errandom.

ARGOS Privacy Notice

Version 1.0-beta - Effective 17 August 2026

1. Who is responsible

errandom Fischer, a sole proprietorship operated by Kenneth Fischer, Hardstrasse 20, CH-8304 Wallisellen, Switzerland, is the controller responsible for personal data processed through ARGOS.

Privacy contact: info@errandom.com

EU representative: Not appointed; the current invitation-only beta is not directed at the EU market. This must be reassessed before actively offering ARGOS to people in the EU.

Data protection officer: Not appointed.

2. Scope

This Notice applies to the ARGOS website, application, support and invitation-only beta. A connected third party processes data under its own privacy notice when it acts independently, for example Microsoft, Google, TikTok, a travel provider or a smart-home provider.

3. Data we process

Depending on the features you use, ARGOS may process:

Some of this information, particularly health data and body-progress photographs, may be sensitive personal data under Swiss law or special-category data under GDPR.

4. Sources

We receive data:

5. Why and on what basis we process data

Purpose Typical GDPR legal basis
Create and secure your account; authenticate sessions Contract; legitimate interests in security
Provide requested assistant, workspace, connector and automation features Contract
Process optional health, sensitive or provider-specific AI context Explicit consent where required; otherwise contract where legally appropriate
Personalise recommendations and maintain your chosen context Contract; consent for optional sensitive sources
Send data to the AI provider identified for the request Contract and/or consent, depending on the data, feature and jurisdiction
Operate diagnostics, prevent abuse and investigate incidents Legitimate interests; legal obligation
Respond to support and privacy requests Contract; legal obligation; legitimate interests
Improve reliability using bounded, minimised operational records Legitimate interests, balanced against user rights
Meet accounting, legal and regulatory duties Legal obligation

Under the Swiss FADP, we process personal data according to the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and security. Where we rely on consent, you may withdraw it for future processing without affecting prior lawful processing.

We do not use private account content for behavioural advertising.

6. AI processing

ARGOS is an AI system. To answer a request, it may combine your prompt with relevant profile information, connected-service content and stored records, then send the necessary context to the external AI provider shown to you.

The provider may receive sensitive data or data about other people if it appears in the context you ask ARGOS to use. Data may be processed outside Switzerland or the EEA even when ARGOS's primary application and durable storage are hosted in Switzerland.

Before an external provider is used, ARGOS identifies the provider in its legal and setup information. The current private beta uses the configured provider for the deployment. A new external provider will not be introduced without updating the relevant disclosure and obtaining consent where required.

Current and potential providers are listed in the ARGOS Subprocessor and Third-Party Service List. We configure provider services to avoid model training on private content and minimise provider retention where the contracted service permits.

7. Connected services

ARGOS accesses a connected service only after an authorisation flow or other deliberate setup. Permissions vary by connector and may include reading data or, where clearly enabled, performing an action.

Live source data may be retrieved for a request. ARGOS may also store user-created records, imports, uploads, derived summaries, connector preferences, cached results and audit information. Therefore, disconnecting a source stops future access but is not the same as deleting all related ARGOS data.

Connected providers retain their own copies under their terms. Deleting data in ARGOS does not delete the original email, file, calendar event, social post, booking, health record or device record at the provider.

8. Storage and separation

The production ARGOS application and its primary durable Azure storage are currently hosted in Switzerland North. User data is namespaced by tenant and user. Secrets and OAuth credentials are separated from portable user-content exports.

We use access controls, managed identities, encrypted transport, provider security features, secure session cookies, logging redaction and other technical and organisational measures appropriate to the beta's risks. No system can guarantee absolute security.

The AI provider and connected services may process data in other countries. See Sections 9 and 10.

9. Recipients

We may disclose personal data to:

We do not sell personal data.

10. International transfers

Recipients may process data in Switzerland, the EEA, the United Kingdom, the United States or other countries identified in the subprocessor list or connected provider's notice.

Where required, we rely on an adequacy decision, certification under an applicable data privacy framework, approved standard contractual clauses with Swiss adaptations, or another legally recognised safeguard. Where necessary, we assess supplementary technical and organisational measures.

You can request information about the applicable safeguard from info@errandom.com.

11. Retention

We retain personal data only for as long as needed for the purposes described, your account settings, security, dispute resolution and legal obligations.

Data Current private-beta rule
Account and durable user content Retained while the account remains active, until the user deletes it or the Operator closes the beta account
Uploads and workspace files Retained until user deletion or account deletion; no automatic inactivity purge is currently implemented
OAuth credentials Until disconnect, expiry, revocation or account deletion
Decision/audit records Bounded to the most recent 500 records; no separate time-based purge is currently implemented
Failure/diagnostic records Bounded to the most recent 1,000 records; no separate time-based purge is currently implemented
Support and beta feedback Retained during the private beta for issue resolution and product learning, then removed with the reporting user's account data or earlier when no longer needed
Security records Retained according to the configured Azure service and application-log settings, and longer only when needed to investigate an incident or meet a legal duty
Backups and deletion remnants May remain temporarily in access-restricted provider recovery copies and are removed through the ordinary Azure storage recovery and overwrite lifecycle
Legal/accounting records For the statutory period

Time-based retention automation is not yet implemented for all private-beta data. This Notice will be updated when those controls change.

12. Export, correction and deletion

Authenticated users can download a portable archive of durable ARGOS account content. OAuth access and refresh tokens are excluded because they are authentication secrets.

Users can also trigger an irreversible deletion of their ARGOS durable account namespace and stored connection credentials. The feature attempts to delete shared-workspace links and related user data before completing. It does not delete data independently retained by connected providers, recipients, legal archives or unexpired backups.

You may correct many records in the Service. You may also contact us to request access, correction or deletion.

13. Your rights

Depending on applicable law, you may have the right to:

We may need to verify your identity. Rights can be limited where another person's rights, legal privilege, security, fraud prevention or a legal retention duty applies.

Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.

If GDPR applies, you may also complain to the supervisory authority in your habitual residence, place of work or place of the alleged infringement.

14. Automated decisions and profiling

ARGOS creates recommendations and prioritisation based on information you provide. It is designed as decision support for the user, not to make solely automated decisions that produce legal or similarly significant effects on another person.

Do not use ARGOS as the sole basis for employment, credit, insurance, healthcare, education, housing or other consequential decisions about a person. If a future feature introduces applicable automated decision-making, we will provide specific information about its logic, significance, consequences and available human review before use.

15. Data about children and other people

ARGOS accounts are for adults aged 18 or over. Users may enter information about children or other people only where they have appropriate authority and where the processing is necessary and proportionate. Do not use ARGOS for covert monitoring or to make consequential decisions about a child.

If you believe a child's data was provided improperly, contact info@errandom.com.

16. Cookies and browser storage

ARGOS currently uses essential session cookies needed for authentication and security. Details appear in the Cookie Notice.

We will not introduce non-essential analytics, advertising or cross-site tracking cookies without updating the notice and obtaining consent where required.

17. Security incidents

If we identify a personal-data breach, we will investigate, mitigate it and notify affected people and authorities when required by applicable law. Report suspected security issues to info@errandom.com.

18. Changes

We may update this Notice when the Service or law changes. We will publish the version and effective date and provide prominent notice of material changes. Where a new purpose requires consent, we will ask before starting that processing.

19. Contact

errandom Fischer
Hardstrasse 20
CH-8304 Wallisellen, Switzerland
info@errandom.com