Legal

ArgusX — Privacy Policy

Last updated: 10 May 2026

1. About This Policy

This Privacy Policy explains how Argus AI Group LLC and Argus AI Group UK Ltd (together "Argus", "we", "our", or "us") collect, use, disclose, and otherwise process personal data in connection with the ArgusX service (the "Service"), accessible at argus-x.ai.

This Policy should be read alongside our Terms and Conditions of Service (the "Terms") and, where applicable, our Data Processing Addendum ("DPA"). Capitalised terms not defined here have the meaning given in the Terms.

In short: your data stays private. We host our core infrastructure in the UK and Europe, we never sell or share information about you or how you use the Service, and our staff do not look at the content of your scans without your explicit written permission, except for the narrow technical purposes described in Section 9.

2. Who Is the Controller

The Argus entity that acts as controller (or, where applicable, business under US state privacy laws) of your personal data is determined by your location, in the same way as the contracting entity under Section 2 of the Terms:

You can contact either entity at info@argusgroup.ai.

3. Two Categories of Personal Data

The Service processes personal data in two distinct capacities, and the rules differ for each.

3.1 Customer Data (you, our user)

When you register for or use the Service, we act as controller of personal data relating to you and your account. This includes:

3.2 Subject Data (the X accounts scanned through the Service)

When you submit a query through the Service, we retrieve and process publicly available content posted to X (formerly Twitter) by the account or accounts you specify (each a "Subject"), and we generate Output classifying that content.

In respect of Subject Data, the Customer (you) is the controller and Argus acts as a processor on the Customer's behalf, processing Subject Data solely in accordance with the Customer's instructions as set out in the Terms and the DPA. The Customer is solely responsible for establishing a lawful basis for the processing, conducting any required legitimate interests assessment, data protection impact assessment, or transfer impact assessment, providing any transparency information required under Articles 13 and 14 UK GDPR / EU GDPR, and responding to Subject rights requests, as set out in Sections 9 and 13 of the Terms.

Where, by operation of law, Argus is nonetheless deemed to be a controller or joint controller in respect of any Subject Data, the lawful basis on which we rely is legitimate interests under Article 6(1)(f) UK GDPR / EU GDPR (the legitimate interest being the provision of an analytical tool to professional Customers conducting due diligence, compliance, and reputational risk activities). Where Subject Data incidentally reveals special category personal data, we rely on Article 9(2)(e) UK GDPR / EU GDPR on the basis that such data has been manifestly made public by the Subject.

4. Sources of Personal Data

We obtain personal data from:

5. Purposes of Processing

We process personal data for the following purposes:

PurposeCategories of DataLawful Basis (UK/EU)
Providing and operating the ServiceCustomer Data; Subject Data (as processor)Contract performance; legitimate interests
Account creation, authentication, and securityCustomer DataContract performance; legitimate interests (security)
Billing, payment processing, and tax complianceCustomer DataContract performance; legal obligation
Customer support (see Section 9 on access to scans)Customer DataContract performance; legitimate interests
Service improvement, debugging, and quality assuranceCustomer Data; aggregated/anonymised dataLegitimate interests
Compliance with legal and regulatory obligationsAll categoriesLegal obligation
Defence of legal claimsAll categoriesLegitimate interests
Direct marketing to existing or prospective Customers (see Section 14)Customer DataLegitimate interests or consent (depending on jurisdiction)

For US Customers, the equivalent CCPA/CPRA "business purposes" are: providing the Service, performing services on the Customer's behalf, security and fraud prevention, debugging, internal research for product improvement, and compliance with law.

6. Automated Processing and Output

The Service uses automated and machine-learning processes, including profiling within the meaning of the UK GDPR and EU GDPR, solely to classify and flag publicly available content and to generate Output for analysis by the Customer. Output is generated by automated means and does not involve human review of scan content (see Section 9).

The Service does not make any decision that produces legal effects concerning, or similarly significantly affects, any Subject within the meaning of Article 22 UK GDPR / EU GDPR. Customers are contractually prohibited under Section 8 of the Terms from using the Service or Output to make any decision that has a legal or similarly significant effect on a natural person based solely on automated processing, or for any determination governed by the U.S. Fair Credit Reporting Act or equivalent legislation in any jurisdiction.

7. Recipients and Sub-Processors — We Never Sell or Share Your Data

We never sell, rent, trade, or share personal data about our Customers or their use of the Service — including your account details, usage data, scan history, or queries — with any third party for that third party's own purposes. We also do not "share" personal data for cross-context behavioural advertising within the meaning of the CCPA/CPRA. Aggregated or anonymised data derived from use of the Service is used only internally to operate, secure, and improve the Service and is never published, sold, or disclosed to third parties.

The only recipients of personal data are the following, each bound by appropriate contractual obligations to protect the data and, in the case of sub-processors, acting solely on our documented instructions to deliver the Service:

A current list of sub-processors is available on request to info@argusgroup.ai. We will give Customers notice of any new sub-processor in accordance with the DPA.

8. Where We Store Your Data and International Transfers

UK and EU hosting. The Service's primary application and database infrastructure — including the databases in which your account data, scan results, and Output are stored — is hosted in data centres located in the United Kingdom and/or the European Economic Area.

Certain of our sub-processors listed in Section 7 are established in the United States and may process limited personal data there in the course of providing their services to us (for example, payment processing by Stripe and automated content classification via the Anthropic API).

Where we transfer personal data outside the UK or the EEA to a country that has not been the subject of an adequacy decision, we rely on appropriate safeguards, including:

You may request a copy of the relevant safeguards by emailing info@argusgroup.ai.

9. Our Access to Your Scans and Output

We treat the content of your scans as yours. Argus personnel do not access, view, or review the content of your scans, queries, or Output in the ordinary course of operating the Service.

We do not carry out any substantive or in-depth review of the content of any scan or Output unless you have given us prior explicit written permission to do so. Any such review takes place only: (a) for the purposes of helping you use the Service or troubleshooting an issue you have raised; and (b) to the extent of the permission you have given.

The only exceptions are:

For the avoidance of doubt, the automated processing that generates Output (described in Section 6) does not involve human review of scan content.

10. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

Where personal data is no longer required, we delete or anonymise it. Upon termination or expiry of your Subscription, we will, at your election, delete or return all personal data processed on your behalf within a reasonable time, unless retention is required by Applicable Law (see Section 13.10 of the Terms).

11. Security

We implement and maintain appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, alteration, disclosure, or destruction. These include encryption of data in transit and at rest, access controls and role-based authentication, logging and monitoring, regular security assessments and reviews of our security posture, and staff confidentiality and training obligations, designed to ensure a level of security appropriate to the risk. No system is completely secure, and we cannot guarantee absolute security.

12. Your Rights

12.1 Rights under UK GDPR and EU GDPR

If you are located in the UK or EEA, you have the following rights in respect of personal data we hold about you as controller:

12.2 Rights under US state privacy laws

If you are a resident of California, Colorado, Connecticut, Virginia, Texas, Utah, or another US state with a comprehensive privacy law, you have the following rights, subject to the conditions of your state's law:

To exercise any of these rights, contact us at info@argusgroup.ai. We will verify your identity before responding and will respond within the timeframes required by Applicable Law (one month under UK/EU GDPR; 45 days under CCPA/CPRA, extendable). You may use an authorised agent to submit a request on your behalf, where permitted by Applicable Law.

12.3 Requests from Subjects

If you believe you have been the subject of a scan through the Service and you wish to exercise rights in respect of Subject Data, please note that the Customer who initiated the scan is the controller of that data. Where you contact us, we will:

We may require additional information from you to verify your identity and to locate any data we hold.

13. Children

The Service is not directed to children, and we do not knowingly collect personal data from individuals under 18. Customers are contractually prohibited under Section 8 of the Terms from using the Service to investigate, profile, or generate Output relating to any individual whom they know or should reasonably know to be a minor, save in the narrow circumstances where such processing is expressly permitted by Applicable Law and supported by an appropriate lawful basis, as set out in the Terms.

If we become aware that personal data of a minor has been processed through the Service, we will take reasonable steps to delete such data as soon as practicable. If you believe a minor's data has been processed, contact us at info@argusgroup.ai.

14. Marketing, Cookies and Tracking

We send electronic marketing communications only in accordance with Applicable Law, including PECR, and we obtain consent where required. Every marketing communication includes a clear means of opting out, and we honour opt-out requests promptly.

The Service uses cookies and similar technologies as set out in our Cookie Notice, which forms part of this Policy. Where required by Applicable Law, we obtain your consent before placing non-essential cookies.

15. Changes to This Policy

We may amend this Policy from time to time. We will post the revised Policy on the Service and update the "Last updated" date. Where changes are material, we will give at least thirty (30) days' prior notice (for example by email or through the Service) before the changes take effect.

Your continued use of the Service after the effective date of any amendment constitutes acceptance of the revised Policy.

16. Contact and Complaints

Questions, requests, or complaints relating to this Policy or our processing of personal data:

Argus AI Group UK Ltd — 119 Marylebone Rd, London NW1 5PU, United Kingdom. Email: info@argusgroup.ai

Argus AI Group LLC — 2810 N Church St, Suite 311793, Wilmington, DE 19802, USA. Email: info@argusgroup.ai

UK and EEA residents may also lodge a complaint with the Information Commissioner's Office (ico.org.uk) or the supervisory authority in their member state. California residents may contact the California Privacy Protection Agency (cppa.ca.gov).

— End of Privacy Policy —