Last updated 30 August 2026
Privacy Notice
What personal data Architera holds about dealership users, prospects and dealership customers, why we hold it, who else sees it, and what you can ask us to do.
Who we are
Architera FZ L.L.C is the company behind Architera. We are a free zone company registered with the Expo City Dubai Authority under business licence and registration number 00374.
Our registered address is Unit No: EC-SD-201-24, 14 Mangrove Quarter B, Expo City Dubai, Dubai, United Arab Emirates.
For anything in this notice, including a request about your own data, write to accounts@architera.ai.
Scope
This notice covers the personal data Architera handles in three situations: when you visit our website or contact us, when you use an Architera product as a dealership user, and when a dealership uses Architera to talk to its own customers.
It explains what we hold, why we hold it, who else sees it, how long we keep it, and what you can ask us to do.
Is Architera a data controller or a data processor?
We are both, in different situations, and the difference decides who you ask when you want something done.
We are a data controller for our own business. That covers the account data of dealership users who sign in to Architera, the enquiries people send us through our website, the business contacts we research for our own sales, and the traffic records from our website. In these cases we decide why the data is held and how it is used, so you can bring a request straight to us.
We are a data processor for the customers of a dealership. When a dealership uses Architera to message the people who buy or service cars with it, that dealership decides what happens to its customers' data, and we act only on its documented instructions under a data processing agreement. If you are a customer of a dealership and you want your data changed or deleted, the dealership is the one who decides, and we carry out what it instructs. You can still write to us and we will pass your request to the dealership and tell you we have done so.
The personal data we process
Architera handles personal data about three groups of people: dealership users, who sign in to Architera to do their job; prospects, the business contacts we hold for our own sales; and dealership customers, the people a dealership talks to through Architera.
| Category | Personal information examples |
|---|---|
| Dealership user account details | Name, work email address, job role and permissions inside the workspace, the dealership and workspace the user belongs to, sign in times, and preferences |
| Prospect business contact details | Name, job title, dealership or company, work email address, work phone number, the source the detail came from, and notes about the company |
| Enquiry content | The message you send us through a form or by email, what you asked about, and the product you were looking at |
| Dealership customer contact details | Name, phone number, email address, and the messaging identifier for the channel used |
| Message content | The messages, attachments and images sent and received between a dealership and its customer, delivery and read status, timestamps, and the language used |
| Vehicle and enquiry context | The vehicles a customer asked about, quotes and configurations discussed, appointment and test drive details, and any vehicle a customer already owns |
| Consent and contact preferences | Records of consent given or withdrawn, per person, per channel and per purpose, and opt out records |
| Website traffic data | A random first party visitor identifier stored in your browser, a random identifier for the current browser tab, the Architera page path, whether it is a product page, and the time of the page view |
| Technical and connection data | IP address, browser and device type, requested pages, timestamps, and diagnostic logs our servers need to deliver and protect the site |
| Security, support and audit records | Support conversations, audit entries recording who changed what and when, and security event records |
| Billing and contract records | The dealership's contract, order form, invoices, and the named contacts for billing |
We do not ask for, and do not want, special category data such as health, biometric, political or religious information. If a customer volunteers something of that kind in a message, it sits inside the message content the dealership controls, and the dealership decides what happens to it.
Where the data comes from
Most of it comes from you. Dealership users give us their details when an account is created for them. Prospects and enquirers give us their details when they contact us, and we also research business contact details from public or licensed sources. Dealership customers give their details to the dealership, in the conversation itself.
The rest is generated as the service runs: message delivery records from the messaging platform carrying the conversation, traffic and diagnostic data from our own website, and audit records written by the product as people use it.
Why we process it, and our legal bases
We process personal data to run and secure the service, to answer enquiries and arrange demonstrations, to give a dealership the workflows and safeguards it has switched on, to send and receive messages on a dealership's behalf, to provide support, to bill for the service, and to meet our legal obligations.
Where data protection law asks us to name a legal basis, we rely on the following. We rely on the contract with a dealership for the account data of its users and for running the service. We rely on our legitimate interests in developing our business for prospect records and website traffic measurement, balanced against the interests of the people concerned, and we stop on request. We rely on consent where consent is what the law requires, in particular for dealer initiated marketing messages to a customer, which do not go out without a current, explicit, purpose matched consent record. We rely on legal obligation for tax, accounting and regulatory records.
For dealership customer data we act on the dealership's instructions, and the dealership is responsible for having a legal basis for what it asks us to do.
We do not sell personal data.
Automated decision-making and AI
Where a reply to a customer is written with the help of AI, it is identified as such. Architera uses AI to draft replies, summaries and suggestions for dealership staff. Dealership staff can review, change or withhold any AI-drafted message, and a dealership can require human approval before anything is sent. We do not make decisions that have a legal or similarly significant effect on a person solely by automated means. We do not use message content to train general-purpose AI models.
The channels we cover
Architera works across messaging and engagement channels, including WhatsApp, web chat, email, SMS and voice, together with any further messaging channels a dealership connects as we make them available. The same rules in this notice apply whichever channel carries the conversation.
Where a dealership connects a WhatsApp Business account, the messages travel over a platform operated by Meta, and Meta handles them as the operator of that platform.
International transfers
Customer data is stored and processed in the European Union, in Frankfurt, on infrastructure operated by our hosting provider.
Architera's own operations are in the United Arab Emirates, so our team accesses the service from the UAE.
Some of the platform providers who carry messages, and some AI service providers, operate globally and process data in the country where their own service runs.
Where personal data moves between countries, we rely on the safeguards available to us for that transfer, which include the transfer terms in our contracts with providers, standard contractual clauses where a provider offers them, and, where applicable, an adequacy decision or an equivalent recognised mechanism.
Security
Data is encrypted in transit and at rest. Each dealership's data is separated from every other dealership's data at the database level, so one workspace cannot read another's. Access is through named individual accounts with least privilege, and changes to data are written to an append only audit record. We keep security and dependency risk under a documented review process and we test the isolation controls.
No system is completely secure. If a breach affects your personal data and the law requires us to tell you, we will.
How long we keep it
| Data | How long |
|---|---|
| Prospect records | Anonymized after 24 months with no contact. The period runs from the most recent enquiry, reply, call, meeting, or other contact. Anonymization clears the personal fields and keeps the non personal parts needed for counting |
| Website traffic records | Deleted after 90 days |
| Dealership user account data | Kept for the term of the dealership's contract, then deleted or anonymized when it is no longer needed |
| Dealership customer data | Kept as the dealership instructs us under the data processing agreement, and deleted or returned when it instructs us or when the contract ends |
| Billing, tax and audit records | Kept for the period the law requires |
Limited security, audit, billing, backup, dispute and legal records may be kept beyond these periods where we need them to protect the service, establish or defend a legal claim, or comply with the law. Those records are restricted to that purpose and deleted or anonymized when the period ends.
Website analytics and email tracking
We count website traffic using a random first party visitor identifier stored in your browser and a random identifier for the current tab. We record the Architera page path, whether it is a product page, and the time of the page view. The traffic record does not contain an email address, IP address, cookie, fingerprint, full referrer, query string, or form content. Raw traffic records are deleted after 90 days.
When you submit a demo or contact request, we attach a bounded journey from the current browser tab to that request. It may include the page paths you viewed, visible active time on each page, page view counts, the labels and counts of links or buttons you used, and campaign fields beginning with utm_. We do not attach form field contents, other query string values, referrers, external destinations, cookies, fingerprints, or browsing from other tabs. If you do not submit a request, this journey is not saved to our enquiry records.
If you follow a unique Architera link we sent you, or you submit a demo form, we may associate that first party visitor identifier with your contact record. Later visits from the same browser can then appear in our sales activity, so we can understand your product interest and follow up usefully. This works only on Architera's own website. We do not follow you across other websites, and clearing this site's browser storage resets the identifier.
Emails we send to prospects from our own sales team may include a small image that tells us whether the email was opened. We use this only to follow up usefully, and you can stop it by blocking images in your email client.
Marketing to businesses
We may contact people in a business capacity about Architera by email, phone or LinkedIn. You can opt out at any time by replying, by using the unsubscribe link in an email, or by writing to accounts@architera.ai. When you opt out, we suppress your address from future research, import and contact.
Cookies and browser storage
Our website does not use advertising or third-party tracking cookies. It uses first-party browser storage for the visitor and tab identifiers described above and for essential site functions. Signed-in Architera products use strictly necessary cookies to keep you signed in and to protect your session.
Children
Architera is a business service. Our website and products are not directed at anyone under 18, and we do not knowingly collect personal data from children.
Links to other sites
Our website may link to other sites. Their privacy practices are their own, and this notice does not cover them.
Your rights and how to exercise them
Depending on where you live, you may have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent you have given. Withdrawing consent does not undo what we did before you withdrew it.
To exercise any of these, email accounts@architera.ai. We may need to confirm your identity first, and we will not disclose or delete one person's data at another person's request. We acknowledge a request within 5 business days and complete a verified request within 30 calendar days.
If you are a customer of a dealership, the dealership decides on your request. Contact the dealership you spoke with. If you cannot reach it, write to us and we will forward your request to the dealership and tell you we have done so.
Our Data Deletion Instructions explain the deletion route in full.
Complaints
If you are unhappy with how we have handled your personal data, tell us first at accounts@architera.ai and we will try to put it right.
You can also complain to the data protection authority in your country, or to the UAE Data Office where UAE law applies to your data.
Changes to this notice
We update this notice when our products, providers or processing change. The date at the top of the page shows when this version was last revised. If a change materially affects how we use your data, we will take reasonable steps to tell you.
Contact
Architera FZ L.L.C
Unit No: EC-SD-201-24, 14 Mangrove Quarter B
Expo City Dubai, Dubai, United Arab Emirates
accounts@architera.ai
Dealership customers should contact the dealership they dealt with in the first instance.