ConSergio

Data Processing Agreement (DPA)

Version 1.1 · Gültig ab 1. September 2026 · Veröffentlicht am 3. September 2026

Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)

ConSergio.ai — DevInterface srl Version 1.1 · Last updated: 20 August 2026

Language. This English text is a courtesy translation of the Italian original. In the event of any discrepancy or conflict between the two versions, the Italian version shall prevail.

This Data Processing Agreement (the “DPA”) supplements the ConSergio.ai Terms and Conditions of Service (the “Terms”) and governs the processing of personal data carried out by DevInterface on behalf of the Customer in the course of providing the Service. The DPA is deemed accepted together with the Terms upon registration and forms an integral and essential part thereof.


1. Parties and roles

1.1 The Customer — the accommodation business subscribing to the Service — acts as Data Controller of the personal data of Guests collected or generated through the Service.

1.2 DevInterface srl, VAT no. 04080300231, Via Guglielmo Marconi 20, 37012 Bussolengo (VR), Italy, acts as Data Processor, processing such data solely on behalf of and on documented instructions from the Controller.

1.3 This DPA also applies to the personal data of Staff Users processed within the platform for account and permission management, in respect of which DevInterface likewise acts as Processor.

1.4 DevInterface acts instead as an independent Data Controller — outside the scope of this DPA and as described in its Privacy Policy — in relation to: the Customer’s contact and billing data, management of the contractual relationship and service communications, security data and technical logs processed under legal obligation or legitimate interest, and the aggregated and anonymous data referred to in Article 14.

2. Subject matter, nature, purpose and duration of processing

  • Subject matter: provision of the ConSergio.ai platform, comprising the Guest-facing web app, request management, the AI conversational assistant and the management panel.
  • Nature: collection, recording, organisation, structuring into fragments (chunks) and vector representations, processing by artificial intelligence models, automated translation, storage, consultation, retrieval, erasure and anonymisation.
  • Purpose: to enable Guests to consult the Property’s content, submit requests to staff and interact with the AI assistant; to enable the Customer to manage those requests, content and statistics; to deliver the features of the Service according to the Plan subscribed.
  • Duration: for the entire term of the contractual relationship and for the retention periods set out in Article 12, subject to any differing legal obligations.

Processing details are set out in Annex A.

3. Categories of data subjects and personal data

3.1 Data subjects: Guests of the Property who access the web app; the Customer’s Staff Users.

3.2 Categories of data. The Service is designed on the principle of data minimisation: no identifying data is required from the Guest in order to access it, no registration or login is required, and no Guest payment instrument data is processed by the Service. The following are processed:

  • room identifier and associated access token;
  • content of requests submitted to staff;
  • content of messages exchanged with the AI assistant and the language detected for each message;
  • Guest name and stay period, only where entered by the Customer’s Staff Users;
  • technical and connection data (IP address, user agent, timestamp, security logs);
  • for Staff Users: name, e-mail address, role, credentials in encrypted form, logs of actions performed.

3.3 Special categories of data (Article 9 GDPR). The Service neither requires nor is intended to collect special categories of data. The Customer acknowledges, however, that given the nature of the hospitality context a Guest may spontaneously communicate, in chat or in a request, information falling within special categories — by way of example: food allergies and intolerances, needs related to health conditions or disability, requests for medical or pharmaceutical assistance, religious dietary requirements. The Parties acknowledge that:

  • DevInterface neither solicits nor structures the collection of such data and does not use it for purposes beyond generating the response and transmitting the request to staff;
  • the Customer, as Controller, must identify an appropriate legal basis and adequately inform its Guests;
  • the Customer undertakes to instruct its Staff Users not to deliberately enter special category data into free-text fields of the platform;
  • such data is subject to the same security measures and erasure periods provided for in this DPA.

3.4 Minors. The Customer acknowledges that access via the QR code placed in the room is by its nature available to anyone present in the room, including minors. The Service collects no identifying data and does not profile users; the Customer must take this into account in its own privacy notice and risk assessment.

3.5 The Customer undertakes not to use the Service to process data relating to criminal convictions and offences (Article 10 GDPR).

4. Documented instructions of the Controller

4.1 DevInterface processes personal data solely on the documented instructions of the Controller, consisting of the Terms, this DPA and the configurations set by the Customer within its Account — including the enabling and limits of external source search, content uploaded for the AI assistant, stay associations, retention duration within the Plan ceiling, and Staff User management.

4.2 DevInterface shall inform the Customer without delay if it considers that an instruction infringes the GDPR or other applicable data protection provisions.

4.3 DevInterface does not use personal data processed on behalf of the Controller for its own purposes, nor for training artificial intelligence models.

5. Obligations of the Processor

DevInterface undertakes to:

  • process data solely for the stated purposes and in accordance with the Controller’s documented instructions;
  • ensure that persons authorised to process the data are bound by appropriate confidentiality obligations and are adequately trained;
  • implement and maintain the technical and organisational measures under Article 32 GDPR, described in Annex C;
  • assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (Articles 15-22 GDPR);
  • assist the Controller in complying with Articles 32-36 GDPR (security, breach notification, data protection impact assessment, prior consultation);
  • make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits under Article 15;
  • ensure strict logical isolation of data between the different Properties hosted on the platform.

6. Multi-tenant isolation

6.1 The platform is multi-tenant. DevInterface ensures that each Property’s data is isolated by mandatory application-level scoping across all domain entities, and that such isolation extends to the semantic search used by the AI assistant, whose queries are mandatorily filtered by Property.

6.2 The effectiveness of the isolation is verified by dedicated automated tests, run continuously as part of the release process.

6.3 Under no circumstances may one Property’s content or conversations be retrieved or used to generate responses intended for the Guests of another Property.

7. Artificial intelligence

7.1 The AI assistant generates responses from content supplied by the Customer and, where enabled by the Customer, from external sources. Only the Guest’s message and the context strictly necessary to generate the response are transmitted to the model provider.

7.2 DevInterface undertakes to use provider configurations and contractual options that exclude the use of transmitted data for model training and that minimise data retention on the provider’s side.

7.3 No payment instrument data passes through the AI assistant. DevInterface adopts measures to limit the transmission to the provider of personal data beyond what is necessary.

7.4 The responses generated produce no legal effects concerning Guests, nor do they similarly significantly affect them within the meaning of Article 22 GDPR: the assistant provides information and forwards requests, whose acceptance and assessment remain the responsibility of the Customer’s staff.

7.5 DevInterface adopts containment measures against attempts to manipulate the model’s instructions (prompt injection) in retrieved content and external sources.

7.6 External sources. Where the Customer enables external source search, DevInterface transmits to those sources only the informational query required, free of Guest identifying data. The external sources actually used are logged for verification purposes.

8. Sub-processors

8.1 The Controller grants general authorisation for the use of the sub-processors listed in Annex B. DevInterface imposes on them, by contract, data protection obligations equivalent to those in this DPA and remains fully liable to the Controller for their performance.

8.2 DevInterface shall notify the Customer of any intention to add or replace a sub-processor with at least 30 days’ prior notice. The Customer may object on reasonable grounds within that period; where a well-founded objection cannot be resolved, the Customer may terminate the Service with a pro-rata refund of unused fees.

8.3 Components not entrusted to third parties. The vector index used by the AI assistant is self-hosted on the Processor’s own infrastructure within the European Union: that processing does not involve any additional sub-processor.

8.4 The payment service provider used for billing the Service is not a sub-processor within the meaning of this DPA, as it processes no Guest data: it processes only the Customer’s data, in respect of which it acts as an independent controller or as a processor of DevInterface, as set out in the Privacy Policy.

9. Transfers to third countries

9.1 Primary data and backups are hosted within the European Union.

9.2 The only processing involving a transfer to a third country is processing by the artificial intelligence model provider, supported by appropriate safeguards under Chapter V GDPR (Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework), using EU data residency options where available.

9.3 DevInterface carries out and keeps updated an assessment of the adequacy of the safeguards applied to transfers.

10. Security of processing

DevInterface implements and maintains technical and organisational measures appropriate to the risk, described in Annex C, in accordance with Article 32 GDPR. Measures may be updated over time, provided the overall level of security is not reduced.

11. Personal data breaches

11.1 In the event of a personal data breach, DevInterface shall inform the Controller without undue delay and in any event within 48 hours of becoming aware of it.

11.2 The notification shall contain, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for further information.

11.3 DevInterface shall cooperate with the Controller and provide reasonable assistance to enable it to comply with its obligations to notify the supervisory authority and communicate to data subjects under Articles 33 and 34 GDPR. The assessment as to notification remains the Controller’s responsibility.

11.4 DevInterface shall make no third-party communications regarding the breach that are attributable to the Customer without the Customer’s prior agreement, save where required by law.

12. Retention, erasure and return of data

12.1 The retention period for the history of conversations and requests is determined by the Plan subscribed and constitutes a maximum ceiling, which the Controller may reduce through Account settings but may not extend.

12.2 Irrespective of the Plan, the Service provides for the anonymisation or erasure of Guest-attributable data at the end of the stay, following a technical window necessary for operational handling.

12.3 Once the retention window has elapsed, data is deleted or anonymised; only aggregated information not attributable to identifiable individuals continues to feed the statistics.

12.4 The erasure of any content or data propagates to derived representations, including stored translations and the vector representations used by the AI assistant.

12.5 Upon termination of the contractual relationship, DevInterface shall, at the Controller’s choice, delete or return the personal data processed on its behalf. The Controller has 30 days from termination to request return or to carry out an export using the functions available in the panel; thereafter the data is deleted, unless retention is required by Union or national law.

12.6 Backups are subject to periodic rotation: deleted data persists in backups until the natural expiry of the retention cycle, during which it remains protected by the measures set out in Annex C and is not subject to any active processing.

13. Assistance to the Controller and data subject rights

13.1 Taking into account the nature of the processing, DevInterface assists the Controller by appropriate technical and organisational measures in responding to requests for the exercise of data subject rights.

13.2 Guest requests are ordinarily addressed to the Customer, as Controller. Where a request is received directly by DevInterface, DevInterface shall not act on it independently and shall forward it to the Customer without delay, unless otherwise instructed in writing.

13.3 The Service provides the Controller with data export functions and cascading erasure to respond to access and erasure requests.

13.4 DevInterface provides the Controller with the information necessary to carry out any data protection impact assessments (DPIAs) and prior consultations. The Customer acknowledges that, given the use of artificial intelligence systems in the hospitality context, a DPIA may be advisable and that the relevant assessment is the Controller’s responsibility.

14. Aggregated and anonymous data

DevInterface may process, as an independent controller, aggregated and irreversibly anonymised data — not attributable to the Customer or to Guests — for Service improvement, cost monitoring, internal statistics and benchmarking purposes. Such data does not constitute personal data and falls outside the scope of this DPA.

15. Audits

15.1 DevInterface shall make available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or by an auditor appointed by it and bound by confidentiality obligations.

15.2 Audits shall be carried out on at least 30 days’ written notice, during normal business hours, no more than once per calendar year — save in the event of a confirmed data breach or a specific request from a supervisory authority — and in a manner that does not compromise the security, confidentiality or operational continuity of the platform’s other customers.

15.3 DevInterface may discharge its obligations under this Article by making available documentation, completed questionnaires or independent audit reports, where these are adequate to satisfy the request.

15.4 Audit costs beyond the provision of documentation are borne by the Controller, unless the audit establishes a material breach by DevInterface.

16. Liability

The limitations of liability set out in the Terms also apply to this DPA, to the extent permitted by applicable law and without prejudice to Article 82 GDPR as regards liability towards data subjects.

17. Term, amendments and governing law

17.1 This DPA remains in effect for the entire duration of the processing carried out on behalf of the Controller and ends upon completion of the operations set out in Article 12.5.

17.2 DevInterface may update this DPA to align it with regulatory changes, supervisory authority decisions or developments in the Service, upon reasonable prior notice to the Customer.

17.3 This DPA is governed by Italian law; the Courts of Verona, Italy, shall have exclusive jurisdiction over any dispute.

17.4 In the event of conflict between this DPA and the Terms on matters of personal data protection, this DPA shall prevail.


Annex A — Processing details

Item Content
Controller The Customer (accommodation business)
Processor DevInterface srl
Subject matter Provision of the ConSergio.ai platform
Duration Term of the contract + retention periods (Article 12)
Nature and purpose Content consultation, request management, AI conversational assistance, automated translation, statistics
Categories of data subjects Guests of the Property; the Customer’s Staff Users
Categories of data Room identifier; request content; chat message content and detected language; Guest name and stay period where entered by staff; technical and connection data; Staff User account data
Special categories Not required; possible spontaneous disclosure by the Guest (Article 3.3)
Guest payment data None — the Service does not process payments from Guests
Transfers outside the EU Only to the AI model provider, with safeguards under Chapter V GDPR

Annex B — List of sub-processors

Sub-processor Activity Processing location Transfer safeguards
OpenAI Generation of assistant responses, embedding creation, automated content translation USA, with EU residency options where available SCCs and, where applicable, EU-US Data Privacy Framework
Contabo GmbH Hosting of the application infrastructure and vector index Germany (EU) Not applicable (EU)
Amazon Web Services (S3) Storage of files, images and documents uploaded by the Customer Italy — Europe (Milan) region, eu-south-1 Not applicable (EU)

Notes. The vector index is self-hosted on the infrastructure indicated above and does not involve any additional sub-processor. The payment service provider does not appear in this list as it processes no Guest data (Article 8.4). Any future adoption of a dedicated automated translation provider will be notified under the procedure set out in Article 8.2.

An up-to-date list of sub-processors is available on request and published at the address indicated in the Privacy Policy.

Annex C — Technical and organisational measures (Article 32 GDPR)

Minimisation and protection by design - Guest access without registration, login or provision of identifying data. - Non-sequential, unpredictable room access tokens, regenerable by the Customer in the event of compromise. - No processing of Guest payment instrument data.

Encryption and data protection - Encryption of data in transit via TLS. - Encryption at rest for sensitive data; credentials stored in non-reversible form. - Application secrets managed outside the source code.

Access control and isolation - Strict logical isolation between Properties, with mandatory application-level scoping extended to semantic search. - Dedicated automated tests verifying isolation, run continuously. - Differentiated role and permission system for Staff Users (Owner / Reception). - Segregation of development, test and production environments.

Traceability - Log of sensitive actions (access, configuration changes, exports, deletions). - Structured logging, error tracking and retention of security logs. - Logging of the external sources actually used in responses.

Protection of public endpoints - Rate limiting on the public endpoints of the Guest-facing web app. - Containment measures against attempts to manipulate the AI model’s instructions.

Continuity and resilience - Periodic backups stored within the European Union, with restore procedures. - Service availability monitoring and incident management. - Controlled degradation in the event of AI provider unavailability, with essential functions maintained.

Organisational measures - Confidentiality undertakings for persons authorised to process data. - Administrative access restricted to strictly necessary personnel. - Documented incident and data breach management procedure. - Automated test coverage of domain logic, tenant isolation and payment flows; controlled release process.


Digital acceptance

This document is deemed accepted by the Customer by ticking the relevant box during registration for the Service. The user identifier, document version, date and time of consent are retained. On request, DevInterface will make available a copy of this DPA in signable format.


DevInterface srl — ConSergio.ai Data Processing Agreement — Version 1.1

Sprache: IT EN

Weitere Fassungen: 1.1 1.0

Zurück zur Startseite