Note: This is an English-language adaptation of the original Italian privacy notice, prepared for international visitors. It is not a legally certified translation. For the official version, please refer to the Italian original. This document does not constitute legal advice.
This privacy notice describes how personal data of users visiting the website uretech.it is collected, used and protected, in accordance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code), as amended by Legislative Decree 101/2018.
1. Data Controller
URETECH di Fontanella Federico (sole trader)
VAT No.: IT 04134771205 — Tax Code (C.F.): FNTFRC02D12A944B
Via della Costituzione, 8 — 40068 San Lazzaro di Savena (BO), Italy
Email: [email protected]
PEC (certified email): [email protected]
Phone: +39 02 8286 0103
The Data Controller is responsible for the protection of personal data collected through the site and ensures that processing is carried out in compliance with applicable law.
2. Data Collected and Purposes of Processing
The following describes the categories of personal data collected, the purposes of processing, the legal basis and retention periods for each processing activity.
a) Contact Form (AI Chatbot)
- Data collected: name, email address, company, phone number, message, services requested, indicative budget, project timeline, notes generated by artificial intelligence.
- Purpose: to respond to the user's commercial enquiries and provide personalised quotes based on information provided during the conversation.
- Legal basis: legitimate interest of the Data Controller (Art. 6(1)(f) GDPR) in responding to enquiries from prospective clients, and pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR).
- Retention: data is retained for a maximum period of 24 months from the date of the request, after which it is deleted or anonymised.
- Note: conversations via the chatbot are analysed by third-party AI services (OpenAI, Anthropic) to generate project summaries and assist in preparing quotes. Data transmitted to AI providers is limited to the conversation content and does not include direct contact details (email, phone).
b) Newsletter
- Data collected: email address.
- Purpose: sending commercial communications, service updates, technology news and editorial content.
- Legal basis: explicit consent of the data subject (Art. 6(1)(a) GDPR), given at the time of subscription.
- Retention: data is retained until the data subject withdraws consent.
- Right to withdraw: the user may withdraw consent and unsubscribe from the newsletter at any time via the unsubscribe link included in every email, or by contacting the Data Controller at [email protected].
c) Careers (Job Applications)
- Data collected: first name, surname, email address, mobile number, preferred work location, curriculum vitae (PDF format).
- Purpose: assessment of applications received for open or future positions.
- Legal basis: consent of the data subject (Art. 6(1)(a) GDPR) and pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR).
- Retention: data is retained for a maximum period of 24 months from the date the application is received, unless the candidate requests otherwise. After this period, data is securely deleted.
- Security: CVs are stored in encrypted form on secure servers, with access restricted exclusively to authorised personnel involved in the recruitment process.
d) Browsing Data
- Data collected: IP address, browser user agent, date and time of access.
- Purpose: to ensure the correct technical operation of the website, infrastructure security and the application of rate-limiting mechanisms to protect against abuse.
- Legal basis: legitimate interest of the Data Controller (Art. 6(1)(f) GDPR) in ensuring site security and operability.
- Retention: browsing data is not persistently stored in identifiable form, except where the user submits a form (in which case it is associated with the request for the applicable retention period).
3. Telephone Call Recording
As part of its customer support and request-handling service, the Data Controller may carry out audio recording of telephone calls with clients. Recording is not always active: it is activated by the operator on a case-by-case basis (“on-demand”) only when necessary for the purposes set out below, and concerns exclusively calls with clients (inbound and outbound).
Data processed
- Data collected: audio recording of the conversation and personal data contained therein (identification and contact details possibly provided verbally, content of the request); any transcription and summary generated automatically.
- Calls handled by the voice assistant: text transcript of the conversation; first and last name, phone number and e-mail address provided verbally; appointment data; automatic record of the call; technical and statistical call data without identifying elements (duration, number of exchanges, outcome, department), used solely for service monitoring.
- Special categories: no special category of data (Art. 9 GDPR) is requested or intentionally collected. Callers are asked not to disclose such data during the call.
Purposes of processing
- management and documentation of client requests;
- monitoring and improving service quality and staff training;
- handling complaints, disputes and any evidentiary needs;
- AI-assisted processing of the individual call, solely to summarise the conversation and prepare quotes, activities or projects for the client concerned.
Legal basis
Processing is based on the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR) in documenting client requests, ensuring and improving service quality, efficiently preparing commercial documentation and protecting its rights. The related balancing test (Legitimate Interest Assessment, in line with EDPB Guidelines 1/2024) is kept on file by the Data Controller. The data subject has the right to object at any time to this processing (Art. 21 GDPR — see section “Data Subject Rights”).
Notice and procedure
Before any recording, the data subject is informed by a short voice announcement referring to this section. On inbound calls the announcement is played at the start of the call; on outbound calls it is played when the operator starts recording, before recording begins. Anyone who does not wish to be recorded may inform the operator or use an alternative contact channel. Recording is optional and refusal does not prevent use of the service.
AI voice assistant (systematic transcription)
Inbound calls may first be handled by an AI-based voice assistant (“Ura”), which provides information, collects requests, proposes and manages appointments (always “to be confirmed” by an operator) and routes the call to the relevant department. The voice assistant is active on inbound calls from 30/07/2026. This processing has specific features compared with the on-demand recording above:
- Systematic transcription (text): to handle the request and for service quality, the conversation with the assistant is systematically transcribed into text for every call handled by the assistant; as a rule the audio is not retained, only the text transcript and the necessary structured data (name, contact, type of request, appointment);
- Transfer to an operator — audio recording: if the call is transferred to an operator, from the moment of transfer the conversation with the operator is automatically recorded in audio; the recording is then transcribed and merged with the transcript of the part handled by the assistant, to form a single record of the call. This recording is also subject to the retention terms (no longer than 6 months) and the rights set out in this notice. Anyone who has asked not to be transcribed is informed before the transfer and may refuse it: in that case the call is not transferred and an appointment or call-back is offered;
- Transparency (Art. 50 Reg. (EU) 2024/1689 – AI Act): at the start of the call a voice announcement states that the other party is an artificial-intelligence assistant and that the call may be transcribed; it is always possible to ask to speak with an operator;
- Marking of AI-generated content (Art. 50(2)): the audio generated by the assistant is marked in a machine-readable format and carries an imperceptible technical watermark that allows it to be recognised as artificial content. The assistant’s voice is synthetic: it does not belong to an identifiable real person and does not imitate anyone’s identity;
- Right not to be transcribed / objection (Art. 21): anyone who does not wish to be transcribed may tell the assistant (or ask for an operator): in that case the transcript is not retained;
- Legal basis: the Data Controller’s legitimate interest (Art. 6(1)(f)), with a balancing test (LIA) updated for front-line systematic transcription;
- Retention: transcripts are kept for no longer than 6 (six) months and then automatically deleted; deletion also on the data subject’s request;
- Security: transcripts are held in a dedicated restricted-access area for authorised personnel only, on EU infrastructure not exposed to the Internet, encrypted, with automatic deletion;
- No automated decision-making (Art. 22) and no emotion recognition: the assistant proposes appointments “to be confirmed”; every decision remains with the operator;
- No training of AI models on the transcripts;
- Special categories (Art. 9): the assistant is configured not to request them; users are asked not to disclose them during the call;
- AI processing and providers: processing (speech understanding, transcription, response, summary) may take place on self-hosted/EU infrastructure or via AI providers appointed as Processors (Art. 28) with the safeguards set out in the transfers section; the post-call summary is processed on-premise.
Inbound announcement (in use): “Hello, I’m Ura, UreTech’s artificial-intelligence assistant. This call may be transcribed. Full privacy notice at uretech.it. How can I help you?”
Recipients
Recordings are accessible only to the Data Controller’s authorised personnel. They may be processed by external providers appointed as Data Processors under Art. 28 GDPR, including Hetzner Online GmbH (Germany) for infrastructure and, limited to AI processing, artificial-intelligence service providers (including Google, OpenAI, Anthropic), identified upon activation of that function. For the telephone voice assistant the processors also include:
- Mistral AI SAS (France, European Union) — speech recognition, language processing and speech synthesis for the voice assistant; being established in the European Union, for this component there is no transfer of data outside the European Economic Area. The provider retains the data for a limited period (30 days) solely for service delivery and security purposes and does not use it to train its models;
- Microsoft Ireland Operations Ltd (Microsoft 365) — management of calendar appointments (name, contact, subject of the request) and e-mail through which the call record is sent to the relevant department;
- the Data Controller’s management system/CRM, in which the call record is stored as a note linked to the caller’s phone number, to ensure continuity of service.
The list of providers may change over time; the version in force is the one published in this notice. Data is neither disclosed nor transferred to third parties for their own purposes.
Retention and data location
Recordings are kept for the time strictly necessary and in any case no longer than 6 (six) months from the date of the call, save for retention required to handle disputes or to comply with legal obligations; after that period they are securely and automatically deleted. AI processing outputs follow the same terms. Recordings are stored on infrastructure located in the European Union (Germany). For AI processing only, where providers located outside the European Economic Area are used, the transfer is supported by adequate safeguards (EU-US Data Privacy Framework adequacy decision where applicable, or Standard Contractual Clauses under Art. 46 GDPR); providers do not use the data to train their own models.
Artificial intelligence and absence of automated decision-making
AI processing is of a merely supportive nature to the operator (call summary, draft quote or activity): it does not involve automated decisions producing legal effects or significantly affecting the data subject (Art. 22 GDPR), nor profiling, nor emotion recognition. Recordings and their outputs are not used to train artificial-intelligence models: should the Data Controller intend to pursue such a purpose in the future, it will do so as a separate processing activity, subject to an appropriate legal basis, anonymisation measures and a dedicated impact assessment, updating this notice in advance.
Given the nature of the processing, the Data Controller has carried out a data protection impact assessment (DPIA, Art. 35 GDPR), kept on file.
4. Customer Support via WhatsApp
The Data Controller provides a support channel via WhatsApp, where conversations may be handled by an automated AI virtual assistant named “Ura”, with the option to switch to a human operator at any time (by typing “OPERATORE”).
Data processed
- the user’s WhatsApp phone number and profile name (required for communication on the channel);
- the content of the messages exchanged and any data the user chooses to provide (name, email, company, requirement, etc.);
- voice notes: the audio is automatically transcribed into text and immediately deleted after transcription (it is not retained);
- images that the user may send: they are automatically analysed by the AI assistant to understand content relevant to the request (e.g. a website screenshot, a graphic draft, a commercial document) and immediately discarded after processing (they are not retained); no facial recognition or extraction of biometric data is performed;
- a conversation summary automatically generated at the end of the session, recorded in the Data Controller’s management system/CRM to follow up on the request.
No special categories of data (Art. 9 GDPR) are requested or intentionally collected; users are asked not to disclose them in chat or to send images containing them.
Purposes of processing
- a) responding to and handling requests received via WhatsApp (information on services and indicative prices, qualifying the requirement, scheduling an appointment);
- b) automated assistance via the “Ura” assistant and, where necessary, transfer to a human operator;
- c) recording the request in the Data Controller’s management system/CRM to follow up;
- d) any promotional or proactive communications via WhatsApp, sent only with the specific prior consent of the data subject (collected via a dedicated, non-pre-ticked checkbox) — feature not active by default.
Legal basis
For purposes a), b), c) (responses to inbound requests, initiated by the user who writes first) the legal basis is the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR) in responding promptly and efficiently to client requests and following up on them; the related balancing test (Legitimate Interest Assessment, in line with EDPB Guidelines 1/2024) is kept on file. The data subject has the right to object at any time (Art. 21 GDPR — see section “Data Subject Rights”). For purpose d) (proactive/promotional messages) the legal basis is consent, freely given, specific and revocable (Art. 6(1)(a) GDPR and Art. 130 of Legislative Decree 196/2003); without consent, the Data Controller does not send proactive messages.
Transparency and automated assistant
At the start of each conversation the user receives a transparency notice informing them that they are interacting with an automated virtual assistant and that they can request a human operator at any time, in accordance with Art. 50 of Regulation (EU) 2024/1689 (AI Act). Automated responses are indicative and non-binding.
Recipients
Data is accessible only to the Data Controller’s authorised personnel. It is also processed by parties appointed as Data Processors under Art. 28 GDPR, including: Meta Platforms Ireland Limited (and its affiliate WhatsApp), provider of the WhatsApp Business Cloud API that routes the messages, under the WhatsApp Business Data Processing Terms; Hetzner Online GmbH (Germany) for the infrastructure running the assistant; the hosting provider of the Data Controller’s management system/CRM. AI processing (text, audio transcription and image analysis) is currently entirely self-hosted on the Data Controller’s infrastructure (no third-party AI provider). Data is neither disclosed nor transferred to third parties for their own purposes.
Retention, location and transfers
Session messages are kept for the time necessary to handle the conversation; the session is considered closed after 24 hours of inactivity or upon transfer to an operator. Voice notes are deleted immediately after transcription. The request summary is recorded in the management system/CRM and retained for the time necessary to manage the relationship and meet legal obligations. The assistant and data at rest are on infrastructure located in the European Union (Germany). Routing messages via the Cloud API involves processing by Meta, which may also take place in the United States: such transfer is supported by adequate safeguards under Chapter V GDPR (EU-US Data Privacy Framework adequacy decision and/or Standard Contractual Clauses with a transfer impact assessment). AI processing (text, audio transcription and image analysis) is currently self-hosted in the EU, so for that component there is no transfer outside the EEA. In the future the Data Controller may use an AI model (including multimodal, for text and images) delivered in the cloud via API (e.g. Google – Gemini/Vertex AI, OpenAI, Anthropic), appointed as a Processor under Art. 28: in that case the transfer will be supported by the DPF (adequacy) or by SCCs with an impact assessment, with a signed DPA, use of the API/Enterprise tier only, no training of the models on the data (including images) and, where available, EU-region/zero-retention storage; this notice will be updated before any such activation.
Artificial intelligence and absence of automated decision-making
The “Ura” assistant provides information and support and prepares drafts (e.g. a proposed appointment, always “to be confirmed” by a person): it does not make automated decisions producing legal effects or significantly affecting the data subject (Art. 22 GDPR), nor profiling, nor emotion recognition. Messages and their outputs are not used to train artificial-intelligence models.
Nature of the provision of data
Providing data to obtain assistance via WhatsApp is optional, but the phone number is technically necessary for communication on the channel; failure to provide other data may limit the response. Consent to proactive messages is optional and refusal does not affect support; it may be withdrawn at any time by typing “STOP” on WhatsApp or via the contacts indicated in the “Data Subject Rights” section.
5. Third-Party Services
The website uses third-party services for its operation. The following lists these services and their privacy implications for the user:
- Google Fonts (Google LLC, USA): the site loads typefaces from Google's servers. During loading, the user's IP address is transmitted to Google's servers. More information: Google Privacy Policy.
- CDN — Cloudflare and unpkg.com: the site uses content delivery networks (CDNs) to load JavaScript libraries (including Three.js, React, Lenis). The user's IP address is transmitted to these services during resource loading.
- AI Providers — OpenAI (USA) and Anthropic (USA): the contents of chatbot conversations may be transmitted to these providers for analysis and generation of project summaries. Data transmitted is limited to the conversation content.
- Webhook (if configured): data submitted via forms may be sent to external services via webhooks for business automation purposes (e.g., CRM, lead management, internal notifications).
6. International Data Transfers
Some of the third-party services listed above are based in the United States of America. Personal data may therefore be transferred outside the European Union, in particular to the USA, via the following services:
- Google Fonts (Google LLC)
- OpenAI
- Anthropic
Such transfers take place with adequate safeguards under the GDPR, in particular through:
- The EU-US Data Privacy Framework, for providers that have obtained certification;
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
The user may request further information on the safeguards adopted by contacting the Data Controller at [email protected].
7. Cookies
For detailed information on cookies used by the site, how they are managed and how to disable them, please refer to the Cookie Policy, accessible from the cookie banner displayed on first visit to the site or from the dedicated page.
8. Security Measures
The Data Controller adopts appropriate technical and organisational measures to ensure the security of personal data processed, including:
- Rate limiting on all API endpoints to prevent abuse and automated attacks.
- Validation and sanitisation of all inputs received via site forms.
- Parameterised queries for protection against SQL injection attacks.
- CSRF tokens (WordPress Nonce) for protection against Cross-Site Request Forgery attacks.
- Protected CV storage in directories with restricted access and restrictive permissions.
- HTTPS connection with SSL/TLS certificate for encryption of all data in transit.
9. Data Subject Rights
Under Articles 15–22 of the GDPR, the data subject has the right to:
- Access (Art. 15): obtain confirmation of whether processing is taking place and access their personal data. For telephone calls handled with recording or a voice assistant, an access request may also be satisfied by providing the transcript of the conversation, with third-party identifying elements redacted (Italian DPA, decision no. 391 of 28 May 2026).
- Rectification (Art. 16): obtain correction of inaccurate personal data or completion of incomplete data.
- Erasure (Art. 17): obtain deletion of personal data in the cases provided for by law.
- Restriction of processing (Art. 18): obtain restriction of processing in the cases provided for by law.
- Data portability (Art. 20): receive personal data in a structured, commonly used and machine-readable format.
- Object (Art. 21): object to the processing of personal data based on the Data Controller’s legitimate interest.
- Withdraw consent: withdraw consent given at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
How to exercise your rights
The data subject may exercise their rights by sending a written communication to the Data Controller at: [email protected]
The Data Controller undertakes to respond to the request within 30 days of receipt.
The data subject also has the right to lodge a complaint with the competent supervisory authority:
10. Changes to This Privacy Notice
The Data Controller reserves the right to make changes to this privacy notice at any time, by publishing the updated version on the website. Users are therefore invited to periodically consult this page to check for any updates.
Changes to this notice will take effect from the date of publication on the website.
Notice prepared in accordance with EU Regulation 2016/679 (GDPR) — Articles 13 and 14.
Last revised: 30 July 2026.