pursuant to Articles 13 and 14 of Regulation (EU) 2016/679
Version dated 8 June 2026
Introduction
Archiva Group, a brand owned by Archiva S.r.l. (a single-member company), which comprises the companies listed in Annex A to this notice, hereby informs you about the processing of your personal data carried out in the context of its relationship with its customers. Throughout this notice, Archiva Group may be referred to simply as “Archiva” or, where a specific provision relates solely to a single legal entity within Archiva Group, by the short name of the company to which that provision refers.
This website may include plugins, links to social networks or platforms for the distribution of audiovisual content. Interaction with these elements means that certain data may be transmitted to the provider of the plugin, social media platform or content platform, in order to enable the necessary use of the content provided therein. The privacy notices regarding the processing of personal data carried out by the aforementioned providers can be found on their respective websites.
Data Controller
With regard to personal data processed via the website or other information systems (CRM, HR management system, ERP), Archiva acts as the Data Controller, in accordance with Article 4(7) of Regulation (EU) 2016/679 (hereinafter the “GDPR”).
However, in specific operational scenarios, Archiva may process personal data on behalf of other companies, or vice versa, acting as a Data Processor in accordance with Article 28 of the GDPR. Such cases include, for example, the provision of infrastructure services, the technical management of the website, or the hosting of online forms and platforms. The roles between the companies within the Archiva Group are formalised through internal joint-controller agreements or appointments as Data Processors, signed between the parties, which transparently regulate their respective responsibilities. The up-to-date list of processing operations for which a Data Processor role is envisaged may be requested from each company via the contact details provided below in this notice.
Purposes, legal basis and duration of processing
The processing of personal data serves the following possible purposes:
| Purposes of processing | Type of data subject | Categories of data processed | Legal basis for processing | Duration of processing |
| a) for purposes relating to the performance of pre-contractual or contractual measures, activities connected with and/or instrumental to the provision of such a service, and for purposes relating to the further processing of the same data; | Prospects and Customers | General data: first name, surname, email address, telephone number |
Article 6.1.b: processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the data subject’s request; |
For the entire duration of the existing contractual relationship and, following its termination, for a maximum of 10 years in accordance with Article 2220 of the Italian Civil Code (Keeping of accounting records) |
| b) for administrative and accounting purposes, such as the management of accounts and cash flow, as well as invoicing, in accordance with the requirements of current legislation or for the fulfilment of other obligations laid down by laws, regulations and national and EU legislation; | Prospects and Customers | General data: first name, surname, email address, telephone number | Article 6.1.c: processing is necessary to comply with a legal obligation to which the data controller is subject | For the entire duration of the existing contractual relationship and, following its termination, for a maximum of 10 years in accordance with Article 2220 of the Italian Civil Code (Keeping of accounting records) |
| c) for purposes related to the need to consult accounting, fiscal, tax and administrative documentation in general, beyond the statutory 10-year retention period, in order to respond to any requests and/or inspections by the relevant authorities; | Prospects and Customers | General data: first name, surname, email address, telephone number |
Article 6.1.f: processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, provided that the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data, in particular where the data subject is a child. |
For a period of 10 years following the expiry of the retention period laid down in Article 2220 of the Italian Civil Code; |
| d) to assert and/or defend the Data Controller’s rights in out-of-court and judicial proceedings, dispute resolution, cases of breach of contract, formal notices, settlements, debt recovery, credit protection and arbitration | Prospects and Customers | General data: first name, surname, email address, telephone number |
Article 6.1.f: the processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, to provided that the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child. |
For the entire duration of the out-of-court and judicial proceedings until the expiry of the limitation periods for the right and/or the forfeiture of the right of action and/or the period within which appeals may be lodged. |
Nature and methods of processing
Archiva Group declares that the processing of personal data carried out for the purposes indicated above will be conducted in compliance with the applicable national and supranational regulations governing ‘personal data protection’.
In accordance with the aforementioned laws, the processing carried out by Archiva Group will be based on the principles of fairness, lawfulness and transparency, safeguarding the rights and freedoms of data subjects.
The provision of personal data is mandatory for the purposes listed above. Therefore, failure to provide such data, or the provision of incomplete or inaccurate data, could result in the Data Controller being objectively unable to process and carry out the activities relating to the request made by the data subject in the normal course of business. Personal data will be processed electronically or in paper form, using methods strictly related to the aforementioned purposes.
This privacy notice does not apply to websites other than the one explicitly mentioned.
Data processing is carried out by adopting appropriate technical and organisational measures, in line with the principles of data protection by design and data protection by default. Archiva carries out periodic security checks and has obtained numerous third-party certifications, which can be viewed at https://www.archivagroup.com/it/archiva/sicurezza-e-privacy.
Personal data is processed primarily at the Data Controller’s premises and will not be transferred to countries outside the EU.
Categories of recipients to whom personal data may be disclosed
Personal data processed by Archiva Group may be disclosed to employees or contractors of the Data Controller, for processing within their respective areas of responsibility; these individuals, operating under the direct authority of the Data Controller and in compliance with specific security measures provided to them, will process personal data in accordance with data protection principles.
Personal data may also be transmitted to any Data Processors appointed pursuant to Article 28 of the GDPR who, acting under the direct authority of the Data Controller, will receive appropriate instructions. The same will apply to any Data Processors in relation to their employees or collaborators.
Please also note that personal data may be disclosed to parties essentially falling within the following categories; a full list of these may be requested from the Data Controller via the contact details set out in Annex A to this notice:
- Public bodies and administrations: for audits and checks in compliance with tax and civil law obligations.
- Banks and credit institutions: for the execution of financial transactions (payments/receipts);
- Law firms, consultancy firms, notaries and accountants: for consultancy services within their respective areas of professional expertise;
- IT infrastructure maintenance companies, software suppliers and manufacturers, and cloud service providers: for the production and delivery of software, for routine hardware and software maintenance, for any data recovery, and for the delivery of multimedia content;
- Companies specialising in the disposal and storage of paper-based documentation: for the destruction and storage of such documentation;
- Certification and accreditation bodies: for verification activities aimed at obtaining and/or maintaining the certifications held by Archiva S.r.l., a single-member company;
- Communications and event management agencies: for activities falling within their remit.
Data Protection Officer (DPO)
Archiva Group has appointed a Data Protection Officer who can be contacted by email at the following address:dpo.privacy@archivagroup.it.
The following is a non-exhaustive list of situations in which the DPO may be contacted and/or should be contacted:
- if you wish to exercise a right recognised by the European General Data Protection Regulation;
- if you wish to contest the rejection of a request to exercise a right, or if you consider that the response was unsatisfactory or was not provided within the specified timeframe;
- if you believe that your personal data has been breached during processing carried out by the Data Controller or the Data Processor;
- if you believe that the privacy notice provided to you is not sufficiently clear and transparent;
- if you consider it necessary to receive clarification or further details regarding the processing of your personal data (purposes, legal basis, retention periods, methods of processing, etc.);
- if you need information in order to lodge a complaint with the supervisory authority.
Rights of the data subject
The data subject may, at any time, exercise their rights vis-à-vis the Data Controller in accordance with Articles 15 to 21 of the GDPR, the full text of which is hereby incorporated by reference.
The data subject shall have the right to request from the Data Controller access to their personal data, the rectification or erasure of such data, or to object to their processing; they shall also have the right to request the restriction of processing, as well as to obtain, in a structured, commonly used and machine-readable format, the data concerning them. Furthermore, the data subject may, at any time, withdraw their consent for processing operations based on that legal basis, without this affecting the lawfulness of any processing carried out on the basis of consent prior to the withdrawal.
Finally, the data subject may lodge a complaint with the competent supervisory authority if they consider that their rights have not been respected, in breach of the principles of the GDPR, in accordance with the procedures set out, for example, on the Data Protection Authority’s website, accessible at www.garanteprivacy.it.
These rights may be exercised by completing the relevant form available on the website http://www.archivagroup.com/ or by sending a message to the certified email address: privacy@pec.archivagroup.it (which can also be contacted via standard email).
Changes to the privacy notice
This privacy notice may be subject to updates in accordance with national and European regulatory provisions, as well as by virtue of operational decisions made by the Data Controller. Unless otherwise specified, it will continue to apply to personal data processed up to that point. In the event of significant changes to the privacy notice, notification will be provided via a banner on the website or a direct email, where applicable.