How Stepcode SRL collects, uses, retains and protects personal data in connection with the Supportfast.ai software and related services, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
The Controller of personal data is Stepcode SRL, with registered office at Via Valpolicella 238, 37015 Sant’Ambrogio di Valpolicella (VR), Italy, VAT IT05205700239, Tax ID 05205700239, SDI recipient code K95IV18.
Contacts:
Stepcode SRL has not currently appointed a Data Protection Officer (DPO), as it does not fall within the cases of mandatory appointment under Article 37 GDPR. All privacy-related requests can be addressed to the dedicated e-mail contact.
This Privacy Policy applies to the processing of personal data carried out by Stepcode SRL in the context of:
supportfast.ai and its sub-domains.app.supportfast.ai and the other operational sub-domains of the service.In the provision of the Supportfast.ai service, Stepcode operates in two distinct roles under the GDPR.
Stepcode is autonomous Controller of the processing for:
This Privacy Policy applies to such processing.
For the personal data of the Customer’s end users (e.g. persons interacting with a chatbot integrated on a Customer’s website, or calling a number handled by the voice module), the Customer is Controller of the processing and Stepcode is external Processor pursuant to Article 28 GDPR. The full regime is set out in the Data Processing Agreement.
Customers using Supportfast on their own channels must provide their end users with adequate privacy notice pursuant to Articles 13 and 14 GDPR.
| Category | Examples |
|---|---|
| Identification and contact data | Name, surname, e-mail, phone, company name, job role. |
| Tax and billing data | VAT, tax ID, SDI code, PEC, IBAN, billing address. |
| Account access data | Username, password (hash), session tokens, access logs, IP. |
| Service usage data | Chatbot configurations, knowledge bases, activated integrations, usage statistics. |
| Conversational data (chat module) | Text of messages, attachments, conversation metadata (timestamp, channel). |
| Voice data (voice module) | Call audio (if recorded), text transcriptions, telephone number, call metadata. |
| Technical browsing data | IP, user-agent, device, browser, language, in pseudonymised form. |
| Marketing data | Preferences, interactions with e-mails and content, event participation. |
Stepcode does not voluntarily collect Special Categories of Data (ethnic origin, political opinions, health data, etc.). Should the Customer configure the chatbot for processing involving such categories (e.g. in the healthcare sector), the Customer must give prior notice to Stepcode and sign a specific addendum to the DPA. Reference is made to Annex C, Section 3 of the DPA for details.
Stepcode processes personal data for the purposes listed below, on a modular basis. Each purpose is autonomous with respect to the others: refusal of one does not affect the others, unless otherwise indicated.
Purpose: creation and management of the Customer’s Account, authentication, access security, management of the contractual relationship.
Legal basis: performance of the Contract, Article 6(1)(b) GDPR.
Data processed: name, surname, e-mail, password (hash), job role, company name, tax data, IP, access logs.
Retention: duration of the contractual relationship plus 30-day grace period for data export.
Purpose: operation of the Customer’s chatbots on the channels website, WhatsApp Business, Instagram, Facebook Messenger, e-mail; storage of conversations; integrations.
Legal basis: performance of the Contract with the Customer Controller, Article 6(1)(b) GDPR. For end users, legal basis collected by the Customer.
Data processed: conversation content, end-user identifiers, metadata.
AI sub-processors: OpenAI (see Section 7).
Retention: default 12 months for conversations, configurable by the Customer in the console.
Purpose: operation of voice assistants for handling inbound and outbound calls; audio-to-text transcription, voice synthesis, conversational logic.
Legal basis: performance of the Contract, Article 6(1)(b) GDPR. For the recording of end-user calls: explicit consent collected by the Customer Controller.
Data processed: call audio (transmitted in real time, not recorded by default), text transcriptions, telephone numbers, metadata. Voiceprint is neither generated nor stored.
Architecture: orchestration via LiveKit Cloud with EU region pinning (Belgium); SIP telephony natively integrated in LiveKit Cloud. Audio and metadata remain in the EU region for the entire duration of the call. LiveKit Cloud does not record or retain audio streams by default.
Sub-processors: LiveKit Cloud (orchestration and SIP, EU region), Deepgram (speech-to-text), ElevenLabs (text-to-speech). See sub-processors page.
Notice to Customer: the Customer is responsible for informing its end users of the recording and collecting consent pursuant to Articles 13 and 7 GDPR. Stepcode makes sample disclosure texts available.
Retention: audio (if recording enabled) 30 days by default; transcriptions same retention as conversation logs (default 12 months).
Purpose: invoice issuance, payment management, bookkeeping, tax filings.
Legal basis: legal obligation, Article 6(1)(c) GDPR; performance of the Contract, Article 6(1)(b) GDPR.
Data processed: identification data, VAT, tax ID, amounts, payment methods (tokenised via Stripe).
Retention: 10 years from the date of issue of the invoice, as required by tax legislation.
Purpose: sending communications necessary for the provision of the service (confirmations, technical notices, contractual changes, security alerts).
Legal basis: performance of the Contract, Article 6(1)(b) GDPR; legitimate interest, Article 6(1)(f) GDPR.
Retention: for the entire duration of the relationship.
Purpose: sending promotional communications about products or features similar to those already purchased.
Legal basis: legitimate interest, Article 6(1)(f) GDPR; soft spam under Article 130(4) of Legislative Decree 196/2003. The data subject may object at any time.
Retention: until objection, in any case no longer than 24 months from the last interaction.
Purpose: sending newsletters, commercial communications, invitations to events to persons who have expressed interest.
Legal basis: explicit consent, Article 6(1)(a) GDPR. Revocable at any time.
Retention: until withdrawal of consent, in any case no longer than 24 months from the last interaction.
Purpose: collection of feedback through surveys, interviews, NPS, aggregated usage analysis.
Legal basis: legitimate interest, Article 6(1)(f) GDPR. Participation always voluntary.
Retention: 24 months in identified form; subsequently only in aggregated or anonymous form.
Purpose: statistical analysis of the use of the showcase website supportfast.ai and the console app.supportfast.ai to identify usability issues and improve the product.
Legal basis: user’s consent for tools requiring non-technical cookies, Article 6(1)(a) GDPR; legitimate interest for aggregated anonymous analysis, Article 6(1)(f) GDPR.
Data processed: usage events (clicks, navigation), pages viewed, session duration, device, browser, language. Pseudonymised or truncated IP. For users authenticated in the console: account identifier associated with the events.
Tools: Microsoft Clarity (anonymised heatmaps and session recording) and PostHog (product analytics). Both used on the showcase website and in the console. Microsoft and PostHog act as external Processors of Stepcode pursuant to Article 28 GDPR.
Transfers: PostHog configured on the EU region (Frankfurt), intra-EU transfer. Microsoft Clarity: DPF + SCC.
Retention: 24 months, then anonymisation or deletion.
Purpose: security monitoring, intrusion detection, abuse prevention, incident management.
Legal basis: legitimate interest, Article 6(1)(f) GDPR.
Retention: 12 months for standard application logs; minimum 6 months for system administrator logs under the Italian DPA Provision of 27 November 2008; up to 5 years for logs relating to security incidents.
Purpose: exercise or defence of rights in court or out of court.
Legal basis: legitimate interest, Article 6(1)(f) GDPR; where applicable, Article 9(2)(f) GDPR.
Retention: for the entire duration of the litigation and within the applicable statute of limitations.
Personal data is retained for the time strictly necessary for the purposes for which it is collected. Summary of the main periods:
| Category | Retention | Basis |
|---|---|---|
| Account and configurations | Duration of the Contract + 30 days grace period | Performance of contract |
| Chat conversations | 12 months by default (configurable) | Customer configuration |
| Voice audio (if recorded) | 30 days by default (configurable) | Customer configuration |
| Voice transcriptions | 12 months by default (configurable) | Customer configuration |
| Invoices and tax documents | 10 years | Legal obligation |
| Prospect marketing | Until withdrawal / 24 months | Consent |
| Customer marketing | Until objection / 24 months | Legitimate interest |
| Application logs | 12 months | Security |
| System administrator logs | 6 months minimum | Italian DPA Provision 27/11/2008 |
| Security incident logs | Up to 5 years | Legitimate interest |
| Post-termination backups | 90 days from deletion | DPA procedure |
Upon expiry of the periods indicated above, data is deleted or irreversibly anonymised, except where retention is required by law or for the defence of a right.
Stepcode uses third-party vendors that, in the provision of certain services, process personal data on behalf of Stepcode as external Processors pursuant to Article 28 GDPR. They are bound by written agreements and selected on the basis of security and compliance criteria.
Updated public list: supportfast.ai/en/sub-processors
Main sub-processors as at the date of publication:
| Vendor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the main application infrastructure | Germany (EU) | Intra-EU |
| Amazon Web Services | CDN storage cdn.supportfast.ai | eu-central-1 (DE) | Intra-EU |
| OpenAI, LLC | Language models for chatbots and voice | USA | DPF |
| Acumbamail S.L. | Transactional and marketing e-mails | Spain (EU) | Intra-EU |
| Stripe Payments Europe | Payment processing | Ireland | Intra-EU |
| Cloudflare, Inc. | CDN, WAF, anti-DDoS | USA / global | DPF |
| Google Ireland Ltd. | Google Workspace (internal corporate e-mails) | Ireland + USA | SCC + DPF |
| PostHog Inc. | Product analytics, EU region | Frankfurt (EU) | Intra-EU |
| Microsoft Ireland Operations | Microsoft Clarity (heatmaps, behavioural analysis) | Ireland + USA | SCC + DPF |
| Meta Platforms Ireland | WhatsApp Business API, Instagram, Messenger | Ireland + USA | SCC + DPF |
| LiveKit, Inc. | LiveKit Cloud, voice and SIP orchestration, EU region | EU (Belgium) | DPF + SCC |
| Deepgram, Inc. | Speech-to-text for voice module (if active) | USA | DPF |
| ElevenLabs Inc. | Text-to-speech for voice module (if active) | USA | DPF |
Data may also be communicated to authorised persons (e.g. tax advisors, legal advisors, authorities) within the limits provided by law.
The primary servers for conversational, voice and application data are located in European territory (Hetzner DE, AWS Frankfurt, LiveKit Cloud EU region Belgium, PostHog Frankfurt, Acumbamail Spain).
Some sub-processors (in particular AI model and CDN providers) may process data in the United States. In such cases the transfer takes place on the basis of:
Supportfast.ai uses third-party artificial intelligence models for the operation of chatbots and voice assistants. The provider currently in use is OpenAI, LLC. Further providers may be integrated in the future and will be announced with 30 days’ prior notice through the sub-processors page.
Stepcode uses exclusively AI providers configured in such a way as to exclude the use of transmitted data for the training of their models. In particular, the OpenAI APIs are used with the settings that provide for no data retention for training; this obligation is reflected in the relevant contractual agreements.
The Customer may choose to use the AI models by configuring an API key in its own name towards the AI provider (for example, the Customer’s own corporate OpenAI key). In this mode:
Stepcode constantly monitors the application of Regulation (EU) 2024/1689 (AI Act) and updates product and contracts to ensure compliance with the applicable requirements. The service is designed not to constitute a high-risk AI system within the meaning of the AI Act. The Customer, in its role as deployer, undertakes not to use the service for purposes that would qualify it as a high-risk system without prior assessment and fulfilment of the related obligations.
Outputs generated by AI models may contain errors, inaccuracies or outdated information. The Customer is invited not to use the service for autonomous decisions in the medical, legal, financial or public safety fields, without adequate human supervision and without having carried out the verifications within its competence.
Stepcode adopts technical and organisational measures suitable to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR. Main measures:
For further details on the technical and organisational measures, the Customer may contact [email protected]. The complete measures are detailed in Annex B of the Data Processing Agreement.
In the event of a personal data breach, Stepcode follows its internal procedures and:
The data subject may exercise at any time the rights provided by Articles 15-22 GDPR:
To exercise the rights, write to [email protected]. Stepcode responds within 30 days (extendable by a further 60 days for complex requests, with notice to the data subject).
For the Customer’s end users: requests relating to data processed by Stepcode as external Processor must be addressed to the Customer Controller, possibly with the operational support of Stepcode as provided in the DPA.
Contact details of the Italian Data Protection Authority (Garante per la protezione dei dati personali):
The supportfast.ai website and the app.supportfast.ai console use cookies and similar technologies to ensure operation, analyse the use of the service and, subject to explicit consent, for marketing purposes.
For details of the cookies used, their purpose and duration, as well as for how to manage preferences, please refer to the Cookie Policy and to the consent management panel accessible from the website.
Stepcode reserves the right to amend this Privacy Policy to reflect regulatory developments, organisational changes or service updates. The current version is always available on this page, with version number and effective date indicated.
Material changes are communicated to Customers by e-mail and through in-console notice with reasonable advance notice before the effective date. Minor changes (typo corrections, link updates, non-material regulatory adjustments) may be made without prior notice, with update of the version number.