1. Who processes your data
The data controller is Purposeful Revelations S.r.l., Via Ammiraglio Caracciolo 22, 76012 Canosa di Puglia (BT), Italy, tax code and VAT no. 08518240729, hereinafter “Purposeful”.
You can contact the controller at info@purposeful-revelations.it or via certified email at purposefulrevelationssrl@pec.it. For product support you may use connect@ialive.it.
Purposeful has not appointed a Data Protection Officer. If this changes, the relevant contact details will be published here.
2. What this notice covers
This notice covers:
- the public website ialive.it and future related pages;
- the Aliv@ application available at workspace.ialive.it and other official domains;
- registration, authentication, Accounts, Plans, support and communications;
- conversations, prompts, matters, uploaded documents, metadata and Outputs;
- cookies, local storage and similar technologies described in the Cookie Policy.
External websites reached through links process data according to their own notices.
3. Different privacy roles
Purposeful’s role depends on the specific processing activity.
- Controller: Purposeful determines purposes and means for website browsing, registration, authentication, Account administration, contract management, billing, security, abuse prevention, support, its own communications and marketing.
- Processor: when a professional, firm, company or entity uploads data relating to clients, counterparties, employees or other third parties for its own activity, the Client determines the purposes and Purposeful processes those data on its behalf under the agreement required by Article 28 GDPR.
- Sub-processor: if the Client itself acts as a processor for its own principal, Purposeful may act as sub-processor within the applicable instructions and authorisations.
These roles do not overlap for the same purpose. This notice mainly describes processing for which Purposeful acts as controller. The data processing agreement governs Client Data processed on behalf of professional Clients.
4. Data processed
| Category | Examples | Source |
|---|---|---|
| Identification and contact data | Name, surname, email, phone, address, optional profile image | You, organisation administrator, Google sign-in |
| Professional and organisational data | Firm or company, role, sector, VAT number, authorised Users | You or the Client inviting you |
| Authentication and security | Password hash, identifiers, tokens, IP, device, browser, access events, attempts and anomalies | You, Aliv@ systems, Google if selected |
| Contract and payment | Plan, orders, renewals, invoices, payment results and references | You, Client, any payment processor |
| Use of the Service | Functions used, date and time, chats, settings, matters, support requests | Application use |
| Content | Prompts, documents, attachments, metadata, extractions, embeddings, history and Outputs | You, Clients, authorised integrations |
| Browsing and technical data | IP, URL, date and time, response status, logs, cookies and similar identifiers | Website, application, infrastructure and browser |
| Communications | Requests, tickets, complaints, preferences and evidence of consent | You and support or email systems |
Legal matters may contain special-category data, criminal-offence data, financial information, professional secrets and data relating to people who do not use Aliv@. The Client must upload only data that are necessary and lawful.
5. Purposes, legal bases and retention
| Purpose | Data and legal basis | Retention |
|---|---|---|
| Provide website, registration, Account, authentication and Aliv@ functions | Identification, access, technical and usage data. Contract or pre-contractual measures, Article 6(1)(b) GDPR. For Users of a corporate Client, legitimate interest in performing and managing the relationship, Article 6(1)(f). | For the life of the Account. Data required to prove the relationship are retained for up to 10 years after termination. |
| Process prompts, documents and Outputs requested by the User | Content, metadata and history. Contract, Article 6(1)(b). For professional Client Data, controller instructions and Article 28 GDPR. | Until deletion by the User or closure. Operational deletion within 30 days and backup rotation within 90 days, subject to obligations or disputes. |
| Manage Plans, payments, accounting and tax | Contract, billing and payment-result data. Contract and legal obligation, Articles 6(1)(b) and 6(1)(c). | 10 years from accounting entry, plus any period necessary for audit or dispute. |
| Support, complaints and service communications | Contacts, Account, request content and technical data. Contract or legitimate interest, Articles 6(1)(b) and 6(1)(f). | 24 months from ticket closure; up to 10 years where required for a dispute. |
| Security, fraud and abuse prevention, technical diagnosis and protection of rights | IP, access events, logs, Account and usage. Legitimate interest, Article 6(1)(f), and security obligations, Articles 6(1)(c) and 32. | Ordinary logs up to 12 months. Incident or unlawful-activity data for the time needed for investigation and protection. |
| Incomplete registration, verification and Account recovery | Email, temporary codes and technical data. Pre-contractual measures, contract and security. | Incomplete registrations within 30 days. Codes and links according to technical expiry, usually no more than 24 hours. |
| Improve performance and usability using strictly aggregated statistics | Technical events and aggregated data. Legitimate interest, Article 6(1)(f). No profiling tracking without consent. | Individual data up to 12 months; genuinely aggregated results may be retained longer. |
| Send newsletters or promotional communications | Contacts, interests and consent. Consent, Article 6(1)(a) GDPR and Article 130 Italian Privacy Code. Any soft spam remains within legal limits. | Until withdrawal and in any event no more than 24 months from the last meaningful interaction, except evidence of consent and objection. |
| Document privacy choices and consents | Choice, date, version and technical identifiers. Legal obligation and legitimate interest in evidence. | For the period necessary to demonstrate compliance, generally up to 10 years. |
The periods above include blocking and deletion according to technical cycles. Data required for proceedings, authority orders or defence of rights may be retained longer, only for that purpose.
6. Whether data are required
Data identified as necessary are required to register the Account, authenticate you, provide the Plan, comply with legal obligations and protect the Service. Without them we cannot provide the requested function. Optional data may improve the profile or communications; not providing them does not prevent essential functions. Marketing consent is always optional.
7. How Aliv@ uses artificial intelligence
Documents and requests may be processed through cloud and AI services necessary for Aliv@ to operate. Purposeful configures those services according to applicable contractual, security and data-protection requirements. Outputs remain informational assistance and must be checked by a person.
Aliv@ informs the User that they are interacting with an AI system. It does not autonomously make decisions producing legal or similarly significant effects on the User within the meaning of Article 22 GDPR. Outputs remain informational assistance and require human verification.
8. Recipients and providers
Data are accessible only to authorised personnel and, where necessary, to the following categories:
- cloud, hosting, network, protection, database, logging and AI providers;
- authentication, email, support and communications providers;
- payment processors, banks, accounting and tax advisers where required by a paid Plan;
- legal advisers, insurers and authorities where necessary for obligations or protection of rights;
- parties involved in corporate transactions, subject to appropriate confidentiality obligations.
| Main provider | Function | Processing area |
|---|---|---|
| Google Ireland Limited and Google LLC | Google sign-in, only if selected by the User | EEA and, depending on the service, the United States and other countries under the safeguards indicated by Google. |
| Technical and cloud providers | Hosting, security, storage, authentication, AI processing and services necessary for operation | According to the applicable processing areas and contractual safeguards |
You may request the current list of processors and sub-processors at info@purposeful-revelations.it.
9. Transfers outside the European Economic Area
Primary storage of application and document data takes place in Ireland. Some global services, particularly content delivery, edge security and Google sign-in, may involve temporary processing or access from countries outside the EEA.
Where a transfer occurs, Purposeful uses an adequacy decision, including the EU-U.S. Data Privacy Framework for covered recipients and services, or European Commission Standard Contractual Clauses, a transfer assessment and appropriate supplementary measures. You may request information and a copy of the safeguards, subject to necessary redactions, from the controller contacts.
10. Security
Purposeful adopts measures proportionate to risk, including encryption in transit and at rest, network isolation, least-privilege access control, protected secret management, application firewall, event logging, monitoring and logical data separation.
No system is risk-free. You must protect credentials and devices, minimise uploaded data and promptly report suspicious events. Purposeful handles personal-data breaches under Articles 33 and 34 GDPR and, when acting as processor, informs the Client without undue delay.
11. Data relating to people outside the Account
We may receive data not collected directly from you, for example when an administrator invites you, a Client uploads a matter or an authorised integration transfers content. In those cases, the source is the Client or integration and the data categories are those described above.
When Purposeful acts as processor, the Client is responsible for providing notices to data subjects and handling their rights. Purposeful assists under the relevant agreement. When Purposeful acts as controller and individual information is not impossible or disproportionate, it provides the information required by Article 14 GDPR.
12. Minors
Aliv@ is not intended for people under 18 and does not allow them to create an Account. If you believe a minor has registered or that minors’ data have been uploaded unlawfully, contact the controller. The data will be reviewed and deleted where the legal conditions are met.
13. Your rights
Where applicable, you may request:
- access to data and a copy;
- rectification or completion;
- erasure;
- restriction of processing;
- portability of data provided by you where processing is automated and based on contract or consent;
- objection to processing based on legitimate interest and, at any time, to direct marketing;
- withdrawal of consent without affecting earlier lawful processing;
- safeguards concerning automated decisions where Article 22 GDPR applies.
Send requests to info@purposeful-revelations.it. We may request proportionate information to verify identity. We respond within one month; in complex cases the period may be extended by two months, with notice within the first month.
If data are processed on behalf of a professional Client, we will forward the request to the Client or tell you how to contact it, unless otherwise instructed.
14. Complaint and judicial protection
You may lodge a complaint with the Italian Data Protection Authority or the competent authority of your Member State and may seek judicial remedies.
15. Cookies and similar technologies
For information about identifiers, local storage, authentication functions and preference management, see the Cookies and similar technologies Policy.
16. Changes
Purposeful updates this notice when laws, functions or processing activities change. The date and version are shown at the beginning. Material changes are communicated in the Account or by email before they take effect where possible and required.
