Skip to main content

Trust center

Trust is documented.

Where the data lives, who can see it, how it is protected and what we sign: the answers a careful customer asks before starting — all on one page.

Personal data and GDPR

  • Privacy by design and by default (art. 25 GDPR) in every project: minimization, mapped legal bases, defined retention.
  • Data Processing Agreement (DPA) available on request where we act as processor.
  • Complete, compliant notices: privacy policy with per-purpose legal bases and cookie policy following the Italian DPA's guidelines.
  • No data selling, no use of customer data to train third-party models.

Where the data lives

  • UEBB-managed cloud on Italian datacenters, or on-premise on your infrastructure: you choose, project by project.
  • Air-gap option for environments that must never touch the internet: we have already done it, with LLMs and vision served on site.
  • Non-EU sub-processors only where necessary and declared, with adequate safeguards (e.g. EU-US Data Privacy Framework).

Application security

  • UEBB CyberSystem®: three-layer AES-256-GCM envelope encryption, one key per file, master-key rotation without re-encrypting.
  • Personal recovery codes derived with Argon2id, TOTP two-step verification (RFC 6238), zero plaintext secrets.
  • Immutable audit trail with 5-year retention on systems that require it.
  • Sanitized inputs, security headers (HSTS, nosniff, frame-deny) and minimal exposed surface.

Operational security

  • The same technologies we bring to customers protect us too: endpoints and network on the Sophos stack (Silver Partner), immutable backups and disaster recovery with Veeam (Cloud & Service Provider).
  • Least-privilege access and separation of development, test and production environments.
  • Regular updates and patching, monitored dependencies and security audits on our own website.

EU AI Act and governance

  • Every AI system we deliver is born with proportionate risk classification, technical documentation, logging and human oversight.
  • AI literacy (art. 4) and transparency towards users (art. 50) treated as project requirements, not attachments.
  • AI system registry and impact assessments coordinated with GDPR (DPIA/FRIA) when needed.

Verifiable partnerships

  • NVIDIA Inception Program for AI technologies.
  • Sophos Silver Partner for cybersecurity.
  • Veeam ProPartner (Cloud & Service Provider) for backup and data resilience.
  • AWS, Microsoft Azure and Google Cloud Partner for cloud architectures.

Need the DPA or a specific answer?

Write to us: we reply with documents, not slides.

Request the DPA