Legal
This policy explains what data Artica collects, why, who helps us process it, and the choices you have. It covers the marketing site at askartica.com, the Artica application at app.askartica.com, and the Artica Chrome extension.
Two roles to keep straight. For your Artica account data (name, email, workspace, billing), Artica is the data controller. For the support-ticket data inside the Zendesk instance you connect — which contains your own customers' personal data — you are the controller and Artica is a processor acting on your instructions. If you're a support requester of a company that uses Artica, contact that company directly; we'll assist them as their processor.
Artica is a B2B service that analyzes a company's Zendesk support tickets to find help-center coverage gaps, and helps that company write and export help-center articles. It is operated by Hosam Hassan LLC ("Artica," "we," "us"), a Wyoming limited liability company at 30 N Gould St. # 48472, Sheridan, WY 82801, USA. For any privacy matter: hello@askartica.com.
Your account. Your name and email address, via our sign-in provider Clerk (Google sign-in or email/password — Clerk holds the credentials; we never see passwords), plus a user identifier, your workspace membership and role (Owner / Editor / Viewer), invitations you send (invitee email, role, timestamps — the invite link token itself is stored only as a hash), and your email preferences.
Your Zendesk connection. Your Zendesk subdomain, the OAuth scopes you granted, your help center's locale, the identity of the person who authorized the connection, and the OAuth tokens — encrypted with AES-256-GCM before storage.
The product's output (derived data). Topic categories and topics: AI-generated titles, descriptions, and example questions; numerical embedding vectors; ticket volume counts by month; and Zendesk ticket ID numbers used as links back into your own Zendesk. Also metadata about your already-published help-center articles: title, public URL, section, a content hash, and an embedding.
Content you author. Articles drafted in Artica and images you add, including workflow screenshots captured by the Chrome extension. Screenshots are automatically redacted in your browser — emails, card numbers, credentials, phone numbers, SSNs, IBANs, password fields — before upload; the unredacted image never reaches our servers.
Billing. Handled by Stripe. We store only your Stripe customer and subscription identifiers — never card numbers.
Operational records. Job status and progress, error messages, and AI usage records (token counts and cost — no content).
This is the core of the product's design, and it is enforced by an automated check in our build pipeline that fails any code change creating a place for ticket content to live:
The full technical story, including how the guarantee is enforced, is on our Security page.
We do not sell personal data, and we do not use your data for third-party advertising. Where laws such as the GDPR require a legal basis: performance of a contract (providing the service), legitimate interests (securing and improving it), consent where we ask for it, and legal obligation.
Artica uses AI providers to do its core work: OpenAI converts text to embedding vectors, and Anthropic (Claude) labels topics, analyzes redacted screenshots, and helps draft and match articles. Ticket text reaches these providers only transiently, during a processing run, to produce a result. Under our API terms with OpenAI and Anthropic, API content is not used to train their models. AI credentials are held server-side and are never exposed to browsers or the extension.
We share data only with the vendors that run the service, each under data-protection obligations, and where the law requires it. The current list, with what each receives, is maintained at askartica.com/subprocessors. We update that page and notify workspace Owners by email at least 30 days before adding or replacing a subprocessor.
Summarized here — the full picture is at askartica.com/security: TLS in transit; encryption at rest; application-level AES-256-GCM for Zendesk OAuth tokens; authenticated sessions on every product route; per-workspace isolation of data and files; and the build-pipeline check that enforces the no-ticket-text guarantee on every code change.
The application uses essential cookies set by our authentication provider (Clerk) to keep you signed in — required for the product to function. The marketing site uses no analytics at all — nothing counts, profiles, or identifies your visit. We use no advertising cookies and no cross-site tracking, anywhere.
Artica operates from the United States and our subprocessors are US-based. If you use Artica from outside the US, your data is processed in the US. For personal data transferred from the EU/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar), you may have rights to access, correct, delete, export, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. For your Artica account data, email hello@askartica.com — we won't discriminate against you for exercising your rights. For personal data inside support tickets, the company that connected the Zendesk instance is the controller: contact them, and we'll assist as their processor. Notably, Artica cannot search stored data for a ticket requester's information — ticket text and requester identities are never retained.
Artica is a business product not directed at children, and we don't knowingly collect personal data from anyone under 16.
We'll post updates here, revise the date above, and notify workspace Owners by email of material changes before they take effect.
hello@askartica.com, or Hosam Hassan LLC, 30 N Gould St. # 48472, Sheridan, WY 82801, USA.