GDPR Compliance

GDPR & Data Protection

Last updated: January 27, 2026

arc is operated by Quantini OÜ, a company registered in Estonia (Registry Code: 17114373). As an EU-based Data Controller, we are fully committed to compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

This document outlines how we process personal data, the safeguards we implement, and your rights as a data subject when using our managed Actual Budget hosting services.

Data Controller

Company Details

Name: Quantini OÜ

Registry Code: 17114373

Jurisdiction: Republic of Estonia, European Union

Address: Tallinn, Estonia

Data Protection Contact

Email: privacy@arc.moi

Support: connect@arc.moi

For GDPR-related inquiries, data subject requests, or complaints, please contact us at the email addresses above.

1.Legal Basis for Processing

We process personal data under the following legal bases as defined in Article 6 of the GDPR:

Contract Performance (Art. 6(1)(b))

Processing necessary to provide you with arc services, including account creation, managed instance provisioning, and customer support.

Legitimate Interests (Art. 6(1)(f))

Processing for fraud prevention, security monitoring, and service improvement, where our interests do not override your fundamental rights.

Consent (Art. 6(1)(a))

Where you have given explicit consent, such as subscribing to marketing communications. You may withdraw consent at any time.

Legal Obligation (Art. 6(1)(c))

Processing required to comply with applicable laws, such as tax regulations and anti-money laundering requirements.

2.Categories of Personal Data

We categorize the data we process as follows:

Data CategoryExamplesGDPR ClassificationOur Role
Authentication DataEmail, Apple ID, Google IDPIIController
Instance IdentifierUnique instance URLPseudonymousController
Budget DataTransactions, categories, accountsUser Content (E2EE)Processor
Technical DataIP address, device info, logsOperationalController

End-to-End Encryption (E2EE)

Your budget data is encrypted on your device before transmission. We cannot access, read, or process your financial information. This constitutes a high-level "Technical Measure" under GDPR Article 32, significantly reducing liability in case of a data breach.

3.Sub-Processors

We use the following third-party sub-processors to deliver our services. Each sub-processor has been vetted for GDPR compliance and appropriate data processing agreements are in place.

Google Cloud Platform (GCP)

United States & European Union

Purpose: Infrastructure & Instance Hosting

Safeguards: EU-US Data Privacy Framework certified. Data Processing Addendum in place.

Convex

United States

Purpose: Database & Authentication Services

Safeguards: SOC 2 Type II certified. Standard Contractual Clauses (SCCs) in place.

Resend

United States

Purpose: Transactional Email Delivery

Safeguards: Data Processing Agreement in place. Minimal data retention.

Google Gemini API

United States

Purpose: AI Transaction Categorization

Safeguards: Only generic transaction descriptions sent. No personal identifiers, account numbers, or user information transmitted. EU-US DPF certified.

Local LLM Development: We are actively working on local LLM support to enable fully on-device AI processing, ensuring your data never leaves your device for categorization features.

4.International Data Transfers

As an Estonian (EU) company, GDPR applies to all data we process, regardless of user location. When data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

EU-US Data Privacy Framework (DPF)

Google is certified under the DPF, allowing lawful data transfers from the EU to US servers.

Standard Contractual Clauses (SCCs)

Where DPF is not applicable, we rely on EU-approved SCCs to ensure adequate protection.

Data Residency Options

For privacy-conscious users, we offer the option to host your Actual Budget instance in the European Union:

  • Default: US region (us-central1) for optimal global performance
  • EU Option: European region (europe-west1) available upon request

Contact connect@arc.moi to request EU-based data residency for your instance.

5.Your Rights Under GDPR

As a data subject, you have the following rights under the General Data Protection Regulation. To exercise any of these rights, please contact us at privacy@arc.moi.

Right of Access (Art. 15)

Request a copy of the personal data we hold about you and information about how it is processed.

Right to Rectification (Art. 16)

Request correction of inaccurate personal data or completion of incomplete data.

Right to Erasure (Art. 17)

Request deletion of your personal data ('right to be forgotten') under certain circumstances.

Right to Restriction (Art. 18)

Request restriction of processing while we verify accuracy or assess objections.

Right to Portability (Art. 20)

Receive your personal data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling.

Response Time: We will respond to your request within 30 days. If the request is complex, we may extend this by an additional 60 days, in which case we will notify you of the extension.

6.Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data TypeRetention PeriodDeletion Trigger
Account DataDuration of account + 30 daysAccount deletion request
Instance DataDuration of subscription + 7 daysSubscription cancellation
Budget Data (E2EE)Until instance deletionInstance destruction
Technical Logs90 daysAutomatic rotation
Financial Records7 years (legal requirement)Statutory period expiry

Complete Deletion: When you request account deletion, we perform a hard delete of all associated data. There are no "soft deletes" or retained backups beyond the stated periods. Your Docker container and all attached volumes are permanently destroyed.

7.Security Measures

In accordance with GDPR Article 32, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

End-to-End Encryption

Budget data encrypted before leaving your device using AES-256

Encryption at Rest

All stored data encrypted using Google-managed encryption keys

Encryption in Transit

TLS 1.3 for all data transmission between services

Access Controls

Role-based access with principle of least privilege

Instance Isolation

Each user's instance runs in isolated containers

Regular Audits

Periodic security assessments and vulnerability scanning

8.Data Breach Procedures

In the event of a personal data breach, we follow strict procedures in accordance with GDPR Articles 33 and 34:

1

Detection & Assessment

Immediate assessment of the breach scope, affected data, and potential impact.

2

Authority Notification

Report to the Estonian Data Protection Inspectorate (AKI) within 72 hours if required.

3

User Notification

Direct notification to affected users without undue delay if there is high risk to rights and freedoms.

4

Remediation

Implementation of measures to mitigate harm and prevent recurrence.

E2EE Protection: Due to our end-to-end encryption architecture, even in the unlikely event of a breach, your budget data would be cryptographically protected and unusable to attackers.

9.Cookies & Tracking

We use minimal cookies necessary for the operation of our services:

Cookie TypePurposeDuration
EssentialAuthentication, session managementSession / 30 days
PreferencesRemember user settings1 year
Campaign measurementWebsite visit reporting for paid campaigns, without budget data, transaction data, account balances, receipts, emails, phone numbers, or advanced matching identifiers.Set by advertising platform

We do not use campaign measurement for financial profiling: We do not sell your financial data, share your budget data with advertisers, or use your transactions for targeted advertising.

10.Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)

Address: Tatari 39, 10134 Tallinn, Estonia

Phone: +372 627 4135

Email: info@aki.ee

Website: www.aki.ee

11.Changes to This Policy

We may update this GDPR & Data Protection page from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on this page and, where appropriate, by email notification. The "Last updated" date at the top of this page indicates when this policy was last revised.

12.Contact Us

For any questions regarding this GDPR policy, to exercise your data subject rights, or to report a data protection concern:

Quantini OÜ

Registry Code: 17114373

Tallinn, Estonia

Data Protection: privacy@arc.moi

General Support: connect@arc.moi