Privacy Policy

Last updated: March 2026

1. Data Controller

The data controller is:

  • WebGlobalBuild — a brand of Global Svapo S.r.l.s.
  • Registered office: Via Dino Buzzati 3, 91026 Mazara del Vallo (TP), Italy
  • VAT / Tax ID: 02717040816 — REA: TP-191921
  • Share capital: €500.00 fully paid
  • Email: [email protected]
  • Certified email (PEC): [email protected]

2. Types of data collected

This website collects personal data in connection with the following features. For each, we indicate the type of data, purpose, legal basis, and retention period.

2.1 Contact form

Data collectedName, email, project type, message, phone number (optional)
PurposeRespond to user inquiries and create a support ticket
Legal basisConsent (Art. 6.1.a GDPR) — mandatory checkbox before submission
RetentionData is retained until ticket closure and for a maximum of 24 months after closure, unless legally required otherwise
Third partiesResend (confirmation and notification emails)

2.2 Cost estimator

Data collectedEmail, project type, complexity, selected features, estimated price range, additional notes
PurposeGenerate an indicative estimate and create a quote request ticket
Legal basisConsent (Art. 6.1.a GDPR) — mandatory checkbox before submission
RetentionUp to 24 months from ticket creation
Third partiesResend (confirmation email)

Anonymous configuration data from the estimator (project type, complexity, features, price range) may be saved without identifying information for internal statistical purposes.

2.3 Support ticket system

Data collectedName, email, phone, request type, title, description, budget, timeline, technologies, attachments (PDF, JPEG, PNG, WebP — max 5 MB each, max 3 files)
PurposeManage support and quote requests
Legal basisPerformance of pre-contractual measures (Art. 6.1.b GDPR)
RetentionUp to 24 months after ticket closure
Third partiesResend (email notifications), Supabase Storage (file storage)

2.4 AI chat

Data collectedName (optional), email (optional), message text, conversation history
PurposeProvide automated assistance via AI chatbot
Legal basisLegitimate interest (Art. 6.1.f GDPR) — providing immediate support to visitors
RetentionChat sessions are retained for up to 12 months
Third partiesAnthropic (Claude API) — conversation text is transmitted to Anthropic's servers in the United States for response generation. See section 5 for extra-EU transfer safeguards

2.5 Live chat with human operator

Data collectedName (optional), email (optional), message text
PurposeProvide direct assistance through a human operator
Legal basisLegitimate interest (Art. 6.1.f GDPR)
RetentionUp to 12 months after session closure
Third partiesNone — operator messages are handled internally

2.6 Client portal

Data collectedEmail, password (bcrypt hash), project data, invoices, quotes, messages, reviews
PurposeContract management, project progress monitoring, billing
Legal basisPerformance of a contract (Art. 6.1.b GDPR)
RetentionFor the duration of the contractual relationship and for 10 years thereafter for tax obligations
Third partiesResend (invitation emails, password reset), Anthropic (portal AI chat — see section 5)

Portal access uses a session cookie (wgb-portal-session) containing a signed JWT with the minimum data necessary for authentication (client ID, email, project ID). The cookie lasts 30 days and is HttpOnly, Secure, and SameSite Strict.

2.7 AI-powered quote generation (admin area)

Data transmittedProject description, project type
PurposeAutomatically generate quote line items
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
Third partiesAnthropic (Claude API) — description text is transmitted to Anthropic's servers in the USA

2.8 Rate limiting and security

Data collectedIP address (SHA-256 hashed with a cryptographic salt before storage)
PurposeAbuse prevention, protection against automated attacks
Legal basisLegitimate interest (Art. 6.1.f GDPR) — website security
RetentionRate limit records expire automatically at the end of the configured time window

2.9 IMAP email client (admin area)

Data collectedContent of emails sent to [email protected] (sender, subject, body, attachments)
PurposeManaging correspondence with clients and prospects through the admin panel
Legal basisLegitimate interest (Art. 6.1.f GDPR) — operational management of communications
RetentionEmails are stored on the Aruba IMAP server and accessible only by the administrator through the admin panel
Third partiesAruba S.p.A. (IMAP email hosting) — data is not shared with any other third parties

2.9bis — AI email reply suggestions (admin area)

Data transmittedEmail subject, sender, message body
PurposeGenerate AI-powered reply suggestions for received emails
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
Third partiesAnthropic (Claude API) — email content is transmitted to Anthropic's servers in the USA for suggestion generation

2.10 Push notifications (Web Push API)

Data collectedPush subscription endpoint, browser encryption keys
PurposeSend push notifications to the site administrator for relevant events (new tickets, messages, etc.)
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
RetentionSubscription endpoints are stored in Supabase until revocation or deactivation
Third partiesNo public user data is involved — push notifications are intended exclusively for the administrator

2.11 Demo account

The website provides a demo account ([email protected]) with entirely fictitious data to allow evaluation of the client portal features. No real data is associated with this account.

2.12 Google Analytics 4

Data collectedAnonymous browsing data (pages visited, session duration, scroll depth, UI interactions), IP address (automatically anonymized)
PurposeStatistical analysis of traffic and user behavior on the website
Legal basisConsent (Art. 6.1.a GDPR) — activated only after explicit acceptance via cookie banner
RetentionAccording to Google Analytics retention policies (default 14 months)
Third partiesGoogle LLC (Google Analytics 4) — data is transferred to Google servers in the USA. Google Signals and ad personalization are disabled. See section 5

2.13 Vercel Analytics and Speed Insights

Data collectedPages visited, referrer, browser, operating system, device type, Core Web Vitals metrics (LCP, FID, CLS, TTFB)
PurposeWebsite performance monitoring and aggregate traffic analysis
Legal basisConsent (Art. 6.1.a GDPR) — activated only after explicit acceptance via cookie banner
RetentionAccording to Vercel retention policies
Third partiesVercel, Inc. — see section 5

2.14 Public reviews

Data collectedName, email, company name (optional), role (optional), review text (max 500 characters), rating (1-5 stars)
PurposeCollect and publish testimonials on the website. Reviews are moderated by the administrator before publication
Legal basisConsent (Art. 6.1.a GDPR) — voluntary form submission
RetentionUntil the user requests deletion
Third partiesNone — data is not shared with third parties

The name and optional company name are published on the website once the review is approved.

2.15 Google Indexing API (admin area)

Data transmittedURLs of published, updated, or removed site pages (blog posts, portfolio projects)
PurposeNotify Google for timely content indexing
Legal basisLegitimate interest (Art. 6.1.f GDPR) — search engine visibility
Third partiesGoogle LLC (Indexing API) — only public URLs are transmitted, no personal data

2.16 — AI content generation and translation (admin area)

Data transmittedPortfolio project descriptions, blog article content
PurposeGenerate portfolio case studies and translate content from Italian to English
Legal basisLegitimate interest (Art. 6.1.f GDPR) — operational efficiency, multilingual publishing
Third partiesAnthropic (Claude API) — texts are transmitted to Anthropic's servers in the USA for processing and translation

2.17 — AI usage logging and transparency

All interactions with AI systems are logged internally (ai_usage_log) tracking: feature name, token count, and estimated cost.

The log contains no personal data — it only records the feature identifier and a truncated prompt preview (maximum 100 characters). The purpose is cost monitoring, transparency, and compliance with EU Regulation 2024/1689 (AI Act).

3. Cookies

This website uses technical cookies necessary for its operation and, with user consent, analytics cookies (Google Analytics 4) and performance monitoring tools (Vercel Analytics, Speed Insights). No profiling or advertising cookies are used. For detailed information, please see our Cookie Policy.

4. Third parties

ServiceData receivedPrivacy policy
ResendEmail, name, message content for transactional email deliveryresend.com/legal/privacy-policy
AnthropicChat conversation text, project descriptions for AI response and quote generationanthropic.com/privacy
SupabaseAll stored personal data (database and file storage)supabase.com/privacy
Google LLCAnonymous browsing data for traffic analysis (Google Analytics 4), public URLs for indexing (Indexing API)policies.google.com/privacy
VercelIP address, user agent, HTTP request logs (hosting and CDN), performance metrics and anonymous browsing data (Vercel Analytics and Speed Insights)vercel.com/legal/privacy-policy
ArubaInbound and outbound emails (IMAP server for [email protected] mailbox)aruba.it/informativa-privacy

5. Extra-EU data transfers

Some personal data is transferred to the United States to the following providers:

  • Anthropic, PBC (San Francisco, USA) — receives chat conversation text and project descriptions for response generation via the Claude API. The transfer is based on the Standard Contractual Clauses (SCC) adopted by the European Commission (Decision 2021/914). Anthropic does not use data submitted via API to train its models.
  • Vercel, Inc. (San Francisco, USA) — website hosting and distribution. The transfer is covered by SCCs and Vercel's Data Processing Agreement.
  • Resend, Inc. (USA) — transactional email delivery. The transfer is covered by SCCs.
  • Google LLC (Mountain View, USA) — receives anonymous browsing data via Google Analytics 4 and public URLs via the Indexing API. The transfer is based on SCCs and Google's Data Processing Terms.

Data stored in Supabase (database and file storage) is hosted in the EU region (AWS eu-west-1, Ireland). No extra-EU transfer occurs for data stored in the database.

6. Data subject rights

Under Articles 15-22 of the GDPR, users have the right to:

  • Access — obtain confirmation of the existence of their personal data and access its content
  • Rectification — update or correct inaccurate or incomplete data
  • Erasure — request deletion of data, within the limits provided by law
  • Restriction — request restriction of processing in certain cases
  • Portability — receive their data in a structured, commonly used, and machine-readable format
  • Objection — object to processing on legitimate grounds
  • Withdrawal of consent — withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal

To exercise your rights, please contact:

7. Right to lodge a complaint

Users have the right to lodge a complaint with the competent supervisory authority:

7bis. Artificial intelligence systems — AI Act compliance

This website uses artificial intelligence systems in compliance with EU Regulation 2024/1689 (AI Act). All systems used are classified as minimal or limited risk under the regulation.

AI systems used include: public chatbot for visitor assistance, client portal chat, quote line item generation, email reply suggestions, portfolio content generation, and article translation. All are based on Anthropic's Claude model.

The chatbot is clearly identified as AI in the interface. All AI-generated content is reviewed by a human operator before publication.

For detailed information, see our dedicated AI Disclosure page.

8. Changes to this policy

The data controller reserves the right to modify this policy at any time. Changes will be published on this page with an updated date shown at the top. Continued use of the website after the publication of changes constitutes acceptance thereof.