Privacy Policy
Last updated: 2026-03-09
Data Controller
ARCHIGENIUS, UNIPESSOAL LDA
NIF: 519232526
Rua Elias Garcia, 45, 3.ΒΊ Dto Frente
4430-091 Mafamude, Vila Nova de Gaia, Portugal
Email: support@archigenius.ai
Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, company name
- Product data: product descriptions, materials, supplier information entered into DPP forms
- Usage data: pages visited, features used, timestamps
- Technical data: IP address, browser type, device information
- Payment data: processed securely by Stripe (we do not store card details)
How We Use Your Data
- Provide and maintain the DPP Studio service
- Generate and publish Digital Product Passports
- Process payments and manage subscriptions
- Provide customer support
- Improve and optimise the platform
- Comply with legal obligations (ESPR, GDPR)
Legal Basis for Processing
- Contract performance: processing necessary to provide the service you subscribed to
- Legitimate interest: analytics to improve the platform, fraud prevention
- Legal obligation: regulatory compliance (ESPR record-keeping, tax obligations)
- Consent: marketing communications (opt-in only)
Data Storage & Location
All data is stored in the European Union (Supabase, Frankfurt region). Backups are encrypted and retained within the EU. We use Vercel for hosting with EU edge deployment.
Data Sharing
We share data only with the following service providers, all with appropriate data processing agreements:
- Supabase (EU Frankfurt) β Database, authentication, file storage
- Vercel (EU) β Hosting and edge functions
- Stripe (EU/US with SCC) β Payment processing
- Resend (US with SCC) β Transactional emails
We never sell, rent, or trade your personal data to third parties.
Data Retention
Account data is retained for the duration of your subscription plus 30 days. DPP data is retained for the lifetime of the product plus 10 years, as required by ESPR. Audit logs are retained indefinitely for regulatory compliance. You may request deletion of your account data at any time.
Your Rights
Under GDPR, you have the following rights:
- Right of access β obtain a copy of your personal data
- Right to rectification β correct inaccurate data
- Right to erasure β request deletion of your data
- Right to restrict processing β limit how we use your data
- Right to data portability β receive your data in a structured format
- Right to object β object to processing based on legitimate interest
To exercise any of these rights, contact us at support@archigenius.ai. We will respond within 30 days.
Cookies
We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party advertising cookies. No cookie consent banner is required as we only use strictly necessary cookies.
Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the service after changes constitutes acceptance.
Contact
For any privacy-related questions or requests, contact us at:
support@archigenius.ai