Privacy Policy
This Privacy Policy explains how Arkos Systems, LLC, operating under its trade name Arkos Learning Solutions (“Arkos,” “we,” “us”), handles information in connection with the Workflow application, the Nexus account portal, and related licensing services (the “Service”). It is part of, and incorporated into, our Terms of Service.
1. The core principle: your project data stays with you
Workflow is local-first. Your project content — including workspaces, workflows, flows, actions, tasks, descriptions, notes, comments, requirements, checklists, contacts and waiting-party details, attachments and documents, linked email metadata, calendar and meeting details, Microsoft Forms questions and responses, time entries, tags, analytics, status histories, cycle-time metrics, and audit history — is stored on your device and, only if you choose to enable it, in your own Microsoft 365 environment under your own account.
Arkos does not receive, collect, store, transmit, proxy, or process your project content. The Service is designed so that this information never reaches Arkos infrastructure.
2. Information Arkos does collect
To provide accounts and licensing, Arkos collects and stores only the following account and license information:
- Account identifiers: your name, email address, optional organization name, and (for administrators) a username;
- Authentication data: a securely hashed password, email-verification status, and session tokens;
- Account status and consent: approval status and your acknowledgements (e.g., the restricted-data notice and these terms);
- License data: license number, product identifier, issue/activation/expiration dates, status, and feature entitlements;
- Device activation data: a device record, the device’s generated public key, a key identifier, the application version, and the last validation timestamp;
- Service requests: renewal requests and any support tickets and messages you choose to submit;
- Optional, privacy-safe diagnostics only if you explicitly enable them (e.g., app version, activation success, update success, crash occurrence).
We do not collect Microsoft access or refresh tokens (those remain in your device Keychain), and we do not store any project-derived value in license requests, URLs, headers, telemetry, logs, or analytics.
3. How we use information
- to create and verify accounts and review applications for approval;
- to issue, activate, validate, renew, suspend, transfer, and revoke licenses and device activations;
- to deliver downloads and signed application updates;
- to respond to support requests you submit;
- to operate, secure, and improve the Service and to comply with law.
We rely on the performance of our contract with you, our legitimate interests in operating and securing the Service, your consent (where applicable), and compliance with legal obligations.
4. How we share information
We do not sell your personal information. We may share account/license information only with: service providers acting on our behalf under confidentiality obligations (e.g., hosting, email delivery); authorities when required by law or to protect our rights; and a successor in a merger, acquisition, or asset sale. We never share project content because we do not have it.
5. Cookies & local storage
The Nexus portal uses browser local storage to keep you signed in (a session token) and to remember preferences. It does not use advertising cookies or third-party trackers for the Workflow portal.
6. Data security
We apply reasonable administrative, technical, and organizational safeguards, including password hashing, encrypted transport (TLS), signed license entitlements, least-privilege access, and audit logging of administrative actions. On your device, the application stores secrets in the macOS Keychain and supports encrypted exports. No method of transmission or storage is perfectly secure, and you are responsible for safeguarding your device and your Microsoft account and for maintaining backups.
7. Data retention
We retain account and license records for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion of your account, which removes your associated account and license records from Arkos systems. Project content lives on your device and in your Microsoft environment and is controlled and deleted by you.
8. Your choices & rights
- You can view and manage your account and license in the Nexus portal and request account deletion there.
- Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object or withdraw consent. To exercise these, contact us at contact@arkossystems.com.
- Diagnostics, where offered, are off by default and require your explicit opt-in.
9. Children’s privacy
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect information from children.
10. International users
Arkos operates in the United States, and account/license information is processed there. If you access the Service from outside the United States, you consent to that processing. Additional regional disclosures (e.g., GDPR for the EU/UK, CCPA/CPRA for California) must be added by counsel before serving those regions.
11. Changes
We may update this Policy; material changes will be reflected by an updated “Effective date.” Continued use after changes take effect constitutes acceptance.
12. Contact
Arkos Systems, LLC (d/b/a Arkos Learning Solutions)
Attn: Privacy · contact@arkossystems.com
© 2026 Arkos Systems, LLC. Arkos Learning Solutions is a trade name of Arkos Systems, LLC. All rights reserved.