ARCNM

Privacy Policy

How rattle mng GmbH processes personal data when you use ARCNM, under the GDPR and BDSG. EU-hosted; no tracking or marketing cookies. The binding version is the German original.

Last updated: 17 August 2026.

We, rattle mng GmbH, provider of the ARCNM platform,
Langgasse 21
88662 Überlingen, Germany,
represented by the management: Dr. Alexander Menges,
email: [email protected], phone: +49 151 21603565,
take the protection of your personal data very seriously. Below we inform you – in a comprehensible but legally binding form – about the nature, scope and purpose of the collection, processing and use of your personal data in connection with the use of the ARCNM platform and our website. In doing so we observe all applicable data-protection provisions, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

B2B notice: In accordance with Section 1 of the Terms, ARCNM is directed exclusively at entrepreneurs within the meaning of § 14 BGB. Personal data is processed in particular in connection with the business use by customers’ employees and agents. The platform is not directed at children; we do not knowingly process personal data of persons under 18 years of age.

1. Controller within the meaning of the GDPR

The controller for the data processing on the website and for the Provider’s own processing within the platform is the rattle mng GmbH named above. Where the Customer uses the platform to process personal data of third parties, the Customer is the controller within the meaning of Art. 4 No. 7 GDPR; rattle mng GmbH then acts as processor under Art. 28 GDPR. The details follow from the data processing agreement (DPA) integrated into Annex 1 of the Terms.

2. Principles of data processing

Scope of processing: We collect and process personal data only to the extent required for the operation of the website and the SaaS platform and for the provision of our services.

Legal bases: Depending on the purpose, we base the processing on one of the following legal bases:

Storage period and deletion: Personal data is deleted or blocked as soon as the purpose of storage ceases to apply and no statutory retention periods remain. Where such periods apply, we limit the processing to the necessary minimum. The specific storage periods for the individual processing activities are set out below in each case.

3. Visiting the website and log data (server log files)

When you access our website, information is automatically collected that your browser transmits to our server (so-called server log files). These include:

For requests via the REST API, the following data is additionally logged: request ID, HTTP status code, API key prefix (not the full key) and rate-limit counters. This data is used exclusively for technical provision, system security (e.g. defence against attacks), error analysis, enforcement of rate limits and abuse detection. Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in secure and trouble-free operation) and Art. 6 (1)(c) GDPR in conjunction with Art. 32 GDPR (obligation to ensure the security of processing). Storage period: standard log files are kept for a maximum of 30 days; security-relevant events (failed authentication, access denials, IP rejections) for up to 12 months, in order to be able to trace attack patterns.

4. Cookies and local storage

On our website and in the application we use exclusively technically necessary cookies and comparable storage mechanisms (local storage) that are indispensable for the operation of the website and the provision of our services. These include in particular:

These items of storage are technically necessary to provide the functions expressly requested by the user and are based on § 25 (2) No. 2 TDDDG (formerly TTDSG) and Art. 6 (1)(b) GDPR (performance of a contract) or (f) (legitimate interest in stable operation of the application). No consent is required in this respect.

No tracking or marketing cookies (binding commitment): We use no analytics, tracking or marketing cookies, embed no advertising pixels (e.g. Facebook Pixel, LinkedIn Insight Tag, Google Analytics) and carry out no profiling. We undertake contractually not to introduce any such technologies without first updating this Privacy Policy and – where required – without first obtaining your express consent under Art. 6 (1)(a) GDPR and § 25 (1) TDDDG.

5. Registration, user account and login data

When you create a user account on ARCNM, we process the data requested in the registration form. The mandatory details are:

We process this data to enable you to use the platform and your account (creating and managing part data, calculations, user administration within the company, login). Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) and, as regards the documented entrepreneur status, Art. 6 (1)(f) GDPR (legitimate interest in being able to evidence the B2B relationship under Section 1 of the Terms). Storage period: for the duration of the contractual relationship; after the end of the contract in accordance with Section 5 of the Terms (30-day export transition period, then deletion). Statutory retention obligations: Where data is contained in invoices, vouchers or business letters, the commercial and tax retention periods apply – in particular 10 years for accounting and invoice documents (§ 257 (4) HGB, § 147 (3) AO, GoBD) and 6 years for other business correspondence. During this time the processing remains limited to the statutory minimum (Art. 17 (3)(b) GDPR).

5d. Sign-in via external identity providers (OAuth / single sign-on)

Where activated, instead of the classic email/password sign-in you can sign in via the “Continue with Google” or “Continue with GitHub” buttons. This function relies on the OAuth 2.0 / OpenID Connect procedure of the respective identity provider.

Process: By clicking an OAuth button you are redirected to the sign-in page of the chosen provider. There the authentication takes place exclusively at the respective provider; your password is not transmitted to ARCNM. After successful sign-in we receive from the provider an identity assertion (ID token) and the profile information required to create the account. By default these are:

Recipients of the data: By clicking an OAuth button, connection and profile data is necessarily transmitted to the respective identity provider:

Legal basis: Art. 6 (1)(b) GDPR (initiation or performance of the usage contract through authentication) for the processing in the platform; vis-à-vis the identity provider, the provider-side profile release is regularly based on your consent there (Art. 6 (1)(a) GDPR), which you can withdraw at any time via the security/connection settings of your provider account (effect for the future).

Storage period: The link between your ARCNM account and the external identity provider (provider, provider-side user ID, email) is kept for the duration of the contractual relationship and deleted together with the account. You can dissolve this link at any time on request via [email protected], without your ARCNM account ending (you can then sign in again by email/password).

Note on activation: The OAuth buttons appear only if the corresponding credentials are configured on the server side. In deployments without OAuth configuration, no data is transmitted to Google/GitHub.

5a. API access and API keys

Within the user account you can create API keys for programmatic access. The following data is processed when creating and managing them:

Legal basis: Art. 6 (1)(b) GDPR (performance of a contract – API keys are technically necessary to enable the contractually agreed programmatic access). Storage period: for the duration of the contractual relationship; revoked or deleted keys are kept in audit logs in accordance with the periods stated below.

5b. API access logs (audit logging)

For each request via the REST API, a structured access log (audit log) is created. The following is recorded:

Security-relevant events are logged separately: failed authentication attempts (HTTP 401), access denials (HTTP 403), rate-limit exceedances (HTTP 429) and IP rejections due to configured allow-lists.

Purpose: IT security, abuse and attack detection, error analysis and fulfilment of the obligation to take appropriate technical and organisational measures under Art. 32 GDPR. Legal basis: Art. 6 (1)(f) GDPR (legitimate interest) in conjunction with Art. 6 (1)(c) GDPR (legal obligation under Art. 32 GDPR). Storage period: standard access logs 30 days; security-relevant events 12 months. Right to object: Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to this processing based on legitimate interest. We point out that we generally have compelling legitimate grounds for the processing (IT security, statutory security obligations).

5c. Webhook data transmission

Where the Customer (controller) configures webhook endpoints in its account management, the platform automatically sends event notifications via HTTPS POST to the configured endpoints. This takes place exclusively on the Customer’s instruction, the Customer determining which event types are transmitted to which endpoint.

Categories of data in webhook payloads: depending on the event type, these may be master and transaction data of the platform (e.g. part references, calculation results, user IDs, quote status). Specific personal data of third parties is transmitted only to the extent the Customer has actively entered it into the platform.

Security: Each webhook delivery is provided with an HMAC-SHA256 signature per the Standard Webhooks scheme (HTTP header webhook-signature: v1,<base64(HMAC-SHA256(id.timestamp.body))>), which allows the recipient to verify the authenticity and integrity of the message. Delivery is made exclusively to HTTPS-secured endpoints.

Responsibility: The webhook configuration constitutes an instruction from the Customer (controller) to us (processor). Upon delivery to the Customer’s endpoint, further processing of the transmitted data is the Customer’s responsibility. Legal basis: Art. 6 (1)(b) GDPR (performance of a contract – webhooks are part of the agreed platform functionality).

5e. Error reports (Report a problem)

Enabled users can submit error reports via the platform (“Report a problem”). In doing so we process the description you enter, the affected page (route), the time, app version and browser identifier (user agent), a technical correlation ID, and a limited excerpt of the browser console that is automatically scrubbed of sensitive patterns. Screenshots are processed only if you actively attach them to your report (up to three); they are stored tenant-separated and encrypted. Please take care not to include personal or confidential content that is not needed. From linked records, at most a narrowly limited technical extract is included (indicators and status – no geometry, prices or free text); original files you uploaded (e.g. CAD files) are not included in the error report. Purpose: analysing and fixing the reported issue, and follow-up questions and status updates on your report. Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) and Art. 6 (1)(f) GDPR (legitimate interest in the stability and security of the platform). Retention: error reports including screenshots are deleted after 90 days; the link to your account is severed when the account is deleted. Internal access to error reports is restricted by role and logged.

Recipients and third-country transfer: so that a reported issue can be fixed, we open an internal ticket for it in our development tracker GitHub (GitHub, Inc., USA – a Microsoft company). Transferred are your description, the scrubbed console excerpt, the affected page, the time, app version and browser identifier, the narrowly limited technical extract from linked records, and – if we asked you a follow-up question – that question and your answer. Screenshots are not transferred; the ticket only states how many exist, and the images themselves stay in the EU. The transfer relies on an adequacy decision (EU-US Data Privacy Framework), with EU standard contractual clauses in addition. Please do not include other people's personal data in your description where it is not needed to fix the issue.

6. Contacting us

When you contact us (e.g. by email to [email protected]), we process the data you provide (e.g. your email address, name and the content of your message) in order to handle and respond to your enquiry. Depending on the content of the matter, we base this processing on Art. 6 (1)(b) GDPR (pre-contractual measures or performance of a contract) or Art. 6 (1)(f) GDPR (legitimate interest in the efficient handling of enquiries). Your details are used exclusively to handle your matter and are deleted as soon as the enquiry has been dealt with and no statutory retention obligations conflict.

7. Disclosure of personal data to third parties and services used

Your personal data is not transmitted to third parties without your express consent – unless one of the following grounds applies:

Where we use external service providers, they are obliged exclusively on the basis of a data processing agreement under Art. 28 GDPR and may process the data only on our behalf and on our instructions.

Categories of recipients and sub-processor directory

We select all service providers carefully and ensure an appropriate level of data protection. By category, we currently use: hosting, payment processing, transactional email delivery, AI-assisted drawing analysis (an open-weights model at a processor inside the EU; no fallback to a model outside the EU), object storage and edge infrastructure (CDN/DNS/TLS), web-font delivery, and – only where you use it – single sign-on. The current, complete list of the individual sub-processors – with name, location, purpose, the data processed and the applicable Art. 46/45 GDPR transfer safeguard – is published in our sub-processor directory; that directory also constitutes Annex 1.2 of the Terms. We announce changes with 30 days' notice under Annex 1 § 6 of the Terms.

These third-party providers receive only the data required to perform their respective service. The individual sub-processors, with name, location, the data processed and the applicable legal basis, are set out in the sub-processor directory.

AI drawing analysis: within the EU only. The AI-assisted analysis of your drawings is performed by a processor inside the EU (open-weights model, Paris data centre, France). No third-country transfer arises for it. There is no fallback to a model outside the EU: if the EU path fails, the analysis runs purely deterministically and rule-based, without any AI model. The details and current status are set out in the sub-processor directory.

Third-country transfers: Where data is transferred to countries outside the EU/EEA – in particular for object-storage and edge infrastructure and, where applicable, for payment processing and single sign-on – we ensure an adequate level of data protection through appropriate safeguards under Art. 46 GDPR (as a rule, EU Standard Contractual Clauses); where an adequacy decision of the EU Commission under Art. 45 GDPR applies (e.g. the EU-US Data Privacy Framework), we rely on it. For every US transfer we have carried out a transfer impact assessment (TIA) in line with the CJEU's Schrems II case law and implemented supplementary technical measures (transport and content encryption, data minimisation, pseudonymisation). A copy of the appropriate safeguards (in particular the EU Standard Contractual Clauses) is available on request at [email protected] (Art. 13 (1)(f) GDPR). The AI providers we engage do not use the transmitted content to train their models under the applicable processing terms.

We use no advertising pixels, no CAPTCHA services, no web analytics, no geolocation services and no embedded third-party content (e.g. videos, maps, calendars). Web fonts are self-hosted exclusively (same origin, with no call to an external CDN); no direct call to external CDNs such as fonts.googleapis.com, fonts.gstatic.com or to advertising/analytics networks takes place. Should we wish to use further services in future, we would amend this Privacy Policy in advance and – where required – obtain your consent.

"Book a call" (scheduling): The "Book a call" button is a plain web link (not embedded content) to a Google scheduling page (calendar.app.google). Our application transmits no data to Google. Only if you actively click the link and book a slot on Google's page do you enter the details requested there (name, email, preferred time) directly with Google; the booking lands in our Google Calendar. This transfer to Google (USA), initiated by you, is covered by the Art. 46/45 GDPR safeguards; see the sub-processor directory.

No use of your data for training (binding commitment): We do not at any time use your uploaded content, the results generated from it, or your corrections to train, fine-tune or evaluate our own or any third party's AI models – neither in identifiable, nor in anonymised, nor in aggregated form, and not across customers. To improve, calibrate and validate our models we use exclusively our own, synthetic or publicly available data. We process your content – including any personal data it contains that you knowingly provide (e.g. a name in a drawing's title block) – solely to deliver the service you requested (Art. 6 (1)(b) GDPR). The AI providers we engage likewise do not use the transmitted content to train their models under the applicable processing terms. Purely technical operational and security metrics unrelated to your content (e.g. error/response rates) are unaffected. The details are governed by sections 10a and 10b of the Terms.

8. Data security

We employ extensive technical and organisational measures to protect your personal data against accidental or unlawful manipulation, loss, destruction and unauthorised access. The measures are summarised in Annex 1.3 (TOMs) of the Terms and include, among others:

Despite all measures, no method of data transmission or storage is absolutely secure. Should security-relevant incidents affecting your data come to our knowledge (e.g. a data-protection incident/breach), we will inform you and the competent supervisory authorities in accordance with the statutory requirements (Art. 33, 34 GDPR). This also includes the compromise of API keys to the extent personal data is affected.

8a. Support access by the Provider (view-only inspection)

To handle support requests, to analyse and remedy faults and to investigate security incidents, individual employees of the Provider who are bound to confidentiality may, on a case-by-case basis, view content of your account. This access is strictly read-only in a technically enforced read-only mode, requires additional authentication and approval by a second authorised person (four-eyes principle), expires automatically after a short time and is logged including start and end; we retain the access logs for accountability purposes. Legal basis: Art. 6 (1)(b) GDPR (performance of a contract – support and fault remediation); where we act as a processor for you, the access takes place as processing on documented instructions under Art. 28 GDPR (Annex 1 of the Terms). The content viewed is not used for any other purpose – in particular not for training AI models (Section 10b of the Terms).

9. No automated decision-making in individual cases

There is no solely automated decision-making, including profiling, within the meaning of Art. 22 (1) GDPR that produces legal effects concerning you or similarly significantly affects you. The calculations, price recommendations and plausibility checks generated in ARCNM serve solely as a decision aid; responsibility for the decision and its legal effect always remains with the using company or the persons acting for it.

Where AI models (see Section 7 and the sub-processor directory) are used to produce these decision aids, this is expressly not a conclusive automated decision within the meaning of Art. 22 GDPR. The output of the AI models is a non-binding proposal which a human processor reviews, approves or rejects before any further use. A decision based solely on the AI output with legal effect on a data subject does not take place in ARCNM.

10. Obligation to provide data

The provision of the data required for the performance of the contract (in particular email address, name, company name and – for paid plans – billing data) is neither legally nor contractually mandatory; however, it is necessary for the conclusion of the contract within the meaning of Art. 13 (2)(e) GDPR. If you do not provide this data, we cannot set up an account and you cannot use the platform. Other details (e.g. additional profile information, a tax ID outside of invoicing) are voluntary.

11. Your rights as a data subject

As a person affected by the data processing, you have the following rights, provided the statutory conditions are met:

To exercise your rights you can contact us informally – e.g. by email – at [email protected]. We will review your request and act on it in accordance with the statutory requirements. Where appropriate, we will request additional information to ensure that the information is provided to the correct person (proof of identity).

Manifestly unfounded or excessive requests: In the case of manifestly unfounded or – in particular in the case of frequent repetition – excessive requests, we reserve the right under Art. 12 (5) GDPR to charge a reasonable fee on the basis of the administrative costs incurred or to refuse to act on the request. We bear the burden of demonstrating the manifestly unfounded or excessive character.

Note on reporting unlawful content: You can report suspected unlawful content made available via ARCNM to [email protected] (Art. 16 DSA).

12. Right to lodge a complaint with a supervisory authority

Without prejudice to other remedies, you have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR). In Baden-Württemberg (the registered office of our company) the competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart (www.baden-wuerttemberg.datenschutz.de). The right to complain exists independently of any other remedy.

13. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time in order to adapt it to new legal requirements or changed services. The respective current version is published in the same place on our website. We will notify you of material changes (in particular new processing purposes or sub-processors) in a suitable manner (e.g. by email or as a notice in the account).

14. Contact

If you have any questions or concerns about data protection, you can contact us at any time – please use the contact details given above (see Controller).

Last updated: 17 August 2026. The German version (/de/privacy) is authoritative.