Terms of Use
Last updated: May 15, 2026
These Terms of Use (“Terms”) govern access to and use of the arcalyze.com website, platform, APIs, reports, screening tools, and related services (“Services”) provided by Herokode, LLC (“Company,” “we,” “us,” or “our”). By accessing or using the Services, you agree to these Terms on behalf of yourself and, if applicable, the organization you represent.
1. Acceptance of Terms
You must be at least the age of majority in your jurisdiction and authorized to bind the organization you represent, if any. If you do not agree to these Terms, you may not access or use the Services.
2. Relationship to Privacy Policy
Our collection and use of personal information is described in our arcalyze.com Privacy Policy, which is incorporated into these Terms by reference. By using the Services, you acknowledge that you have read and understood the Privacy Policy, and you consent to the handling of information as described there. The Privacy Policy governs privacy practices; these Terms govern use of the Services and contractual rights and obligations.
3. Services
The Services provide arcalyze.com users with tools to bulk search third-party entities and individuals against U.S. government and other publicly available restricted party lists, including sanctions, export-control, denied-party, and similar screening lists made available through our platform. We may provide name-matching, fuzzy-search, batch screening, monitoring, alerts, reporting, and workflow features. Government lists may change, be updated, or be removed without notice, and screening results may depend on the source data and matching logic used.
4. No Legal Advice
The Services are provided for informational and compliance-support purposes only and do not constitute legal advice, export-control advice, sanctions advice, or a guarantee of compliance. You are solely responsible for obtaining advice from qualified legal, compliance, or trade-control professionals where appropriate.
5. Customer Responsibilities
You represent and warrant that:
- You have all rights, authority, and lawful basis necessary to submit names, business identifiers, and related data for screening.
- You will use the Services only for lawful compliance, diligence, and risk-management purposes.
- You will not use the Services to make unlawful decisions, discriminate, harass, or misuse personal information.
- You will provide required notices and obtain any required permissions or consents for the data you submit.
- You are responsible for reviewing screening results and making all compliance decisions.
6. Permitted and Prohibited Uses
You may use the Services only as permitted by these Terms and applicable law. You may not:
- Scrape, reverse engineer, or attempt to bypass security, rate limits, or access controls.
- Use the Services to violate export controls, sanctions laws, privacy laws, or anti-discrimination laws.
- Upload false, malicious, or unlawful content.
- Resell, sublicense, or redistribute the Services or reports except as expressly authorized in writing.
- Use the Services to screen individuals for employment or other decisions in a manner that violates applicable law.
- Remove or obscure proprietary notices.
7. Accounts and Security
You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account. You must notify us promptly of any unauthorized use or suspected security incident. We may suspend or terminate access if we believe account activity poses a risk to the Services, other users, or legal compliance.
8. Screening Data and Results
The Services may return matches, possible matches, or non-matches based on data available at the time of screening. Results are not definitive legal determinations. Government lists and related records may contain inaccuracies, delays, aliases, transliterations, or incomplete identifiers, and false positives may occur. You should independently verify material results before taking action.
9. Government List Sources
The Services may use public and licensed data sources that include, among others, U.S. government restricted party and sanctions lists maintained by relevant agencies such as the Treasury, Commerce, and State departments. Those lists and related materials remain the property of their respective owners and may be subject to separate terms, disclaimers, or restrictions.
10. Intellectual Property
We and our licensors own the Services, software, interfaces, algorithms, reports, and content we provide, excluding third-party government data and customer-submitted data. Subject to these Terms and payment of applicable fees, we grant you a limited, revocable, non-exclusive, non-transferable right to access and use the Services for your internal business purposes. All intellectual property rights held by a party prior to the provision and/or access of the services, whichever came first, shall be retained by such party. All Arcalyze and Herokode character and design trademarks are the exclusive property of Herokode, LLC and shall not be used or reproduced without our express written permission.
11. Fees and Payment
If the Services are offered on a paid basis, you agree to pay all fees, taxes, and charges described in your order form, subscription plan, or invoice. Unless otherwise stated, fees are non-refundable. We may suspend access for nonpayment after notice where permitted by law.
12. Confidentiality
“Confidential Information” means all nonpublic information disclosed by either party, whether oral, written, electronic, or visual, including business, technical, financial, security, compliance, customer, product, pricing, contract, and operational information, as well as all nonpublic outputs, reports, and analyses generated through the Services.
The receiving party will use Confidential Information only to perform under these Terms, will protect it with reasonable care, and will not disclose it except to personnel and service providers with a need to know and who are bound by confidentiality obligations.
The parties acknowledge that unauthorized use or disclosure of Confidential Information may cause irreparable harm, and the disclosing party may seek injunctive or other equitable relief, including preliminary relief, without showing proof of actual damages and without posting bond, to the extent permitted by law.
13. Data Protection
If we process personal information on your behalf in connection with the Services, the parties will be bound by our Data Processing Addendum appended hereto these Terms, and by the Privacy Policy incorporated into these Terms by reference. You agree not to upload sensitive personal data unless we have expressly agreed in writing to process it.
14. Service Availability
We may modify, suspend, or discontinue any feature of the Services at any time, with or without notice, to the extent permitted by law. We do not guarantee uninterrupted or error-free operation.
15. Disclaimer of Warranties
THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF ACCURACY, COMPLETENESS, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
16. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST DATA, OR BUSINESS INTERRUPTION. OUR TOTAL LIABILITY ARISING OUT OF OR RELATING TO THE SERVICES WILL NOT EXCEED THE AMOUNTS PAID BY YOU TO US FOR THE SERVICES IN THE PRECEDING TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM.
17. Indemnification
You will defend, indemnify, and hold harmless Company and its affiliates, officers, directors, employees, and agents from claims, damages, liabilities, losses, and expenses arising from your use of the Services, your submitted data, your breach of these Terms, or your violation of any law or third-party right.
18. Term and Termination
These Terms remain in effect until terminated in writing by either party hereto. We may suspend or terminate access immediately if you materially breach these Terms, pose a security risk, or use the Services unlawfully. Upon termination, your right to access the Services ends immediately, but sections that by their nature should survive will survive, including but not limited to governing law and jurisdiction, data protection, confidentiality, indemnification and limitations of liability.
19. Changes to Terms
We may update these Terms, including the Privacy Policy and Data Processing Addendum, from time to time. If we make material changes, we will post the updated Terms and revise the “Last Updated” date. Your continued use of the Services after the effective date of changes constitutes acceptance.
20. Governing Law
These Terms including the incorporated Privacy Policy and Data Processing Addendum are governed by the laws of the State of Michigan (USA) without regard to conflicts-of-law principles. Venue and jurisdiction will be in the state and federal courts located in Oakland County, Michigan, and the Parties hereby submit irrevocably to the exclusive jurisdiction of such courts.
21. Contact
Questions about these Terms should be sent to:
Herokode, LLCArcalyze Support TeamEmail: support@arcalyze.comData Processing Addendum
Last updated: May 15, 2026
This Data Processing Addendum (“DPA”) to the Arcalyze Terms of Use (“Terms”) is between Herokode, LLC (“Company”) and You, the individual Arcalyze user (“Customer”), and applies when Company processes Customer Personal Data on behalf of Customer in connection with the Services as defined in the Terms.
1. Roles
Customer is the controller or business, and Company is the processor or service provider, with respect to Customer Personal Data processed under this DPA, except where Company processes data for its own independent business purposes, such as account administration, compliance, security, and direct marketing, in which case Company acts as an independent controller or business.
2. Instructions
Company will process Customer Personal Data only:
- On Customer’s documented instructions.
- To provide, maintain, secure, and support the Services.
- As required by applicable law.
If an instruction, in Company’s reasonable opinion, would violate applicable data protection law, Company will notify Customer.
3. Data Types and Data Subjects
The Customer Personal Data processed may include:
- Employee and contractor names.
- Business email addresses.
- Job titles.
- Company name and department.
- Login and account data.
- Support, billing, and usage information.
Data subjects may include Customer employees, contractors, agents, and other authorized users.
4. Customer Responsibilities
Customer represents and warrants that:
- It has a lawful basis to disclose Customer Personal Data to Company.
- It has provided all required notices and obtained any necessary consents.
- Its instructions comply with applicable data protection law.
- It will not provide sensitive personal data unless expressly agreed in writing or required for the Services.
5. Confidentiality
Company will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations.
6. Security Measures
Company will implement appropriate technical and organizational measures to protect Customer Personal Data, including access controls, least-privilege access, encryption in transit, monitoring, backup procedures, and employee security training.
7. Subprocessors
Customer authorizes Company to engage subprocessors to support the Services. Company will require subprocessors to be bound by written obligations no less protective than those in this DPA.
8. Data Subject Requests
To the extent required by law, Company will provide reasonable assistance to Customer in responding to requests to access, delete, correct, restrict, or port Customer Personal Data.
9. Breach Notification
Company will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably available to assist Customer’s compliance obligations.
10. Deletion or Return
Upon termination of the Services, Company will delete or return Customer Personal Data, at Customer’s election by written request, unless retention is required by law or legally permitted for legitimate business records.
11. Standard Contractual Clauses
To the extent Customer Personal Data is transferred from the EEA, Switzerland, or the UK to a jurisdiction that does not benefit from an adequacy decision, the parties agree that the European Commission’s 2021 Standard Contractual Clauses, together with any applicable UK addendum or equivalent transfer mechanism, shall apply as applicable and are incorporated into this DPA by reference. The applicable SCC module will be determined by the transfer scenario, and the SCCs will prevail over this DPA to the extent of any conflict for the relevant transfer.
12. Audit and Compliance Information
Upon reasonable request, Company will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audits or inspections subject to confidentiality and security protections.
13. Marketing and Independent Use
Customer acknowledges that Company may process business contact information, such as employee names and business email addresses, for its own marketing and sales activities as an independent controller or business, subject to the Privacy Policy and applicable opt-out rights. This DPA does not apply to that independent processing.
14. Order of Precedence
If there is a conflict between this DPA and the Terms regarding data protection matters, this DPA controls.