Legal · Privacy
Privacy Policy
ArcMedium.io is committed to protecting your personal data. This policy explains what we collect, why, and what rights you have.
1. Who We Are
Arcadia, trading as ArcMedium, is the data controller within the meaning of the General Data Protection Regulation (GDPR / AVG).
KvK 91300339 · btw-id NL004035204B37
Contact: [email protected] · +31 6 4221 6520
2. What Data We Collect
When you fill in the survey on this site: the answers you give, including anything you type into the free-text box. Since the survey asks for your email address only at the end, your answers are stored before you have given us any contact detail — and if you never give one, they stay without one. We also record which page you started from, the country inferred from a Cloudflare header (your IP address is never stored), and whether you were on a phone, tablet or desktop.
If you then ask us to send you the result: your email address, and — if you fill them in — your name, company name and phone number.
A random session and device identifier, generated in your browser, so we can tell one visit apart from another without knowing who you are. These exist only if you allowed analytics; if you declined, no such identifier is created and none is stored with your enquiry.
If you reached us through a campaign link, the campaign labels in that link — the source, medium, campaign, content and term values in the web address. They tell us which post or advert brought you here. They describe the link, not you, they are read from the address bar and never stored on your device, and we never keep them on their own — only alongside the answers or contact details described above, including a survey you started and never finished.
Self-hosted analytics (only if you consent): page visited, country, device type, browser language, colour scheme preference, and referring URL.
Google Analytics 4 and LinkedIn Insight Tag (only if you consent): standard analytics and advertising cookies used to measure site traffic and campaign performance. See our Cookie Policy for the full list.
Cloudflare Web Analytics (always on): cookieless, aggregated traffic metrics. No personal data or cookies involved.
3. Purpose and Legal Basis
The details you enter in the contact funnel: used to answer you, to prepare the free audit you asked for, and to work out which of our services fits — Article 6(1)(b) GDPR, because these are steps taken at your request before a possible agreement.
The campaign labels from the link you arrived on: kept with your enquiry so we can tell which of our own posts and adverts actually reach people, and stop paying for the ones that do not — Article 6(1)(f) GDPR, our legitimate interest in knowing whether our marketing works. They are read from the web address, nothing is stored on your device for this, and they are deleted together with the answers or enquiry they belong to.
Self-hosted analytics, Google Analytics 4, and LinkedIn Insight Tag: used to understand site usage and measure campaign performance — Article 6(1)(a) GDPR, your consent, given through the cookie banner. You can withdraw it at any time (see section 8).
Cloudflare Web Analytics: cookieless aggregate metrics — Article 6(1)(f) GDPR, legitimate interest; no personal data is processed.
4. Retention Period
Details left in the survey are kept for as long as we are in contact about your request, and for a maximum of 12 months after our last contact. After that they are deleted automatically.
Survey answers that never reached an email address — someone who started and did not finish — are deleted after 60 days.
The internal message we send ourselves the moment your enquiry arrives stays in our mailbox and falls under that mailbox's own retention, not under the automatic deletion above. If you ask us to delete your data, we delete that message too.
Analytics records are kept for a maximum of 24 months.
If we go on to work together, the contract and the records tax law requires us to keep fall under a separate statutory retention period of seven years.
5. Who Else Processes Your Data
We do not sell your data and we do not share it for anyone else's marketing. We do use suppliers who process it on our behalf:
— Hetzner (hosting): runs the website and the database the details you leave are stored in. The server is in Germany (Hetzner, Nuremberg), and that data does not leave the EU.
— Cloudflare (network and security): sits in front of the site, so every request passes through it. Cloudflare is established in the United States; its data processing addendum applies to our account and relies on the European Commission's Standard Contractual Clauses, and Cloudflare is separately certified under the EU–U.S. Data Privacy Framework.
— Cal.com (appointment booking): if you book the free audit, the name and email you enter on the booking page go to Cal.com. Cal.com is established in the United States.
— Google Workspace (our mailbox): as soon as you complete the form or the survey, we send ourselves a message containing what you entered, so that your enquiry does not sit unseen. That message goes to [email protected] — our own mailbox, the same place you reach if you email us directly. Google's data processing terms rely on the European Commission's Standard Contractual Clauses, and Google is separately certified under the EU–U.S. Data Privacy Framework.
— Google (Analytics 4) and LinkedIn (Insight Tag): only after you consent, and only for the category you consented to. Google's data processing terms rely on the European Commission's Standard Contractual Clauses, and Google is separately certified under the EU–U.S. Data Privacy Framework. LinkedIn's data processing agreement relies on the Standard Contractual Clauses.
Where a supplier is established outside the EU we name the mechanism the transfer rests on rather than leaving it general. The details you leave in the contact funnel are stored on our own server in Germany. One copy travels as a message to our own Google Workspace mailbox, as described above — beyond that they go nowhere, and we put them nowhere else.
6. Security
We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. Access to the stored details is limited to those inside ArcMedium who need it to answer you.
7. Your Rights
Under the GDPR you have the following rights:
— Right of access: you may request what data we hold about you.
— Right to rectification: you may have inaccurate data corrected.
— Right to erasure: you may request deletion of your data.
— Right to restriction of processing.
— Right to object to processing.
— Right to data portability.
To exercise any of these rights, email us at [email protected]. We will respond within one month.
8. Withdrawing Your Consent
Consent for analytics can be withdrawn at any time, and it is as easy to withdraw as it was to give: use the cookie settings link in the footer of any page to reopen the banner and change your choice. Withdrawing does not affect anything that happened while your consent was still in place.
Withdrawing analytics consent does not delete details you entered in the contact funnel — those rest on a different legal basis. To have those removed, email [email protected].
9. Filing a Complaint
If you believe we are not handling your personal data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
10. Changes to This Policy
We may update this privacy policy from time to time. The latest version is always available on this page. Last updated: September 2026.