Data Processing Agreement (DPA)
Pursuant to Art. 28 GDPR
Widgeto.ai — DevInterface SRL
Version 1.0 · Last updated: 1 July 2026
This Data Processing Agreement ("DPA") supplements the Widgeto.ai Terms of Service and governs the processing of End Users' personal data carried out by DevInterface on behalf of the Customer. The DPA is deemed accepted together with the Terms of Service upon registration.
1. Parties and roles
The Customer acts as Data Controller of the End Users' personal data collected through the widget. DevInterface SRL (VAT no. IT04080300232, Via Guglielmo Marconi 20, 37012 Bussolengo (VR)) acts as Data Processor, processing such data exclusively on behalf of and under the instructions of the Controller.
2. Subject matter, nature and purpose of processing
- Subject matter: provision of the Widgeto.ai AI conversational assistant service.
- Nature: collection, recording, processing via AI models, storage and deletion.
- Purpose: generating automated responses to End Users' messages and providing the Service's functionalities.
- Duration: for the entire duration of the contractual relationship, subject to any legal obligations.
3. Categories of data subjects and data
- Data subjects: visitors of the Customer's website who interact with the widget.
- Categories of data: data contained in the messages (potentially name, contact details and other information provided by the User), technical and connection data.
The Customer undertakes not to convey through the widget special categories of data (Art. 9 GDPR) unless they have established the appropriate legal bases and measures.
4. Documented instructions of the Controller
DevInterface processes personal data only on the basis of the Controller's documented instructions, consisting of the Terms of Service, this DPA and the configurations set by the Customer in their Account. DevInterface informs the Customer if, in its opinion, an instruction infringes applicable law.
5. Obligations of the Processor
DevInterface undertakes to:
- process data only for the purposes indicated above and in accordance with the Controller's instructions;
- ensure that persons authorised to process data are bound by adequate confidentiality obligations;
- adopt the technical and organisational security measures set out in Art. 32 GDPR;
- assist the Controller in responding to requests from data subjects (Arts. 15-22);
- assist the Controller with the obligations set out in Arts. 32-36 (security, breach notification, DPIA);
- make available the information necessary to demonstrate compliance and allow for reasonable audits.
6. Sub-processors
The Controller authorises the use of the sub-processors listed below. DevInterface imposes on them data protection obligations equivalent to those of this DPA and gives prior notice of any changes, allowing the Customer to object on justified grounds.
- OpenAI — processing of conversations via API — USA with EU residency where configured; transfers covered by SCC.
- Contabo — hosting of the production infrastructure — Germany (EU).
- Hetzner — hosting for dedicated installations of individual customers — EU.
- Amazon Web Services (S3) — storage of files/documents — Ireland (eu-west-1, EU).
7. Transfers to third countries
With the exception of processing via OpenAI, all processing takes place within the European Union. The transfer to OpenAI is supported by appropriate safeguards under Chapter V of the GDPR (Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework).
8. Security of processing
DevInterface adopts appropriate technical and organisational measures, including: encryption of data in transit, access control, environment segregation, backups, event logging and incident management procedures, in compliance with Art. 32 GDPR.
9. Personal data breaches
In the event of a personal data breach, DevInterface informs the Controller without undue delay after becoming aware of it, providing the information necessary for the Controller to fulfil its notification obligations under Arts. 33 and 34 GDPR.
10. Assistance to the Controller
DevInterface provides the Controller, taking into account the nature of the processing, with reasonable assistance in responding to data subjects' requests and in carrying out impact assessments (DPIA) and any necessary prior consultations.
11. Deletion or return of data
Upon termination of the contractual relationship, DevInterface, at the Controller's choice, deletes or returns the personal data processed on its behalf, unless retention is required by Union or national law.
12. Audit
DevInterface makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in Art. 28 GDPR and allows for and contributes to audit activities, including inspections, conducted with reasonable notice and in a manner that does not compromise the security and confidentiality of other customers.
13. Duration and governing law
This DPA is effective for the entire duration of the processing carried out on behalf of the Controller. It is governed by Italian law; the Court of Verona shall have jurisdiction over any dispute. In the event of a conflict between this DPA and the Terms of Service regarding data protection, this DPA shall prevail.
Digital acceptance. This document is deemed accepted by the Customer by ticking the relevant box during registration for the service. The user identifier, document version, date and time of consent are retained.