1. Who we are
Archivez is a tenant-scoped AI assistant operated by Open Kinetix doo Kragujevac ("Open Kinetix", "we", "us"), a company registered in the Republic of Serbia. Open Kinetix is the data controller for personal data processed through Archivez.
- Registered address: Kazimira Veljkovica 45, 34000 Kragujevac, Serbia
- Contact for privacy and data protection: privacy@archivez.io
- Website: https://archivez.io
2. What this policy covers
This policy explains what personal data Archivez processes, why, where it is stored, how long it is kept, who it is shared with, and what rights you have as a data subject under the EU General Data Protection Regulation (GDPR) and comparable laws.
3. What data we collect
3.1 Account data
When your tenant organisation provisions an Archivez account for you, we process:
- Your email address and name (from your organisation's single sign-on provider)
- Role and permission metadata needed to enforce access control
3.2 Email data (only if you connect a mailbox)
If you choose to connect an email mailbox, Archivez connects to it over IMAP using an app password that you generate with your email provider (for example, a Gmail, Fastmail, or iCloud app password). Archivez indexes only the messages exchanged with the tracked contacts you explicitly designate inside Archivez. This means:
- We index correspondence in both directions — messages you received from and messages you sent to a tracked contact — so Archivez reads both your Inbox and your Sent folder for those contacts. Mail with anyone you have not designated as a tracked contact is not fetched, stored, or processed.
- For those messages we read the subject, body, and metadata (sender, recipients, timestamps, thread ID).
- Archivez only reads your mail — it never sends, modifies, or deletes messages.
- You control which contacts are tracked, and you can disconnect the mailbox or revoke its app password at any time, which immediately stops indexing.
- You can optionally trigger a one-time history pull for a tracked contact. Before anything is stored, Archivez shows you a preview — how many messages and roughly how much data — for you to confirm.
3.3 Uploaded documents
Files (PDF, DOCX, TXT, and similar) that you or a colleague upload into your Archivez tenant are indexed and stored in the tenant's private storage scope.
3.4 Usage data
To run the service we process:
- Chat questions and answers (used to render source citations and maintain conversation history)
- Service logs (request timestamps, error traces, rate-limit counters)
- Aggregate usage metrics (chunk counts, token counts, cost attribution)
- Crash diagnostics from the Archivez mobile and web applications: stack traces, breadcrumbs of preceding actions, and device or browser metadata. Email addresses, OAuth tokens, and JWT-shaped strings are stripped from messages and breadcrumbs before they leave your device or our servers.
4. How we use your data
- To provide the core product: retrieving relevant passages from your own content library and generating cited answers
- To enforce tenant isolation: every row of every database table is scoped by
tenant_id, and access is filtered at both the application and query layers - To operate, maintain, and troubleshoot the service
- To comply with legal obligations
We do not sell your data. We do not use your data to train third-party AI models. Prompts sent to AWS Bedrock are not retained by Anthropic or Cohere for model training.
5. How we store your data
- Encryption at rest:
- Document storage (uploaded files and indexed email content) is held in private S3 buckets with AWS server-side encryption (SSE-S3, AES-256).
- The application database (PostgreSQL on AWS RDS) is encrypted at rest with AES-256 using AWS RDS-managed encryption.
- Mailbox credentials — the IMAP app password for each connected mailbox — receive an additional layer of protection: they are envelope-encrypted with AWS KMS, with a distinct Data Encryption Key (DEK) per connection wrapped by a KMS-managed master key.
- Encryption in transit: TLS 1.2 or higher for all connections.
- Tenant isolation: database rows are scoped to
tenant_id; application-layer and query-layer checks both enforce the boundary. - Location: data is stored in the European Union. Primary region is
eu-central-1(Frankfurt, Germany). Large language model calls route through the AWS Bedrock EU cross-region inference profile, which is guaranteed by AWS to stay within EU data-residency boundaries (Frankfurt, Stockholm, Milan, Spain, Ireland, Paris).
6. How long we retain your data
| Category | Retention |
|---|---|
| Indexed email content | Until you disconnect the mailbox, remove the tracked contact, or your tenant account is deleted |
| Uploaded documents | Until deleted by you or your tenant admin |
| Chat history | 180 days by default; your tenant admin may change this |
| Service logs | 90 days rolling |
| Crash diagnostics | 90 days rolling (Sentry default retention) |
| Aggregate usage metrics | 24 months (cost attribution and capacity planning) |
| Account data | Duration of your tenant's contract with Open Kinetix |
When you disconnect a mailbox, embedded chunks derived from it are deleted within 24 hours. When your tenant account is closed, all tenant data is deleted within 30 days.
7. Who we share your data with
Archivez does not sell, rent, or share your personal data with third parties for their own purposes.
We use the following sub-processors to operate the service:
| Sub-processor | Purpose | Location / routing |
|---|---|---|
| Amazon Web Services, Inc. | Primary cloud infrastructure (compute, storage, databases, AI inference via Bedrock) | EU — eu-central-1 primary; EU CRI for Bedrock |
| Anthropic, via AWS Bedrock | Large language model inference (Claude family) | EU-only routing via Bedrock EU CRI |
| Cohere, via AWS Bedrock | Multilingual embedding model | EU region |
| Functional Software, Inc. (Sentry) | Application crash diagnostics and error tracking | Sentry EU region (Frankfurt, Germany) — de.sentry.io |
| Paddle.com Market Limited (30 Old Bailey, London EC4M 7AU; England & Wales no. 08172165) | Processor for the billing and subscription data we send it, under Paddle's Data Processing Addendum (Paddle is separately our merchant of record — see Payments below) | UK / EU |
All sub-processors are bound by contractual data protection obligations. A current sub-processor list can be requested at privacy@archivez.io.
Payments. Paddle is our merchant of record — the seller of record to your organisation. For buyers in the EU/UK this is Paddle.com Market Limited (30 Old Bailey, London EC4M 7AU; England & Wales no. 08172165); Paddle contracts through its local entities for buyers elsewhere (Paddle.com Inc. in the United States; Paddle.com (Canada) Ltd in Canada). In its merchant-of-record role Paddle sets the applicable taxes, issues the invoice in its own name, and is an independent controller for the payment data you provide to it. Separately, Paddle.com Market Limited also acts as our processor for the billing and subscription data we send it, under Paddle's Data Processing Addendum (listed in the sub-processor table above). The applicable terms are Paddle's Seller Terms and DPA, accepted at account registration.
8. Your rights under GDPR
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights:
- Access — request a copy of personal data we process about you
- Rectification — correct inaccurate personal data
- Erasure ("right to be forgotten") — request deletion of your personal data
- Portability — receive your personal data in a structured, machine-readable format
- Restriction — request that we limit processing in specified circumstances
- Objection — object to processing based on legitimate interests
- Withdraw consent — for processing based on consent (e.g., a connected mailbox), you can withdraw at any time
To exercise any of these rights, email privacy@archivez.io. We respond within 30 days.
You also have the right to lodge a complaint with a data protection authority — for example the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik) in Serbia, or your national supervisory authority in the EU.
9. Cookies and similar technologies
This website (archivez.io) sets no cookies at all. It carries no analytics, no tracking pixels, and no requests to any third party. The only script on the page is a one-line handler that opens the translated version when you use the language selector; it stores nothing and contacts no third party. There is nothing for a consent banner to disclose.
The Archivez application sets no cookies of its own. It keeps data in your browser's local and session storage instead: your sign-in session, which workspace you are viewing, and interface preferences such as language, sidebar state, table layout, and notices you have dismissed. None of it is used for advertising, analytics, or tracking. You can clear it at any time through your browser; doing so signs you out.
Signing in is handled by our identity provider at kc.archivez.io, which sets strictly necessary session cookies (such as AUTH_SESSION_ID) for the duration of the sign-in flow and your session. They are used only to authenticate you and to keep you signed in.
We use no advertising cookies, no analytics cookies, and no third-party trackers on any of these properties.
10. International transfers
Archivez processes personal data in the European Union. We do not transfer personal data outside the EU in the course of normal operations.
11. Connected mailbox data and use limitation
When you connect an email mailbox, Archivez accesses it over IMAP using an app password and indexes only the messages exchanged with the tracked contacts you designate (see §3.2). We apply the following limits to that data:
- Use limitation. Mailbox data is used exclusively to provide and improve the user-facing features of Archivez — namely, retrieving relevant passages from your tracked-contact emails and generating cited answers to your questions. We do not use this data for any unrelated purpose.
- No advertising. We do not use mailbox data for advertising, ad targeting, ad measurement, or any form of ad personalisation.
- No transfer except as needed. We do not transfer mailbox data to third parties except as necessary to provide or improve the user-facing features above, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- No human access. We do not allow humans to read your mailbox data unless (a) we have your explicit consent for specific messages, (b) access is necessary for security purposes such as investigating abuse, (c) access is necessary to comply with applicable law, or (d) the data has been aggregated and anonymised and is used only for internal operations.
Archivez processes connected-mailbox data exclusively within the European Union (AWS eu-central-1, Frankfurt). Message content is stored encrypted at rest and is isolated per tenant. You can disconnect the mailbox or revoke its app password at any time, which immediately stops indexing, and you can request deletion of all indexed email-derived data by emailing privacy@archivez.io; deletion completes within 30 days.
12. Security and breach notification
We maintain administrative, technical, and organisational measures appropriate to the nature of the data we process, including encryption, access controls, logging, and least-privilege IAM. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the affected tenant admins without undue delay and, where required by law, the competent data protection authority within 72 hours.
13. Children
Archivez is a business product and is not intended for children under 16. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy to reflect changes to the service or to legal requirements. Material changes will be announced to tenant admins by email at least 30 days before they take effect. The "Last updated" date at the top of this page is always current.
15. Contact us
- Privacy and data protection: privacy@archivez.io
- General support: support@archivez.io
- Abuse reports: abuse@archivez.io
- Legal entity: Open Kinetix doo Kragujevac (Open Kinetix d.o.o.), Kazimira Veljkovića 45, 34000 Kragujevac, Republic of Serbia — company no. (matični broj) 21614602, tax ID (PIB) 112140379