arc is operated by Quantini OÜ, a company registered in Estonia (Registry Code: 17114373). As an EU-based Data Controller, we are fully committed to compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This document outlines how we process personal data, the safeguards we implement, and your rights as a data subject when using our managed Actual Budget hosting services.
Data Controller
Company Details
Name: Quantini OÜ
Registry Code: 17114373
Jurisdiction: Republic of Estonia, European Union
Address: Tallinn, Estonia
Data Protection Contact
Email: privacy@arc.moi
Support: connect@arc.moi
For GDPR-related inquiries, data subject requests, or complaints, please contact us at the email addresses above.
1.Legal Basis for Processing
We process personal data under the following legal bases as defined in Article 6 of the GDPR:
Contract Performance (Art. 6(1)(b))
Processing necessary to provide you with arc services, including account creation, managed instance provisioning, and customer support.
Legitimate Interests (Art. 6(1)(f))
Processing for fraud prevention, security monitoring, and service improvement, where our interests do not override your fundamental rights.
Consent (Art. 6(1)(a))
Where you have given explicit consent, such as subscribing to marketing communications. You may withdraw consent at any time.
Legal Obligation (Art. 6(1)(c))
Processing required to comply with applicable laws, such as tax regulations and anti-money laundering requirements.
2.Categories of Personal Data
We categorize the data we process as follows:
| Data Category | Examples | GDPR Classification | Our Role |
|---|---|---|---|
| Authentication Data | Email, Apple ID, Google ID | PII | Controller |
| Instance Identifier | Unique instance URL | Pseudonymous | Controller |
| Budget Data | Transactions, categories, accounts | User Content (E2EE) | Processor |
| Technical Data | IP address, device info, logs | Operational | Controller |
End-to-End Encryption (E2EE)
Your budget data is encrypted on your device before transmission. We cannot access, read, or process your financial information. This constitutes a high-level "Technical Measure" under GDPR Article 32, significantly reducing liability in case of a data breach.
3.Sub-Processors
We use the following third-party sub-processors to deliver our services. Each sub-processor has been vetted for GDPR compliance and appropriate data processing agreements are in place.
Google Cloud Platform (GCP)
United States & European UnionPurpose: Infrastructure & Instance Hosting
Safeguards: EU-US Data Privacy Framework certified. Data Processing Addendum in place.
Convex
United StatesPurpose: Database & Authentication Services
Safeguards: SOC 2 Type II certified. Standard Contractual Clauses (SCCs) in place.
Resend
United StatesPurpose: Transactional Email Delivery
Safeguards: Data Processing Agreement in place. Minimal data retention.
Google Gemini API
United StatesPurpose: AI Transaction Categorization
Safeguards: Only generic transaction descriptions sent. No personal identifiers, account numbers, or user information transmitted. EU-US DPF certified.
Local LLM Development: We are actively working on local LLM support to enable fully on-device AI processing, ensuring your data never leaves your device for categorization features.
4.International Data Transfers
As an Estonian (EU) company, GDPR applies to all data we process, regardless of user location. When data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
EU-US Data Privacy Framework (DPF)
Google is certified under the DPF, allowing lawful data transfers from the EU to US servers.
Standard Contractual Clauses (SCCs)
Where DPF is not applicable, we rely on EU-approved SCCs to ensure adequate protection.
Data Residency Options
For privacy-conscious users, we offer the option to host your Actual Budget instance in the European Union:
- Default: US region (us-central1) for optimal global performance
- EU Option: European region (europe-west1) available upon request
Contact connect@arc.moi to request EU-based data residency for your instance.
5.Your Rights Under GDPR
As a data subject, you have the following rights under the General Data Protection Regulation. To exercise any of these rights, please contact us at privacy@arc.moi.
Right of Access (Art. 15)
Request a copy of the personal data we hold about you and information about how it is processed.
Right to Rectification (Art. 16)
Request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Art. 17)
Request deletion of your personal data ('right to be forgotten') under certain circumstances.
Right to Restriction (Art. 18)
Request restriction of processing while we verify accuracy or assess objections.
Right to Portability (Art. 20)
Receive your personal data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling.
Response Time: We will respond to your request within 30 days. If the request is complex, we may extend this by an additional 60 days, in which case we will notify you of the extension.
6.Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period | Deletion Trigger |
|---|---|---|
| Account Data | Duration of account + 30 days | Account deletion request |
| Instance Data | Duration of subscription + 7 days | Subscription cancellation |
| Budget Data (E2EE) | Until instance deletion | Instance destruction |
| Technical Logs | 90 days | Automatic rotation |
| Financial Records | 7 years (legal requirement) | Statutory period expiry |
Complete Deletion: When you request account deletion, we perform a hard delete of all associated data. There are no "soft deletes" or retained backups beyond the stated periods. Your Docker container and all attached volumes are permanently destroyed.
7.Security Measures
In accordance with GDPR Article 32, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
End-to-End Encryption
Budget data encrypted before leaving your device using AES-256
Encryption at Rest
All stored data encrypted using Google-managed encryption keys
Encryption in Transit
TLS 1.3 for all data transmission between services
Access Controls
Role-based access with principle of least privilege
Instance Isolation
Each user's instance runs in isolated containers
Regular Audits
Periodic security assessments and vulnerability scanning
8.Data Breach Procedures
In the event of a personal data breach, we follow strict procedures in accordance with GDPR Articles 33 and 34:
Detection & Assessment
Immediate assessment of the breach scope, affected data, and potential impact.
Authority Notification
Report to the Estonian Data Protection Inspectorate (AKI) within 72 hours if required.
User Notification
Direct notification to affected users without undue delay if there is high risk to rights and freedoms.
Remediation
Implementation of measures to mitigate harm and prevent recurrence.
E2EE Protection: Due to our end-to-end encryption architecture, even in the unlikely event of a breach, your budget data would be cryptographically protected and unusable to attackers.
9.Cookies & Tracking
We use minimal cookies necessary for the operation of our services:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management | Session / 30 days |
| Preferences | Remember user settings | 1 year |
| Campaign measurement | Website visit reporting for paid campaigns, without budget data, transaction data, account balances, receipts, emails, phone numbers, or advanced matching identifiers. | Set by advertising platform |
We do not use campaign measurement for financial profiling: We do not sell your financial data, share your budget data with advertisers, or use your transactions for targeted advertising.
10.Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
11.Changes to This Policy
We may update this GDPR & Data Protection page from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on this page and, where appropriate, by email notification. The "Last updated" date at the top of this page indicates when this policy was last revised.
12.Contact Us
For any questions regarding this GDPR policy, to exercise your data subject rights, or to report a data protection concern:
Quantini OÜ
Registry Code: 17114373
Tallinn, Estonia
Data Protection: privacy@arc.moi
General Support: connect@arc.moi