A ARIATrust Center
Contact DPO

Spentia compliance portal

ARIA security and compliance overview.

Sovereign, EU-only, audit-ready. This page gives DPOs and procurement teams the current operational facts behind ARIA.

EU-only processingCustomer personal data stays in the European Union.
GDPR alignedProcessor controls, DSAR tooling and Article 30 records.
Sovereign stackMistral AI, Scaleway and Brevo are French-domiciled providers.

Hosting and data residency

Production data flows are EU-centered by design.

No customer personal data is processed outside the European Union. TLS certificates are issued by Let's Encrypt; no ARIA customer personal data is exchanged with the certificate authority.

AssetProviderLocation

Subprocessors

Active subprocessors used by ARIA.

Security measures

Public summary of Article 32 controls.

This public view exposes categories and labels only. Internal configuration details remain restricted.

Compliance

Built for European B2B procurement.

GDPR

Spentia acts as Processor under Article 28 on behalf of the Customer as Controller.

EU AI Act

ARIA is not classified as a high-risk AI system under Annex III. Participant transparency is handled during onboarding.

AI transparency notice

Italian deployments

ARIA is aligned with Law No. 132/2025 worker information duties and the defensibility requirements of the Statuto dei Lavoratori.

Italian compliance memorandum

Certifications and audits

External assurance roadmap.

We currently rely on technical audits and operational controls documented in our Article 30 records. External certifications are part of our 2026-2027 roadmap.

Operational status

Production health is monitored continuously.

Dedicated public status page coming soon. Health endpoint is available.

Open status

Data subject rights

Participants keep GDPR rights through their employer DPO.

If you participated in an ARIA campaign, exercise GDPR rights by contacting your employer's DPO. For technical routing questions, write to dpo@spentia.com.

Contact

Ask for the right document or contact the DPO.

Contact DPO

Request DPA

Subprocessor notifications