This Privacy Policy explains how TO_BE_UPDATED, an individual entrepreneur registered in Republic of Armenia, registration number to_be_updated, TIN to_be_updated, with registered address at to_be_updated, operating under the Artivale trade name (“Artivale”, “we”, “us”, or the “Data Controller”), collects and processes personal data.
This Policy applies to visitors of artivale.space, prospective and existing clients, client representatives, contractors, and other persons who communicate with Artivale.
1. Data controller
TO_BE_UPDATED
Individual Entrepreneur
Registration number: to_be_updated
TIN: to_be_updated
Registered address: to_be_updated, Republic of Armenia
All enquiries and notices: hello@artivale.space
2. Personal data we collect
Depending on the nature of the interaction, we may process:
- identity and business information, including name, company name, position, country, and business registration details;
- contact information, including email address, telephone number, messenger identifier, and business address;
- enquiry and communication data, including messages, requests, feedback, and related correspondence;
- project information, including requirements, technical documentation, source materials, repository information, access details, and delivery records;
- contractual and billing information, including invoices, order numbers, service descriptions, amounts, currencies, payment status, transaction references, and settlement records;
- compliance information reasonably required by payment providers, banks, professional advisers, or competent authorities;
- technical data, including IP address, browser type, device information, requested pages, timestamps, and server security logs; and
- any other information voluntarily provided in connection with an enquiry or engagement.
We do not intentionally request sensitive personal data unless it is necessary for a specific engagement and appropriate safeguards have been agreed.
3. How we collect data
We may collect personal data:
- directly from the person concerned;
- from the Client or its authorised representatives;
- through email, messengers, repositories, project management systems, and other agreed communication channels;
- from payment providers, settlement partners, banks, and transaction networks;
- automatically through hosting and security infrastructure; and
- from publicly available business or professional sources where necessary to verify a Client or protect our legitimate interests.
4. Purposes and legal grounds
We process personal data where necessary to:
- respond to enquiries and communicate about potential Services;
- prepare and issue invoices and establish contractual relationships;
- provide, manage, secure, and document the Services;
- deliver software, technical support, maintenance, and consulting;
- process and reconcile payments, settlements, cancellations, and refunds;
- maintain accounting, tax, contractual, and business records;
- prevent fraud, abuse, security incidents, and unlawful activity;
- establish, exercise, or defend legal claims;
- comply with applicable legal, regulatory, banking, tax, and compliance obligations; and
- operate, protect, and improve the website and technical infrastructure.
Depending on the circumstances, processing is based on the performance of a contract, steps taken at the request of a prospective Client, compliance with a legal obligation, consent, or the legitimate interests of Artivale or a third party, provided that such interests do not override the rights of the person concerned.
5. Client project data
5.1. When Artivale processes personal data contained in systems, databases, source materials, or other resources controlled by a Client solely for the purpose of providing the Services, the Client generally determines the purposes and means of that processing.
5.2. In such cases, Artivale processes the data only as necessary to perform the agreed Services and in accordance with the Client’s lawful written instructions, the applicable Order Documents, and applicable law.
5.3. The Client is responsible for ensuring that it has a lawful basis to provide such personal data to Artivale. Where appropriate, the parties may enter into a separate data processing agreement.
5.4. Artivale treats the identity of each Client, the existence and nature of the engagement, and all non-public project information and materials as confidential. Artivale will not identify a Client, publish a case study, display a Client’s name or logo, or disclose or demonstrate a Client’s project, deliverables, screenshots, source materials, or project details without the Client’s prior written consent, including after a project has been completed or publicly launched.
5.5. Consent to one specific publication or disclosure does not constitute consent to any other use. Artivale may disclose confidential Client or project information without consent only to the extent strictly required by applicable law, a binding court order, or a lawful demand from a competent authority. Where legally permitted, Artivale will give the Client reasonable advance notice and will disclose only the minimum information required.
6. Payment providers and settlement partners
6.1. Artivale may make independent payment providers or settlement partners available to the Client.
6.2. When a Client uses an external payment interface, the relevant provider may independently collect and process identity, payment, wallet, transaction, device, and compliance information under its own terms and privacy policy.
6.3. Artivale does not receive or store private cryptographic keys, complete payment card details, or authentication credentials belonging to the Client.
6.4. Artivale may receive transaction references, payment status, amount, currency, payer information made available by the provider, and other information necessary to identify, reconcile, refund, or document a payment.
7. Recipients of personal data
Where necessary for the purposes described in this Policy, personal data may be disclosed to:
- hosting, infrastructure, email, communications, repository, and project management providers;
- accountants, auditors, lawyers, tax advisers, and other professional advisers;
- payment providers, settlement partners, transaction networks, and banks;
- subcontractors assisting with the Services under appropriate confidentiality obligations;
- government authorities, regulators, courts, law enforcement bodies, or other persons where disclosure is required by law; and
- a successor or potential successor in connection with a lawful sale, transfer, or reorganisation of the business.
We do not sell or rent personal data.
8. International transfers
8.1. Artivale is established in the Republic of Armenia, while Clients and service providers may be located in other countries.
8.2. Personal data may therefore be processed or stored outside the country in which it was originally collected. International transfers are made only where necessary for the relevant processing purpose and subject to the requirements of applicable law.
8.3. Where required, Artivale uses contractual, organisational, or other lawful safeguards for international transfers.
9. Data retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected. Unless a longer period is required by law or reasonably necessary for a legal claim:
- unanswered or inactive enquiries may be retained for up to 12 months after the last communication;
- ordinary website security logs may be retained for up to 30 days;
- project communications and delivery records may be retained for the duration of the engagement and up to three years after its completion;
- credentials provided for project access are deleted or returned when they are no longer required; and
- invoices, transaction records, contractual documents, and accounting or tax records are retained for the period required by applicable Armenian law.
Data may be retained for a longer period where necessary to comply with a legal obligation, resolve a dispute, prevent fraud, or establish, exercise, or defend a legal claim.
10. Data security
10.1. Artivale applies reasonable technical and organisational measures appropriate to the nature of the data and the risks of processing.
10.2. These measures may include access restrictions, authentication controls, encryption in transit, secure credential exchange, software updates, backups, and confidentiality obligations.
10.3. No internet transmission or storage system can be guaranteed to be completely secure. Clients must not send passwords, private keys, seed phrases, or other highly sensitive credentials through ordinary email.
11. Rights of data subjects
Subject to applicable law, a person may request:
- information about the processing of their personal data;
- access to their personal data;
- correction of inaccurate or incomplete data;
- deletion of personal data where there is no lawful reason to retain it;
- restriction of processing;
- withdrawal of consent where processing is based on consent; and
- information about the persons or categories of persons to whom the data may be disclosed.
11.1. A request may be submitted to hello@artivale.space. The subject line should state “Privacy Request”.
11.2. Artivale may request information reasonably necessary to verify the identity and authority of the requester. This verification applies only to privacy requests and does not require every Client to submit identity documents during the ordinary ordering process.
11.3. A person may also contact the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia regarding the processing of their personal data.
12. Cookies and analytics
12.1. Artivale does not currently use advertising cookies, behavioural profiling, or third-party analytics on artivale.space.
12.2. The website may use strictly necessary technical mechanisms required for security, routing, and reliable operation. If analytics, advertising technologies, or non-essential cookies are introduced, this Policy and the website’s consent mechanisms will be updated before such technologies are used.
13. Children
13.1. The Services are intended for persons acting for business or professional purposes and are not directed to children.
13.2. Artivale does not knowingly collect personal data from persons under 18 years of age. If such data is identified, it will be deleted unless retention is required by law.
14. Automated decision-making
14.1. Artivale does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects.
14.2. Independent payment providers may conduct automated fraud prevention, sanctions screening, or compliance checks under their own policies.
15. Changes to this policy
15.1. Artivale may update this Policy to reflect changes in its Services, infrastructure, providers, or legal obligations.
15.2. The updated version will be published on artivale.space with a revised effective date. Material changes affecting an active engagement may also be communicated through the available contact details.