Legal

Privacy Policy

How archevis and Monolithiq handle personal data, lawful bases, retention, transfers, and user rights.

Version

2026-05-17

Effective date

May 17, 2026

Jurisdiction

European Union

This Privacy Policy explains how archevis and its operator, MONOLITHIQ Single-Member Private Company (IKE) ("Monolithiq", "we", "us"), handle personal data when you visit the website, create an account, use the workspace, request support, or interact with billing and compliance flows.

1. Controller identity and contact details

For the processing described in this Privacy Policy, Monolithiq acts as the controller unless another role is expressly stated.

Controller details:

  • Legal name: MONOLITHIQ Single-Member Private Company (IKE)
  • Registered seat: Sidiras Merarchias 8, 42100 Trikala, Greece
  • Contact email: info@monolithiq.co
  • Website: www.monolithiq.co

2. What personal data we process

Depending on how you use archevis, we may process:

  • account and identity data, such as name, email address, user ID, locale, and authentication status;
  • billing and subscription data, such as customer IDs, plan status, billing email, invoices, billing country, and subscription events;
  • workspace and project data, such as project names, settings, project history, export requests, deletion requests, and support context;
  • files and generated content, such as uploaded sketches, reference images, derived previews, generated compositions, and export bundles;
  • security and operational data, such as request metadata, diagnostic reference IDs, rate-limit state, and security-event records;
  • compliance and preference data, such as legal-acceptance events, checkout-disclosure acknowledgements, export and deletion requests, timestamps, paths, locale, user agent, and a hashed network indicator used for compliance evidence where needed.

3. Sources of personal data

We collect personal data:

  • directly from you when you create an account, upload files, subscribe, contact support, request exports or deletion, or configure settings;
  • automatically when you use the service, including authentication, security, consent, and workflow events;
  • from service providers that support authentication, billing, analytics, storage, database hosting, and related infrastructure;
  • from payment and identity events needed to reconcile subscriptions, support requests, security incidents, or legal requests.

4. Purposes and legal bases

We process personal data for the following purposes and legal bases:

PurposeExamplesLegal basis
Provide and operate archevisaccount access, project storage, generation workflows, exports, support responsesperformance of a contract
Manage subscriptions and hosted billingcheckout initiation, billing status, invoice and subscription reconciliationperformance of a contract; legal obligation where accounting or tax records are required
Protect the service and usersaccess control, abuse prevention, fraud prevention, incident response, logging, rate limitinglegitimate interests in service security, fraud prevention, and reliable operation
Maintain compliance evidenceconsent records, deletion records, export records, audit logs, legal-hold handlinglegal obligation; legitimate interests in documenting compliance and defending legal claims
Anonymous product analyticscookieless aggregate page and product-usage measurement through Plausible without advertising, profiling, or persistent identifierslegitimate interests in understanding aggregate service use; Plausible does not use optional tracking cookies in the current setup

Where we rely on legitimate interests, those interests include keeping archevis secure, preventing abuse, diagnosing failures, maintaining product reliability, and documenting compliance and dispute history.

Where we rely on consent, you may withdraw that consent at any time for future processing.

5. Service providers and recipients

We use named service providers for authentication, payments, database hosting, storage, analytics, rate limiting, and GPU-backed processing.

The current named provider register, roles, public legal links, and transfer posture appear on the Service Providers and Transfers page.

We share only the categories of personal data reasonably needed for the relevant service function.

6. Business-customer processor context

If you are a business customer and archevis processes personal data that you submit on behalf of your own clients, staff, contractors, or other end users, Monolithiq acts as processor for that Customer Personal Data under the Data Processing Addendum.

Monolithiq remains controller for its own account, billing, support, security, compliance, and aggregate analytics processing.

7. International transfers

Some named service providers may process personal data outside the EEA or support the service from multiple jurisdictions.

Where personal data is transferred outside the EEA, we rely on the lawful transfer mechanism appropriate to the relationship, such as an adequacy decision, standard contractual clauses, or another valid safeguard under applicable law.

You can request more information about our current transfer posture by contacting info@monolithiq.co.

8. Retention

We keep personal data only for as long as necessary for the purposes described above. Current retention windows and criteria include:

  • account and active workspace records: while the account remains active and for a reasonable post-termination period needed to close the service relationship and resolve disputes;
  • subscription, accounting, and tax records: up to 7 years where required for accounting, tax, or financial-record retention;
  • compliance audit records and related deletion/export evidence: typically up to 3 years, and longer where legal hold or claims handling requires it;
  • user-generated content retained under deletion lifecycle categories: default internal retention categories currently range from 180 days to 7 years depending on the legal or operational category applied;
  • temporary GDPR export bundles: 48 hours from creation before expiry and cleanup.

Where a longer retention period is required by law, legal hold, fraud prevention, or security needs, we may retain data for that longer period.

9. AI-generation and file processing

When you use generation features, archevis processes your uploaded files, feature inputs, settings, and related job metadata to create or transform outputs.

You remain responsible for ensuring that you have a valid legal basis to upload and process any personal data contained in your inputs, and for deciding whether downstream disclosure, review, or additional legal analysis is required for your outputs.

10. Cookies, local storage, and analytics

archevis uses necessary browser storage for authentication continuity, session security, locale handling, interface preferences, and related service operation.

archevis uses Plausible Analytics for anonymous cookieless analytics. Plausible is configured for aggregate measurement and does not set analytics cookies or use persistent browser identifiers in the current setup.

Because the current setup does not use optional tracking cookies, archevis does not show a cookie banner or cookie-preferences control today. If we introduce optional cookies or similar browser storage later, we will add the required controls before activating that functionality.

More detail appears in the Cookie Policy.

11. Your rights

Subject to applicable law, you may have the right to:

  • access your personal data;
  • rectify inaccurate or incomplete data;
  • erase data in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests;
  • data portability for data processed by automated means where the legal test is met;
  • withdraw consent where processing depends on consent;
  • lodge a complaint with your local supervisory authority.

You can currently:

  • request an export through the account privacy area;
  • submit a deletion request through the account privacy area; or
  • contact info@monolithiq.co for privacy requests.

We aim to respond to rights requests within the period required by applicable law, typically within one month unless an extension is lawfully available.

12. Security

We use technical and organizational measures appropriate to the risk profile of the service, including authenticated routes, access controls, protected storage access, audit logging, and operational monitoring.

No system can guarantee absolute security, and you should also protect your own account credentials and devices.

13. Automated decision-making

archevis uses automated generation systems to produce and transform visual outputs, but this Privacy Policy is not intended to describe a legally significant automated decision about a person in the sense of Article 22 GDPR.

If that changes in a relevant context, we will update this Policy and any required notices.

14. Changes to this Policy

We may update this Privacy Policy to reflect legal, technical, or product changes. The current version and effective date are published on the legal page, and significant changes will be communicated where required.

15. Contact and complaints

For privacy questions or requests, contact:

  • MONOLITHIQ Single-Member Private Company (IKE)
  • Sidiras Merarchias 8, 42100 Trikala, Greece
  • info@monolithiq.co

You may also contact the competent supervisory authority in your jurisdiction if you believe your rights have been infringed.