Privacy Policy
Widgeto.ai — DevInterface SRL
Version 1.0 · Last updated: 1 July 2026
This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and describes how DevInterface SRL processes personal data in the context of the Widgeto.ai service.
1. Data Controller
DevInterface SRL, Via Guglielmo Marconi 20, 37012 Bussolengo (VR), Italy — VAT no. IT04080300232 — email: [email protected]. The Controller has not appointed a Data Protection Officer (DPO), as it is not legally required to do so.
2. Roles: who processes what
Two levels of processing must be distinguished:
- Data of Widgeto Customers (those who subscribe to the service): DevInterface acts as Data Controller.
- Data of End Users (visitors who chat with the widget on the Customer's website): the Customer is the Data Controller and DevInterface acts as Data Processor, in accordance with the Data Processing Agreement (DPA).
3. Categories of data processed
- Registration and account data: name, email, billing data, credentials.
- Usage data: access logs, IP address, technical data of the device and browser.
- Uploaded content: texts, documents and URLs provided to train the widget.
- Conversation content: the messages exchanged between the End User and the widget, which may contain personal data.
4. Purposes and legal bases
- Provision of the Service — legal basis: performance of the contract (Art. 6(1)(b) GDPR).
- Tax and accounting obligations — legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Security, abuse prevention and improvement of the Service — legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Service communications — legal basis: performance of the contract or legitimate interest.
5. Third-party providers and Processors (sub-processors)
To provide the Service, DevInterface relies on the following providers, which process personal data on its behalf:
- OpenAI — processing of conversations via API. Data is processed with EU residency where configured; any transfers to the United States take place on the basis of Standard Contractual Clauses (SCC).
- Contabo — hosting of the production infrastructure — Germany (EU).
- Hetzner — hosting for dedicated installations of individual customers — EU.
- Amazon Web Services (S3) — storage of files and documents — Ireland region (eu-west-1, EU).
With the exception of OpenAI, the infrastructure is located entirely within the European Union.
6. Transfers outside the EU
The only transfer of data outside the European Union concerns processing via OpenAI. This transfer is supported by appropriate safeguards under Chapter V of the GDPR (Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework certification).
7. Retention period
Data is retained for as long as necessary for the stated purposes and in compliance with legal obligations. Account data is retained for the duration of the relationship; logs and conversation content are retained according to the Service's retention policy and subsequently deleted or anonymised.
8. Rights of data subjects
The data subject may exercise the rights provided for in Articles 15-22 of the GDPR: access, rectification, erasure, restriction, portability and objection, as well as the right to lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali). Requests may be sent to [email protected].
Note: for data processed as a Processor on behalf of Customers, End User requests must be addressed to the relevant Customer (Controller), whom DevInterface assists in accordance with the DPA.
9. Amendments to this Policy
This Policy may be updated. The current version is always available within the Service, indicating the date of the last update.
Digital acknowledgement. This document is deemed acknowledged by the Customer by ticking the relevant box during registration for the service. The user identifier, document version, date and time of consent are retained.