ArchivEye

Legal information

Privacy Notice

Last updated: September 10, 2026Public document

This notice describes how Pura Digital S.r.l. processes the personal data of people who visit the ArchivEye website, request a demo, create an account, use the platform, make purchases, or contact the team. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR").

Pura Digital S.r.l. acts as controller for data relating to its relationship with users and customers, including account, security, service use, support, and billing data. When it processes personal data contained in documents or other content uploaded by a customer for purposes determined by that customer, Pura Digital generally acts as processor under Article 28 GDPR.

The Italian version of this Notice is the only legally valid and authentic version. Translations into other languages are provided for convenience only.

This English translation is provided for convenience. In case of conflict, ambiguity, or divergence in interpretation, the Italian text prevails.

Go to Privacy & Security →

1. Controller and contact details

The controller is Pura Digital S.r.l., with registered office at Via Ponte dei Granili 24, 80146 Naples (NA), Italy, VAT IT09624921210, Tax ID 09624921210.

Privacy email: info@puradigital.it

Pura Digital S.r.l. has not formally appointed a Data Protection Officer (DPO). Privacy requests may be sent to the email address above.

2. Scope of this notice and privacy roles

Pura Digital acts as controller when it determines the purposes and means of processing data relating to the website, accounts, contractual relationship, platform management, billing, communications, and the security of its systems.

This notice does not govern processing carried out by third-party websites or services accessible via links, which operate under their own privacy notices. Providers engaged by Pura Digital to deliver parts of the website or communications are listed in the recipients section.

The contractual conditions governing the website and services are available in the Terms of Service.

3. Data processed and sources

We process only data relevant to the activities described in this notice. Data may come from the data subject, the organization they work for, the systems used to access the Service, and, for identity, payment, and security data, from providers used by Pura Digital.

Identification, contact, and authentication data: name, verified email address, account identifier, linked Google or Microsoft identity (if chosen by the user), public keys and metadata of any passkeys, sessions, and information needed to verify access.

Profile and onboarding data: avatar, language, role, use case, team size, referral source, and other optional information provided by the user.

Organization and collaboration data: organization name and logo, memberships, roles, invitations, and email addresses of members or invitees.

Contractual and usage data: subscription plan, subscription status, credits, features used, operations performed, requests, identifiers, and dates of application events.

Billing and payment data: customer and subscription identifiers, amounts, currency, payment status, and, at the payment provider, company name, billing email, address, tax ID or VAT number, and payment instrument data.

Customer content: uploaded documents, files, images, text, names and descriptions, metadata, annotations, instructions, processing outputs, transcription results, exports, training configurations, and metrics.

Preferences, consents, and authorizations: subscription status, revocation, interface preferences, and authorizations granted to external applications, including client identifiers, permissions, and approval or revocation dates.

Communications data: content of requests sent to Pura Digital and the related responses.

Technical and security data: IP address, date and time, requested URL, technical headers, request or session identifiers, browser or device type, logs, and events required to prevent abuse and diagnose errors.

Authentication and sessions are managed directly by Pura Digital. You can sign in with a one-time email code, or, if you choose, via Google or Microsoft. For the latter methods, we receive from the provider the identification and profile data needed to access and link the account. From the account, you can manage linked methods, sessions, and authorized applications.

Pura Digital does not receive the full card data used through the payment system. We also do not ask users to enter special categories of personal data, criminal-offence data, credentials, or identity documents in public forms. Please do not send such information through the website forms.

4. Purposes, legal bases, and retention

Demo request

Data processed
first name, last name, email, and, if provided, company, industry, and message.
Purpose and legal basis
manage the request, organize the demo, and take pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR).
Retention
up to 24 months from the last substantive contact. If a contractual relationship is established, the data flows into the relevant documentation and follows the applicable retention terms.

Account, authentication, sessions, and authorized applications

Data processed
verified email, account identifier, linked identities, public keys and passkey metadata, sessions, application authorizations, and security data.
Purpose and legal basis
create and manage the account, authenticate the user, and perform the contract (Art. 6(1)(b) GDPR); prevent unauthorized access and protect the Service based on the legitimate interest of Pura Digital and its users (Art. 6(1)(f) GDPR).
Retention
for the duration of the account. Upon closure, access is disabled; identifying profile data is normally deleted or anonymized within 30 days from when the user no longer belongs to any organization, subject to legal, security, or legitimate defense requirements.

Profile and onboarding

Data processed
name, avatar, language, role, use case, team size, referral source, and preferences.
Purpose and legal basis
configure the experience, provide requested features, and perform the contract (Art. 6(1)(b) GDPR); understand and improve onboarding and the Service based on the legitimate interest of Pura Digital (Art. 6(1)(f) GDPR).
Retention
for the duration of the account and normally up to 30 days after closure, except for aggregated or effectively anonymized data.

Organizations, roles, and invitations

Data processed
organization name and logo, memberships, roles, invitee email addresses, and invitation status.
Purpose and legal basis
create and administer organizations, manage access and collaboration, and perform the contract (Art. 6(1)(b) GDPR); ensure security and access traceability based on legitimate interest (Art. 6(1)(f) GDPR).
Retention
for the duration of the organization. Open invitations normally expire after 7 days; essential access information may be retained longer for security needs, contractual obligations, or protection of legitimate rights.

Platform delivery

Data processed
plan, credits, usage events, uploaded documents and their versions, files, images, text, metadata, annotations, instructions, outputs, transcription results, exports, training configurations and history, metrics, and model versions requested by the customer.
Purpose and legal basis
provide, maintain, and support the requested Service and perform the contract (Art. 6(1)(b) GDPR). For personal data contained in customer materials, Pura Digital normally acts as processor and the legal basis is determined by the customer acting as controller.
Retention
for the duration of the relationship and according to the customer's deletion choices, the Terms of Service, and any applicable DPA. Temporary exports normally expire after 7 days; deletions, backups, and legal obligations may follow different technical timelines.

Subscriptions, credits, payments, and invoices

Data processed
plan, customer and subscription identifiers, credits, amounts, currency, transaction status, and tax or billing data.
Purpose and legal basis
enter into and perform the contract (Art. 6(1)(b) GDPR), comply with tax and accounting obligations (Art. 6(1)(c) GDPR), prevent fraud or protect legitimate rights (Art. 6(1)(f) GDPR).
Retention
for the duration of the relationship; tax, accounting, and contractual documents are normally retained for 10 years. The payment provider also applies its own retention terms for financial, anti-fraud, and legal obligations.

Operational email and support

Data processed
email, name, organization, and information strictly necessary to describe the event, request, or outcome of an operation.
Purpose and legal basis
send invitations, account notifications, export notifications, and notifications relating to requested operations; provide support; perform the contract (Art. 6(1)(b) GDPR). Reliability and support are also pursued based on legitimate interest (Art. 6(1)(f) GDPR).
Retention
for the time necessary to deliver and manage the event; support correspondence is normally retained for up to 24 months after closure, subject to contractual, legal, or security requirements.

Direct communications

Data processed
contact data and communication content.
Purpose and legal basis
respond to data subject requests: pre-contractual measures (Art. 6(1)(b) GDPR) or legitimate interest in managing correspondence (Art. 6(1)(f) GDPR), depending on content.
Retention
up to 24 months after the request is closed, unless the communication must be retained for a contractual relationship or dispute.

Website and platform delivery, and security

Data processed
IP address, technical data, logs, events, and request or session identifiers.
Purpose and legal basis
deliver the systems, maintain reliability, prevent abuse and incidents, diagnose errors; contract performance for requested features (Art. 6(1)(b) GDPR) and legitimate interest of Pura Digital in security and proper system operation (Art. 6(1)(f) GDPR).
Retention
technical logs are normally retained for up to 30 days; authentication security events for up to 180 days. Data relating to an incident may be isolated and retained for up to 12 months or longer if necessary to comply with an obligation or protect legitimate rights.

Preferences and technical browser storage

Data processed
language, theme, editor preferences, tutorial state, last sign-in method used, and technical identifiers for a session or pending invitation.
Purpose and legal basis
remember requested settings, maintain the session, and complete initiated flows; contract performance (Art. 6(1)(b) GDPR) and legitimate interest in proper interface operation (Art. 6(1)(f) GDPR).
Retention
depending on function: for the session; until expiry or logout; for 7 days for sidebar preference; or until the user changes the setting or clears site data.

5. Provision of data and withdrawal of consent

Fields marked as required in the demo form are necessary to respond to the request; without them we cannot handle it. Data needed to create and protect the account, use contractual features, or complete a purchase is required to deliver the relevant Service. Other profile and onboarding data is optional, unless otherwise indicated in the interface.

The customer decides which content to upload to the platform and is responsible for having a valid legal basis, providing required information to data subjects, and complying with restrictions in the Terms and any applicable DPA. Not uploading content does not prevent account use but makes the related operations impossible.

To withdraw consent, use the unsubscribe link in our messages or write to info@puradigital.it.

6. Recipients and processors

Data is accessible to authorized Pura Digital staff and collaborators, within the limits required by their duties. It may also be communicated to the following recipients:

When they process data on behalf of Pura Digital, providers act as processors under an agreement compliant with Article 28 GDPR. Some providers may process data as independent controllers for their own legal or security obligations; in such cases, their respective privacy notices apply.

  • Amazon Web Services EMEA SARL, for primary cloud infrastructure, including compute, databases, object storage, and language models, configured in European Union regions (Frankfurt).
  • Stripe, Inc. (Stripe Payments Europe, Limited), for checkout, subscriptions, credits, billing, tax calculation, fraud prevention, and payment management.
  • Google LLC and Microsoft Corporation, only when the user chooses to sign in with their account or connect a document connector, for data required by the relevant authentication or authorization flow under their respective privacy notices.
  • Legal, tax, or technical advisors bound by confidentiality, where necessary.
  • Public authorities, supervisory bodies, or entitled parties where required by law.

For more information on cloud infrastructure, see the Amazon Web Services privacy notice.

For optional sign-in with Google, see the Google privacy notice.

For optional sign-in with Microsoft, see the Microsoft privacy notice.

For more information on payments, see the Stripe privacy notice.

7. Transfers outside the European Economic Area

Customer content, the platform's primary database, and object storage are configured on Amazon Web Services infrastructure in European Union regions (Frankfurt). Text embeddings and the semantic search engine are managed on servers owned by Pura Digital in the same EU area. This does not mean, however, that all processing connected to the Service takes place exclusively within the European Economic Area.

If the user chooses sign-in with Google or Microsoft, those providers may process authentication and technical data outside the European Economic Area under their respective notices. Stripe and financial network participants may process payment, billing, and anti-fraud data through international organizations. Authorized personnel or group companies of providers may also access data from other countries as necessary.

Where processing involves a transfer to a country not covered by an adequacy decision, Pura Digital requires appropriate safeguards under Articles 44 et seq. GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, participation in the Data Privacy Framework, together with supplementary measures proportionate to the risk.

Information on applicable safeguards may be requested by writing to info@puradigital.it.

8. Cookies and local browser storage

Pura Digital does not currently use profiling, advertising, or analytics cookies and does not track users across different websites.

On the marketing website, a cookie banner collects consent for non-essential third-party services such as Google reCAPTCHA and stores the user's choice in local storage.

The website and platform use cookies or equivalent technologies to provide requested functions and protect access. Pura Digital directly manages protected authentication and session cookies that cannot be accessed by page JavaScript (HttpOnly), are transmitted over HTTPS (Secure), and use SameSite protection. Sessions may last up to 90 days and expire after 30 days of inactivity; temporary cookies protect sign-in and linking flows for up to 10 minutes. The platform also uses a functional cookie to remember sidebar state for 7 days.

Language, theme, editor preferences, tutorial state, last sign-in method used, and a pending invitation identifier may be stored in local storage. OAuth tokens and security parameters of authentication flows are not stored in the application's local storage or session storage. Preferences remain until the user changes them or clears site data; tutorial state is removed on logout or account change.

Users can delete cookies and local storage from browser settings; this may sign out the account, interrupt an active flow, or reset preferences.

This section will be updated and, where required, consent will be obtained before introducing analytics, advertising, or profiling tools that are not strictly necessary.

9. Data security

Pura Digital adopts technical and organizational measures proportionate to the risks, including access control, data minimization, protection of communications in transit, system updates, credential management, and use of contractually selected providers.

No Internet-connected system can be considered risk-free. In the event of a personal data breach, Pura Digital will apply the procedures required by Articles 33 and 34 GDPR, including notification to the supervisory authority and data subjects where required.

10. Data subject rights

In the cases and within the limits provided by the GDPR, the data subject may request:

To exercise these rights, write to info@puradigital.it. We may request information needed to verify the identity of the requester.

Pura Digital responds without undue delay and normally within one month. In complex cases or with numerous requests, the deadline may be extended by two months, with information to the data subject within the first month. Exercising rights is free, except for manifestly unfounded or excessive requests as permitted by law.

The data subject may also lodge a complaint with the Italian Data Protection Authority or the supervisory authority of the State where they reside or work or where the alleged violation occurred.

  • access to personal data and a copy thereof;
  • rectification of inaccurate data or completion of incomplete data;
  • erasure of data;
  • restriction of processing;
  • data portability for data provided, where processing is automated and based on consent or a contract;
  • to object, for reasons related to their particular situation, to processing based on legitimate interest;
  • to object at any time to direct marketing;
  • to withdraw consent at any time.

11. Profiling and automated decisions

Pura Digital does not use account, website, or platform data to profile people for advertising purposes and does not use decisions based solely on automated processing that produce legal effects or similarly significant effects on the data subject under Article 22 GDPR. AI-assisted features produce outputs that must be verified by the user and are not intended to autonomously make such decisions about natural persons.

12. Third-party data, minors, and sensitive data

Anyone providing personal data of other people must be authorized to do so and must provide those people with the necessary information. Where Pura Digital receives data other than directly from the data subject, it fulfills information obligations under Article 14 GDPR where applicable.

The ArchivEye website and services are intended for adults and organizations and are not directed at children under sixteen. If we become aware of children's data collected without a valid basis, we delete it or take other measures required by law.

Do not enter health, biometric, genetic, political opinions, religious beliefs, sexual life, ethnic origin, trade union membership, convictions or offences, or other information not necessary to the request through public forms.

Customers may process third-party data on the platform only if they have a valid legal basis and comply with the DPA, instructions, and applicable measures. Special categories of data, criminal data, or other high-risk content must not be uploaded until the applicable DPA and Plan expressly authorize it and adequate safeguards have been agreed.

13. Data processed on behalf of customers

When a customer uses the platform to process personal data for its own purposes, the customer determines the purposes and essential means and normally acts as controller; Pura Digital normally acts as processor and follows the customer's documented instructions.

Before uploading third-party personal data, the customer must enter into or accept a Data Processing Agreement compliant with Article 28 GDPR, governing, among other things, instructions, confidentiality, security measures, sub-processors, assistance, incidents, audits, transfers, and deletion or return of data.

Data subjects must address requests relating to customer datasets to the customer itself, without prejudice to the assistance Pura Digital is required to provide.

14. Updates to this notice

Pura Digital may update this notice to reflect regulatory, organizational, or technical changes. The current version is published on this page with the date of the last update.

Substantial changes will be communicated through proportionate means, for example on the website or by email where relevant contacts are available. If new processing requires consent, it will be requested before it begins; continued browsing alone will not be considered consent.

Before introducing new processing, data categories, or providers, Pura Digital will assess the impact on this notice and update it where necessary. If new processing requires consent, it will be obtained before launch.

The Italian version of this Privacy Notice is the only legally valid and authentic version. In case of conflict, ambiguity, or divergence in interpretation between it and a translation, the Italian text prevails.

For questions about privacy, the DPA, or data subject rights, write to info@puradigital.it.