🔥 Lite Plan for just €19.00/month! 🔥

Data Processing Agreement (DPA)

Agreement on the processing of personal data between the Customer, acting as Data Controller, and Stepcode SRL, provider of the Supportfast.ai platform, acting as external Data Processor pursuant to Article 28 of Regulation (EU) 2016/679. Constitutes Annex A to the General Terms of Service.

Version: 2.3 | Effective from: 19/05/2026 | Reference language: Italian
The Parties. Data Controller: the Customer, natural or legal person who has accepted the General Terms of Service of Supportfast.ai and activated one or more chatbots or voice assistants through the platform. Identification data are those indicated in the Customer’s Account.

Data Processor: Stepcode SRL, Via Valpolicella 238, 37015 Sant’Ambrogio di Valpolicella (VR), Italy, VAT / Tax ID IT05205700239. Privacy contact: [email protected].

1.Recitals

This Data Processing Agreement (“DPA”) constitutes Annex A to the General Terms of Service (“Agreement”) and forms an integral and substantial part of it. It governs the processing of personal data carried out by Stepcode SRL on behalf of the Customer in the context of the provision of the Supportfast.ai software and services.

  1. The Customer, by accepting the General Terms and activating the service, fully accepts this DPA.
  2. The Processor declares that it has the experience, reliability and technical and organisational resources necessary to carry out the envisaged processing, in compliance with the GDPR and applicable national legislation.
  3. The processing carried out by the Processor in performance of the Agreement takes place exclusively on the documented instructions of the Controller, as specified in the Agreement, in this DPA, in the configurations operated by the Customer in the console and in any further written instructions provided by the Controller.
  4. This DPA prevails, in case of conflict, over the other contractual provisions for aspects relating to the processing of personal data, without prejudice to the Privacy Policy, to be considered a complementary document.

In light of the foregoing, the Customer appoints Stepcode SRL as Processor of personal data pursuant to and for the purposes of Article 28 GDPR, in accordance with the terms and conditions set out below.

2.Definitions

In addition to the terms defined in the Agreement, in this DPA the following capitalised terms shall have the meaning indicated:

2.1 “Personal Data”: any information relating to an identified or identifiable natural person (Data Subject), processed by the Processor on behalf of the Controller in performance of the Agreement.

2.2 “Special Categories of Data”: the data referred to in Article 9 GDPR.

2.3 “GDPR”: Regulation (EU) 2016/679.

2.4 “Italian DPA”: the Italian Data Protection Authority (Garante per la protezione dei dati personali).

2.5 “Data Subject”: the identified or identifiable natural person to whom the Personal Data relate. In the context of this DPA, Data Subjects are mainly the end users of the Customer who interact with the chatbots and voice assistants distributed through Supportfast.ai.

2.6 “Processing”: any operation applied to Personal Data, whether automated or not.

2.7 “Sub-processor”: the third party engaged by the Processor to carry out specific processing activities on behalf of the Controller, pursuant to Article 28(2), (3) and (4) GDPR.

2.8 “Personal Data Breach”: the security breach that accidentally or unlawfully results in the destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

2.9 “Customer Data”: the set of contents, configurations, knowledge bases, conversation logs, audio recordings and any other data that the Customer or end users upload or generate through the platform.

2.10 “DPF”: the EU-U.S. Data Privacy Framework, subject of the European Commission’s adequacy decision of 10 July 2023.

2.11 “SCC”: the standard contractual clauses adopted by the European Commission with Decision 2021/914/EU.

3.Subject matter and scope of the appointment

3.1 The Customer, by signing the Agreement, appoints Stepcode SRL as Processor of the processing pursuant to Article 28 GDPR, authorising it to process Personal Data on behalf of the Controller, exclusively for the purposes, in accordance with the instructions and within the limits defined by this DPA.

3.2 The subject matter of the processing includes:

  • Chat module: configuration, execution and management of the Customer’s chatbots on the channels website, WhatsApp Business, Instagram, Facebook Messenger, e-mail.
  • Voice module (Centralino AI): configuration, execution and management of voice assistants, including speech transcription, voice synthesis and conversational logic.
  • Storage and logs: retention of conversations, configurations, knowledge base, audio recordings (where enabled) and operational metadata.
  • Integrations: connection with third-party systems configured by the Customer.
  • Reporting and analytics: generation of aggregated statistics on conversations.
  • Technical support: assistance to the Customer, with possible temporary access to Customer Data strictly necessary.

3.3 This DPA does not govern the processing carried out by Stepcode SRL as autonomous Controller for its own purposes (account, billing, marketing towards the Customer, system security), which is regulated by the Privacy Policy.

4.Categories of personal data and data subjects

4.1 The categories of Personal Data and Data Subjects processed by the Processor on behalf of the Controller are detailed in Annex C.

4.2 Special Categories of Data (Article 9 GDPR)

The Customer undertakes to configure the service in such a way as not to solicit, collect or induce end users to communicate Special Categories of Data without a suitable legal basis pursuant to Article 9(2) GDPR and without adequate notice. Should such categories need to be processed, the Customer is required to give prior notice to the Processor and to request a specific addendum to this DPA.

4.3 Upon written request of the Controller, the Processor updates, modifies, corrects or deletes the Personal Data processed within 15 days of receipt of the request, save where legal obligations prevent this.

5.Purposes of processing and Controller’s instructions

5.1 The Processor processes Personal Data exclusively for the following purposes, in strict performance of the Agreement:

  1. Provision of the Supportfast.ai software and services as configured by the Customer.
  2. Execution of the operational instructions given by the Customer through the console or in writing.
  3. Provision of the technical support requested by the Customer.
  4. Compliance with legal obligations to which the Processor is subject, notifying the Controller in advance unless prohibited by law.

5.2 The Processor does not use Customer Data for its own further purposes beyond those listed. In particular, Customer Data is not used for the training or improvement of artificial intelligence models (see Section 7).

5.3 The Processor may process Personal Data in aggregated and anonymised form, no longer traceable to any Data Subject, for internal statistical, security and operational improvement purposes of the service.

5.4 Should the Processor consider that an instruction of the Controller infringes the GDPR or other applicable provisions, it immediately informs the Controller and reserves the right to suspend the execution of the instruction pending clarification.

6.Obligations of the Processor

The Processor undertakes to:

  1. Fully comply with the GDPR and the applicable privacy legislation.
  2. Process Personal Data exclusively on the documented instructions of the Controller, save for the legal obligations referred to in Article 28(3)(a) GDPR.
  3. Ensure that persons authorised to process are bound by an obligation of confidentiality and are trained periodically.
  4. Adopt and maintain the technical and organisational measures described in Annex B, suitable to ensure a level of security appropriate to the risk (Article 32 GDPR).
  5. Maintain a record of processing activities carried out on behalf of the Controller, pursuant to Article 30(2) GDPR.
  6. Notify the Controller of any request from Data Subjects relating to the exercise of the rights under Articles 15-22 GDPR, without delay and in any case within 5 working days.
  7. Communicate to the Controller any dispute, investigation or proceeding brought by Authorities concerning the processing covered by this DPA.
  8. Assist the Controller in fulfilling the obligations under Articles 32-36 GDPR.
  9. Select Sub-processors with due diligence and impose on them in writing obligations equivalent to those set out in this DPA.
  10. Return or delete Personal Data at the end of the Agreement, in accordance with Section 14.

7.Prohibition on use for training of artificial intelligence systems

Binding commitment. The Processor undertakes not to use Customer Data, including chatbot configurations, knowledge bases, conversation logs, audio recordings and any personal data of Data Subjects, for the training, development, fine-tuning or improvement of artificial intelligence models, machine learning algorithms, automated systems or any other system, whether owned by the Processor or by third parties.

7.1 The Processor uses exclusively artificial intelligence model providers configured in such a way as to exclude the reuse of transmitted data for the training of their models (opt-out from training or zero data retention for training mode).

7.2 The Processor guarantees that the Sub-processors providing AI models (currently OpenAI, LLC; any future providers will be notified with prior notice pursuant to Section 8) are contractually bound to the same prohibition and, where available, to the APIs or endpoints that exclude the use of transmitted data for training purposes.

7.3 The Processor may, however, use aggregated and anonymised data, no longer traceable to any Data Subject, for service improvement purposes. Such use is limited to technical metrics, usage statistics and security analyses, and in no case entails the processing of Personal Data.

8.Sub-processors and BYOK mode

8.1 The Controller, by signing this DPA, grants the Processor general authorisation to engage Sub-processors for the processing activities necessary for the performance of the Agreement, pursuant to Article 28(2) GDPR.

8.2 The updated list of Sub-processors is publicly available at supportfast.ai/en/sub-processors and in Annex A to this DPA.

8.3 The Processor selects Sub-processors on the basis of criteria of reliability, security and compliance, and imposes on them in writing, through agreements pursuant to Article 28 GDPR, obligations equivalent to those set out in this DPA, including the prohibition on the use of Customer Data for AI training purposes referred to in Section 7.

8.4 Notification of changes. The Processor communicates to the Controller any change to the list of Sub-processors (addition or replacement) with at least 30 days’ prior notice, through publication on the dedicated page, notice in the console and, for material changes, communication by e-mail.

8.5 Right to object. The Controller may object on legitimate and documented grounds to a change in the list of Sub-processors within the notice period. In such case, the Parties shall negotiate in good faith a solution; failing agreement, the Controller may withdraw from the Agreement without penalty.

8.6 The Processor is liable to the Controller for breaches of the GDPR committed by Sub-processors within the limits set out in Article 28(4) GDPR.

8.7 Bring Your Own Key (BYOK) mode

8.7.1 The Controller may choose to configure its Chatbots using an API key in its own name towards an artificial intelligence model provider (for example, an OpenAI key from the Controller’s own account). In such mode, conversational data flows directly from the Processor’s system to the AI provider using the Controller’s credentials.

Legal qualification of BYOK mode. In BYOK mode, the relationship for the processing carried out by the AI provider is directly between the Controller and the provider: the AI provider does not qualify as a Sub-processor of the Processor for that specific processing. The qualification of the Processor remains unchanged for the other components of the processing (storage, logs, infrastructure, orchestration), which continue to be regulated by this DPA.

8.7.2 In BYOK mode, the Controller:

  • Is directly responsible for the selection of the AI provider and for the verification of its terms of service, privacy policy and Article 28 GDPR agreement.
  • Is directly liable to Data Subjects for the processing carried out by the AI provider.
  • Ensures that the legal basis for the extra-EU transfer of data to the AI provider has been verified and documented.
  • Indemnifies the Processor against third-party claims arising from the processing carried out in BYOK mode at the chosen AI provider.

9.Transfers of data outside the European Union

9.1 The Processor prefers the use of Sub-processors with servers located in the European Economic Area (EEA). The main application infrastructure and the storage of conversational data are hosted on servers located in EU territory (Hetzner DE, Amazon S3 eu-central-1 Frankfurt). The voice module uses LiveKit Cloud with EU region pinning (Belgium).

9.2 For Sub-processors that process data outside the EEA (in particular AI model and CDN providers), the transfer takes place exclusively on the basis of:

Data Privacy Framework (DPF)

Where the Sub-processor is certified to the EU-U.S. Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023), the transfer takes place on the basis of that decision. The certification is verifiable on the official register dataprivacyframework.gov.

Standard Contractual Clauses (SCC)

For Sub-processors not certified to the DPF or located in countries without an adequacy decision, the Processor signs the Standard Contractual Clauses 2021/914/EU, supplemented by additional technical and organisational measures (encryption, pseudonymisation) on the basis of a documented assessment.

9.3 Upon written request of the Controller, the Processor makes available, in redacted form where necessary for reasons of commercial confidentiality, a copy of the SCCs signed with individual Sub-processors and the summary of the transfer impact assessments.

10.Technical and organisational security measures

10.1 The Processor adopts and maintains the technical and organisational measures listed in Annex B, suitable to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR.

10.2 The measures include, on a non-exhaustive basis: encryption in transit (TLS 1.2/1.3) and at rest, robust authentication with optional MFA, role-based access controls, audit logs of administrative accesses, logical data segregation per Customer, periodic backups with disaster recovery procedures, continuous security monitoring, vulnerability management, staff training.

10.3 The Processor reviews and updates security measures periodically to take account of technological evolution and risks.

11.Assistance to the Controller

11.1 The Processor assists the Controller, with appropriate technical and organisational measures, in particular for:

  • Data Subject rights: handling of requests for access, rectification, erasure, restriction, portability, objection. The Processor makes available tools in the console for the export and deletion of data.
  • Security and breaches: as specified in Section 13.
  • Impact assessment (DPIA): the Processor provides the technical information reasonably necessary for the DPIA under Article 35 GDPR.
  • Prior consultation: the Processor assists the Controller in any prior consultations with the Italian DPA under Article 36 GDPR.

11.2 Assistance provided within the standard functionalities of the platform is included in the fee under the Agreement. Further or non-standard assistance activities may be invoiced to the Controller, subject to written quotation.

12.Audits and inspections

12.1 The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR.

12.2 Ordinary procedure. The Controller is entitled to request, with at least 30 days’ written notice, a copy of the documentation relating to security measures, current certifications, internal audit reports and the results of penetration tests, in redacted form where necessary for confidentiality reasons.

12.3 On-site inspection. In exceptional and reasoned circumstances (e.g. serious security incident, documented suspected non-compliance, request from Authorities), the Controller may request an on-site audit, with at least 60 days’ written notice, to be carried out during working hours. The audit is subject to confidentiality obligations and costs are borne by the Controller, unless a material breach of the DPA by the Processor emerges.

12.4 The Processor may satisfy the obligations of this Section also through the sharing of independent third-party audit reports (e.g. ISO 27001, SOC 2), where available.

13.Personal data breach

13.1 In the event of a Personal Data Breach in processing carried out on behalf of the Controller, even if caused by a Sub-processor, the Processor:

  1. Notifies the Controller without undue delay and, in any case, within 48 hours of becoming aware of the event, providing the information referred to in Article 33(3) GDPR to the extent of its knowledge at the time.
  2. Prepares and updates an internal register of breaches pursuant to Article 33(5) GDPR, with description of the nature of the breach, categories and approximate number of Data Subjects involved, possible consequences, measures adopted.
  3. Promptly adopts the technical and organisational measures necessary to contain the effects of the breach.
  4. Cooperates with the Controller and with any competent Authorities, providing all reasonably necessary assistance.

13.2 Notification to the Italian DPA pursuant to Article 33 GDPR and any communication to Data Subjects pursuant to Article 34 GDPR remain the responsibility of the Controller. The Processor provides the support necessary to enable the Controller to fulfil such obligations within the time limits set by law.

13.3 The 48-hour deadline under clause 13.1 is specific to the relationship between Processor and Controller and is more stringent than the 72-hour deadline provided by Article 33 GDPR for the Controller’s notification to the Italian DPA, in order to enable the Controller to comply with the latter deadline.

14.Duration and end of processing

14.1 This DPA enters into force on the date of acceptance of the Agreement and remains effective for the entire duration thereof. Upon termination of the Agreement, for any cause, the DPA automatically ceases to have effect, save for the provisions which by their nature must survive (e.g. confidentiality, liability).

14.2 End of processing. Upon termination of the Agreement, the Processor, subject to different legal obligations:

  1. Retains the Customer Data for a grace period of 30 days, during which the Customer may export its data through the tools available in the console or request assistance.
  2. After the grace period, proceeds to delete the Customer Data from production environments and, within a further 90 days, from system backups, without prejudice to copies that may be necessary for legal needs or for the defence of a right.
  3. Upon explicit request of the Controller made before the expiry of the grace period, returns the Customer Data in a structured and commonly used format (e.g. JSON, CSV).

14.3 Upon request, the Processor provides written confirmation of deletion at the end of the periods referred to above.

15.Liability of the Parties

15.1 The liability of each Party under this DPA is governed by Article 82 GDPR. Each Party is liable for damages caused by processing carried out in breach of the GDPR or of this DPA.

15.2 Save as mandatorily provided by law, the overall liability of the Processor for damages arising from this DPA is subject to the same limits of liability provided by the Agreement, with the exception of damages caused by wilful misconduct or gross negligence.

15.3 The Customer, as Controller, indemnifies the Processor against third-party claims arising from processing carried out on the Controller’s instructions in breach of the GDPR, unless the breach is attributable to the Processor.

16.Communications and amendments

16.1 Communications relating to this DPA are made in writing, to the addresses indicated in the Agreement or to [email protected] for communications directed to the Processor.

16.2 The Processor may amend this DPA to reflect regulatory developments, organisational changes or improvements in the guarantees in favour of the Controller. Amendments are communicated to the Controller with at least 30 days’ prior notice by e-mail and in-console notice. The Controller is entitled to withdraw from the Agreement within such period should it consider the amendments prejudicial.

16.3 Purely formal updates, correction of typos or non-material regulatory updates may be made without prior notice, with indication of the version change in the document header.

17.Governing law and jurisdiction

17.1 This DPA is governed by Italian law.

17.2 Any dispute concerning the validity, effectiveness, interpretation or performance of this DPA is subject to the exclusive and mandatory jurisdiction of the Court of Verona.

Annex A: Sub-processors

The updated and complete list is available at supportfast.ai/en/sub-processors. The following is a representation of the main Sub-processors as at the date of publication of this DPA.

VendorPurposeLocationTransfer basis
Hetzner Online GmbHHosting of the main application infrastructure (servers, databases)Nuremberg, Germany (EU)Intra-EU
Amazon Web Services EMEA SARLStorage and CDN for cdn.supportfast.aiFrankfurt, Germany (eu-central-1)Intra-EU
OpenAI, LLCLanguage models (LLM) for chatbots and voice, Stepcode modeSan Francisco, CA, USADPF
Acumbamail S.L.Sending of transactional and marketing e-mailsCuenca, Spain (EU)Intra-EU
Cloudflare, Inc.CDN, WAF, anti-DDoS, SSLUSA / global (EU PoP)DPF
Stripe Payments Europe Ltd.Payment processingDublin, Ireland (EU)Intra-EU
Google Ireland Ltd.Google Workspace (internal corporate e-mails)Ireland, USA groupSCC + DPF
Microsoft Ireland Operations Ltd.Microsoft Clarity (product analytics)Ireland + USASCC + DPF
PostHog Inc.Product analytics, EU region (Frankfurt)Frankfurt (EU)Intra-EU
Meta Platforms Ireland Ltd.WhatsApp Business API, Instagram, Messenger (if active)Ireland, USA groupSCC + DPF
LiveKit, Inc.LiveKit Cloud, WebRTC orchestration and SIP telephony for voice moduleEU, region pinning BelgiumDPF + SCC
Deepgram, Inc.Speech-to-text, voice moduleUSADPF
ElevenLabs Inc.Text-to-speech, voice moduleUSADPF

The Processor may, during the term of the Agreement, replace, add or remove Sub-processors in accordance with the procedure set out in Section 8. The updated list on the public page constitutes the current list.

Annex B: Technical and organisational security measures

Measures adopted by the Processor pursuant to Article 32 GDPR, suitable to ensure a level of security appropriate to the risk.

B.1 – Encryption and data protection

  • Encryption in transit: TLS 1.2 minimum, TLS 1.3 preferred, on all communication channels (HTTPS, API, webhook). Certificates managed through Cloudflare SSL.
  • Encryption at rest: databases and storage encrypted with industry-standard algorithms (AES-256 or equivalent).
  • Key management: periodic rotation, separation of roles, secure storage.

B.2 – Access control

  • Authentication: username and password with complexity requirements; multi-factor authentication (MFA) available.
  • Authorisation: role-based access control (RBAC); principle of least privilege.
  • Session management: secure tokens, automatic expiry, possibility of centralised revocation.
  • Administrative access: limited to strictly necessary personnel, subject to audit log.

B.3 – Data segregation

  • Logical data segregation per Customer; no cross-Customer access.
  • Opaque identifiers for main resources; impossibility to enumerate or access data of other Customers through manipulation of identifiers.

B.4 – Infrastructure security

  • Servers managed on Hetzner infrastructure (Germany, EU).
  • Network and application-level firewall (Cloudflare WAF); anti-DDoS protection.
  • Continuous monitoring of services (uptime, performance, anomalies).
  • Hardening of operating systems; removal of unnecessary services and ports.

B.5 – Vulnerability management

  • Regular patching of operating systems, dependencies and libraries.
  • Continuous monitoring of known vulnerabilities (CVE) on dependencies in use.
  • Code review before release to production; separate staging environments.
  • Periodic security testing.

B.6 – Logging and audit

  • Audit log of administrative accesses and critical operations.
  • Application logs retained for 12 months in pseudonymous form.
  • System administrator logs retained for a minimum of 6 months pursuant to the Italian DPA Provision of 27 November 2008.
  • Security logs retained for up to 5 years in case of incidents.

B.7 – Backup and disaster recovery

  • Periodic automatic backups of production data.
  • Retention of backups for a limited period (max 90 days post-deletion).
  • Documented and periodically tested disaster recovery procedures.

B.8 – Personnel

  • Formal designation of personnel authorised to process pursuant to Article 29 GDPR.
  • Contractual confidentiality obligations for all employees and collaborators.
  • Periodic training on GDPR, IT security and incident management procedures.
  • Onboarding/offboarding procedures with timely revocation of access.

B.9 – Incident management

  • Documented internal procedure for the management of Personal Data Breaches.
  • Vulnerability reporting channels ([email protected]).
  • Internal register of breaches pursuant to Article 33(5) GDPR.

B.10 – Sub-processors

  • Selection of Sub-processors on the basis of documented security and compliance criteria.
  • Agreements pursuant to Article 28 GDPR with all Sub-processors.
  • Periodic review of the security of main Sub-processors.

Annex C: Categories of data and data subjects

Specifications of the processing carried out by the Processor on behalf of the Controller, pursuant to Article 28(3) GDPR.

C.1 – Nature and purpose of the processing

The processing consists in the provision of the Supportfast.ai software and services as configured by the Controller: configuration of chatbots and voice assistants, execution of conversations on integrated channels, storage and management of conversations and audio, integration with third-party systems configured by the Controller, generation of reporting.

C.2 – Categories of Data Subjects

  • End users of the Controller who interact with chatbots and voice assistants (customers, prospects, suppliers, contacts).
  • Visitors of the Controller’s digital channels who use the bots.
  • Collaborators of the Controller authorised to access the console.

C.3 – Categories of Personal Data

CategoryExamples
Identification dataName, surname, channel identifiers (WhatsApp number, Instagram ID, e-mail).
Contact dataE-mail, telephone number.
Conversational contentText of messages, attachments, audio recordings (voice module), transcriptions.
Conversational metadataTimestamp, channel, duration, outcome, rating.
Enriched profile dataCategories and tags attributed by the Customer to conversations or contacts.
Technical dataIP, user-agent, device, in pseudonymised form.
Any other dataData communicated voluntarily by end users in the interactions, under the responsibility of the Controller.

C.4 – Special Categories of Data (Article 9 GDPR)

By default, the Processor does not process Special Categories of Data. Should the Controller configure the service in such a way as to process such categories (e.g. chatbots in the healthcare sector), the Controller is required to give prior notice to the Processor, to verify the existence of a suitable legal basis pursuant to Article 9(2) GDPR, to provide adequate notice to Data Subjects and to request a specific addendum to this DPA.

C.5 – Duration of the processing

For the entire duration of the Agreement, with retention periods of individual data defined by the Customer’s configurations in the console and, failing that, by the default values:

  • Chat conversation logs: default 12 months, configurable.
  • Voice audio (if recording enabled): default 30 days, configurable.
  • Voice transcriptions: default 12 months, configurable.
  • Configurations and knowledge bases: for the entire duration of the Agreement.

Upon termination of the Agreement, the procedure under Section 14 applies.

Signing of this DPA. This DPA is deemed signed and accepted by the Customer at the time of acceptance of the General Terms of Service in the registration phase or when accessing the platform. The date and time of acceptance are recorded electronically in the system, with identification of the account, IP address and version of the DPA accepted. The Customer may request a countersigned copy of this DPA, duly signed by the legal representative of Stepcode SRL, by writing to [email protected].
Language. This English version is provided for convenience. In case of conflict or inconsistency, the Italian version prevails as the binding legal text, given the Italian law and jurisdiction governing this DPA.