Everything your security review will ask for.
Where your data lives, who processes it, what we encrypt, and which documents we can put in front of your legal team. If something here is not enough, ask and we will send the rest.
The short answers
Who is the controller?
Arcana Soft, Avenue Habib Bourguiba, Bir Mchergua, Zaghouan 1141, Tunisia. Tax registration 1815896P.
Where is our data hosted?
The hosting region for your tenant is set at provisioning and recorded in your service agreement. Tell us before signature if you need a specific region.
Is Tunisia covered by an adequacy decision?
No. Transfers out of the EEA or UK therefore rely on Standard Contractual Clauses together with a transfer impact assessment, both provided as part of our data processing agreement.
What exactly is encrypted?
Traffic runs over TLS. The credentials we store on your behalf, meaning SMTP passwords, PMS client secrets and push signing keys, are encrypted with AES-256-GCM under a key held outside the database. Infrastructure-level encryption at rest is provided by our hosting platform and covered under NDA.
How is access controlled?
Roles are assigned per property and checked by guards on the server, so the API refuses what the interface does not offer. Every authenticated request resolves a tenant context before a query runs.
What gets logged?
Security-relevant actions write an append-only record carrying actor identity and email, the action, the target, before and after state, and a timestamp, across auth, data, admin, configuration, GDPR and system categories.
What happens to our data if we leave?
Operational data is retained for the subscription term plus 90 days, exportable throughout that window, then permanently deleted.
What if Arcana Soft is acquired?
We notify you before your data becomes subject to a different privacy policy, and you may object, terminate and export. Terms of Service section 10 carries the assignment clause.
Do you hold ISO 27001 or SOC 2?
Not today, and we do not claim certifications we do not hold. This page describes the controls that exist in the product now, and we will evidence any of them on request.
How do you handle a breach?
Affected customers are notified by email. Availability incidents and scheduled maintenance follow section 6 of the Terms of Service, which also sets the service-credit terms.
Documents
Published pages are linked below. The rest we send on request, usually within one business day.
- Privacy PolicyPublished
- Terms of ServicePublished
- Security overviewPublished
- Data Processing AgreementOn request
- Sub-processor list with processing locationsOn request
- Standard Contractual Clauses and transfer impact assessmentOn request
- Data map and retention scheduleOn request
Sub-processors
Every third party that touches your data, and what it receives.
| Processor | Purpose | Data it receives |
|---|---|---|
| Mistral AI | AI dispatch, work-order analysis, report summarisation | Work-order text submitted for analysis |
| Google reCAPTCHA | Bot protection on public forms | Visitor IP address and browser signals |
| Calendly | Demo scheduling | Name and email of people who book a demo |
| Transactional email provider | Work-order notifications, escalations, account messages | Recipient name and email, notification content |
| Cloud hosting and database provider | Application hosting and data storage | All operational and account data |
We notify customers of additions before they take effect. Request the version applicable to your contract, naming each provider and its processing location.
Report a vulnerability
Send it to contact@arcana-soft.com. We acknowledge within two business days, triage by severity, and keep you updated until it is resolved. We do not pursue good-faith researchers.