ConSergio

Privacy Policy

Version 1.1 · En vigueur à partir du 3 septembre 2026 · Publié le 3 septembre 2026

ConSergio.ai — DevInterface srl Version 1.1 · Last updated: 20 August 2026

Language. This English text is a courtesy translation of the Italian original. In the event of any discrepancy or conflict between the two versions, the Italian version shall prevail.

This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and describes how DevInterface srl processes personal data in the context of the ConSergio.ai service and its related website.


1. Data Controller

DevInterface srl Via Guglielmo Marconi 20, 37012 Bussolengo (VR), Italy VAT no. 04080300231 E-mail: [email protected]

The Controller has not appointed a Data Protection Officer (DPO), as the conditions for mandatory appointment under Article 37 GDPR do not apply.

2. Who this Policy is for

This Policy is addressed to:

  • accommodation businesses that subscribe to or are evaluating ConSergio.ai, and the natural persons acting on their behalf;
  • Staff Users of those businesses, as regards service communications and platform security;
  • visitors to the ConSergio.ai website.

Are you a guest at a property? If you have scanned a QR code in your room and are using the web app, your data is processed by the property where you are staying, which is the Data Controller. DevInterface acts solely as a technology provider, on the property’s behalf. The privacy notice that applies to you is the one made available by the property within the web app: that is who you should contact to exercise your rights. This Policy does not govern that processing.

3. Roles: who processes what

Two distinct levels of processing must be distinguished.

  DevInterface acts as… Reference document
Customer data (account, contacts, billing, platform usage, security) Data Controller This Privacy Policy
Guest data collected through the web app (requests, conversations, name and any stay details) Data Processor on behalf of the property, which is the Controller Data Processing Agreement (DPA)

For Staff User data processed within the platform (accounts, roles, permissions, action logs), DevInterface acts as Processor on behalf of the property. It acts as Controller in respect of service communications, support and platform security.

4. Categories of data processed

  • Registration and account data: first and last name, role, e-mail address, property name and details, credentials in encrypted form.
  • Billing data: company name, address, VAT and tax identification numbers, e-invoicing recipient code, invoice and payment history. We do not process payment card data, which is collected directly by the payment service provider.
  • Usage and technical data: access logs, IP address, timestamp, device and browser type, actions performed in the management panel.
  • Service consumption data: metrics relating to the use of features and artificial intelligence resources, used for billing, cost monitoring and technical capacity planning.
  • Content uploaded by the property: service descriptions, images, documents and other informational materials. Such content should not contain personal data; where it does, it remains the property’s responsibility.
  • Communications: the content of support, quotation or information requests sent to DevInterface.
  • Website browsing data: collected as described in Article 9.

5. Purposes and legal bases

Purpose Legal basis
Provision of the Service, account management and support Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Management of the free trial period Performance of pre-contractual measures (Art. 6(1)(b) GDPR)
Billing, payment and overage management Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Tax, accounting and document retention obligations Legal obligation (Art. 6(1)(c) GDPR)
Platform security, prevention of abuse and fraud, data integrity Legitimate interest (Art. 6(1)(f) GDPR)
Service improvement, technical analysis and cost monitoring Legitimate interest (Art. 6(1)(f) GDPR)
Service communications (technical notices, contractual changes, usage thresholds) Performance of a contract (Art. 6(1)(b) GDPR)
Marketing communications regarding similar products and services to existing customers Legitimate interest, with the right to object at any time (Art. 6(1)(f) GDPR and Art. 130(4) of Italian Legislative Decree 196/2003)
Newsletters and promotional communications to non-customers Consent, withdrawable at any time (Art. 6(1)(a) GDPR)
Establishment, exercise or defence of legal claims Legitimate interest (Art. 6(1)(f) GDPR)

Provision of registration and billing data is necessary for activation and delivery of the Service: failure to provide it prevents use of the Service. Provision of data for promotional purposes is optional.

6. Method of processing and automated decision-making

Data is processed by electronic means, applying technical and organisational measures appropriate to ensure its security and confidentiality, and is accessible only to authorised personnel.

DevInterface does not carry out automated decision-making or profiling producing legal effects or similarly significantly affecting data subjects within the meaning of Article 22 GDPR.

7. Third-party providers

To deliver the Service, DevInterface uses the following providers, which process personal data on its behalf as processors, except where otherwise indicated:

Provider Activity Location
Contabo GmbH Hosting of the application infrastructure and vector index Germany (EU)
Amazon Web Services (S3) Storage of files, images and documents Italy — Europe (Milan) region, eu-south-1
OpenAI Generation of assistant responses, embeddings, automated content translation USA, with EU residency options where available
Stripe Payment, subscription and billing management. In respect of payment instrument data, Stripe acts as an independent controller under its own privacy policy EU / USA

The vector index used by the AI assistant is self-hosted on the infrastructure indicated above and does not involve any additional provider.

An up-to-date list of the providers processing data on behalf of customer properties is set out in Annex B of the DPA. Data may also be disclosed to tax, legal and accounting advisers, and to competent authorities in the cases provided for by law.

8. Transfers to third countries

Primary data and backups are hosted within the European Union. The only processing involving a transfer to a third country concerns processing by the artificial intelligence model provider, supported by appropriate safeguards under Chapter V GDPR (Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework). A copy of the safeguards adopted may be requested at the address given in Article 1.

9. Cookies and measurement tools

The website and the platform take a privacy-first approach: by default, only technical cookies necessary for operation and authentication are used, which do not require consent. Any non-essential cookies or measurement tools are disabled by default and activated only with prior consent, which may be withdrawn at any time through the preference management panel.

10. Retention periods

Category of data Retention
Account and configuration data For the term of the contractual relationship and for 30 days after termination, subject to the below
Billing data and documents 10 years from the accounting entry, as required by law
Access and security logs 6 months, save for extension for as long as necessary to investigate and handle security incidents
Service consumption metrics For the term of the relationship; thereafter retained in aggregated and anonymous form
Support requests and communications 24 months from closure of the request
Data processed for promotional purposes Until objection or withdrawal of consent and, in any event, no longer than 24 months from the last contact
Data required to defend a legal claim For the duration of the proceedings and until expiry of the time limits for appeal

Guest data is retained for the periods set by the property, within the limits of the Plan subscribed, as described in the DPA and the Terms of Service.

11. Data subject rights

Data subjects may exercise at any time the rights set out in Articles 15-22 GDPR: access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interest — including objection to marketing communications — as well as the right to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

Requests may be sent to [email protected]. DevInterface will respond within one month of receipt, extendable by two months where the request is particularly complex.

Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory authority of their habitual residence or of the place of the alleged infringement.

Requests from Guests. For data processed by DevInterface as Processor on behalf of properties, Guest requests must be addressed to the property where they stayed, which is the Controller. Where a request is received directly by DevInterface, it will be forwarded without delay to the property concerned, which DevInterface will assist as provided in the DPA.

12. Changes to this Policy

This Policy may be updated to reflect regulatory changes, supervisory authority decisions or developments in the Service. The version in force is always available within the Service and on the website, showing the date of last update. Material changes are notified to customers with reasonable prior notice.


Acknowledgement. This document is deemed to have been reviewed by the Customer by ticking the relevant box during registration for the Service. The user identifier, document version, date and time are retained.


DevInterface srl — ConSergio.ai Privacy Policy — Version 1.1

Langue: IT EN

Autres versions: 1.1 1.0

Retour à l'accueil