1. Data Controller
The data controller for personal data is Sviluppiamo S.r.l., with registered office in Italy. For any privacy-related inquiry or request, you can contact us at: privacy@sviluppiamo.dev
2. Data Collected
We collect the following personal data:
- Email address (for authentication and service communications)
- First and last name (if provided via Google OAuth)
- Profile photo (if provided via Google OAuth)
- Usage data: prompts submitted, projects created, credits consumed
- Billing data (handled securely by Stripe — we never view or store full card details)
- Session cookies to maintain your login status
3. Purpose of Processing
Your data is processed exclusively for:
- Providing and improving the sviluppiamo.dev service
- Managing account authentication, sessions, and security
- Processing payments and managing subscription plans
- Sending transactional service updates (feature notices, renewal alerts, security warnings)
- Analyzing aggregated usage to improve user experience
- Compliance with applicable statutory and regulatory obligations
4. Legal Basis
The processing of your data is based on: (a) performance of the service agreement, (b) explicit consent provided at registration, and (c) our legitimate interest in service optimization, stability, and fraud prevention.
5. Data Retention
Account data is retained for the duration of the contractual relationship and for up to 12 months following account deletion, unless longer statutory retention applies. Billing records are preserved for 10 years for statutory tax and accounting obligations.
6. Third-Party Sharing & Sub-processors
We share your data strictly with the following GDPR Art. 28 compliant sub-processors under signed Data Processing Agreements (DPAs):
Supabase Inc. — Database, authentication, and file storage. Data is hosted exclusively in the EU (eu-central-1, Frankfurt).
DPA → Stripe Inc. — Payment processing and fraud detection. We do not store or process raw credit card numbers.
DPA → Anthropic PBC (Claude) — AI code generation from user prompts. Prompts may contain user context. Anthropic does not train models on API data without explicit consent.
DPA → OpenAI LLC (GPT-4o) — AI prompt processing (fallback provider). OpenAI does not train AI models on customer API payloads.
DPA → Google LLC (Gemini) — Image and architectural generation via Google AI Studio. API requests are not used for model training without consent.
DPA → Vercel Inc. — Application hosting and global CDN. EU traffic is routed to European edge nodes wherever available.
DPA → We never sell your data to third parties or use it for behavioral ad targeting.
7. Your Rights Under GDPR
Under the GDPR, you have the following guaranteed rights:
- Access your stored personal data (Art. 15)
- Rectify inaccurate or outdated information (Art. 16)
- Request complete erasure / Right to be forgotten (Art. 17)
- Restrict or object to processing (Art. 18 & 21)
- Data portability in structured JSON format (Art. 20)
- Withdraw consent at any time without retroactive penalty (Art. 7)
- Lodge a complaint with the supervisory authority (Italian Garante Privacy or your national DPA)
You can exercise key rights directly from within the application:
For any other GDPR requests, email us at privacy@sviluppiamo.dev. We respond within 30 days as mandated by GDPR.
8. Cookies & Consent Management
We utilize specific categories of cookies. For full details on cookie names, lifespans, and vendors, see our Cookie Policy.
- Essential technical cookies: required for authentication, CSRF tokens, and core system functionality. Exempt from consent requirements.
- Anonymous session cookies: temporary state token for visitors — deleted upon browser closure.
- Analytical cookies (optional): anonymized usage insights, activated only after explicit opt-in.
On first visit, we present a consent banner compliant with EU/Italian Data Protection Authority guidelines, giving equal visual weight to 'Accept all' and 'Essential only' options.
Every consent choice is logged in our audit trail with timestamp, masked IP, and policy version. You can inspect your consent history or adjust preferences in Settings at any time.
8a. International Data Transfers (Art. 44-49 GDPR)
Certain cloud infrastructure providers may route queries outside the European Economic Area (EEA). In such cases, safeguards are established via European Commission Standard Contractual Clauses (SCCs):
- Stripe Inc. (USA) — payment gateway: Standard Contractual Clauses + EU-U.S. Data Privacy Framework
- OpenAI / Anthropic / Google (USA) — AI prompt processing: Executed Standard Contractual Clauses
- Vercel Inc. (USA) — edge deployment: European edge servers preferred, SCC fallback
- Supabase Inc. (USA) — database: Dedicated European datacenter (eu-central-1)
To request a copy of relevant Standard Contractual Clauses, write to privacy@sviluppiamo.dev.
9. Security & Breach Notification
We implement robust technical and organizational safeguards including full HTTPS encryption, strict Row Level Security (RLS) policies on Supabase, and least-privilege administrative access. In the event of a verified data breach, we will notify affected users and regulatory authorities within 72 hours.
10. Policy Updates
We may periodically revise this Privacy Policy. In the event of substantial changes, we will notify registered users via email or prominent dashboard banner at least 14 days before effective date.