Data protection information Suppliers

pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Version dated 18 June 2026

Introduction

Archiva Group, a brand owned by Archiva S.r.l. (a single-member company), which comprises the companies listed in Annex A to this notice, hereby informs you about the processing of your personal data carried out in the context of its relationship with its suppliers. Throughout this notice, Archiva Group may be referred to simply as “Archiva” or, where a specific provision relates solely to a single legal entity within Archiva Group, by the short name of the company to which that provision refers.  
This website may include plugins, links to social networks or platforms for the distribution of audiovisual content. Interaction with these elements means that certain data may be transmitted to the provider of the plugin, social media platform or content platform, in order to enable the necessary use of the content provided therein. The privacy notices regarding the processing of personal data carried out by the aforementioned providers can be found on their respective websites.

Data Controller

With regard to personal data processed via the website or other information systems (CRM, HR management system, ERP), Archiva acts as the Data Controller, in accordance with Article 4(7) of Regulation (EU) 2016/679 (hereinafter the “GDPR”).
However, in specific operational scenarios, Archiva may process personal data on behalf of other companies, or vice versa, acting as a Data Processor pursuant to Article 28 of the GDPR. Such cases include, for example, the provision of infrastructure services, the technical management of the website, or the hosting of online forms and platforms. The roles between the companies within the Archiva Group are formalised through internal joint-controller agreements or appointments as Data Processors, signed between the parties, which transparently regulate their respective responsibilities. The up-to-date list of processing operations for which a Data Processor role is envisaged may be requested from each company via the contact details provided below in this notice.

Purposes, legal basis and duration of processing

The processing of personal data serves the following possible purposes:  

Purposes of processing Type of data subject Categories of data processed Legal basis for processing Duration of processing
a) for purposes relating to pre-contractual obligations (e.g. quotation management) and/or contractual obligations between Archiva and the Supplier. The processing may also involve the personal data of the Supplier’s employees/collaborators involved in the activities; Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.b: processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request; For the entire duration of the contractual relationship and, following its termination, for a maximum of 10 years in accordance with Article 2220 of the Italian Civil Code (Keeping of accounting records);
b) for the completion of self-certifications or documentation relating to the requirements necessary for the provision of the service covered by the Archiva-Fornitore contract; Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.b: processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request; For the entire duration of the contractual relationship and, following its termination, for a maximum of 10 years in accordance with Article 2220 of the Italian Civil Code (Keeping of accounting records);
c) for administrative and accounting purposes, such as the management of accounts and administration, in accordance with the requirements of current legislation, or for the fulfilment of other obligations laid down by laws, regulations and EU legislation; Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.c: processing is necessary for compliance with a legal obligation to which the data controller is subject; For the entire duration of the contractual relationship and, following its termination, for a maximum of 10 years in accordance with Article 2220 of the Italian Civil Code (Keeping of accounting records);
d) for purposes related to the need to consult accounting, fiscal, tax and administrative documentation in general, beyond the statutory 10-year retention period, in order to respond to any requests and/or inspections by the relevant authorities Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.f: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child. For a period of 10 years following the expiry of the retention period laid down in Article 2220 of the Italian Civil Code;
e) to assert and/or defend the Data Controller’s rights in out-of-court and judicial proceedings, dispute resolution, cases of breach of contract, formal notices, settlements, debt recovery, credit protection and arbitration; Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.f: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child. For the entire duration of any out-of-court and court proceedings, until the expiry of the limitation periods for the right and/or the forfeiture of the right to bring an action and/or the period within which appeals may be lodged;
f) to verify that Suppliers meet the requirements set out in the selection policies and procedures Suppliers Common data: first name, surname, email address, telephone number Articolo 6.1.f: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.

For the entire duration of the existing contractual relationship and, following its termination, for a maximum of 20 years.

Nature and methods of processing

Archiva Group declares that the processing of personal data carried out for the purposes indicated above will be conducted in compliance with the applicable national and supranational regulations governing ‘personal data protection’.
In accordance with the aforementioned laws, the processing carried out by Archiva Group will be based on the principles of fairness, lawfulness and transparency, safeguarding the rights and freedoms of data subjects.
The provision of personal data is mandatory for the fulfilment of the purposes listed above. Therefore, failure to provide such data, or the provision of incomplete or inaccurate data, could result in the Data Controller being objectively unable to process and carry out the activities relating to the request made by the data subject in the normal course of business. Personal data will be processed electronically or in paper form, using methods strictly related to the aforementioned purposes.
Processing is carried out by adopting appropriate technical and organisational measures, consistent with the principles of data protection by design and data protection by default. Archiva implements periodic security checks and has obtained numerous third-party certifications, which can be viewed at https://www.archivagroup.com/it/archiva/sicurezza-e-privacy.
Personal data is processed primarily at the Data Controller’s premises and will not be transferred to countries outside the EU.

Categories of persons who may become aware of personal data

Personal data processed by Archiva Group may be disclosed to employees or contractors of the Data Controller, for processing within their respective areas of responsibility; these individuals, operating under the direct authority of the Data Controller and in compliance with specific security measures provided to them, will process personal data in accordance with data protection principles.
Personal data may also be disclosed to any Data Processors appointed pursuant to Article 28 of the GDPR who, acting under the direct authority of the Data Controller, will receive appropriate instructions. The same will apply to any Data Processors in relation to their employees or staff members.
Please also note that personal data may be disclosed to parties essentially falling within the following categories; a full list of these may be requested from the Data Controller via the contact details set out in Annex A to this notice:

  • Public bodies and authorities: for audits and checks in compliance with tax and civil law obligations.
  • Banks and credit institutions: for the execution of financial transactions (payments/receipts);
  • Law firms, consultancy firms, notaries and chartered accountants: for consultancy services within their respective areas of professional expertise;
  • IT infrastructure maintenance companies, software suppliers: for routine hardware and software maintenance, software production and distribution, or for any data recovery;
  • Paper document disposal companies: for the destruction of paper documents;
  • Certification bodies and accreditation bodies: for verification activities aimed at obtaining and/or maintaining the certifications held by Archiva S.r.l., a single-member company

Data Protection Officer (DPO)

Archiva Group has appointed a Data Protection Officer who can be contacted by email at the following address:dpo.privacy@archivagroup.it.
The following is a non-exhaustive list of situations in which the DPO may be contacted and/or should be contacted:

  • if you wish to exercise a right recognised by the European General Data Protection Regulation;
  • if you wish to contest the rejection of a request to exercise a right, or if you consider that the response was unsatisfactory or was not provided within the specified timeframe;
  • if you believe that your personal data has been breached during processing carried out by the Data Controller or the Data Processor;
  • if you believe that the privacy notice provided to you is not sufficiently clear and transparent;
  • if you consider it necessary to receive clarification or further details regarding the processing of your personal data (purposes, legal basis, retention periods, methods of processing, etc.);
  • if you need information in order to lodge a complaint with the supervisory authority.

Rights of the data subject

The data subject may, at any time, exercise their rights vis-à-vis the Data Controller in accordance with Articles 15 to 21 of the GDPR, the full text of which is hereby incorporated by reference.
The data subject shall have the right to request from the Data Controller access to their personal data, the rectification or erasure of such data, or to object to their processing; they shall also have the right to request the restriction of processing, as well as to obtain, in a structured, commonly used and machine-readable format, the data concerning them. Furthermore, the data subject may, at any time, withdraw their consent for processing operations based on that legal basis, without this affecting the lawfulness of any processing carried out on the basis of consent prior to the withdrawal.
Finally, the data subject may lodge a complaint with the competent supervisory authority if they consider that their rights have not been respected, in breach of the principles of the GDPR, in accordance with the procedures set out, for example, on the Data Protection Authority’s website, accessible at www.garanteprivacy.it.
These rights may be exercised by completing the relevant form available on the website http://www.archivagroup.com/ or by sending a message to the certified email address: privacy@pec.archivagroup.it (which can also be contacted via standard email).

Changes to the privacy notice

This privacy notice may be subject to updates in accordance with national and European regulatory provisions, as well as by virtue of operational decisions made by the Data Controller. Unless otherwise specified, it will continue to apply to personal data processed up to that point. In the event of significant changes to the privacy notice, notification will be provided via a banner on the website or a direct email, where applicable.