Privacy

Privacy Policy

Effective and last updated: 9 September 2026

1. What this policy covers

This policy explains how we handle personal information when you use the Arit product, connect services to Arit, visit the public Arit website or join Arit First Access communications. Product use and First Access marketing are separate: agreeing to receive First Access updates does not give us permission to use your Personal Intelligence for marketing.

Arit is provided by GlobalMind AI Ltd (company number 16658452), trading as Noventir. Its registered office is 21 Hill Street, Haverfordwest, Pembrokeshire, Wales, SA61 1QQ. In this policy, “we”, “us” and “our” mean GlobalMind AI Ltd.

Arit is currently offered under its Terms to users aged 18 or over in the United Kingdom and European Union. This policy covers both individual and business use. In most situations described here, GlobalMind AI Ltd is the controller of the personal information. Our role may differ for a business service and will be explained in the relevant commercial or data-processing terms.

2. Information Arit may handle

The information involved depends on the features you choose and the services you connect. It can include:

Your Personal Intelligence may include sensitive information if you choose to add it or ask Arit to work with it. We do not assume that one legal basis or one retention rule applies to every kind of information.

3. Why we use information

We use information where needed to:

Noventir does not sell Personal Intelligence and does not use it to build advertising or marketing profiles.

Noventir does not use your Personal Intelligence, Conversations, Documents, Projects or other owner content to train shared AI models or models for other users unless you separately and explicitly agree to that in future.

4. Our lawful bases

The lawful basis depends on what we are doing:

Some activities or sensitive categories of information may require a more specific basis or additional condition. Where that applies, we will provide appropriate information rather than treating consent as permission for everything.

5. Arit may know a lot about you. The AI model doesn’t need to.

OpenAI is the current hosted reasoning provider. Arit does not send your entire Personal Intelligence to an external AI model by default. It selects the information needed for the particular request.

Some questions can be answered using information and governed services available to Arit without involving an external AI model. When external reasoning is useful, Arit builds a bounded, request-specific context. Identifying details may be removed or pseudonymised where they are not needed, although some identifiers may remain when they are genuinely necessary for the request.

Your Memory, Projects, Notes, Conversations and accumulated history are not simply handed to an external AI provider on every request.

We do not describe this process as universally anonymous and do not claim that personal information can never reach an external AI provider.

6. Current Microsoft connection

Hosted Arit currently uses Microsoft permissions for sign-in and the authorised Microsoft 365 connection. Arit requests only the permissions needed for the capabilities enabled for that connection.

The current hosted connection can read signed-in profile information; read, list and search email; retrieve a message body when a message is opened; read or list Calendar events; and send email through a governed approval flow.

Hosted Arit does not create Microsoft mailbox drafts, create, update or delete Microsoft Calendar events, read or modify Microsoft Contacts, or retrieve email attachments. Email sending is not automatic or unrestricted: Arit prepares the proposed message within Arit and sends it only after the required approval.

Arit Contacts are separate records created or governed within Arit; Microsoft Contacts are not currently connected. Information retrieved from Microsoft does not automatically become Arit Memory or Knowledge merely because Arit reads it.

7. Google connectivity when enabled

Google V1 connectivity is approved and in implementation, but is not yet fully live. When Google connectivity is enabled, Arit will use Google user data only to provide the connected functionality requested by the user.

The approved Google scopes are:

Under these scopes, Arit cannot read or search Gmail, inspect Gmail metadata, browse the Gmail mailbox or generally modify Gmail. Arit does not create a Gmail-native draft. It may prepare email content internally, show you a preview and send the message using gmail.send only after the required governed approval.

Calendar event access is limited to what calendar.events and your Google permissions allow. Arit’s own authority controls still apply, and Calendar actions are not automatic or unrestricted.

Arit’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

8. Web research and Brave Search

Brave Search is a current supported search provider. Arit aims to send only what is needed for the search you request and does not intend to add personal context unnecessarily. A query may still contain personal or identifying information when that is genuinely needed to fulfil your explicit request.

Search queries, returned research and related provenance may be kept within Arit so that the source and context of the research remain available to you.

9. Providers and connected services

Depending on the feature enabled, Arit may use:

Other providers will be used only where they are actually enabled and appropriately disclosed. Connected providers operate under their own terms and privacy information, and their availability or changes can affect Arit.

Hosted voice is not universally enabled. Additional voice-specific privacy information may be provided when hosted voice features are enabled; we do not make a fixed promise here about raw-audio retention before those arrangements are finalised.

10. Staff access and service security

Noventir staff do not have routine access to your Personal Intelligence. Routine Admin and service tooling is designed around account, service and security metadata rather than exposing owner content.

Where necessary for a genuine support, security, suspected-misuse or legal need, exceptional access to owner content may occur only where it is lawful, specifically authorised, limited to what is needed and auditable. This does not mean routine browsing or surveillance of Personal Intelligence, and it does not claim that a particular automated “break-glass” capability already exists.

We use proportionate technical and organisational measures to protect information, but no online service can guarantee absolute security.

11. Hosting location and international processing

Where Noventir controls the hosting location, we aim to use UK or EEA infrastructure where reasonably possible. The current Azure staging architecture is in UK South, but staging should not be treated as a fully hardened production estate or as a guarantee that all processing stays in the United Kingdom.

Some connected services and external providers may process information outside the UK or EEA. Where data-protection law requires safeguards for those transfers, we will use appropriate safeguards. We do not claim that one specific transfer mechanism applies to every provider before it has been verified for that processing.

12. Cookies, Turnstile and operational records

Hosted Arit uses essential secure session cookies to keep you signed in and operate the service. The public First Access site uses Cloudflare Turnstile to protect the form from abuse; Turnstile processes browser and network signals, including the visitor IP used when its token is validated.

No first-party advertising or marketing analytics script is currently present in the inspected public-site source. That is not an absolute claim that no technical or network signals are processed by the hosting and security services involved.

Arit aims to keep operational, security and audit logging bounded and minimal. Some operational, security or audit records may contain identifiers or content needed to operate, troubleshoot or secure the service. Logs are not intended to become another copy of your Personal Intelligence, and Noventir is continuing to minimise personal-content exposure in audit and logging paths.

13. Observations, suggestions and automated decisions

Arit may use your information to generate observations, suggestions and personalised relevance intended to help you decide what deserves attention. This is a form of personalised processing, but an observation does not silently become a fact about you.

Arit does not currently make decisions about owners based solely on automated processing that produce legal or similarly significant effects.

14. How long we keep information

We use purpose-based retention rather than one invented period for every type of data. Personal Intelligence is generally kept while your account and the requested service need it. Security, audit, consent and accountability records may need to be kept longer where reasonably necessary or legally required.

Exact periods can vary by the type of information, the feature and the provider involved. Backup copies are removed through normal operational expiry rather than necessarily disappearing immediately when a live record is deleted.

First Access unsubscribe stops future updates but does not automatically erase the signup, withdrawal and consent history needed for suppression, accountability or legal evidence. Optional answers should not be retained merely because they were originally supplied; we will review and minimise what remains necessary after unsubscribe. No automated First Access purge period is currently implemented.

15. Access, correction, deletion and portability

You can ask us to access, correct, delete or restrict personal information we hold about you. You can also withdraw consent where consent is the basis for processing. Some requests currently require help from Noventir rather than a complete self-service control.

We will action requests in line with applicable law and the technical state of the service. Some limited records may remain where genuinely needed for security, legal obligations, consent or withdrawal evidence, accountability, legal claims or normal backup expiry. Deletion does not necessarily cause immediate physical removal from every backup.

We do not think your digital life should be deliberately trapped inside Arit. Available access and export scope and formats depend on current product capability. This principle is not a claim that complete account-wide export or physical erasure is already available for every data type.

16. Arit First Access communications

If you join Arit First Access, we use the information you submit to send an automated welcome email, occasional updates about Arit and invitations to relevant research or early-access opportunities. This consent is separate from use of your Personal Intelligence in the Arit product.

First Access records can include your name, email address, optional answers, campaign or source, consent version and timestamp, consent-event history, subscription status, an unsubscribe-token hash and welcome-delivery metadata.

Cloudflare hosts the public site and D1 database. Cloudflare Turnstile receives its validation token and the visitor IP needed for validation; the inspected D1 First Access schema does not store the visitor IP.

Resend delivers First Access email. The private founder notification contains the submitted name, email, campaign, optional answers and signup timestamp. The welcome email contains the recipient name and email address and an unsubscribe URL.

Unsubscribing changes the subscription status and stops future First Access updates, but it does not automatically delete the First Access record. We may retain the limited signup, suppression, withdrawal and consent evidence reasonably needed for accountability. You can separately ask us to delete or restrict your information.

We do not sell First Access information, use it to make solely automated decisions producing legal or similarly significant effects, or treat First Access consent as permission to use your Personal Intelligence for marketing.

17. Your data-protection rights

Depending on the law and circumstances, you may have rights to:

These rights do not all apply in every circumstance. We may need to verify your identity before acting on a request. To make a request, email info@noventir.com.

UK users may complain to the Information Commissioner’s Office. EU users may contact the data-protection supervisory authority in the country where they live or work. We would appreciate the opportunity to address your concern first.

18. Changes to this policy

We may update this policy as Arit develops or as legal, security, provider or operational arrangements change. We will communicate material changes appropriately and seek consent where a change requires it.

19. Contact

GlobalMind AI Ltd
Company number: 16658452
Trading as: Noventir
Registered office: 21 Hill Street, Haverfordwest, Pembrokeshire, Wales, SA61 1QQ
Email: info@noventir.com
Website: https://www.noventir.com/
Product: https://arit.noventir.com/

← Return to Arit