Skip to content

Privacy Policy

Last updated: 22 September 2026

Notice given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

1. Controller

The controller is Archiva Group (the “Controller”), which operates the Perlegis service. The Controller's contact details and, where appointed, those of the Data Protection Officer are published on the Controller's official channels and reachable at [email protected].

2. Categories of data processed

  • identification and contact data (name, email address);
  • credentials and authentication data, handled by a self-hosted authentication service on the Controller's own infrastructure;
  • service usage data: calendar events, deadlines, matters, shares, preferences and backups;
  • documents and attachments uploaded to the archive or to the assistant, together with the text extracted from them (including by optical character recognition);
  • the content of tasks handed to the assistant and of its replies, including any voice dictation;
  • notification identifiers (push tokens) for the devices on which alerts are enabled;
  • billing data and subscription status;
  • technical metadata (IP address, user agent, timestamp) processed for security and audit purposes;
  • anonymous browsing data on the perlegis.ai site (pages visited, interactions, session recording), only with consent to analytics cookies — see the Cookie Policy.

Case files entered into the service may contain third parties' personal data, including special categories, covered by professional secrecy. In respect of that data the user acts as an independent controller and the Controller acts as processor under Article 28 GDPR.

3. Purposes and legal bases

  • performance of the contract and provision of the service (Art. 6.1.b GDPR);
  • legal, accounting and tax obligations (Art. 6.1.c GDPR);
  • platform security, abuse prevention and protection of rights (Art. 6.1.f GDPR);
  • operation of the assisted features — extracting data from uploaded filings and preparing the assistant's proposals — as part of the service requested (Art. 6.1.b GDPR);
  • commercial communications, only where an appropriate legal basis exists.

4. How data is processed

Processing uses electronic tools and organisational measures suited to ensuring confidentiality, integrity and availability. Data is encrypted in transit and at rest, and isolation between users is enforced at the database layer, not only in the application.

5. Retention

Data is kept for as long as necessary for the purposes stated and in line with legal obligations. Periods may vary with the user's requests, tax obligations and the need to establish or defend a legal claim. On account closure data is deleted or returned at the user's request.

Encrypted database backups are retained for a maximum of 14 days, after which they are deleted automatically. Deletion requested by the user takes effect immediately on the production systems; it is completed within that window, once backups predating the request are themselves deleted.

6. Recipients and processors

Data may be processed by suppliers appointed as processors, including:

  • the infrastructure provider hosting the servers, located in the European Union;
  • the network and edge protection provider;
  • the payment services provider, for subscription management;
  • the artificial intelligence provider that processes the text, documents and audio sent to the assistant, established in the United States of America;
  • the provider of the perlegis.ai site's analytics (PostHog, Inc.), limited to browsing data on the public pages and only with consent to analytics cookies, with data collected and stored on the provider's European infrastructure (Frankfurt, Germany); what is collected is detailed in the Cookie Policy.

Service email is sent through a relay operated directly by the Controller. Text extraction from uploaded documents, optical character recognition included, also runs on the Controller's own infrastructure, with no third-party supplier.

In the application, the introductory video offered at first sign-in is hosted on YouTube. If you choose to start it, your browser sends Google Ireland Limited your IP address and the technical data of the request, which Google processes as an independent controller under its own privacy policy; if you do not start it, nothing reaches Google. Details in the Cookie Policy.

Where the account was provisioned by a reseller, that reseller is appointed as a processor for first-line support: it can read the text of the support requests you raise from the application, their attachments, and the transcript of the assistant conversation that produced the request, if any.

The reseller can also open the account in read-only mode for support purposes: for up to thirty minutes it sees the application as you see it, including matters, deadlines, clients and archived documents. During such a session the reseller cannot create, change or delete any data, and full data export and the calendar synchronisation address remain excluded in any case. Every opening and every closing is logged, with the operator's identity, the instant and the reason given, if any; the log is kept by the Controller and can be consulted at the data subject's request. The access takes place within the instructions given by the Controller to the processor and is covered by a duty of confidentiality.

The assisted features are optional: if you do not use the assistant and do not upload documents, no case-file content is sent to the artificial intelligence provider. An up-to-date list of processors is available on request at [email protected].

7. Transfers outside the EU

The servers hosting the service, the backups and the document archive are located in the European Union. The exception is the artificial intelligence provider named in section 6: text, documents and audio sent to the assistant are transmitted to the United States of America solely to produce the reply. For that transfer the Controller applies the safeguards required by Chapter V GDPR, including Standard Contractual Clauses, and has agreed terms with the provider that exclude use of the content for model training. The site's analytics provider is established in the United States of America but collects and stores browsing data in the European Union; any access by the provider is covered by the same safeguards, Standard Contractual Clauses included. Data the video player sends to Google, if you start the introductory video, is processed by Google under its own responsibility and may be processed outside the European Union too, with the safeguards described in its privacy policy.

8. Data subject rights

Data subjects may exercise the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, objection, portability and withdrawal of consent where applicable. A complaint may also be lodged with the Italian Data Protection Authority.

9. Whether provision is required

Providing the data needed to operate the service is required to conclude and perform the contract; refusal makes provision of the service impossible.

10. Automated decision-making

No decisions are taken solely on the basis of automated processing producing legal effects for the data subject. Automatic computation of procedural deadlines is a support tool: the proposed dates require the practitioner's verification, and the practitioner remains solely responsible for meeting the terms. The same applies to the assistant's proposals and to data extracted from uploaded filings: they stay proposals until the practitioner confirms them, and produce no effect on their own.

11. Updates

This notice may be updated over time. The version in force is always available on the site's legal pages.

Contact

To exercise your rights, or for any question about this notice, write to [email protected].

Back to the home page