Last updated: August 18, 2026
1. The short version
Arkonyk's public sites are static pages with a small, single-purpose backend for forms. We do not
process card payments, hold cardholder data, or operate user accounts on arkonyk.com. The personal
data we handle is what you choose to send us — a contact form, a report download, a benchmark
run, a subscription — plus standard website analytics described in our
privacy policy.
2. Architecture
- arkonyk.com is a static site — no database, no server-side sessions, no
login. Static architecture keeps the attack surface deliberately small.
- Form submissions go to a single-purpose API we operate, which validates the input, relays it
by email, and records it in our CRM. Nothing else runs there.
- All traffic is served over TLS (HTTPS). Our email domain enforces SPF, DKIM and a DMARC
quarantine policy.
3. What we collect, and how long we keep it
- Enquiries and leads: the details you submit (name, email, company, message or
benchmark answers). Kept while relevant to a business relationship; deleted on request.
- Analytics: aggregated usage data with IP anonymization, no advertising
signals, 14-month retention. Visitors in the EEA, UK and Switzerland see a consent banner and are
not tracked without opting in. We honour the Global Privacy Control signal.
- What we never collect on these sites: card numbers, transaction data,
passwords, or government identifiers.
4. Sub-processors
These providers process data on our behalf in the operation of arkonyk.com and whobilled.me:
- GitHub (Microsoft) — static site hosting, US.
- Vercel — form and API infrastructure, US.
- Railway — application hosting for whobilled.me, US.
- Resend — transactional email delivery, US.
- Google (Workspace & Analytics) — business email and website
analytics, US.
- Attio — customer relationship management, US/EU.
- Apollo.io — company-level website visitor identification, US.
- RB2B — person-level visitor identification, US traffic only, US.
- GoDaddy — domain registration and DNS, US.
We review this list when providers change and update this page accordingly.
5. Practices
- Access to production systems and mailboxes is restricted to Arkonyk personnel with
multi-factor authentication.
- API keys are stored in provider secret managers, scoped to least privilege, and rotated when
personnel or providers change.
- Form endpoints validate input and screen abuse (honeypots, disposable-address checks), and
only serve our own domains.
- We keep an independent audit log of every lead released or email sent, so we can answer
“what happened to my data” precisely.
6. Reporting a vulnerability
If you believe you have found a security issue on any Arkonyk property, email
info@arkonyk.com with “Security” in the subject
line. We read every report, we will not take legal action against good-faith research, and we ask
that you give us a reasonable window to fix an issue before public disclosure.
7. Data requests
To access, correct, or delete personal data we hold about you, email
privacy@arkonyk.com. Details of your rights are in our
privacy policy.