ARC
Pricing
Discord
Talk to an engineerStart free
Start free
ARCby FenxLabsCollective Intelligence

Platform

  • How it works
  • Custom routing and governance
  • Use cases
  • Example architectures

Deployment

  • Hosted Platform
  • Managed Service
  • Self-hosted Licence
  • For ISVs
  • Open the portal

Services

  • Assessment and planning
  • Architecture and integration
  • Model Adaptation
  • EU AI Act readiness
  • Managed Service operations

Resources

  • Cost modeller
  • Compare approaches
  • Pricing
  • FAQ
  • Transparency
  • Get started
  • Discord community

Legal

  • Privacy notice
  • Terms and conditions
  • Sub-processors
  • Accessibility

For individuals

  • FenxChat

FenxLabs. KvK 91762782.

Herengracht 320, 1016 CE Amsterdam, Netherlands

+31 85 060 5273contact@fenxlabs.ai

© 2026 FenxLabs. All rights reserved.

FenxARC Privacy Policy

Last updated: 27 August 2026

  • Our Privacy Commitment
  • Introduction
  • Definitions
  • 3. Data Controller
  • 4. Data Protection Contact
  • 5. What Personal Data We Collect
  • 6. Legal Bases for Processing
  • 7. How We Use Your Personal Data
  • 8. Data Sharing and Sub-Processors
  • 9. Cookies
  • 10. International Data Transfers
  • 11. Data Retention
  • 12. Data Security
  • 13. Your Rights
  • 14. Children's Data
  • 15. Reporting of Wrongdoing
  • 16. Changes to This Policy
  • 17. Language and Previous Versions
  • 18. Contact Us

On this page

  • Our Privacy Commitment
  • Introduction
  • Definitions
  • 3. Data Controller
  • 4. Data Protection Contact
  • 5. What Personal Data We Collect
  • 6. Legal Bases for Processing
  • 7. How We Use Your Personal Data
  • 8. Data Sharing and Sub-Processors
  • 9. Cookies
  • 10. International Data Transfers
  • 11. Data Retention
  • 12. Data Security
  • 13. Your Rights
  • 14. Children's Data
  • 15. Reporting of Wrongdoing
  • 16. Changes to This Policy
  • 17. Language and Previous Versions
  • 18. Contact Us

Our Privacy Commitment

FenxLabs is committed to a privacy-first approach. We collect only the minimum personal data necessary to provide and improve our services. We design our systems so that:

  • We do not track your behaviour on the Platform or the Chat App
  • We do not use your prompts or responses to train any AI model
  • We do not analyse your content to build profiles or target advertising
  • We do not sell, rent, or trade your personal data to third parties
  • Your query content passes through our routing infrastructure in encrypted form: we do not access, read, inspect, or decrypt it

1. Introduction

This Privacy Policy explains how FenixMinds B.V., trading as FenxLabs (“FenxLabs,” “we,” “us,” or “our”), collects, uses, stores, and protects personal data in connection with the FenxARC platform, the Chat App, and the fenxarc.com Website.

Naming. FenxARC™ is the current product name. References in previous versions of this policy to “ARC” or the “ARC Platform” refer to FenxARC.

FenxLabs is committed to a privacy-first approach. We collect only the minimum personal data necessary to provide and improve our services, and we do not sell, rent, or trade your personal data to third parties.

This policy is issued in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, as amended) (“GDPR”) and applicable Dutch data protection legislation.

2. Definitions

For the purposes of this Privacy Policy:

  • “Chat App” means the consumer-facing AI chat application offered by FenxLabs through interfaces made available by FenxLabs from time to time. The Chat App is built on the same technical architecture as the Platform but is a separate product in which FenxLabs determines the routing logic and AI Provider selection.
  • “Platform” means the authenticated FenxARC service accessible at https://askarc.app, including all features, tools, and interfaces available to registered users for configuring AI routing and model selection.
  • “Website” means the public-facing pages at https://fenxarc.com, including marketing pages, documentation, articles, and any other pages accessible without authentication.
  • “Services” means the Platform, the Chat App, and the Website collectively.
  • “Personal Data” has the meaning given in Article 4(1) of the GDPR.
  • “Processing” has the meaning given in Article 4(2) of the GDPR.
  • “User,” “you,” or “your” means any individual who accesses the Website, uses the Platform, or uses the Chat App.

Where this policy refers to data collection or processing that applies only to the Platform, the Chat App, or the Website, this is stated expressly.

3. Data Controller

FenxLabs is the data controller for Personal Data that it collects and processes for its own purposes, including Account Data, Billing Data, Technical Data, and Communication Data as described in Section 5.

Where FenxLabs processes Personal Data on behalf of the User in its capacity as routing infrastructure (including the routing of queries to AI Providers), FenxLabs acts as a data processor. The roles of the parties are set out in detail in Schedule A (Data Processing Agreement) of the Terms of Service.

FenixMinds B.V. (trading as FenxLabs)
Registered office: Amsterdam, The Netherlands
KvK: 91762782
BTW: NL865763495B01
Email: contact@fenxlabs.ai
Telephone: +31 85 060 5273

4. Data Protection Contact

FenxLabs has designated a Data Protection Contact who can be reached regarding any questions or concerns about this policy, our data processing practices, or to exercise your rights under data protection law:

Data Protection Contact: Joe Shenouda
Email: joe@fenxlabs.ai

5. What Personal Data We Collect

5.1 Account Data (Platform and Chat App)

When you create an account on the Platform or the Chat App, we collect:

  • Full name
  • Email address
  • Organisation name (if provided)
  • Authentication credentials (managed via our authentication provider; we do not store passwords directly)
  • Account preferences and settings

5.2 Usage Data (Platform and Chat App)

We do not track your behaviour on the Platform or the Chat App. We do not use analytics tools, behavioural tracking, session recording, or similar technologies within the authenticated Platform or Chat App environments.

The only usage data we process is:

  • Credit consumption records and Subscription usage records (for billing purposes)
  • API request metadata (model selected, timestamp, token count), used solely for billing, rate limiting, and service delivery
  • Error and performance logs (automatically generated, containing no user content, retained for a maximum of 30 days)

5.3 User Content (Platform and Chat App)

When you use the Platform or the Chat App, you submit prompts and receive responses from third-party AI models. We process this content solely to deliver the service. Our handling of user content is governed by the following principles:

  • No training by FenxLabs: FenxLabs does not use your prompts or responses to train any AI model. FenxLabs does not sell, licence, or otherwise make your content available for training purposes. However, FenxLabs cannot control or guarantee the data handling practices of third-party AI Providers to which your queries are routed. You are responsible for reviewing each AI Provider's terms regarding training data use. On the Platform, you select the AI Providers to which your queries are routed. On the Chat App, FenxLabs selects AI Providers whose terms prohibit training on API-submitted data where commercially available, but cannot guarantee that any AI Provider will not process data in ways beyond FenxLabs's control.
  • No FenxLabs retention: Conversation content passes through only for response delivery and is not retained by FenxLabs.
  • No profiling: We do not analyse your content to build profiles, target advertising, or make automated decisions about you.

For full details on how we process user content as a data processor on your behalf, please refer to Schedule A (Data Processing Agreement) of the Terms of Service.

5.4 Website Analytics Data (Website only)

On the public-facing Website (not the Platform or the Chat App), we use Google Analytics to understand how visitors interact with our marketing and documentation pages. This data is collected only with your prior consent (see Section 9 — Cookies).

When you consent to analytics cookies on the Website, Google Analytics may collect:

  • Pages visited and navigation paths
  • Approximate geographic location (country/region level, derived from anonymised IP addresses)
  • Browser type and operating system
  • Referring website
  • Session duration and interaction data

IP anonymisation is enabled, meaning your full IP address is not stored by Google Analytics.

5.5 Communication Data

When you contact us via email, support channels, or contact forms, we collect:

  • Your name and email address
  • The content of your communication
  • Any attachments you provide

5.6 Billing Data

We collect billing information necessary to process payments, including:

  • Billing name and address
  • Payment method details (processed and stored by our payment processor; we do not store full card numbers)
  • Transaction history and invoices

6. Legal Bases for Processing

We process personal data only where we have a lawful basis to do so under GDPR Article 6(1). The legal bases we rely on are:

Legal bases for processing
PurposeLegal BasisGDPR Article
Providing the Platform and delivering the servicePerformance of a contractArt. 6(1)(b)
Account creation and managementPerformance of a contractArt. 6(1)(b)
Billing and payment processingPerformance of a contractArt. 6(1)(b)
Website analytics (Google Analytics)ConsentArt. 6(1)(a)
Responding to your enquiriesLegitimate interestArt. 6(1)(f)
Compliance with legal obligations (e.g., tax, accounting)Legal obligationArt. 6(1)(c)
Service security and abuse preventionLegitimate interestArt. 6(1)(f)
Sending service-related communicationsPerformance of a contract / Legitimate interestArt. 6(1)(b) / Art. 6(1)(f)

Where we rely on legitimate interest, we have conducted balancing tests to ensure our interests do not override your rights and freedoms. You may request details of these assessments by contacting the Data Protection Contact.

Where we rely on consent (specifically for Website analytics), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. How We Use Your Personal Data

We use your personal data for the following purposes:

  1. Service delivery: To operate the Platform and the Chat App, process your requests, route them to the appropriate AI model provider, and return responses.
  2. Account management: To create and maintain your account, authenticate your identity, and manage your subscription.
  3. Billing: To process payments, issue invoices, and maintain financial records as required by law.
  4. Service communications: To send you essential service-related messages, including security notifications, billing confirmations, and material changes to the Services.
  5. Website improvement: To understand how visitors use the public Website and improve its content and usability (analytics data, with consent only).
  6. Security: To detect, prevent, and respond to security incidents, fraud, and abuse.
  7. Legal compliance: To comply with applicable laws, regulations, and legal processes.

We do not use your personal data for:

  • Advertising or ad targeting
  • Selling or renting to third parties
  • Automated decision-making with legal or similarly significant effects (see Section 13.9 for a qualification regarding payment fraud detection)
  • Building user profiles for purposes unrelated to service delivery

8. Data Sharing and Sub-Processors

8.1 Categories of Recipients

We share personal data only with the following categories of recipients, and only to the extent necessary for the purposes described in this policy:

  • AI model providers (routing infrastructure): When you submit a prompt via the Platform or the Chat App, FenxLabs's routing infrastructure transmits it to an AI Provider. On the Platform, you select and configure which AI Providers receive your queries (or use the Default Model Baseline, which you may change at any time). On the Chat App, FenxLabs determines the AI Provider selection in its sole discretion. In both cases, FenxLabs operates with a zero-access architecture: your query content passes through the routing infrastructure in encrypted form, and FenxLabs does not access, read, inspect, or decrypt it. Your relationship with each AI Provider is governed by that provider's own terms and data processing practices.
  • Payment processors: To process payments and manage subscriptions.
  • Authentication providers: To manage secure login and account authentication.
  • Hosting and infrastructure providers: To host and deliver the Services.
  • Analytics providers: Google Analytics processes Website analytics data only (not Platform data), and only where you have provided consent.

8.2 Sub-Processor List

A current list of our sub-processors, including their names, purposes, and locations, is published at fenxarc.com/sub-processors.

We will update this list at least 30 days before any new sub-processor begins processing Personal Data. If you have subscribed to sub-processor change notifications (available in your account settings or upon request), we will notify you of any changes in advance.

8.3 Safeguards

All sub-processors are bound by data processing agreements that impose obligations no less protective than those set out in Schedule A (Data Processing Agreement) of the Terms of Service.

8.4 Other Disclosures

We may disclose personal data where required by law, regulation, or legal process, or where necessary to protect the rights, property, or safety of FenxLabs, our users, or the public.

9. Cookies

9.1 Overview

The Services use a minimal number of cookies, and we distinguish clearly between the Website and the Platform.

9.2 Essential Cookies (Platform and Website)

Essential cookies are necessary for the Services to function and cannot be disabled. These include:

Essential cookies
CookiePurposeDuration
Session cookieMaintains your authenticated session on the PlatformSession
CSRF tokenProtects against cross-site request forgery attacksSession
Cookie consent preferenceRemembers your cookie consent choice on the Website12 months

These cookies are set under the legal basis of legitimate interest (Art. 6(1)(f) GDPR), as they are strictly necessary for the operation of the Services.

9.3 Analytics Cookies (Website only)

Analytics cookies are used only on the public-facing Website and are never set within the Platform or the Chat App.

Analytics cookies
CookieProviderPurposeDuration
_gaGoogle AnalyticsDistinguishes unique visitors2 years
_ga_*Google AnalyticsMaintains session state2 years

Analytics cookies are set only after you provide affirmative consent via the cookie banner. You may withdraw consent at any time by adjusting your cookie preferences.

The legal basis for processing analytics data is consent (GDPR Art. 6(1)(a)).

9.4 No Other Cookies

We do not use advertising cookies, social media tracking cookies, or any other non-essential cookies.

10. International Data Transfers

10.1 General Principle

Your personal data is primarily stored and processed within the European Economic Area (EEA). Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place as required by GDPR Chapter V.

10.2 Transfer Mechanisms

We use the following mechanisms to safeguard international transfers, depending on the recipient:

  • EU-US Data Privacy Framework (DPF): Where a sub-processor is certified under the EU-US Data Privacy Framework, we rely on that framework as the primary transfer mechanism. This applies to transfers to US-based providers that maintain active DPF certification, including Google (for Website analytics).
  • Standard Contractual Clauses (SCCs): Where a sub-processor is not covered by an adequacy decision or the DPF, we use the European Commission's Standard Contractual Clauses as the transfer mechanism. We supplement SCCs with additional technical and organisational measures where appropriate, based on transfer impact assessments.
  • Adequacy decisions: Where the European Commission has issued an adequacy decision for a recipient country, we rely on that decision.

10.3 AI Providers

When you submit a prompt via the Platform or the Chat App, your query content is transmitted to AI Providers through FenxLabs's routing infrastructure. FenxLabs does not access or retain query content; it passes through the routing infrastructure in encrypted form. The data transfer mechanisms applicable to AI Providers are listed at fenxarc.com/sub-processors. You are responsible for evaluating the data transfer practices of the AI Providers to which your queries are routed.

10.4 Your Rights Regarding Transfers

You have the right to request information about the specific safeguards applied to any transfer of your personal data outside the EEA. To make such a request, contact the Data Protection Contact at joe@fenxlabs.ai.

11. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data retention periods
Data CategoryRetention PeriodRationale
Account dataDuration of account + 30 days after deletionService delivery; grace period for account recovery
User content (unsaved)Duration of session onlyService delivery
User content (saved)Until you delete it, or account deletion + 30 daysYour choice to retain
Billing and transaction records7 years after the transactionDutch tax and accounting law (AWR)
API request metadata90 daysBilling reconciliation and dispute resolution
Error and performance logs30 daysService reliability
Website analytics data14 monthsGoogle Analytics default retention period
Communication records2 years after last communicationSupport quality and legal compliance
Cookie consent records12 monthsDemonstrating valid consent

Upon account deletion, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g., billing records).

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest
  • Access controls based on the principle of least privilege
  • Regular security assessments and vulnerability testing
  • Incident response procedures, including breach notification processes
  • Employee and contractor confidentiality obligations

For details on our security measures as they relate to data processing, see Schedule A (Data Processing Agreement) of the Terms of Service.

13. Your Rights

Under the GDPR, you have the following rights regarding your personal data. You may exercise any of these rights by contacting the Data Protection Contact at joe@fenxlabs.ai.

13.1 Right of Access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and, if so, to access that data together with information about the purposes, categories, recipients, retention periods, and safeguards applied.

13.2 Right to Rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data corrected and incomplete personal data completed.

13.3 Right to Erasure (Art. 17 GDPR)

You have the right to request the deletion of your personal data where, among other grounds, the data is no longer necessary for the purposes for which it was collected, you withdraw consent, or the data has been unlawfully processed.

13.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or where the processing is unlawful but you oppose erasure.

13.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller, where the processing is based on consent or contract and is carried out by automated means.

13.6 Right to Object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interest at any time. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

13.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on consent (e.g., Website analytics), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

13.8 Right to Lodge a Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a supervisory authority. As FenxLabs is established in the Netherlands, our lead supervisory authority is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Postbus 93374
2509 AJ Den Haag
The Netherlands
Website: autoriteitpersoonsgegevens.nl
Telephone: +31 70 888 8500

You may also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence or place of work.

13.9 Right Not to Be Subject to Automated Decision-Making (Art. 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects you.

FenxLabs does not itself engage in automated decision-making that produces legal or similarly significant effects. However, our payment processor, Stripe, uses automated fraud detection algorithms as part of its payment processing services. If Stripe's fraud detection flags a transaction, the payment may be declined or held for review. In such cases: you will be notified that the payment could not be processed; you may contact FenxLabs at contact@fenxlabs.ai or Stripe directly to request a review; and you may use an alternative payment method to complete your purchase.

13.10 Exercising Your Rights

We will respond to all legitimate requests within one month. In exceptional cases where requests are complex or numerous, we may extend this period by a further two months, in which case we will inform you of the extension within the initial one-month period.

We will not charge a fee for processing your request, except where requests are manifestly unfounded or excessive.

14. Children's Data

The Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child under 16 has provided us with personal data, please contact us at joe@fenxlabs.ai, and we will take steps to delete such data promptly.

15. Reporting of Wrongdoing

For information about how FenxLabs handles reports of suspected illegal activity, see Part 10 of the Terms of Service.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Where changes are material, we will notify you by: displaying a prominent notice on the Website or Platform; and/or sending a notification to the email address associated with your account.

Where a material change to this Privacy Policy is, in FenxLabs's reasonable assessment, disadvantageous to you as a consumer, you have the right to close your Account free of charge and receive a refund of unused Credits within 30 days of being notified of the change, in accordance with Article 19 of Directive (EU) 2019/770.

We encourage you to review this policy periodically. The “Last updated” date at the top of this policy indicates when it was most recently revised.

17. Language and Previous Versions

The business and contractual language of FenxLabs is English. The English version of this Privacy Policy is the authoritative version. Translations may be provided for convenience and accessibility. If a translated version differs from, is incomplete compared with, or could reasonably be interpreted differently from the English version, the English version will prevail to the maximum extent permitted by applicable law.

Nothing in this language provision limits any data protection right, mandatory consumer right, statutory language requirement, or other protection that cannot lawfully be excluded. FenxLabs retains dated copies of previous versions of this policy. Previous versions may be requested by contacting contact@fenxlabs.ai.

18. Contact Us

If you have any questions about this Privacy Policy, our data processing practices, or wish to exercise your rights, you may contact us at:

FenixMinds B.V. (trading as FenxLabs)
Email: contact@fenxlabs.ai
Telephone: +31 85 060 5273

Data Protection Contact:
Email: joe@fenxlabs.ai