1. Controller and contact details
The controller is Pura Digital S.r.l., with registered office at Via Ponte dei Granili 24, 80146 Naples (NA), Italy, VAT IT09624921210, Tax ID 09624921210.
Privacy email: info@puradigital.it
Pura Digital S.r.l. has not formally appointed a Data Protection Officer (DPO). Privacy requests may be sent to the email address above.
2. Scope of this notice and privacy roles
Pura Digital acts as controller when it determines the purposes and means of processing data relating to the website, accounts, contractual relationship, platform management, billing, communications, and the security of its systems.
This notice does not govern processing carried out by third-party websites or services accessible via links, which operate under their own privacy notices. Providers engaged by Pura Digital to deliver parts of the website or communications are listed in the recipients section.
The contractual conditions governing the website and services are available in the Terms of Service.
3. Data processed and sources
We process only data relevant to the activities described in this notice. Data may come from the data subject, the organization they work for, the systems used to access the Service, and, for identity, payment, and security data, from providers used by Pura Digital.
Identification, contact, and authentication data: name, verified email address, account identifier, linked Google or Microsoft identity (if chosen by the user), public keys and metadata of any passkeys, sessions, and information needed to verify access.
Profile and onboarding data: avatar, language, role, use case, team size, referral source, and other optional information provided by the user.
Organization and collaboration data: organization name and logo, memberships, roles, invitations, and email addresses of members or invitees.
Contractual and usage data: subscription plan, subscription status, credits, features used, operations performed, requests, identifiers, and dates of application events.
Billing and payment data: customer and subscription identifiers, amounts, currency, payment status, and, at the payment provider, company name, billing email, address, tax ID or VAT number, and payment instrument data.
Customer content: uploaded documents, files, images, text, names and descriptions, metadata, annotations, instructions, processing outputs, transcription results, exports, training configurations, and metrics.
Preferences, consents, and authorizations: subscription status, revocation, interface preferences, and authorizations granted to external applications, including client identifiers, permissions, and approval or revocation dates.
Communications data: content of requests sent to Pura Digital and the related responses.
Technical and security data: IP address, date and time, requested URL, technical headers, request or session identifiers, browser or device type, logs, and events required to prevent abuse and diagnose errors.
Authentication and sessions are managed directly by Pura Digital. You can sign in with a one-time email code, or, if you choose, via Google or Microsoft. For the latter methods, we receive from the provider the identification and profile data needed to access and link the account. From the account, you can manage linked methods, sessions, and authorized applications.
Pura Digital does not receive the full card data used through the payment system. We also do not ask users to enter special categories of personal data, criminal-offence data, credentials, or identity documents in public forms. Please do not send such information through the website forms.
4. Purposes, legal bases, and retention
Demo request
- Data processed
- first name, last name, email, and, if provided, company, industry, and message.
- Purpose and legal basis
- manage the request, organize the demo, and take pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR).
- Retention
- up to 24 months from the last substantive contact. If a contractual relationship is established, the data flows into the relevant documentation and follows the applicable retention terms.
Account, authentication, sessions, and authorized applications
- Data processed
- verified email, account identifier, linked identities, public keys and passkey metadata, sessions, application authorizations, and security data.
- Purpose and legal basis
- create and manage the account, authenticate the user, and perform the contract (Art. 6(1)(b) GDPR); prevent unauthorized access and protect the Service based on the legitimate interest of Pura Digital and its users (Art. 6(1)(f) GDPR).
- Retention
- for the duration of the account. Upon closure, access is disabled; identifying profile data is normally deleted or anonymized within 30 days from when the user no longer belongs to any organization, subject to legal, security, or legitimate defense requirements.
Profile and onboarding
- Data processed
- name, avatar, language, role, use case, team size, referral source, and preferences.
- Purpose and legal basis
- configure the experience, provide requested features, and perform the contract (Art. 6(1)(b) GDPR); understand and improve onboarding and the Service based on the legitimate interest of Pura Digital (Art. 6(1)(f) GDPR).
- Retention
- for the duration of the account and normally up to 30 days after closure, except for aggregated or effectively anonymized data.
Organizations, roles, and invitations
- Data processed
- organization name and logo, memberships, roles, invitee email addresses, and invitation status.
- Purpose and legal basis
- create and administer organizations, manage access and collaboration, and perform the contract (Art. 6(1)(b) GDPR); ensure security and access traceability based on legitimate interest (Art. 6(1)(f) GDPR).
- Retention
- for the duration of the organization. Open invitations normally expire after 7 days; essential access information may be retained longer for security needs, contractual obligations, or protection of legitimate rights.
Platform delivery
- Data processed
- plan, credits, usage events, uploaded documents and their versions, files, images, text, metadata, annotations, instructions, outputs, transcription results, exports, training configurations and history, metrics, and model versions requested by the customer.
- Purpose and legal basis
- provide, maintain, and support the requested Service and perform the contract (Art. 6(1)(b) GDPR). For personal data contained in customer materials, Pura Digital normally acts as processor and the legal basis is determined by the customer acting as controller.
- Retention
- for the duration of the relationship and according to the customer's deletion choices, the Terms of Service, and any applicable DPA. Temporary exports normally expire after 7 days; deletions, backups, and legal obligations may follow different technical timelines.
Subscriptions, credits, payments, and invoices
- Data processed
- plan, customer and subscription identifiers, credits, amounts, currency, transaction status, and tax or billing data.
- Purpose and legal basis
- enter into and perform the contract (Art. 6(1)(b) GDPR), comply with tax and accounting obligations (Art. 6(1)(c) GDPR), prevent fraud or protect legitimate rights (Art. 6(1)(f) GDPR).
- Retention
- for the duration of the relationship; tax, accounting, and contractual documents are normally retained for 10 years. The payment provider also applies its own retention terms for financial, anti-fraud, and legal obligations.
Operational email and support
- Data processed
- email, name, organization, and information strictly necessary to describe the event, request, or outcome of an operation.
- Purpose and legal basis
- send invitations, account notifications, export notifications, and notifications relating to requested operations; provide support; perform the contract (Art. 6(1)(b) GDPR). Reliability and support are also pursued based on legitimate interest (Art. 6(1)(f) GDPR).
- Retention
- for the time necessary to deliver and manage the event; support correspondence is normally retained for up to 24 months after closure, subject to contractual, legal, or security requirements.
Direct communications
- Data processed
- contact data and communication content.
- Purpose and legal basis
- respond to data subject requests: pre-contractual measures (Art. 6(1)(b) GDPR) or legitimate interest in managing correspondence (Art. 6(1)(f) GDPR), depending on content.
- Retention
- up to 24 months after the request is closed, unless the communication must be retained for a contractual relationship or dispute.
Website and platform delivery, and security
- Data processed
- IP address, technical data, logs, events, and request or session identifiers.
- Purpose and legal basis
- deliver the systems, maintain reliability, prevent abuse and incidents, diagnose errors; contract performance for requested features (Art. 6(1)(b) GDPR) and legitimate interest of Pura Digital in security and proper system operation (Art. 6(1)(f) GDPR).
- Retention
- technical logs are normally retained for up to 30 days; authentication security events for up to 180 days. Data relating to an incident may be isolated and retained for up to 12 months or longer if necessary to comply with an obligation or protect legitimate rights.
Preferences and technical browser storage
- Data processed
- language, theme, editor preferences, tutorial state, last sign-in method used, and technical identifiers for a session or pending invitation.
- Purpose and legal basis
- remember requested settings, maintain the session, and complete initiated flows; contract performance (Art. 6(1)(b) GDPR) and legitimate interest in proper interface operation (Art. 6(1)(f) GDPR).
- Retention
- depending on function: for the session; until expiry or logout; for 7 days for sidebar preference; or until the user changes the setting or clears site data.
Legal obligations and protection of rights
- Data processed
- data necessary to respond to privacy requests, authorities, or disputes.
- Purpose and legal basis
- comply with legal obligations (Art. 6(1)(c) GDPR) and establish, exercise, or defend a right in court (Art. 6(1)(f) GDPR).
- Retention
- for the period required by law. Privacy requests and related evidence are normally retained for 5 years; accounting and contractual documents, where applicable, for 10 years.
5. Provision of data and withdrawal of consent
Fields marked as required in the demo form are necessary to respond to the request; without them we cannot handle it. Data needed to create and protect the account, use contractual features, or complete a purchase is required to deliver the relevant Service. Other profile and onboarding data is optional, unless otherwise indicated in the interface.
The customer decides which content to upload to the platform and is responsible for having a valid legal basis, providing required information to data subjects, and complying with restrictions in the Terms and any applicable DPA. Not uploading content does not prevent account use but makes the related operations impossible.
To withdraw consent, use the unsubscribe link in our messages or write to info@puradigital.it.
6. Recipients and processors
Data is accessible to authorized Pura Digital staff and collaborators, within the limits required by their duties. It may also be communicated to the following recipients:
When they process data on behalf of Pura Digital, providers act as processors under an agreement compliant with Article 28 GDPR. Some providers may process data as independent controllers for their own legal or security obligations; in such cases, their respective privacy notices apply.
- Amazon Web Services EMEA SARL, for primary cloud infrastructure, including compute, databases, object storage, and language models, configured in European Union regions (Frankfurt).
- Stripe, Inc. (Stripe Payments Europe, Limited), for checkout, subscriptions, credits, billing, tax calculation, fraud prevention, and payment management.
- Google LLC and Microsoft Corporation, only when the user chooses to sign in with their account or connect a document connector, for data required by the relevant authentication or authorization flow under their respective privacy notices.
- Legal, tax, or technical advisors bound by confidentiality, where necessary.
- Public authorities, supervisory bodies, or entitled parties where required by law.
For more information on cloud infrastructure, see the Amazon Web Services privacy notice.
For optional sign-in with Google, see the Google privacy notice.
For optional sign-in with Microsoft, see the Microsoft privacy notice.
For more information on payments, see the Stripe privacy notice.
7. Transfers outside the European Economic Area
Customer content, the platform's primary database, and object storage are configured on Amazon Web Services infrastructure in European Union regions (Frankfurt). Text embeddings and the semantic search engine are managed on servers owned by Pura Digital in the same EU area. This does not mean, however, that all processing connected to the Service takes place exclusively within the European Economic Area.
If the user chooses sign-in with Google or Microsoft, those providers may process authentication and technical data outside the European Economic Area under their respective notices. Stripe and financial network participants may process payment, billing, and anti-fraud data through international organizations. Authorized personnel or group companies of providers may also access data from other countries as necessary.
Where processing involves a transfer to a country not covered by an adequacy decision, Pura Digital requires appropriate safeguards under Articles 44 et seq. GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, participation in the Data Privacy Framework, together with supplementary measures proportionate to the risk.
Information on applicable safeguards may be requested by writing to info@puradigital.it.
9. Data security
Pura Digital adopts technical and organizational measures proportionate to the risks, including access control, data minimization, protection of communications in transit, system updates, credential management, and use of contractually selected providers.
No Internet-connected system can be considered risk-free. In the event of a personal data breach, Pura Digital will apply the procedures required by Articles 33 and 34 GDPR, including notification to the supervisory authority and data subjects where required.
10. Data subject rights
In the cases and within the limits provided by the GDPR, the data subject may request:
To exercise these rights, write to info@puradigital.it. We may request information needed to verify the identity of the requester.
Pura Digital responds without undue delay and normally within one month. In complex cases or with numerous requests, the deadline may be extended by two months, with information to the data subject within the first month. Exercising rights is free, except for manifestly unfounded or excessive requests as permitted by law.
The data subject may also lodge a complaint with the Italian Data Protection Authority or the supervisory authority of the State where they reside or work or where the alleged violation occurred.
- access to personal data and a copy thereof;
- rectification of inaccurate data or completion of incomplete data;
- erasure of data;
- restriction of processing;
- data portability for data provided, where processing is automated and based on consent or a contract;
- to object, for reasons related to their particular situation, to processing based on legitimate interest;
- to object at any time to direct marketing;
- to withdraw consent at any time.
11. Profiling and automated decisions
Pura Digital does not use account, website, or platform data to profile people for advertising purposes and does not use decisions based solely on automated processing that produce legal effects or similarly significant effects on the data subject under Article 22 GDPR. AI-assisted features produce outputs that must be verified by the user and are not intended to autonomously make such decisions about natural persons.
12. Third-party data, minors, and sensitive data
Anyone providing personal data of other people must be authorized to do so and must provide those people with the necessary information. Where Pura Digital receives data other than directly from the data subject, it fulfills information obligations under Article 14 GDPR where applicable.
The ArchivEye website and services are intended for adults and organizations and are not directed at children under sixteen. If we become aware of children's data collected without a valid basis, we delete it or take other measures required by law.
Do not enter health, biometric, genetic, political opinions, religious beliefs, sexual life, ethnic origin, trade union membership, convictions or offences, or other information not necessary to the request through public forms.
Customers may process third-party data on the platform only if they have a valid legal basis and comply with the DPA, instructions, and applicable measures. Special categories of data, criminal data, or other high-risk content must not be uploaded until the applicable DPA and Plan expressly authorize it and adequate safeguards have been agreed.
13. Data processed on behalf of customers
When a customer uses the platform to process personal data for its own purposes, the customer determines the purposes and essential means and normally acts as controller; Pura Digital normally acts as processor and follows the customer's documented instructions.
Before uploading third-party personal data, the customer must enter into or accept a Data Processing Agreement compliant with Article 28 GDPR, governing, among other things, instructions, confidentiality, security measures, sub-processors, assistance, incidents, audits, transfers, and deletion or return of data.
Data subjects must address requests relating to customer datasets to the customer itself, without prejudice to the assistance Pura Digital is required to provide.
14. Updates to this notice
Pura Digital may update this notice to reflect regulatory, organizational, or technical changes. The current version is published on this page with the date of the last update.
Substantial changes will be communicated through proportionate means, for example on the website or by email where relevant contacts are available. If new processing requires consent, it will be requested before it begins; continued browsing alone will not be considered consent.
Before introducing new processing, data categories, or providers, Pura Digital will assess the impact on this notice and update it where necessary. If new processing requires consent, it will be obtained before launch.
The Italian version of this Privacy Notice is the only legally valid and authentic version. In case of conflict, ambiguity, or divergence in interpretation between it and a translation, the Italian text prevails.