safety responsibilities.
ARCTICK and its licensors retain ownership of the software and related intellectual property. Customers retain ownership of the information and files they submit and grant ARCTICK the rights necessary to host, process, display and secure that information for the purpose of providing the service.
Nothing in these terms excludes liability that cannot lawfully be excluded. Free or pilot access is provided without a guaranteed service level. Paid customer orders may include additional commercial terms covering fees, service levels, termination and liability.
These terms are governed by the laws of England and Wales.
Sub-processors & Service Providers
ARCTICK uses third-party providers to operate the service. The current core providers are:
- Supabase — authentication, PostgreSQL database and file storage. Primary project region: West EU (Ireland).
- Cloudflare — DNS, website/app delivery, CDN and security services.
- OpenAI — AI model provider for AI-assisted ARCTICK functionality. Information is only sent to AI services where required to provide an AI feature initiated or configured within ARCTICK.
We may update this list as the service changes. Where a provider processes personal data on our behalf, we aim to use appropriate contractual and security arrangements.
AI-assisted Features
ARCTICK may use AI to assist with maintenance-related workflows. AI output can be inaccurate, incomplete or inappropriate and must be reviewed before use. AI output is not a substitute for competent engineering judgement, statutory requirements, manufacturer instructions or independent safety checks.
Users remain responsible for reviewing and approving AI-assisted output, particularly where it may affect safety, compliance, customer communications or maintenance decisions.
Contact
Support, privacy and legal enquiries can be sent to support@arctick.co.uk.