Privacy Policy
How Arbiter collects, uses and protects your personal data.
Who we are
Arbiter Networks is operated by Arbiter Ltd, registered in Ireland. The company is the data controller for personal data collected through arbiter.ie and the operator portal at portal.arbiter.ie. For tenant-side data that flows through the Arbiter platform on behalf of a customer (RADIUS authentication records, endpoint inventories, certificate metadata) Arbiter Ltd acts as a data processor, and the customer is the controller. Our Data Processing Agreement sets out the processor terms.
For any privacy question, including a request to exercise your rights under GDPR, email privacy@arbiter.ie. We respond within 30 days as required by Article 12(3).
What we collect, and why
Visitors to arbiter.ie
When you load a page on arbiter.ie we record:
- The URL path you visited (for example
/guides/edge-appliance). Query strings are stripped. - A non-reversible 16-character hash derived from your IP address and the current UTC date. The hash rotates every midnight, so the same visitor returning tomorrow appears as a different identifier. We use this to count unique visitors per day, not to track you across visits.
- The country and region your IP address resolves to, looked up at the moment of the request and used only to populate the per-country breakdown on our internal operator dashboard.
- The timestamp of the request.
We do not store your IP address. The IP is used for the geo lookup and for the daily hash, then discarded. It is not written to our database, not retained in logs and not shared with any third party.
We do not use cookies, browser fingerprinting or any third-party analytics script. No information is stored on your device by arbiter.ie for analytics purposes. There is no Google Analytics, no Meta Pixel, no Hotjar, no tracking pixels and no localStorage flags written by our analytics code.
Legal basis: legitimate interest (GDPR Article 6(1)(f)) in understanding which pages are useful and where our visitors come from. The data we keep does not identify any individual.
Retention: 90 days. After 90 days every row is deleted automatically by a daily background job.
Beta sign-up and contact forms
When you fill in a sign-up or contact form on arbiter.ie we collect the fields you provide, typically your name, work email address, company name and any free-text message. We use this only to respond to your enquiry and, if you become a customer, to provision and operate your tenant.
- Legal basis: taking steps prior to entering into a contract (Article 6(1)(b)) and legitimate interest in commercial correspondence (Article 6(1)(f)).
- Retention: kept while the commercial relationship is active. If a sign-up does not progress to a contract within 12 months the record is deleted.
Operator portal users
Operator console access at portal.arbiter.ie is gated by Microsoft Entra ID via oauth2-proxy. We process the operator's email address, the Entra ID subject identifier and the timestamps of administrative actions. Every state-changing operation in the operator console is written to an internal audit log with the operator's email recorded as the actor.
- Legal basis: contractual necessity (Article 6(1)(b)) and our legitimate interest in security and accountability (Article 6(1)(f)). Several entries are also required to meet SOC 2 CC6.1 and ISO 27001 A.5.15 access-control evidence obligations.
- Retention: audit-log entries are kept for the lifetime of the operator's account plus seven years to meet legal and accounting evidence requirements.
Tenant-side data (data we process on behalf of customers)
The Arbiter platform processes network authentication data on behalf of customer organisations. This includes MAC addresses, hostnames, certificate subject and issuer fields, RADIUS attributes, NAS device metadata and authentication outcomes. In respect of this data Arbiter Ltd is a data processor and the customer organisation is the controller. The legal basis for processing, the retention period and the rights process are set by the customer in its own privacy notice.
Our processor obligations, sub-processor list and breach-notification commitments are set out in the Data Processing Agreement. We never use tenant-side data for any purpose other than operating the service we are contracted to provide.
Cookies
arbiter.ie does not set any cookies for analytics, advertising or tracking. The only cookies the site may set are strictly-necessary session cookies created by the operator portal at portal.arbiter.ie after a successful Microsoft Entra ID sign-in. Those cookies are required to keep an authenticated operator signed in for the duration of their session. They are not set on the public marketing site, are not used for tracking and are not shared with any third party.
Because we do not set or read any non-essential information on your device, the consent requirement of Regulation 5 of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 and Article 5(3) of the ePrivacy Directive does not apply, and we do not show a cookie banner.
Sub-processors and international transfers
We use a small number of sub-processors to operate the platform. The current list and the function each performs is maintained at /trust-centre/sub-processors. We notify customers in advance of any change.
All Arbiter primary infrastructure is hosted in the European Economic Area (Hetzner Online GmbH, Nuremberg, Germany). We do not transfer personal data outside the EEA in the normal course of operating the service. Where a sub-processor is established in a third country, the transfer is covered by Standard Contractual Clauses and the additional safeguards described in the sub-processor entry.
Your rights
Under GDPR Articles 15 to 22 you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Request erasure of your data, subject to lawful retention obligations.
- Restrict or object to processing.
- Receive your data in a structured, machine-readable format and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time where consent is the legal basis.
- Lodge a complaint with the Irish Data Protection Commission at dataprotection.ie or with the supervisory authority of your country of residence.
To exercise any of these rights email privacy@arbiter.ie. We respond within 30 days. Where a request relates to tenant-side data, we route it to the customer organisation that controls that data and assist them in responding.
Security
Personal data is encrypted in transit (TLS 1.2 or higher) and at rest. Operator console access is gated by SSO with MFA enforced at the identity provider. Every administrative action is audit-logged. Further detail is on the Trust Centre. Security reports are welcomed at security@arbiter.ie.
Changes to this policy
Material changes are announced on this page and notified by email to customers at least 30 days before they take effect. Minor clarifications (fixing a typo, adding a sub-processor that is not material) are made without notice and dated below.
Last updated May 2026. For questions about this page, contact privacy@arbiter.ie.