BETA VERSION 13 · UPDATED 3 AUGUST 2026
Privacy notice
This notice, provided under Articles 12 and 13 GDPR, explains what Archiviorum processes, why, for how long, and the choices available to you.
1. Controller
Blue Lagoon Maritime Trading Limited, registration C 114006, VAT MT32425417, registered office at Mercieca Suite 4, Triq it-Tabib Anton Tabone, Rabat, Għawdex, VCT 9020, Malta. Contact: trading@blmt-ltd.com.
2. Data and operation
- On-device analysis: uploaded documents, OCR, extracted dates and the local draft remain in your browser during analysis.
- Installable app: if you add Archiviorum to your Home Screen, the browser may store only the manifest, app icons and the technical offline page on the device. The service worker does not cache documents, API responses, account data or payment information.
- Archiviorum account: we process your name, email, a protected password hash, salt, security parameters and technical session data needed to create the account and keep it signed in. We never store the plain-text password.
- Account recovery: when generated, the plain recovery code is shown to you once. The database stores only its hash and technical information used to limit attempts. A new code replaces the previous one; a code used to reset the password is invalidated together with existing sessions.
- Optional cloud: documents, original files and metadata are uploaded only when you expressly choose “Save to cloud”.
- Document content: files may contain personal data about you or third parties selected by you. Archiviorum does not send document content to an artificial-intelligence model: OCR, initial ordering and PDF generation run in the browser. If you use the cloud, content is stored so that you can retrieve it.
- Derived data: dates, categories, confidence levels, summaries, dossier settings and the PDF result from your choices and local analysis. You must verify them before use or sharing.
- Payments: we retain Stripe identifiers, email, dossier, plan, amount, currency, status, billing or subscription dates, terms version and consent evidence. Stripe collects billing and tax details and card data; we do not receive the full card number.
- Beta invitations: the full code is shown to the controller once. We retain only its cryptographic hash, a partial prefix, channel label, expiry, status and use count. When an invitation is redeemed, we record the account, unlocked dossier, date and accepted terms and privacy versions to prevent reuse and preserve free access to that dossier.
- Product measurement: we record technical counts of page loads, actions such as completed upload, preview, checkout, purchase, beta-invitation redemption, PDF generation and download, opening or completing PWA installation, optional answers to closed quality questions, sharing actions and visits from generic links. Campaign links identify only the distribution channel, such as LinkedIn or Product Hunt, never the person opening them. Measurement events contain no free-text comment, email, account identifier, IP address, filename or document content and are not used to reconstruct an individual person’s journey.
- Security: the service and infrastructure providers may produce technical logs, IP addresses, browser information and events needed to prevent abuse and resolve problems.
3. Purposes and legal bases
We process data to provide accounts, optional cloud storage, payment, invoices and export under the contract; to meet tax and legal obligations; to measure feature use in a minimised form and improve the beta product without individual profiling; and to protect the service and prevent fraud based on legitimate interests. We do not sell this data, use it for advertising, or make automated decisions producing legal effects.
Email, password and minimum session data are required to create an account; billing data is required to conclude and document a purchase. Uploads and cloud storage are optional, but without files we cannot create a dossier and without cloud storage we cannot synchronise it across devices. Data comes from you, your actions in the service and, for payments and subscriptions, Stripe.
4. Providers and transfers
We may use OpenAI for the publishing platform, Cloudflare for hosting, database and storage, and Stripe for payment, invoicing and subscription management. They process data in the applicable role; Stripe may also act as an independent controller for certain payment, security and compliance activities. We do not disclose data to advertising intermediaries.
Some processing may take place outside the EEA. Where the GDPR requires it, we rely on adequacy decisions, standard contractual clauses or other applicable safeguards. You may request information about relevant safeguards from the controller.
5. Retention
Local drafts remain until you delete them or clear browser data. Cloud copies remain until you delete them in the app or delete the account. Archiviorum sessions expire after 30 days; a recovery code remains valid until used or replaced. Account data remains until deletion or for as long as needed to provide the service.
Unchanged originals in the ZIP remain unchanged; the dossier PDF uses optimised copies. Payment, billing and accounting records are retained for the period required by applicable law; technical logs only as long as needed for security, diagnosis and abuse prevention. Minimised product events and beta-invitation records are scheduled for deletion after 13 months and removed from the active system during the next relevant cycle, or further aggregated. Account deletion removes beta-redemption data linked to its email first.
6. Account deletion
From Account security, you may request deletion by entering your current password and the required confirmation. This permanently deletes the Archiviorum account, sessions, recovery-code hash, cloud dossiers and metadata, uploaded files, beta redemptions and export entitlements associated with the email. If a subscription is still set to renew, you must first cancel renewal in the Stripe portal; paid access remains available until its scheduled end.
The process also removes local drafts from the device and browser used at that moment. Drafts on other devices or browser profiles must be deleted separately. Account deletion does not remove invoices, transactions or other records that the supplier or Stripe must retain for tax, accounting, fraud-prevention or other legal obligations; where possible, the operational link to the account is removed or de-identified.
7. Your rights
You may request access, correction, deletion, restriction, objection and portability where applicable by emailing trading@blmt-ltd.com. If processing were based on consent, you could withdraw it at any time without affecting prior processing. We may request reasonable information to verify the requester’s identity.
A request is normally free of charge and will be answered without undue delay, generally within one month. Deletion may be limited where processing is needed to comply with a legal obligation or establish, exercise or defend a legal claim. You may complain to Malta’s Information and Data Protection Commissioner or the competent authority in your country.
Your rights on the IDPC website ↗8. Cookies and necessary technologies
We use no advertising or analytics cookies, and product measurement stores no browser identifier. A protected technical session cookie, inaccessible to page scripts, is used only to keep an Archiviorum account signed in. IndexedDB and browser local storage keep drafts and the language preference on the device; the service worker stores only technical PWA resources.
Stripe and infrastructure providers may use technologies strictly necessary for payment, security and operation. If we later introduce advertising, non-essential tools or persistent identifiers, we will update this notice and request consent where required.
9. Security and third-party data
We apply proportionate measures such as salted password derivation, HttpOnly and Secure cookies, attempt limits, origin checks, account authorisation and cloud-file separation. No system is risk-free: use a unique password, store the recovery code safely and upload only relevant documents.
Avoid uploading special-category, criminal-offence or third-party data unless strictly necessary and you have the right and a valid legal basis to do so. If you use Archiviorum for an organisation, you are responsible for checking your duties as controller before uploading customer, employee or other personal data.
10. Children
Purchases and account creation are restricted to adults aged 18 or over. The service is not intentionally directed to children.
11. Updates and language
We may update this notice when the service or applicable rules change. The date and version above identify the current text. The Italian and English versions are the reference texts; any courtesy translation must be reviewed before it is used as legal documentation.