// LEGAL INFORMATION

Privacy policy.

This policy describes how ARQFILES collects, uses, protects and retains information related to its technical services and platform.

  1. 01.Controller identity and scope

    ARQFILES is the controller of personal data collected on this platform. This policy applies to all services, including the ECU file repository, remapping work, remote services, technical-pilot forms and payments.

  2. 02.Types of data we collect

    • Account data: name, company, email address, phone number and professional role.
    • Vehicle or ECU technical data: software or firmware identifiers, DTCs, binary maps, CAN logs and hardware versions.
    • Operational and service data: intervention history, backups, binary snapshots and signature or checksum records.
    • Payment data: processed by third parties through tokenization; we do not store card numbers on our servers.
    • Usage and telemetry data: IP address, access logs, platform activity and performance metrics.
    • Communications: emails, support tickets and technical recordings, where applicable.
  3. 03.Purposes of processing

    • To provide the platform and our remapping, calibration and file-management services.
    • To carry out technical validation, staging, rollback and audits of ECU interventions.
    • To handle pilot requests, billing and customer support.
    • To improve the service, detect fraud and protect operational security.
    • To meet legal and contractual obligations.
  4. 04.Legal basis and consent

    Processing is based on performance of the contract with the customer, explicit consent for remote services and technical tests, and compliance with applicable legal duties.

    For work that involves regulated changes, such as DPF, AdBlue or EGR OFF, we require additional consent and contractual liability clauses.

  5. 05.Minimization and anonymization

    We collect only the data strictly needed to deliver the technical service. Where possible, technical data and logs are stored in pseudonymized or aggregated form for analysis, and anonymization techniques are applied before any broader analytical use.

  6. 06.Data retention

    • Accounts and contracts: for the life of the contract plus five further years for accounting and compliance, or any longer period required by applicable law.
    • Binary backups and snapshots: as agreed in the pilot or deployment contract; two years by default unless otherwise required.
    • Operational logs and telemetry: between 90 and 365 days, depending on how critical they are for detecting anomalies, unless an audit requires a longer period.
    • When the agreed periods end, data are deleted or archived with restricted access.
  7. 07.Security and technical measures

    • Encrypted storage in repositories using AES-256 or an equivalent standard.
    • Role-based access control (RBAC) and multi-factor authentication for administrative access.
    • Signatures and checksums to detect tampering of binary files.
    • Redundancy and backups with periodic restore tests.
    • An immutable audit trail of operations: who, what and when.
    • Scheduled vulnerability assessments, code reviews and penetration tests.
  8. 08.Transfers to third parties and suppliers

    We share data only with suppliers needed to deliver the service, such as payment processors, cloud providers, hardware integrators (flashers or gateways), validation labs and telemetry providers. Those parties must sign confidentiality agreements and processing contracts that require equivalent security measures.

  9. 09.International transfers

    When data are transferred outside the country of origin, we apply appropriate safeguards, such as contractual clauses or equivalent protection standards, and we inform the data subject. For deployments with global manufacturers, we document storage locations and subprocessors.

  10. 10.Data-subject rights

    Users may exercise their rights of access, rectification, erasure, restriction, objection and portability. Requests are handled within the applicable legal time limits through the technical and privacy contact channels listed on this site.

  11. 11.Sensitive data and third-party data

    We do not request sensitive personal data. Vehicle data that could be sensitive because of their technical context are processed under stronger safeguards and only with authorization.

    If a user uploads third-party data inside a file, they confirm that they hold the corresponding authorizations.

  12. 12.Cookies and tracking technologies

    On each visit we process the IP address and browser, without tracking cookies, to record country, device type and the page viewed. We also count WhatsApp clicks and form submissions. We do not identify the individual and we do not retain the IP address. Users may manage or reject optional third-party analytics cookies from the available settings once those cookies are published.

  13. 13.Security incidents and breach notification

    We maintain an incident-response plan. If a breach compromises personal data, we will notify the competent authorities and affected individuals on the terms and timelines required by applicable law. The notice will describe the nature and scope of the incident, the measures taken and recommendations to reduce risk.

  14. 14.Evidence retention and expert support

    Where forensic support or expert evidence is needed for technical or legal disputes, we may retain technical evidence such as logs, snapshots and signatures under restricted custody. That evidence is disclosed only pursuant to a court order or a contractual agreement.

  15. 15.Consent for remote services and tests

    For remote reads or writes via OBD or a customer-controlled flasher, we will request express consent. It will cover a description of the process and its risks, confirmation that a backup has been made, and acceptance of the limitations and shared responsibility during the pilot.

  16. 16.Subcontracting and subprocessors

    General subprocessor categories include cloud services, payments, CDNs and support tools. We will give notice of material changes and publish subprocessors on a dedicated page where appropriate.

  17. 17.Third-party links and liability

    The platform may contain links to external tools or resources, including flashing hardware and software. We are not responsible for data processing carried out by those third parties and recommend reviewing their privacy policies.

  18. 18.Changes to this privacy policy

    We will announce material changes through a notice on the platform and, where required, we will ask again for consent to new processing activities or purposes.

  19. 19.Contact and data protection

    Privacy questions and requests to exercise rights may be submitted through the email address, phone number or contact form published below.