The short version
- Most data in Arez belongs to the organisation that put it there. They decide what is recorded and how long it is kept.
- We do not sell personal data, and we do not use customer data to train publicly available AI models.
- Each customer operates in its own isolated environment. Customer data is never pooled into a shared operational database.
- AI assistant connections are optional, require your approval, and can be switched off at any time.
- If you are a worker or engineer, speak to your employer first, but contact us and we will help.
Who we are
Arez is a facility management and field service management platform operated by EarnFlex Ltd, a company registered in England and Wales.
| Legal entity | EarnFlex Ltd |
| Trading as | Arez / Arez.io |
| Registered office | 137A Molesey Avenue , London KT8 2RY, England |
| Company number | 13723923 |
| ICO registration | ZB404574 |
| Telephone | 020 8148 1882 |
| Privacy contact | privacy@arez.io |
Our role
Arez is used by organisations to manage their own operations. This means we handle personal data in two different capacities, and it matters which one applies to you.
| Role | Which data | Who to contact |
|---|---|---|
| We are a processor | Everything held inside a customer's Arez environment, jobs, sites, assets, worker records, documents, inspections and invoices. | The customer organisation. They decide what is recorded and how long it is kept. |
| We are a controller | Our own account, billing and support records, website visitors and business contacts. | Us, at privacy@arez.io |
If you are a worker, engineer or site contact
The organisation you work for, or that engaged you, decides what is recorded about you in Arez. They are responsible for your data.
If you want to see, correct or delete your records, ask them first. We will support them in responding. If you cannot reach them, contact us and we will help you identify the responsible organisation.
What we handle
Depending on how Arez is configured, this may include:
- Your name, work email address, telephone number, job role and employer
- Login and authentication details
- Work records, jobs, sites, assets, inspections, timesheets, photographs and notes
- Workforce records, where your employer uses Arez for this, qualifications, training, certificates, references and vetting records
- Identity documents and photographs, where your employer uses Arez to verify identity
- Location at the point of clocking in or completing work, where your employer enables this
- Technical records, IP address, device information, and a record of actions taken in the platform
- Support requests and correspondence
Where a customer uses Arez to hold identity documents or vetting records, that customer decides what is collected and is responsible for having a lawful basis to do so. We hold it on their behalf and on their instruction.
Why we use it
| Purpose | Lawful basis |
|---|---|
| To provide the platform to our customer | Contract |
| To authenticate users and keep accounts secure | Legitimate interests |
| To detect and prevent misuse | Legitimate interests |
| To support customers and resolve faults | Contract |
| To bill and administer accounts | Contract and legal obligation |
| To maintain reliability and improve the service | Legitimate interests |
| To contact business customers about our service | Legitimate interests, opt out at any time |
| To meet legal and regulatory obligations | Legal obligation |
We do not sell personal data. We do not use customer operational data to train publicly available AI models. A record of our legitimate interests assessments is available to customers on request.
Mobile applications
Arez mobile applications are used by field workers, engineers and inspectors. Where your organisation uses one, the app may request access to features on your device.
Each permission is requested only where a feature that needs it has been enabled, and you may decline or withdraw it in your device settings, although some features will not work if you do.
| Permission | Used for |
|---|---|
| Location | Recording where work started or finished, and confirming attendance at a site, where your organisation enables this |
| Camera | Photographs of work, assets, inspections and documents |
| Notifications | Alerting you to new or updated work |
| Near-field communication | Scanning asset tags on site |
| Offline storage | Holding work on the device so it remains usable without signal, and syncing when a connection returns |
Your organisation controls which of these features are enabled. We do not collect location in the background or track your device outside the activities described above.
AI features inside Arez
Arez includes AI-assisted features such as reading documents, extracting information from invoices, summarising records and assisting with routine work. These are available only where the customer organisation enables them.
When an AI feature is used, only the information needed for that specific request is sent to the AI service provider. Data is sent to fulfil the request, not retained by us for any other purpose.
Human review
AI features produce drafts, suggestions and extracted values. A person reviews them before they are relied upon. We do not make decisions producing legal or similarly significant effects about individuals by automated means.
Training
We do not use customer operational data to train publicly available AI models. We use AI providers under commercial agreements which restrict the use of submitted data.
Connecting Arez to third-party AI assistants
Arez can be connected to supported AI assistants, including ChatGPT, Claude and Microsoft Copilot, so that authorised users can work with their Arez data from within those tools. This is optional and is enabled by the customer organisation.
This is a different arrangement from the AI features described above. Here, data leaves Arez into a tool operated by a third party under your own organisation's account with that provider.
How the connection is authorised
- You sign in to Arez directly. Your Arez password is never shared with the AI provider.
- Before the connection is made, you are shown a screen setting out what the assistant will and will not be able to access. The connection proceeds only if you approve it.
- The connection is limited to the single customer environment you signed in to. It cannot reach any other organisation's data.
- Access is granted through a short-lived token issued by Arez, which expires automatically.
- The connection can be revoked at any time from within Arez.
What you approve
| The assistant can | The assistant cannot |
|---|---|
|
|
What is recorded
Every action taken through a connected assistant is recorded in the Arez activity log, identifying the user, the assistant used and the time. Administrators at your organisation can review this activity.
What happens on the other side
Once information appears in a conversation inside ChatGPT, Claude or Copilot, that provider's privacy terms and your organisation's settings with them govern how the conversation is stored.
We cannot control the retention or training settings of an account we do not operate.
Phoebe, our voice assistant
Some customers use Phoebe to answer inbound telephone calls, log reactive work and provide basic status information.
What we handle
- The calling telephone number, used to identify which customer the caller is contacting
- What is said during the call
- Audio recordings and written transcripts of calls, where recording is in use
- Any record created in Arez as a result of the call
How calls are handled
- Phoebe accepts calls only from telephone numbers the customer organisation has added to its own list. Calls from other numbers are not answered by the assistant.
- Calls are handled by Telnyx Limited, our telephony provider. Speech is converted to text by Retell AI so that a record can be created and checked. Both act on our behalf under contract.
- What Phoebe can access is deliberately limited to logging work and giving basic status updates. It cannot access commercial data, compliance records or documents.
- The customer organisation is responsible for notifying callers that calls may be recorded, and for the list of numbers it maintains.
APIs and integrations
Customers can connect Arez to their own systems, or to systems operated by their suppliers and partners, using the Arez API.
- Connections are authorised by the customer organisation, using either API credentials issued by Arez or an OAuth connection.
- Each connection is limited to the customer environment it was issued for.
- Customers choose which systems to connect and what those systems are permitted to do.
- Credentials can be revoked by the customer at any time, which immediately ends the connection.
- API activity is recorded in the customer's activity log.
Where a customer connects Arez to a third-party system, that system's own privacy terms apply to any data it receives. We are not responsible for how a connected system uses data once it has been transferred at the customer's instruction.
Activity and audit records
Arez records significant actions so that customers can investigate what happened, resolve disputes and meet their own compliance obligations.
Depending on the action, a record may include the user, the time, the organisation, the action taken, the interface used, web, mobile application, AI assistant or API, and the originating IP address or device.
These records exist for security, accountability and operational integrity. They are visible to administrators at the customer organisation. We access them only where necessary to operate the service, investigate a security concern, or respond to a customer request.
Some records are designed not to be altered or deleted, so that the history of what happened remains intact. This means a request to delete personal data may not remove entries from an audit record where retaining them is necessary for security or to meet a legal obligation.
Who else is involved
We use a limited number of suppliers to deliver the service. Each is engaged under a contract that restricts what they may do with data.
| Purpose | Provider |
|---|---|
| Hosting and storage | Amazon Web Services, Linode (Akamai Technologies) |
| Cloud and document processing | Google Cloud |
| Email and one-time passcodes | Postmark, SendGrid |
| Telephony | Telnyx Limited — call handling for Phoebe |
| Voice and speech processing | Retell AI — speech recognition and conversation for Phoebe |
| Third-party AI assistants | OpenAI, Anthropic, Microsoft — only where a customer enables a connection |
| Other suppliers | A current list is available on request from privacy@arez.io |
The AI provider used depends on the feature enabled by the customer and may change over time as we improve the service. We maintain a current list and notify customers of material changes in accordance with their agreement with us.
Where data is held
Each customer is provisioned in its own isolated Arez environment, with its own database and its own address. Customer data is not pooled into a shared operational database with other customers.
Customer environments are hosted in the cloud region chosen for that customer. Backups are stored within secure backup infrastructure aligned to that deployment arrangement.
Some of our suppliers operate outside the United Kingdom. Where personal data is transferred internationally, we rely on UK adequacy regulations, or on the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses, together with any further safeguards identified by a transfer risk assessment.
Customers may request details of the transfer mechanism applying to any named supplier.
How long we keep it
Where a customer organisation controls the data, that organisation decides how long it is kept. Some records are held for set periods to meet legal or industry requirements, for example, security vetting records are typically kept for seven years, and competency records for six.
Our own account and billing records are kept for six years to meet accounting requirements. Everything else is kept only for as long as we need it for the purpose it was collected.
When data is deleted from the live platform it may remain in secure backups for a period before those backups are overwritten on their normal cycle.
Deleting or anonymising data
A customer can ask us to delete or anonymise personal data relating to an identified individual at any time during the contract. Deletion removes the records; anonymisation removes the identifying details while keeping non-identifying operational records where the customer still needs them.
How it works:
- An authorised contact at the customer organisation submits the request. We confirm it comes from an authorised contact before acting.
- The records are deleted or anonymised in the customer's live environment.
- Some records are kept where we or the customer are required to keep them, for example audit records held for security, and records subject to a legal retention period. Where anything is retained, we identify it in our response rather than keeping it silently.
- Data removed from the live platform remains in secure backups until those backups are overwritten on their normal cycle. Deletion requests are re-applied following any restore, so deleted records are not reintroduced.
- We confirm to the customer once the request is complete.
If you are an individual rather than a customer organisation, see Your rights below. In most cases your request is directed to the organisation that controls your data, and we support them in carrying it out.
Keeping it safe
Each customer operates within its own isolated Arez environment, with a separate database and a separate address. Data is separated at infrastructure level rather than by filtering within a shared database.
We also apply:
- Encryption of data in transit and at rest
- Separate authentication schemes for each route into Arez, web, mobile application, AI connection and API, so that credentials issued for one route are not valid on another
- Role-based access control, so people see only what their role permits
- Support for multi-factor authentication
- Activity logging, monitoring and regular security review
Certifications
EarnFlex Ltd holds ISO 27001:2022, the international standard for information security management systems. We are certified by Alcumus ISOQAR under UKAS accreditation, certificate number 23550-ISMS-001, valid until April 2028. The registered scope covers information security management for the provision of a flexible staffing platform, access to pre-vetted workers, and the provision of compliance software as a service.
The Arez platform is operated within this certified information security management system and was assessed as part of the certification audit. Audit documentation is available to customers and prospective customers under a confidentiality agreement.
We also hold Cyber Essentials, ISO 9001 for quality management, ISO 14001 for environmental management and ISO 45001 for occupational health and safety. A full list, including our memberships, is published on our accreditations page.
If something goes wrong
If a personal data breach occurs, we will notify the affected customer without undue delay so that they can meet their own obligations. Where we are the controller, we will report to the Information Commissioner's Office within 72 hours where required, and notify affected individuals where the risk to them is high.
Your rights
You have the right to ask us to:
- Provide a copy of your personal data
- Correct anything that is inaccurate
- Delete it, in certain circumstances
- Restrict how it is used, in certain circumstances
- Provide it in a portable format, or send it to another provider
- Stop using it, where we rely on legitimate interests
- Stop sending you marketing, at any time, without giving a reason
If your data is held inside a customer's Arez environment, contact that organisation. For data we control, email privacy@arez.io. We will respond within one month.
How to make a request
Email privacy@arez.io or write to us at the address in the Contact us section, telling us which right you wish to exercise. You do not need to use any particular form of words.
- We may ask for enough information to confirm your identity, so that we do not disclose your data to anyone else.
- We respond within one month. If a request is complex, we may extend this by up to two further months and will tell you why.
- There is no charge for a request unless it is manifestly unfounded or excessive.
- If your data sits inside a customer organisation's Arez environment, we act as their processor. We will pass your request to them without undue delay and support them in responding, as they are the controller of that data.
If you are not satisfied with our response
You may complain to the Information Commissioner's Office, the UK supervisory authority for data protection.
ico.org.uk · Helpline 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We would ask you to raise it with us first, so that we have the opportunity to put it right.
Cookies
We use cookies that are strictly necessary to operate the website and keep you signed in. Where we use any other cookies, we ask for your consent first, and you may withdraw it at any time in our cookie settings.
Children
Arez is a workplace product intended for use by organisations and their staff. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact privacy@arez.io and we will work with the relevant organisation to address it.
Data ownership
Information a customer puts into Arez belongs to that customer. We do not sell it, and we do not use it to train publicly available AI models. When a contract ends, data is returned or deleted in accordance with the agreement in place.
Changes
We review this notice at least annually, and whenever we materially change how personal data is used. Where a change materially affects you, we will notify customers in advance through the platform or by email. Previous versions are available on request.
Contact us
For anything relating to privacy, to exercise your rights, or to request our supplier list, data processing agreement or transfer documentation:
| privacy@arez.io | |
| Telephone | 020 8148 1882 |
| Post | 137A Molesey Avenue , London KT8 2RY, England |
| Response time | Within one month |