Privacy Policy
Arete is a digital studio. We build and operate our own companies, and we partner with clients on digital products, brand, and growth. This policy explains what information we process in the course of that work, why, and the choices you have.
Information we process
- Enquiries you send us — the name, email, inquiry type, and message submitted through our contact form or sent to us by email.
- Client, partner, and supplier contacts — the business contact details and correspondence needed to scope, run, and invoice an engagement.
- Applications — anything you choose to tell us when you apply to work with us.
- Site usage — basic, aggregated information about how this website is used, to keep it working and improve it.
How we use it
We use this information to reply to you, to deliver and administer engagements, to meet our legal and accounting obligations, and to run our own business. We do not sell your data, and we do not use enquiry data for unrelated marketing.
Data we handle on behalf of clients
When an engagement involves us processing personal data that belongs to a client — inside their product, their systems, or their marketing — we act as a processor on that client's instructions, under the terms of the engagement agreement and a data processing addendum where one applies. The client remains the controller of that data and their own privacy notice governs it.
Sharing
We share information only with service providers that help us operate (for example hosting, email delivery, and accounting), where required by law, or with your instruction. We ask those providers to protect it on terms no weaker than these.
Retention
We keep enquiry and engagement records for as long as needed for the purpose they were collected and to meet legal obligations, then delete or anonymise them. You can ask us to delete correspondence sooner.
Your rights
Depending on your region, you may have rights to access, correct, delete, or port your data, and to object to certain processing. Email privacy@arete.so and we'll respond within 30 days.
Security
We limit access to the people who need it, use encrypted transport and storage for the systems we control, and review access regularly. Contact us for our Data Processing Addendum or our current security posture.
