Archivista Archives, Inc. · Engine Three: Vista Engine · Intelligence Core · Arc Engine
This unified policy covers all Archivista services and supersedes the standalone Vista Privacy Policy.
1. The Governing Principle: Your Data Is Yours
Archivista builds Private Intelligence infrastructure. Our platform exists so that regulated firms can apply advanced AI to their own records without surrendering ownership, control, or confidentiality of those records.
This policy rests on one commitment, stated plainly:
Your data is never used to train external AI models. Not by Archivista, not by our infrastructure providers, not through anonymization, aggregation, or any workaround. Your information is used to serve you, and only you.
Everything below is the operational detail of that commitment, across the three engines of the Archivista platform and the Microsoft infrastructure they run on.
2. Who We Are and What This Policy Covers
Archivista Archives, Inc. (“Archivista,” “we,” “us”) is a United States corporation that builds private AI and cryptographic records infrastructure for regulated organizations.
This policy covers the Archivista platform, known as Engine Three, comprising:
- Vista Engine: Archivista's Private Intelligence engine, which executes customer-specific agentic processes for complex tasks inside private, fenced environments.
- Intelligence Core: the safeguarded knowledge graph that holds an organization's verified institutional knowledge and compounds it over time.
- Arc Engine: the attestation layer that seals selected records and results into cryptographically verifiable Authentic Record Containers (ARCs).
It also covers our websites, applications, and account services. Contact: privacy@archivista.ai
3. Definitions
- Customer Content: All data, documents, records, prompts, files, knowledge graphs, sealed ARCs, and other information you or your authorized users submit to the platform, together with all Outputs the platform generates from that information.
- Inputs: Content you submit for processing.
- Outputs: Results the platform generates in response to your Inputs, including agentic process results and sealed ARCs derived from them.
- Operational Data: Account information, usage telemetry, and service logs described in Section 5. Operational Data never includes the substance of your Customer Content.
- Private Tenant: The logically isolated environment, dedicated to your organization, in which your instance of the platform and your Customer Content reside.
- Microsoft Infrastructure Layer: The Microsoft Azure and Microsoft Foundry services on which the Archivista platform is hosted and on which model inference runs.
4. The Layered Model: Two Sets of Commitments, One Standard
Your data is protected by two contractual layers that carry the same standard:
Layer one: the Archivista application layer. Archivista designs, operates, and is accountable for Engine Three: the agentic processes, the knowledge graph, the verification gates, and the sealing infrastructure. The commitments in this policy are Archivista's own.
Layer two: the Microsoft infrastructure layer. Archivista systems are hosted on Microsoft Azure and use Microsoft Foundry for model inference. For that hosting layer, Archivista incorporates by reference, and passes through to you, Microsoft's contractual data protection commitments:
- The Microsoft Products and Services Data Protection Addendum (DPA), which governs data processing by the Azure and Foundry services we use.
- The Microsoft Foundry data privacy commitments, under which prompts, completions, embeddings, and training data processed in our Azure environment are not available to other customers, not available to OpenAI or other model providers, not used by model providers to improve their models or services, and not used to train any generative AI foundation model without the customer's permission or instruction. Archivista never grants that permission for Customer Content.
- Microsoft's published privacy principles of user control, transparency, security, and defending data, as documented in the Microsoft Privacy Report and the Microsoft Trust Center.
Where Microsoft's commitments are the stronger or more specific protection at the infrastructure layer, you get the benefit of them. Where Archivista's commitments are stronger at the application layer, Archivista's govern. Adoption of Microsoft's commitments never dilutes the commitments in this policy.
5. Information We Collect
Account information. Name, business email, organization, role, and billing details, provided when your organization enrolls.
Customer Content. The Inputs you submit, the Outputs the platform generates, your Intelligence Core knowledge graph, and the ARCs you seal. This content belongs to you (see Section 6).
Usage and telemetry data. Technical logs necessary to operate, secure, and support the service: authentication events, feature usage, error reports, performance metrics, and audit trails. Audit trails are a feature, not a byproduct; they exist so your organization can prove what happened, when, and by whom.
Support communications. Correspondence when you contact us for help.
We collect no advertising identifiers. We do not track you across other websites or services. We do not sell personal information, and we have never sold personal information.
6. Ownership and Control: The Foundation
Data ownership is not a feature. It is the foundation.
- You own your Customer Content. All right, title, and interest in your Inputs, your Outputs, your knowledge graph, and your sealed ARCs remain yours at all times.
- We own the rails, you own the cargo. Archivista owns Engine Three, the platform, and the infrastructure arrangements that carry your data. Ownership of the platform never extends to ownership of what you run on it.
- You can leave at any time. On request, we will assist you in exporting your Customer Content, including your knowledge graph and sealed ARCs, in standard, portable formats. Departure assistance is a commitment, not a courtesy (see Section 11).
7. How We Use Information
We use Customer Content for exactly one purpose: to provide the platform services to your organization. That means executing the agentic processes you configure in the Vista Engine, maintaining your Intelligence Core, and sealing the ARCs you direct the Arc Engine to create, all within your Private Tenant.
We use Operational Data to operate, maintain, and secure the service; authenticate users and enforce access controls; provide support; produce audit trails for your compliance needs; bill for the service; and comply with legal obligations.
What we never do
- We never use Customer Content to train, fine-tune, or improve any foundation model, whether ours or a third party's.
- We never permit any subprocessor or model provider to retain for training, or learn from, your Customer Content. At the infrastructure layer, Microsoft's Foundry commitments prohibit model providers from accessing or training on your prompts and outputs, and Archivista never grants the permission those commitments reserve to the customer.
- We never use “anonymized,” “de-identified,” or “aggregated” versions of Customer Content for model training. De-identification claims carry re-identification risk, so we do not rely on them. The exclusion is absolute.
- We never share Customer Content across tenants. What the platform learns in your environment serves your organization alone.
- We never sell or rent personal information, and we never use it for advertising.
Where Archivista improves the agentic and orchestration layer of Engine Three, it does so using its own development data, synthetic data, and feedback you explicitly and voluntarily provide, never the substance of your Customer Content.
8. Engine Three: How Each Engine Handles Your Data
- Vista Engine: fenced execution. Agentic processes run inside fenced environments scoped to your Private Tenant. Agents operate on your data under controlled permissions, and process results reach you for review; probabilistic output does not silently become your system of record.
- Intelligence Core: read-guarded, write-protected. Your knowledge graph is the most protected asset on the platform. Agents may receive from the Intelligence Core under permission; they cannot write back to it on their own. Changes to the Core require authorized human sign-off under multi-party controls, so your institutional knowledge is never altered by an unsupervised process.
- Arc Engine: sealing on your instruction. ARCs are created only when you or your authorized processes direct it. A sealed ARC is cryptographically bound and tamper-evident; sealing adds verifiability to your records without transferring any ownership of them.
- Infrastructure beneath all three. Each customer runs in a dedicated Private Tenant on Microsoft Azure with triple redundancy, logically isolated from every other customer.
9. Subprocessors and Third Parties
We use a limited set of subprocessors to deliver the platform, principally Microsoft Corporation (Azure hosting and Foundry model inference). Every subprocessor is bound by written agreements that restrict use of Customer Content to providing services to us, prohibit training any AI model on Customer Content, and require security measures consistent with this policy. Microsoft's processing is additionally governed by the Microsoft DPA described in Section 4.
A current subprocessor list is available on request, and enterprise customers may subscribe to advance notice of subprocessor changes. We do not disclose Customer Content to third parties except (a) to subprocessors under these restrictions, (b) at your direction, or (c) where required by law, as described in Section 13.
10. Security
The platform is built for regulated firms, and its security posture reflects that:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access controls and least-privilege administration
- Single sign-on and multi-factor authentication support
- Logical tenant isolation with fenced execution environments
- Multi-party authorization controls on changes to the Intelligence Core
- Cryptographic sealing and tamper evidence for ARCs
- Triple-redundant storage on Microsoft Azure, inheriting Azure's physical and platform security controls and compliance certifications at the infrastructure layer
- Immutable audit logging
- Personnel access to Customer Content restricted to what is strictly necessary for support and operations, logged and reviewable
No system is invulnerable. If a breach affects your Customer Content, we will notify you without undue delay, consistent with applicable law and our contractual commitments to you.
11. Retention, Deletion, and Export
- During the term: You control your Customer Content. You may delete records through the service or by request, subject to any retention obligations your own regulators impose on you. Sealed ARCs follow the retention rules you configure; deletion of a sealed record is logged so the audit trail itself stays intact.
- On termination: You may export your Customer Content, including your knowledge graph and sealed ARCs, in standard, portable formats within 90 days of termination, with our assistance. After the export window closes, we delete Customer Content from active systems and purge it from backups on the standard rotation cycle, except where law requires longer retention.
- Operational Data: Retained only as long as needed for security, audit, legal, and billing purposes, then deleted or de-identified.
12. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, export, or restrict processing of your personal information, and to object to certain processing.
- For business users: The platform processes Customer Content on behalf of your organization, which acts as the controller of that data. Requests concerning Customer Content should be directed to your organization; we will support your organization in fulfilling them under our Data Processing Agreement.
- For account holders: Contact privacy@archivista.ai to exercise rights over your account information. We respond within the timelines applicable law requires.
- GDPR: Where the EU or UK GDPR applies, our legal bases are performance of contract, legitimate interests (security, fraud prevention, service operation), and legal obligation. International transfers rely on appropriate safeguards, including Standard Contractual Clauses where applicable, and at the infrastructure layer on Microsoft's transfer mechanisms and residency capabilities under the Microsoft DPA.
- US state privacy laws: We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. Residents of California and other states with privacy statutes may exercise the rights above without discrimination.
13. Legal Requests
If we receive a legal demand for Customer Content, we will (a) redirect the request to you where possible, (b) notify you before disclosure unless legally prohibited, and (c) disclose only what we are legally compelled to disclose, after challenging overbroad demands where we have reasonable grounds.
14. Automated Processing and Human Oversight
The platform generates Outputs through AI systems. Outputs are probabilistic and may be inaccurate or incomplete. Engine Three is designed so that consequential results pass through human verification gates before entering your protected records: agentic results are reviewed before they alter the Intelligence Core, and sealing through the Arc Engine happens on human or customer-authorized instruction. We require customers to maintain human review over decisions that produce legal or similarly significant effects on individuals. The platform does not make legally significant automated decisions about individuals on its own.
15. Children
The Archivista platform is a business service for regulated organizations. It is not directed to individuals under 18, and we do not knowingly collect information from them.
16. Changes to This Policy: No Silent Amendments
We will not degrade your privacy protections quietly or retroactively.
- Material changes take effect no sooner than 30 days after we notify administrators by email and post notice in the service.
- No change will ever retroactively expand how previously collected Customer Content may be used. A commitment made is a commitment kept.
- If Microsoft materially changes an infrastructure commitment referenced in Section 4 in a way that affects your protections, we will notify you and describe how we are addressing it.
- The version history of this policy is available on request.
17. Contact
Archivista Archives, Inc.
1912 Capitol Ave, Cheyenne, WY 82001
privacy@archivista.ai
Authentic. Attested. Archived. Auditable.