Privacy Policy
Widgeto.ai — DevInterface SRL
Version 1.1 · Last updated: 15 September 2026
This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and describes how DevInterface SRL processes personal data in the context of the Widgeto.ai service.
1. Data Controller
DevInterface SRL, Via Guglielmo Marconi 20, 37012 Bussolengo (VR), Italy — VAT no. IT04080300231 — email: [email protected]. The Controller has not appointed a Data Protection Officer (DPO), as it is not legally required to do so.
2. Roles: who processes what
Two levels of processing must be distinguished:
- Data of Widgeto Customers (those who subscribe to the service): DevInterface acts as Data Controller.
- Data of End Users (visitors who chat with the widget on the Customer's website): the Customer is the Data Controller and DevInterface acts as Data Processor, in accordance with the Data Processing Agreement (DPA).
3. Categories of data processed
- Registration and account data: name, email, billing data, credentials.
- Usage data: access logs, IP address, technical data of the device and browser.
- Anti-bot verification data: when a public form is submitted, in particular the registration form, the anti-bot challenge processes the IP address, browser and device information, a browser fingerprint and the tracking tools it sets, for the sole purpose of telling a person apart from an automated script.
- Uploaded content: texts, documents and URLs provided to train the widget.
- Conversation content: the messages exchanged between the End User and the widget, which may contain personal data.
4. Purposes and legal bases
- Provision of the Service — legal basis: performance of the contract (Art. 6(1)(b) GDPR).
- Tax and accounting obligations — legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Security, abuse prevention and improvement of the Service, including the anti-bot protection of the registration form and of the other publicly accessible forms — legal basis: legitimate interest (Art. 6(1)(f) GDPR) in keeping the Service available and free from automated abuse.
- Service communications — legal basis: performance of the contract or legitimate interest.
5. Third-party providers and Processors (sub-processors)
To provide the Service, DevInterface relies on the following providers, which process personal data on its behalf:
- OpenAI — processing of conversations via API. Data is processed with EU residency where configured; any transfers to the United States take place on the basis of Standard Contractual Clauses (SCC).
- Cloudflare, Inc. — anti-bot protection of publicly accessible forms, including registration (Cloudflare Turnstile) — United States.
- Contabo — hosting of the production infrastructure — Germany (EU).
- Hetzner — hosting for dedicated installations of individual customers — EU.
- Amazon Web Services (S3) — storage of files and documents — Ireland region (eu-west-1, EU).
With the exception of OpenAI and Cloudflare, the infrastructure is located entirely within the European Union.
6. Transfers outside the EU
Two processing operations involve a transfer of data outside the European Union: the processing of conversations via OpenAI, and the anti-bot verification carried out by Cloudflare, Inc. Both transfers are supported by appropriate safeguards under Chapter V of the GDPR (Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework certification). No other provider involved in the Service processes data outside the European Union.
7. Retention period
Data is retained for as long as necessary for the stated purposes and in compliance with legal obligations. Account data is retained for the duration of the relationship; logs and conversation content are retained according to the Service's retention policy and subsequently deleted or anonymised.
8. Rights of data subjects
The data subject may exercise the rights provided for in Articles 15-22 of the GDPR: access, rectification, erasure, restriction, portability and objection, as well as the right to lodge a complaint with the supervisory authority (in Italy, the Garante per la protezione dei dati personali). Requests may be sent to [email protected].
Note: for data processed as a Processor on behalf of Customers, End User requests must be addressed to the relevant Customer (Controller), whom DevInterface assists in accordance with the DPA.
9. Amendments to this Policy
This Policy may be updated. The current version is always available within the Service, indicating the date of the last update.
Digital acknowledgement. This document is deemed acknowledged by the Customer by ticking the relevant box during registration for the service. The user identifier, document version, date and time of consent are retained.