Legal

Privacy Policy

Last updated: 15 August 2026

This policy explains how Sovereign Arc Software Ltd collects, processes, stores and protects personal data across our website and all platforms operating under our corporate umbrella.

1. Data Controller

Sovereign Arc Software Ltd is the data controller for information collected through this website and is a registered Private Limited Company in England and Wales (Company Registration No. 17401334), registered with the Information Commissioner's Office (ICO).

Sovereign Arc Software Ltd acts as the master data controller for all underlying applications, platforms and CRMs operated under its corporate umbrella, including:

  • MedMonarch AI
  • RevMonarch™

2. Information We Collect

We collect only the data required to operate, support and bill our platforms:

  • Contact information: full name, business name, email address, telephone number and the content of enquiries submitted through our forms.
  • Billing data: subscription plan, billing address and payment status. Card details are captured and stored solely by our PCI-DSS compliant payment processor, Stripe — Sovereign Arc Software Ltd never stores full card numbers.
  • MedMonarch AI: appointment dates, recall and reminder schedules, patient contact identifiers and communication logs.
  • RevMonarch™: vehicle registration and service records, MOT and inspection data, technician notes and workshop media.
  • Technical data: IP address, browser type, device information and essential security/analytics logs.

3. Lawful Basis and Purpose

We process personal data under UK GDPR Articles 6(1)(b) (performance of a contract), 6(1)(c) (legal obligation, including tax and accounting records), 6(1)(f) (legitimate interests in operating and securing our services) and, where required, 6(1)(a) (consent).

Where special category data is processed on behalf of clinical clients using MedMonarch AI, processing is carried out strictly on the documented instruction of the client under Article 9(2)(h) and a written data processing agreement.

4. Compliance Standard

All processing is carried out in strict compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, under ICO registration.

5. Disclosures and Sub-Processors

Sovereign Arc Software Ltd does not sell, rent or trade personal data to any third party under any circumstances, and does not use client or enquiry data to train third-party AI models.

We share data only with vetted sub-processors strictly necessary to deliver the service — including Stripe (payments), cloud hosting and infrastructure providers, and transactional email and telephony providers — each bound by contractual data protection obligations.

We may disclose data where required by law, court order or a lawful request from a UK regulatory authority.

6. Security and Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with role-based access controls, audit logging and least-privilege internal access.

Where applicable, sensitive workloads operate on zero-knowledge and encrypted-at-source protocols, meaning Sovereign Arc personnel cannot read the underlying content of client records outside an authorised, client-authorised support request.

Data is hosted within UK/EU data regions wherever technically possible.

7. Platform Data Processing

Where clients deploy our platforms, Sovereign Arc Software Ltd acts as a data processor under a written agreement. Clinical, customer and vehicle records remain the property of the client and are processed strictly on documented instruction.

8. Retention

Enquiry data is retained for up to 24 months from last contact, after which it is securely deleted. Client platform data is retained for the life of the contract and deleted within 30 days of termination on request. Billing and tax records are retained for 6 years as required by UK law.

9. Your Rights

Under UK GDPR you have the right to access, rectify, erase, restrict or port your personal data, to object to processing, and to withdraw consent at any time.

Data subject access requests (DSARs) and all other data rights requests should be sent to privacy@sovereignarc.com. We respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).

10. Contact

Data protection enquiries: privacy@sovereignarc.com. General support: support@sovereignarc.com.