Home · Privacy policy

Privacy policy

Last updated: September 5, 2026

1. Who we are

The data controller is Werea Srl, via Lamarmora 13/c, 20900 Monza (MB), Italy, VAT IT08833540969 ("AerariumChain", "we"). Our US subsidiary, AerariumChain Corp., may process data on our behalf under an intragroup agreement. For anything in this policy, write to dpo@aerariumchain.com.

2. What this policy covers

This policy covers the website aerariumchain.com, the AerariumChain HUB platform at hub.aerariumchain.com, and the field and desktop applications connected to it (together, the "Services").

3. What we process, and why

Website visitors

By default we store nothing that identifies you. Your cookie consent choice stays in your browser. Only if you accept, Google Analytics 4 measures how the site is used, with anonymized IP addresses (see the cookie policy). If you write to us through the contact form, we process the data you enter (name, email, organization, type of organization, topic, message) to answer you; requests are handled in our customer relationship system, operated on our own infrastructure.

HUB users

If your institution gives you access to the HUB, we process your account data (name, email, role, institution), authentication and security logs, and the activity needed to make the platform work: uploads, approvals, comments, role assignments. Legal basis: performance of the agreement with your institution and our legitimate interest in keeping the Services secure.

Collection content

Scans, models, images and metadata that an institution uploads or commissions belong to that institution. For this content AerariumChain acts as a processor under the GDPR: we process it only on the institution's instructions, under the service agreement and its data processing terms; the institution remains the controller. If collection metadata contains personal data (for example the names of staff in a condition report), it is handled the same way.

Blockchain notarization

The notarization service writes cryptographic fingerprints (hashes) of files to a public blockchain. Hashes contain no personal data and no artwork content, and by the nature of the technology they are permanent and cannot be deleted.

4. Legal bases

Answering your requests and providing the Services: contract or steps at your request (art. 6.1.b GDPR). Analytics: consent (art. 6.1.a), withdrawable at any time. Security, abuse prevention and defense of our rights: legitimate interest (art. 6.1.f). Obligations under law: art. 6.1.c.

5. Retention

Contact requests: up to 24 months after our last exchange. HUB account data: for the duration of the agreement with your institution, then as required by law. Analytics data: 14 months. Collection content: as instructed by the owning institution; on termination the institution can export everything in open formats before deletion.

6. Recipients

Group companies (AerariumChain Corp.) for service operation; Amazon Web Services (hosting, primary region EU, Ireland); Google Ireland Ltd and Google LLC (analytics, only after consent); selected suppliers when you expressly request a service that needs them (for example a 3D print quote, where the supplier gets secure, limited access to the relevant twin); authorities where the law requires it. We do not sell personal data.

7. Transfers outside the EEA

Where data reaches our US subsidiary or US providers, transfers rely on the European Commission's Standard Contractual Clauses or on an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified).

8. Your rights (GDPR)

You can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest, by writing to dpo@aerariumchain.com. You can also lodge a complaint with your supervisory authority; in Italy, the Garante per la protezione dei dati personali.

9. US state privacy rights

For residents of California and states with similar laws: we collect identifiers and professional information you give us, and, only with consent, internet activity on our site. We use them for the purposes above. We do not sell or share personal information as defined by the California Privacy Rights Act, and we do not use it for targeted advertising. The Global Privacy Control signal is honored automatically. You have the right to know, correct and delete your information, and not to be discriminated against for exercising these rights: write to dpo@aerariumchain.com, directly or through an authorized agent.

10. Security

Data is encrypted in transit and at rest; access follows roles; infrastructure runs in the regions the institution chooses, and institutions with stricter requirements can pin storage and processing to their own hardware.

11. Minors

The Services are not directed to children under 16, and we do not knowingly collect their data.

12. Changes

We may update this policy; material changes will be signaled on this page with a new date at the top.