🔥 Lite Plan for just €19.00/month! 🔥

Privacy Policy

How Stepcode SRL collects, uses, retains and protects personal data in connection with the Supportfast.ai software and related services, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Version: 2.3 | Effective from: 19/05/2026 | Controller: Stepcode SRL | Reference language: Italian

1.Data Controller and contacts

The Controller of personal data is Stepcode SRL, with registered office at Via Valpolicella 238, 37015 Sant’Ambrogio di Valpolicella (VR), Italy, VAT IT05205700239, Tax ID 05205700239, SDI recipient code K95IV18.

Contacts:

Stepcode SRL has not currently appointed a Data Protection Officer (DPO), as it does not fall within the cases of mandatory appointment under Article 37 GDPR. All privacy-related requests can be addressed to the dedicated e-mail contact.

2.Scope of application

This Privacy Policy applies to the processing of personal data carried out by Stepcode SRL in the context of:

  • The public website supportfast.ai and its sub-domains.
  • The management console app.supportfast.ai and the other operational sub-domains of the service.
  • The provision of the Supportfast.ai software (chatbots and voice assistants) and the related services.
  • The processing carried out on behalf of Customers using the platform, regulated in the Data Processing Agreement.

3.Stepcode’s dual role: Controller or Processor

In the provision of the Supportfast.ai service, Stepcode operates in two distinct roles under the GDPR.

3.1 Stepcode as autonomous Controller

Stepcode is autonomous Controller of the processing for:

  • Registration and management of the Customer’s Account (B2B or consumer).
  • Billing data and tax obligations.
  • Commercial and marketing communications directed to the Customer.
  • Security of systems, fraud prevention, application logs.
  • Exercise or defence of legal claims.

This Privacy Policy applies to such processing.

3.2 Stepcode as Processor

For the personal data of the Customer’s end users (e.g. persons interacting with a chatbot integrated on a Customer’s website, or calling a number handled by the voice module), the Customer is Controller of the processing and Stepcode is external Processor pursuant to Article 28 GDPR. The full regime is set out in the Data Processing Agreement.

Customers using Supportfast on their own channels must provide their end users with adequate privacy notice pursuant to Articles 13 and 14 GDPR.

4.Categories of data subjects and data processed

4.1 Categories of data subjects

  • Customers: natural persons or representatives of legal entities subscribing to the platform (B2B and consumers).
  • Prospects and visitors: persons visiting the showcase website or requesting commercial information.
  • End users of the Customer: persons interacting with a chatbot or voice assistant managed by a Customer (data processed as Processor, see DPA).
  • Collaborators and suppliers: natural persons of suppliers, partners, consultants.

4.2 Categories of personal data

CategoryExamples
Identification and contact dataName, surname, e-mail, phone, company name, job role.
Tax and billing dataVAT, tax ID, SDI code, PEC, IBAN, billing address.
Account access dataUsername, password (hash), session tokens, access logs, IP.
Service usage dataChatbot configurations, knowledge bases, activated integrations, usage statistics.
Conversational data (chat module)Text of messages, attachments, conversation metadata (timestamp, channel).
Voice data (voice module)Call audio (if recorded), text transcriptions, telephone number, call metadata.
Technical browsing dataIP, user-agent, device, browser, language, in pseudonymised form.
Marketing dataPreferences, interactions with e-mails and content, event participation.

4.3 Special Categories of Data (Article 9 GDPR)

Stepcode does not voluntarily collect Special Categories of Data (ethnic origin, political opinions, health data, etc.). Should the Customer configure the chatbot for processing involving such categories (e.g. in the healthcare sector), the Customer must give prior notice to Stepcode and sign a specific addendum to the DPA. Reference is made to Annex C, Section 3 of the DPA for details.

5.Purposes and legal bases of processing

Stepcode processes personal data for the purposes listed below, on a modular basis. Each purpose is autonomous with respect to the others: refusal of one does not affect the others, unless otherwise indicated.

5.1 Registration, Account management, access to the platform

Purpose: creation and management of the Customer’s Account, authentication, access security, management of the contractual relationship.

Legal basis: performance of the Contract, Article 6(1)(b) GDPR.

Data processed: name, surname, e-mail, password (hash), job role, company name, tax data, IP, access logs.

Retention: duration of the contractual relationship plus 30-day grace period for data export.

5.2 Provision of the service: chat module

Purpose: operation of the Customer’s chatbots on the channels website, WhatsApp Business, Instagram, Facebook Messenger, e-mail; storage of conversations; integrations.

Legal basis: performance of the Contract with the Customer Controller, Article 6(1)(b) GDPR. For end users, legal basis collected by the Customer.

Data processed: conversation content, end-user identifiers, metadata.

AI sub-processors: OpenAI (see Section 7).

Retention: default 12 months for conversations, configurable by the Customer in the console.

5.3 Provision of the service: voice module (Centralino AI)

Purpose: operation of voice assistants for handling inbound and outbound calls; audio-to-text transcription, voice synthesis, conversational logic.

Legal basis: performance of the Contract, Article 6(1)(b) GDPR. For the recording of end-user calls: explicit consent collected by the Customer Controller.

Data processed: call audio (transmitted in real time, not recorded by default), text transcriptions, telephone numbers, metadata. Voiceprint is neither generated nor stored.

Architecture: orchestration via LiveKit Cloud with EU region pinning (Belgium); SIP telephony natively integrated in LiveKit Cloud. Audio and metadata remain in the EU region for the entire duration of the call. LiveKit Cloud does not record or retain audio streams by default.

Sub-processors: LiveKit Cloud (orchestration and SIP, EU region), Deepgram (speech-to-text), ElevenLabs (text-to-speech). See sub-processors page.

Notice to Customer: the Customer is responsible for informing its end users of the recording and collecting consent pursuant to Articles 13 and 7 GDPR. Stepcode makes sample disclosure texts available.

Retention: audio (if recording enabled) 30 days by default; transcriptions same retention as conversation logs (default 12 months).

5.4 Billing, accounting and tax obligations

Purpose: invoice issuance, payment management, bookkeeping, tax filings.

Legal basis: legal obligation, Article 6(1)(c) GDPR; performance of the Contract, Article 6(1)(b) GDPR.

Data processed: identification data, VAT, tax ID, amounts, payment methods (tokenised via Stripe).

Retention: 10 years from the date of issue of the invoice, as required by tax legislation.

5.5 Service communications

Purpose: sending communications necessary for the provision of the service (confirmations, technical notices, contractual changes, security alerts).

Legal basis: performance of the Contract, Article 6(1)(b) GDPR; legitimate interest, Article 6(1)(f) GDPR.

Retention: for the entire duration of the relationship.

5.6 Direct marketing to existing Customers

Purpose: sending promotional communications about products or features similar to those already purchased.

Legal basis: legitimate interest, Article 6(1)(f) GDPR; soft spam under Article 130(4) of Legislative Decree 196/2003. The data subject may object at any time.

Retention: until objection, in any case no longer than 24 months from the last interaction.

5.7 Marketing to prospects

Purpose: sending newsletters, commercial communications, invitations to events to persons who have expressed interest.

Legal basis: explicit consent, Article 6(1)(a) GDPR. Revocable at any time.

Retention: until withdrawal of consent, in any case no longer than 24 months from the last interaction.

5.8 Customer satisfaction and product improvement

Purpose: collection of feedback through surveys, interviews, NPS, aggregated usage analysis.

Legal basis: legitimate interest, Article 6(1)(f) GDPR. Participation always voluntary.

Retention: 24 months in identified form; subsequently only in aggregated or anonymous form.

5.9 Product analytics and usage behaviour analysis

Purpose: statistical analysis of the use of the showcase website supportfast.ai and the console app.supportfast.ai to identify usability issues and improve the product.

Legal basis: user’s consent for tools requiring non-technical cookies, Article 6(1)(a) GDPR; legitimate interest for aggregated anonymous analysis, Article 6(1)(f) GDPR.

Data processed: usage events (clicks, navigation), pages viewed, session duration, device, browser, language. Pseudonymised or truncated IP. For users authenticated in the console: account identifier associated with the events.

Tools: Microsoft Clarity (anonymised heatmaps and session recording) and PostHog (product analytics). Both used on the showcase website and in the console. Microsoft and PostHog act as external Processors of Stepcode pursuant to Article 28 GDPR.

Transfers: PostHog configured on the EU region (Frankfurt), intra-EU transfer. Microsoft Clarity: DPF + SCC.

Retention: 24 months, then anonymisation or deletion.

5.10 Security, fraud prevention and system protection

Purpose: security monitoring, intrusion detection, abuse prevention, incident management.

Legal basis: legitimate interest, Article 6(1)(f) GDPR.

Retention: 12 months for standard application logs; minimum 6 months for system administrator logs under the Italian DPA Provision of 27 November 2008; up to 5 years for logs relating to security incidents.

5.11 Exercise or defence of legal claims

Purpose: exercise or defence of rights in court or out of court.

Legal basis: legitimate interest, Article 6(1)(f) GDPR; where applicable, Article 9(2)(f) GDPR.

Retention: for the entire duration of the litigation and within the applicable statute of limitations.

6.Retention periods

Personal data is retained for the time strictly necessary for the purposes for which it is collected. Summary of the main periods:

CategoryRetentionBasis
Account and configurationsDuration of the Contract + 30 days grace periodPerformance of contract
Chat conversations12 months by default (configurable)Customer configuration
Voice audio (if recorded)30 days by default (configurable)Customer configuration
Voice transcriptions12 months by default (configurable)Customer configuration
Invoices and tax documents10 yearsLegal obligation
Prospect marketingUntil withdrawal / 24 monthsConsent
Customer marketingUntil objection / 24 monthsLegitimate interest
Application logs12 monthsSecurity
System administrator logs6 months minimumItalian DPA Provision 27/11/2008
Security incident logsUp to 5 yearsLegitimate interest
Post-termination backups90 days from deletionDPA procedure

Upon expiry of the periods indicated above, data is deleted or irreversibly anonymised, except where retention is required by law or for the defence of a right.

7.Recipients and sub-processors

Stepcode uses third-party vendors that, in the provision of certain services, process personal data on behalf of Stepcode as external Processors pursuant to Article 28 GDPR. They are bound by written agreements and selected on the basis of security and compliance criteria.

Updated public list: supportfast.ai/en/sub-processors

Main sub-processors as at the date of publication:

VendorPurposeLocationTransfer basis
Hetzner Online GmbHHosting of the main application infrastructureGermany (EU)Intra-EU
Amazon Web ServicesCDN storage cdn.supportfast.aieu-central-1 (DE)Intra-EU
OpenAI, LLCLanguage models for chatbots and voiceUSADPF
Acumbamail S.L.Transactional and marketing e-mailsSpain (EU)Intra-EU
Stripe Payments EuropePayment processingIrelandIntra-EU
Cloudflare, Inc.CDN, WAF, anti-DDoSUSA / globalDPF
Google Ireland Ltd.Google Workspace (internal corporate e-mails)Ireland + USASCC + DPF
PostHog Inc.Product analytics, EU regionFrankfurt (EU)Intra-EU
Microsoft Ireland OperationsMicrosoft Clarity (heatmaps, behavioural analysis)Ireland + USASCC + DPF
Meta Platforms IrelandWhatsApp Business API, Instagram, MessengerIreland + USASCC + DPF
LiveKit, Inc.LiveKit Cloud, voice and SIP orchestration, EU regionEU (Belgium)DPF + SCC
Deepgram, Inc.Speech-to-text for voice module (if active)USADPF
ElevenLabs Inc.Text-to-speech for voice module (if active)USADPF

Data may also be communicated to authorised persons (e.g. tax advisors, legal advisors, authorities) within the limits provided by law.

8.Data transfers outside the European Union

The primary servers for conversational, voice and application data are located in European territory (Hetzner DE, AWS Frankfurt, LiveKit Cloud EU region Belgium, PostHog Frankfurt, Acumbamail Spain).

Some sub-processors (in particular AI model and CDN providers) may process data in the United States. In such cases the transfer takes place on the basis of:

  • EU-U.S. Data Privacy Framework (DPF): adequacy decision of the EU Commission of 10 July 2023, for certified vendors. Status verifiable at dataprivacyframework.gov.
  • Standard Contractual Clauses (SCC): EU Decision 2021/914, supplemented by additional technical measures (encryption, pseudonymisation) on the basis of a documented Transfer Impact Assessment.

9.Artificial intelligence and use of data

Supportfast.ai uses third-party artificial intelligence models for the operation of chatbots and voice assistants. The provider currently in use is OpenAI, LLC. Further providers may be integrated in the future and will be announced with 30 days’ prior notice through the sub-processors page.

9.1 No use of data for AI model training

Stepcode SRL undertakes not to use Customer data, including the content of chatbot configurations, conversation logs and end-user data, for the training, development or improvement of artificial intelligence models, machine learning algorithms or automated systems of its own or of third parties.

Stepcode uses exclusively AI providers configured in such a way as to exclude the use of transmitted data for the training of their models. In particular, the OpenAI APIs are used with the settings that provide for no data retention for training; this obligation is reflected in the relevant contractual agreements.

9.2 Bring Your Own Key (BYOK) mode

The Customer may choose to use the AI models by configuring an API key in its own name towards the AI provider (for example, the Customer’s own corporate OpenAI key). In this mode:

  • Conversational data flows directly from the Stepcode system to the AI provider using the Customer’s credentials.
  • The contractual relationship for that specific processing is directly between Customer and AI provider, not mediated by Stepcode.
  • Stepcode does not act as external Processor for the processing carried out by the AI provider in BYOK mode.
  • The Customer is required to independently verify the terms of service, privacy notice and DPA of the chosen AI provider.
  • The other components of the processing carried out by Stepcode (storage, logs, infrastructure) remain unchanged, and Stepcode continues to act as external Processor for them.

9.3 Compliance with the EU AI Act

Stepcode constantly monitors the application of Regulation (EU) 2024/1689 (AI Act) and updates product and contracts to ensure compliance with the applicable requirements. The service is designed not to constitute a high-risk AI system within the meaning of the AI Act. The Customer, in its role as deployer, undertakes not to use the service for purposes that would qualify it as a high-risk system without prior assessment and fulfilment of the related obligations.

9.4 Limits of generative AI

Outputs generated by AI models may contain errors, inaccuracies or outdated information. The Customer is invited not to use the service for autonomous decisions in the medical, legal, financial or public safety fields, without adequate human supervision and without having carried out the verifications within its competence.

10.Security measures

Stepcode adopts technical and organisational measures suitable to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR. Main measures:

  • Encryption of data in transit (TLS 1.2/1.3) and at rest (AES-256 or equivalent).
  • Robust authentication with MFA available and automatic session expiry.
  • Role-based access control (RBAC) and principle of least privilege.
  • Audit logs of administrative accesses and critical operations.
  • Logical segregation of data per Customer.
  • Periodic backups and disaster recovery procedures.
  • Regular patching, vulnerability monitoring, periodic security testing.
  • Staff training and contractual confidentiality obligations.

For further details on the technical and organisational measures, the Customer may contact [email protected]. The complete measures are detailed in Annex B of the Data Processing Agreement.

11.Personal data breaches

In the event of a personal data breach, Stepcode follows its internal procedures and:

  • Notifies the Italian Data Protection Authority within 72 hours of becoming aware of it, pursuant to Article 33 GDPR, when the relevant conditions are met.
  • Communicates to the data subjects any breaches that may present a high risk to their rights and freedoms, pursuant to Article 34 GDPR.
  • For breaches involving data processed on behalf of a Customer (as external Processor), notifies the Controller Customer within 48 hours of becoming aware of it, as provided in the DPA.
  • Maintains an internal register of breaches pursuant to Article 33(5) GDPR.

12.Data subject rights

The data subject may exercise at any time the rights provided by Articles 15-22 GDPR:

  • Access (Article 15): obtain confirmation of processing and a copy of the data.
  • Rectification (Article 16): correct inaccurate or incomplete data.
  • Erasure (Article 17): request the deletion of data in the cases provided for.
  • Restriction (Article 18): request the restriction of processing in specific cases.
  • Portability (Article 20): receive data in a structured and commonly used format, transmittable to another controller.
  • Objection (Article 21): object to processing based on legitimate interest or direct marketing.
  • Withdrawal of consent: at any time, without affecting the lawfulness of the processing carried out before withdrawal.
  • Complaint to the Supervisory Authority: lodge a complaint with the Italian Data Protection Authority, pursuant to Article 77 GDPR.

To exercise the rights, write to [email protected]. Stepcode responds within 30 days (extendable by a further 60 days for complex requests, with notice to the data subject).

For the Customer’s end users: requests relating to data processed by Stepcode as external Processor must be addressed to the Customer Controller, possibly with the operational support of Stepcode as provided in the DPA.

Contact details of the Italian Data Protection Authority (Garante per la protezione dei dati personali):

13.Cookies and tracking technologies

The supportfast.ai website and the app.supportfast.ai console use cookies and similar technologies to ensure operation, analyse the use of the service and, subject to explicit consent, for marketing purposes.

For details of the cookies used, their purpose and duration, as well as for how to manage preferences, please refer to the Cookie Policy and to the consent management panel accessible from the website.

14.Changes to this Privacy Policy

Stepcode reserves the right to amend this Privacy Policy to reflect regulatory developments, organisational changes or service updates. The current version is always available on this page, with version number and effective date indicated.

Material changes are communicated to Customers by e-mail and through in-console notice with reasonable advance notice before the effective date. Minor changes (typo corrections, link updates, non-material regulatory adjustments) may be made without prior notice, with update of the version number.

Language. This English version is provided for convenience. In case of conflict or inconsistency, the Italian version prevails as the binding legal text, given the Italian law governing this Privacy Policy.