Privacy Policy

Effective September 18, 2026
Last updated September 18, 2026

Archivista Archives, Inc. · Engine Three: Vista Engine · Intelligence Core · Arc Engine

This unified policy covers all Archivista services and supersedes the standalone Vista Privacy Policy.


1. The Governing Principle: Your Data Is Yours

Archivista builds Private Intelligence infrastructure. Our platform exists so that regulated firms can apply advanced AI to their own records without surrendering ownership, control, or confidentiality of those records.

This policy rests on one commitment, stated plainly:

Your data is never used to train external AI models. Not by Archivista, not by our infrastructure providers, not through anonymization, aggregation, or any workaround. Your information is used to serve you, and only you.

Everything below is the operational detail of that commitment, across the three engines of the Archivista platform and the Microsoft infrastructure they run on.

2. Who We Are and What This Policy Covers

Archivista Archives, Inc. (“Archivista,” “we,” “us”) is a United States corporation that builds private AI and cryptographic records infrastructure for regulated organizations.

This policy covers the Archivista platform, known as Engine Three, comprising:

It also covers our websites, applications, and account services. Contact: privacy@archivista.ai

3. Definitions

4. The Layered Model: Two Sets of Commitments, One Standard

Your data is protected by two contractual layers that carry the same standard:

Layer one: the Archivista application layer. Archivista designs, operates, and is accountable for Engine Three: the agentic processes, the knowledge graph, the verification gates, and the sealing infrastructure. The commitments in this policy are Archivista's own.

Layer two: the Microsoft infrastructure layer. Archivista systems are hosted on Microsoft Azure and use Microsoft Foundry for model inference. For that hosting layer, Archivista incorporates by reference, and passes through to you, Microsoft's contractual data protection commitments:

Where Microsoft's commitments are the stronger or more specific protection at the infrastructure layer, you get the benefit of them. Where Archivista's commitments are stronger at the application layer, Archivista's govern. Adoption of Microsoft's commitments never dilutes the commitments in this policy.

5. Information We Collect

Account information. Name, business email, organization, role, and billing details, provided when your organization enrolls.

Customer Content. The Inputs you submit, the Outputs the platform generates, your Intelligence Core knowledge graph, and the ARCs you seal. This content belongs to you (see Section 6).

Usage and telemetry data. Technical logs necessary to operate, secure, and support the service: authentication events, feature usage, error reports, performance metrics, and audit trails. Audit trails are a feature, not a byproduct; they exist so your organization can prove what happened, when, and by whom.

Support communications. Correspondence when you contact us for help.

We collect no advertising identifiers. We do not track you across other websites or services. We do not sell personal information, and we have never sold personal information.

6. Ownership and Control: The Foundation

Data ownership is not a feature. It is the foundation.

7. How We Use Information

We use Customer Content for exactly one purpose: to provide the platform services to your organization. That means executing the agentic processes you configure in the Vista Engine, maintaining your Intelligence Core, and sealing the ARCs you direct the Arc Engine to create, all within your Private Tenant.

We use Operational Data to operate, maintain, and secure the service; authenticate users and enforce access controls; provide support; produce audit trails for your compliance needs; bill for the service; and comply with legal obligations.

What we never do

Where Archivista improves the agentic and orchestration layer of Engine Three, it does so using its own development data, synthetic data, and feedback you explicitly and voluntarily provide, never the substance of your Customer Content.

8. Engine Three: How Each Engine Handles Your Data

9. Subprocessors and Third Parties

We use a limited set of subprocessors to deliver the platform, principally Microsoft Corporation (Azure hosting and Foundry model inference). Every subprocessor is bound by written agreements that restrict use of Customer Content to providing services to us, prohibit training any AI model on Customer Content, and require security measures consistent with this policy. Microsoft's processing is additionally governed by the Microsoft DPA described in Section 4.

A current subprocessor list is available on request, and enterprise customers may subscribe to advance notice of subprocessor changes. We do not disclose Customer Content to third parties except (a) to subprocessors under these restrictions, (b) at your direction, or (c) where required by law, as described in Section 13.

10. Security

The platform is built for regulated firms, and its security posture reflects that:

No system is invulnerable. If a breach affects your Customer Content, we will notify you without undue delay, consistent with applicable law and our contractual commitments to you.

11. Retention, Deletion, and Export

12. Your Privacy Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, export, or restrict processing of your personal information, and to object to certain processing.

13. Legal Requests

If we receive a legal demand for Customer Content, we will (a) redirect the request to you where possible, (b) notify you before disclosure unless legally prohibited, and (c) disclose only what we are legally compelled to disclose, after challenging overbroad demands where we have reasonable grounds.

14. Automated Processing and Human Oversight

The platform generates Outputs through AI systems. Outputs are probabilistic and may be inaccurate or incomplete. Engine Three is designed so that consequential results pass through human verification gates before entering your protected records: agentic results are reviewed before they alter the Intelligence Core, and sealing through the Arc Engine happens on human or customer-authorized instruction. We require customers to maintain human review over decisions that produce legal or similarly significant effects on individuals. The platform does not make legally significant automated decisions about individuals on its own.

15. Children

The Archivista platform is a business service for regulated organizations. It is not directed to individuals under 18, and we do not knowingly collect information from them.

16. Changes to This Policy: No Silent Amendments

We will not degrade your privacy protections quietly or retroactively.

17. Contact

Archivista Archives, Inc.
1912 Capitol Ave, Cheyenne, WY 82001
privacy@archivista.ai


Authentic. Attested. Archived. Auditable.