ARGOS Privacy Notice
Version
1.0-beta- Effective17 August 2026
1. Who is responsible
errandom Fischer, a sole proprietorship operated by Kenneth Fischer, Hardstrasse 20, CH-8304 Wallisellen, Switzerland, is the controller responsible for personal data processed through ARGOS.
Privacy contact: info@errandom.com
EU representative: Not appointed; the current invitation-only beta is not directed at the EU market. This must be reassessed before actively offering ARGOS to people in the EU.
Data protection officer: Not appointed.
2. Scope
This Notice applies to the ARGOS website, application, support and invitation-only beta. A connected third party processes data under its own privacy notice when it acts independently, for example Microsoft, Google, TikTok, a travel provider or a smart-home provider.
3. Data we process
Depending on the features you use, ARGOS may process:
- Account and identity data: name, email address, external identity subject, tenant, role, invitation and authentication/session information.
- Profile and preference data: priorities, principles, relationships, communication preferences, objectives, routines and personal context.
- Requests and generated content: prompts, conversations, drafts, summaries, recommendations, decisions, schedules and AI-generated output.
- Communications and calendar data: message metadata and content, contacts, attendees, events, locations, attachments and related context from connected accounts.
- Files and media: uploads, OneDrive references, documents, images, video metadata, extracted text and user-created workspace projections.
- Career data: employers, roles, applications, documents, communications, evidence dates, interview details and career objectives.
- Health and wellness data: fitness, activity, heart-rate, weight, nutrition, hydration, wellness goals and related notes when you enable those features. For consenting adults, this may also include optional body-progress photographs, submitted body measurements and AI-generated visual body-composition observations. These estimates are not medical diagnosis or attractiveness ratings.
- Travel and location data: home or approximate location, itineraries, bookings, destinations, transport searches and travel preferences.
- Household and device data: household membership, chores, energy data, smart-home device status and authorised device actions.
- Social-media data: strategy, platforms, handles, drafts, schedules, performance information and publishing preferences.
- Third-party personal data: information about family members, colleagues, contacts, event attendees and other people contained in data you provide or connect.
- Technical and security data: IP address, request time, browser information, session and security events, errors, diagnostics, feature use and bounded audit records.
- Support and feedback data: issue reports, messages, screenshots, severity, diagnostics you choose to submit and follow-up communications.
- Connection credentials: OAuth access and refresh tokens and related connection metadata. These are stored separately as secrets and are excluded from portable account exports.
Some of this information, particularly health data and body-progress photographs, may be sensitive personal data under Swiss law or special-category data under GDPR.
4. Sources
We receive data:
- directly from you;
- from services you deliberately connect and authorise;
- from other users who share a permitted household or collaboration feature with you;
- automatically from your browser, device and use of the Service; and
- from generated or inferred records created from the information above.
5. Why and on what basis we process data
| Purpose | Typical GDPR legal basis |
|---|---|
| Create and secure your account; authenticate sessions | Contract; legitimate interests in security |
| Provide requested assistant, workspace, connector and automation features | Contract |
| Process optional health, sensitive or provider-specific AI context | Explicit consent where required; otherwise contract where legally appropriate |
| Personalise recommendations and maintain your chosen context | Contract; consent for optional sensitive sources |
| Send data to the AI provider identified for the request | Contract and/or consent, depending on the data, feature and jurisdiction |
| Operate diagnostics, prevent abuse and investigate incidents | Legitimate interests; legal obligation |
| Respond to support and privacy requests | Contract; legal obligation; legitimate interests |
| Improve reliability using bounded, minimised operational records | Legitimate interests, balanced against user rights |
| Meet accounting, legal and regulatory duties | Legal obligation |
Under the Swiss FADP, we process personal data according to the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and security. Where we rely on consent, you may withdraw it for future processing without affecting prior lawful processing.
We do not use private account content for behavioural advertising.
6. AI processing
ARGOS is an AI system. To answer a request, it may combine your prompt with relevant profile information, connected-service content and stored records, then send the necessary context to the external AI provider shown to you.
The provider may receive sensitive data or data about other people if it appears in the context you ask ARGOS to use. Data may be processed outside Switzerland or the EEA even when ARGOS's primary application and durable storage are hosted in Switzerland.
Before an external provider is used, ARGOS identifies the provider in its legal and setup information. The current private beta uses the configured provider for the deployment. A new external provider will not be introduced without updating the relevant disclosure and obtaining consent where required.
Current and potential providers are listed in the ARGOS Subprocessor and Third-Party Service List. We configure provider services to avoid model training on private content and minimise provider retention where the contracted service permits.
7. Connected services
ARGOS accesses a connected service only after an authorisation flow or other deliberate setup. Permissions vary by connector and may include reading data or, where clearly enabled, performing an action.
Live source data may be retrieved for a request. ARGOS may also store user-created records, imports, uploads, derived summaries, connector preferences, cached results and audit information. Therefore, disconnecting a source stops future access but is not the same as deleting all related ARGOS data.
Connected providers retain their own copies under their terms. Deleting data in ARGOS does not delete the original email, file, calendar event, social post, booking, health record or device record at the provider.
8. Storage and separation
The production ARGOS application and its primary durable Azure storage are currently hosted in Switzerland North. User data is namespaced by tenant and user. Secrets and OAuth credentials are separated from portable user-content exports.
We use access controls, managed identities, encrypted transport, provider security features, secure session cookies, logging redaction and other technical and organisational measures appropriate to the beta's risks. No system can guarantee absolute security.
The AI provider and connected services may process data in other countries. See Sections 9 and 10.
9. Recipients
We may disclose personal data to:
- cloud hosting, storage, identity, security and operational service providers;
- the external AI provider identified for the request;
- a connected service when necessary to carry out your instruction;
- professional advisers, auditors, insurers and authorities where legally necessary;
- a successor in a merger, reorganisation or transfer of the Service, subject to applicable safeguards; and
- another person only when you direct or authorise the sharing.
We do not sell personal data.
10. International transfers
Recipients may process data in Switzerland, the EEA, the United Kingdom, the United States or other countries identified in the subprocessor list or connected provider's notice.
Where required, we rely on an adequacy decision, certification under an applicable data privacy framework, approved standard contractual clauses with Swiss adaptations, or another legally recognised safeguard. Where necessary, we assess supplementary technical and organisational measures.
You can request information about the applicable safeguard from
info@errandom.com.
11. Retention
We retain personal data only for as long as needed for the purposes described, your account settings, security, dispute resolution and legal obligations.
| Data | Current private-beta rule |
|---|---|
| Account and durable user content | Retained while the account remains active, until the user deletes it or the Operator closes the beta account |
| Uploads and workspace files | Retained until user deletion or account deletion; no automatic inactivity purge is currently implemented |
| OAuth credentials | Until disconnect, expiry, revocation or account deletion |
| Decision/audit records | Bounded to the most recent 500 records; no separate time-based purge is currently implemented |
| Failure/diagnostic records | Bounded to the most recent 1,000 records; no separate time-based purge is currently implemented |
| Support and beta feedback | Retained during the private beta for issue resolution and product learning, then removed with the reporting user's account data or earlier when no longer needed |
| Security records | Retained according to the configured Azure service and application-log settings, and longer only when needed to investigate an incident or meet a legal duty |
| Backups and deletion remnants | May remain temporarily in access-restricted provider recovery copies and are removed through the ordinary Azure storage recovery and overwrite lifecycle |
| Legal/accounting records | For the statutory period |
Time-based retention automation is not yet implemented for all private-beta data. This Notice will be updated when those controls change.
12. Export, correction and deletion
Authenticated users can download a portable archive of durable ARGOS account content. OAuth access and refresh tokens are excluded because they are authentication secrets.
Users can also trigger an irreversible deletion of their ARGOS durable account namespace and stored connection credentials. The feature attempts to delete shared-workspace links and related user data before completing. It does not delete data independently retained by connected providers, recipients, legal archives or unexpired backups.
You may correct many records in the Service. You may also contact us to request access, correction or deletion.
13. Your rights
Depending on applicable law, you may have the right to:
- receive information about our processing and access your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- receive data you provided in a portable format;
- object to processing based on legitimate interests;
- withdraw consent for future processing;
- request human review of an applicable solely automated individual decision;
- complain to a competent supervisory authority; and
- obtain information about international-transfer safeguards.
We may need to verify your identity. Rights can be limited where another person's rights, legal privilege, security, fraud prevention or a legal retention duty applies.
Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
If GDPR applies, you may also complain to the supervisory authority in your habitual residence, place of work or place of the alleged infringement.
14. Automated decisions and profiling
ARGOS creates recommendations and prioritisation based on information you provide. It is designed as decision support for the user, not to make solely automated decisions that produce legal or similarly significant effects on another person.
Do not use ARGOS as the sole basis for employment, credit, insurance, healthcare, education, housing or other consequential decisions about a person. If a future feature introduces applicable automated decision-making, we will provide specific information about its logic, significance, consequences and available human review before use.
15. Data about children and other people
ARGOS accounts are for adults aged 18 or over. Users may enter information about children or other people only where they have appropriate authority and where the processing is necessary and proportionate. Do not use ARGOS for covert monitoring or to make consequential decisions about a child.
If you believe a child's data was provided improperly, contact
info@errandom.com.
16. Cookies and browser storage
ARGOS currently uses essential session cookies needed for authentication and security. Details appear in the Cookie Notice.
We will not introduce non-essential analytics, advertising or cross-site tracking cookies without updating the notice and obtaining consent where required.
17. Security incidents
If we identify a personal-data breach, we will investigate, mitigate it and notify
affected people and authorities when required by applicable law. Report suspected
security issues to info@errandom.com.
18. Changes
We may update this Notice when the Service or law changes. We will publish the version and effective date and provide prominent notice of material changes. Where a new purpose requires consent, we will ask before starting that processing.
19. Contact
errandom Fischer
Hardstrasse 20
CH-8304 Wallisellen, Switzerland
info@errandom.com