How ArkForge Trust Layer collects, processes, and protects your data.
Last updated: March 5, 2026
The data controller for the Trust Layer service is:
ArkForge
SIRET: 93208689500013
Email: contact@arkforge.fr
Website: arkforge.fr
Trust Layer is designed to minimize personal data collection. The data we process includes:
When creating an account (Free or Pro plan), the User provides an email address. This address is used for:
The email address is not shared with third parties for commercial purposes.
Each User is issued an API key to authenticate requests. API keys are stored in an encrypted database (AES-128 symmetric encryption, Fernet) and used solely for access control. They are not shared with third parties.
X-Agent-Identity header, if provided. This is typically a software identifier, not a personal name.Important: Trust Layer proofs contain only cryptographic hashes (SHA-256) of payloads, not the payloads themselves. No personal data from the attested transactions is stored in the proofs.
When an API request includes an X-Idempotency-Key header (opt-in), the full service response is temporarily cached on disk to prevent duplicate processing. This cache:
The idempotency cache does not contain personal data beyond what the client itself chose to include in the original request.
IP addresses are collected in server access logs (nginx) for security monitoring and abuse prevention. IP addresses are retained for 7 days and then automatically deleted. They are not included in proofs and are not shared with third parties.
We use Plausible Analytics, a privacy-focused, cookie-free analytics service hosted in the EU. Plausible does not collect personal data, does not use cookies, and is fully GDPR-compliant. No consent banner is required. Plausible analytics are only used on the arkforge.fr website; the Trust Layer API does not include any tracking or analytics.
If you contact us via email, we process your email address and message content to respond to your inquiry. This data is retained for the duration necessary to handle your request.
| Data | Legal basis | GDPR Article |
|---|---|---|
| Registration email | Contract performance | Art. 6(1)(b) |
| API keys | Contract performance | Art. 6(1)(b) |
| SHA-256 hashes, timestamps, proof data | Contract performance | Art. 6(1)(b) |
| IP addresses (server logs) | Legitimate interest (security) | Art. 6(1)(f) |
| Website analytics (Plausible) | Legitimate interest (improvement) | Art. 6(1)(f) |
| Contact emails | Consent | Art. 6(1)(a) |
| Stripe payment data | Contract + legal obligation (tax) | Art. 6(1)(b), 6(1)(c) |
Your data may be shared with the following third-party processors, strictly for the purposes described:
No data is sold, rented, or shared with third parties for advertising or marketing purposes.
ArkForge infrastructure is hosted in France (European Union) by OVH SAS.
The following third-party services may process data outside the EU:
| Data | Retention period |
|---|---|
| Proofs (hashes, timestamps, signatures) | 7 years from creation (commercial dispute resolution) |
| Idempotency cache (opt-in) | 24 hours, then automatically and permanently deleted |
| Registration email | While account is active; deleted within 12 months of closure |
| API keys | While account is active; revoked upon closure |
| IP addresses (nginx server logs) | 7 days |
| Stripe transaction data | Per Stripe's policies and tax obligations (up to 10 years) |
| Contact emails | Duration necessary to respond; deleted within 12 months |
| Website analytics (Plausible) | Aggregated, anonymous data only |
Users are encouraged to download and store their proofs locally before the retention period expires.
Under the GDPR, you have the following rights:
To exercise any of these rights, contact us at contact@arkforge.fr. We will respond within 30 days as required by the GDPR.
The arkforge.fr website does not use cookies. Plausible Analytics is cookie-free. The Trust Layer API does not set any cookies. No consent banner is required.
We implement appropriate technical and organizational measures to protect your data, including:
/v1/pubkey)Trust Layer is a business-to-business (B2B) service intended for use by software developers and organizations. We do not knowingly collect personal data from children under 16 years of age.
Trust Layer does not use automated decision-making or profiling as defined by Article 22 of the GDPR.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the French data protection authority:
CNIL (Commission Nationale de l'Informatique et des Libertés)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
www.cnil.fr
We may update this privacy policy from time to time. Material changes will be posted on this page with an updated date and notified via email to registered users. Continued use of the service after changes constitutes acceptance of the updated policy.
For any privacy-related questions or requests: