ArchivEye

Privacy & Security

Your data. Clear answers.

Where it is stored, who can access it, and how it is used. The information you need to make an informed choice about ArchivEye.

01

Core infrastructure in the EU.

Where is my data?

02

Never used to train third-party models.

Does my data train AI?

03

Permissions, sessions, and connected apps.

Can I control access?

The essentials

01

Where is my data?

Core infrastructure in the EU.

Content, databases, and object storage run on AWS in EU regions (Frankfurt). Embeddings and semantic search run on Pura Digital servers in the same area. Authentication is managed directly by Pura Digital.

Infrastructure and provider details →
02

Does my data train AI?

Never used to train third-party models.

On paid plans, your content and organization data do not train our models either. On Personal Starter, we may use anonymized, aggregated usage data.

The rules for each plan →
03

Can I control access?

Permissions, sessions, and connected apps.

Permissions govern access to your collections. From your account, you can manage linked methods, revoke sessions, and revoke authorizations to external applications, including MCP clients.

Available controls →

How your data is used

On every plan, uploaded content is not used to train third-party models.

Personal

Anonymized, aggregated usage data.

On Personal Starter, we may use effectively anonymized and aggregated usage data to improve ArchivEye's models. Uploaded content is not used to train third-party models.

Business

Your data does not train our models.

Content and organization data are not used to train or improve ArchivEye's models. This guarantee is part of the contract.

Collections have separate access controls. Business Enterprise can include dedicated infrastructure or on-premise deployment, including air-gapped environments.

Compare plans →

Where data flows

Core compute, databases, object storage, and language models run on Amazon Web Services in EU regions (Frankfurt). Embeddings and semantic search run on Pura Digital servers in the same EU area.

Read the notice on recipients and transfers →

Amazon Web Services

Primary cloud infrastructure in EU regions: compute, databases, object storage, and language models.

Pura Digital

Authentication, sessions, text embeddings, and semantic search engine on EU infrastructure.

Stripe

Checkout, subscriptions, credits, billing, tax calculation, and fraud prevention.

Google / Microsoft

Account sign-in, linking, and document connectors, only when you choose these methods.

Not all processing takes place exclusively in the EU. Google, Microsoft, and Stripe may process data outside the EEA under GDPR safeguards.

Controls you can use today

Sign-in and authorizations

Sign in with a one-time email code, a passkey, Google, or Microsoft. Manage linked methods and revoke sessions and apps, including MCP clients. Sensitive changes require a recent sign-in.

Collections and permissions

Organize documents in separate collections and define who can read or query them. API keys and MCP tokens follow the same permissions configured in your account.

Organization SSO and audit logs are coming soon for eligible plans.

More privacy questions

Who can access my data?

Access follows the permissions assigned to your collections. Authorized ArchivEye staff access data only as needed for their duties. Providers process the data needed to deliver their services, under the roles and agreements described in our policies.

What happens if I delete my account?

Access is disabled. Identifying profile data is normally deleted or anonymized within 30 days, subject to legal or security needs. Collection content follows the customer's choices, the Terms, and any applicable DPA; backups and deletion may follow different technical timelines.

Do you use cookies to track me?

We do not use advertising, profiling, or analytics cookies, and we do not track users across websites. Technical cookies and local storage support sign-in, security, and preferences such as language and theme.

Can I upload personal or health data?

Before uploading third-party personal data, you must sign or accept a DPA, the data processing agreement. Health data, criminal-offence data, and other high-risk content require explicit authorization in the DPA and applicable plan. Contact us before uploading to check these conditions.

How do I exercise my data rights?

You can write to info@puradigital.it to request access, a copy, correction, or deletion of personal data. If the data is in a collection managed by your organization, address the request to that organization; Pura Digital provides the required support.

Read the details in the privacy notice →

Transparency and compliance

Privacy by design

Access controls, data minimization, and transparency about processing guide the design of the ArchivEye platform, operated by Pura Digital S.r.l.

Data quality, documentation, and traceability support AI Act workflows. Roles, purposes, rights, and the DPA are described in the full privacy notice.

Full privacy notice

For the controller, recipients, transfers, cookies, data subject rights, and data processed on behalf of customers, see the privacy notice.

Open the privacy notice →

Have a question about your use case?

Write to us to clarify privacy requirements, the DPA, or deployment options before uploading your data.