Effective / last updated 20 August 2026

Privacy Notice

Artnames Ltd, trading as Inficy, operates this service. This notice describes what the product actually processes, because an evidence product that is vague about its own data handling is not worth trusting.

Who we are

Inficy is a trading name of Artnames Ltd. Contact for privacy questions, access and deletion requests: contact@artnames.io. Statutory company details are published in the footer as they are confirmed. Version 2026-08-20.

Account data

Name or display name, email address, account and profile information, and workspace membership. Passwords are handled by our authentication provider and are never stored by the application.

Service data

Agents you create, workspace configuration, plan and usage information, certification credit balances and billing records where billing is enabled.

Execution data

Canonical NexArt Project Bundles exactly as your agent sealed them, plus the execution record derived from them: run identifier, title, status, model, timing, step sequence, tool activity, agent identities, handoffs, human interactions, lineage links, and the inputs and outputs your agent captured in Standard mode, together with evidence metadata such as artifact hashes and verification results.

Execution content is entirely under your control. If a value must never leave your environment, do not put it in a step summary, or use the confidential protocol. We do not mine execution content or use it to train models.

Confidential execution data

Under the confidential protocol, protected values are represented by NexArt confidential commitments. The private disclosure (opening) material remains with you as the data owner and is not sent to Inficy by default; we hold the sealed artifact and cannot reconstruct the hidden values. Confidential is not the same as anonymous, the execution, workspace and agent remain identified.

Technical data

IP address and user agent where processed by our hosting and network layer, authentication and security logs, abuse and rate-limit counters, and operational telemetry about ingestion and job processing.

Payment data

No card payment processor is enabled today. When card payments are enabled, the payment processor will handle card details directly and Inficy will not store card numbers; we will hold only the billing records needed to run the account.

Machine and agent data

You may authorise software agents to interact with Inficy through our machine interfaces. We therefore process machine credentials (stored only as hashes), registration and approval records, spending mandates you approve, and the execution activity those agents submit.

Purposes and lawful bases

This section states our current assessment. It is flagged for professional legal review before commercial launch.

  • Providing the contracted service, authentication and account management, receiving and storing execution evidence, displaying execution activity, optional certification you request, and support, performance of a contract.
  • Billing and payment where enabled, performance of a contract, and legal obligation for statutory accounting records.
  • Fraud and abuse prevention, rate limiting, platform security and operational reliability, legitimate interests in keeping a multi-tenant platform secure, available and free from abuse, balanced against the limited, mostly technical data involved.
  • Internal product milestone records used to understand whether onboarding works - legitimate interests in improving our own product. No third-party analytics, advertising or session-recording technology is used.
  • Records we are required to keep, legal obligation.

We do not rely on consent for the processing described above, so there is no consent to withdraw for it. If we later introduce processing that requires consent (for example marketing email or non-essential analytics), it will be requested separately and will be refusable without affecting the service.

Controller and processor roles

For account, billing and business administration, Artnames Ltd generally acts as controller. For execution content processed on your instructions, which may contain personal data introduced through your AI-agent workflow: Artnames Ltd may act as processor, depending on the circumstances. This allocation requires legal review and confirmation in contract.

A formal data processing agreement is not yet published. Customers who require a DPA contractually should contact contact@artnames.io before onboarding; a DPA will be linked from this trust area once executed.

Retention and deletion

Account information is retained while your account exists. Execution records and canonical artifacts are retained while the owning workspace exists: deleting an agent removes its executions and artifacts, and deleting a workspace removes the records associated with it.

Transient operational data is deleted on a fixed schedule:

  • Rate-limit counters, up to 1 day.
  • Machine idempotency keys, 7 days.
  • Operational counters, 30 days.
  • Security and agent audit records, 90 days.
  • Internal product milestone records, 180 days.

Canonical evidence is never removed by this transient cleanup. Certifications already issued remain verifiable through NexArt by design and are not recalled by deletion.

Honest gap: plans display a retention period, but automatic time-based deletion of execution evidence by plan is not implemented today, so evidence is kept while the workspace exists rather than expiring at the displayed figure. Records needed for billing, security or legal purposes may be kept for as long as those purposes require.

Service providers

Our providers are listed in full, with purposes and locations, on the subprocessors page. In summary:

  • Supabase: Managed Postgres database, authentication and object storage (European Union).
  • Cloudflare: Application hosting, edge delivery and network protection (Global edge network).
  • NexArt: Optional certification of a specific execution, on explicit request (European Union).

Nothing is submitted to the NexArt Node unless you explicitly certify a specific execution; normal recording stays inside the Inficy capture and storage path.

International transfers

Database, authentication and object storage are hosted in the European Union. Application hosting and network protection use a global edge network, so request metadata may be processed outside the UK and EEA in transit. We do not assert specific adequacy decisions or contractual safeguards until they are confirmed from the relevant provider contracts; that confirmation is an open item.

Your rights

Subject to the applicable legal basis and to any exemptions, you may request access to your personal data, correction, deletion, restriction of processing, objection to processing based on legitimate interests, and portability of data you provided under contract or consent. Where we rely on consent, you may withdraw it at any time; rights that only apply to a particular basis are limited accordingly.

Send requests to contact@artnames.io. If you are unhappy with our response, you can complain to the UK Information Commissioner's Office (ICO).

Cookies and local storage

See the cookie policy. We use only strictly necessary and preference storage, and no advertising or third-party analytics trackers.

Contact

Artnames Ltd, trading as Inficy - contact@artnames.io. This notice is not legal advice and has not yet been reviewed by professional counsel.