WGBWEBGLOBALBUILD
ServicesPortfolioBlogAboutContact
Client AreaGet a quote

Privacy Policy

Last updated: March 2026

1. Data Controller

The data controller is:

  • WebGlobalBuild — a brand of Global Svapo S.r.l.s.
  • Registered office: Via Dino Buzzati 3, 91026 Mazara del Vallo (TP), Italy
  • VAT / Tax ID: 02717040816 — REA: TP-191921
  • Share capital: €500.00 fully paid
  • Legal representative and data protection contact: Ivo Guccione
  • Email: info@webglobalbuild.it
  • Certified email (PEC): salvatoreguccione6@pec.it

2. Types of data collected

This website collects personal data in connection with the following features. For each, we indicate the type of data, purpose, legal basis, and retention period.

2.1 Contact form

Data collectedName, email, project type, message, phone number (optional)
PurposeRespond to user inquiries and create a support ticket
Legal basisConsent (Art. 6.1.a GDPR) — mandatory checkbox before submission
RetentionData is retained until ticket closure and for a maximum of 24 months after closure, unless legally required otherwise
Third partiesResend (confirmation and notification emails)

2.2 Cost estimator

Data collectedEmail, project description, target audience, urgency, budget, selected features, contact preference, AI-generated estimate, additional notes
PurposeGenerate an indicative AI-powered estimate and create a quote request ticket
Legal basisConsent (Art. 6.1.a GDPR) — mandatory checkbox before submission
RetentionUp to 24 months from ticket creation
Third partiesResend (confirmation email)

The project description is processed by Claude (Anthropic) to generate the estimate. No personal data (email, name) is transmitted to the AI — only the project description and selected preferences. Anonymous data may be saved for internal statistical purposes.

2.3 Support ticket system

Data collectedName, email, phone, request type, title, description, budget, timeline, technologies, attachments (PDF, JPEG, PNG, WebP — max 5 MB each, max 3 files)
PurposeManage support and quote requests
Legal basisPerformance of pre-contractual measures (Art. 6.1.b GDPR)
RetentionUp to 24 months after ticket closure
Third partiesResend (email notifications), Supabase Storage (file storage)

2.4 AI chat

Data collectedName (optional), email (optional), message text, conversation history
PurposeProvide automated assistance via AI chatbot
Legal basisLegitimate interest (Art. 6.1.f GDPR) — providing immediate support to visitors
RetentionChat sessions are retained for up to 12 months
Third partiesAnthropic (Claude API) — conversation text is transmitted to Anthropic's servers in the United States for response generation. See section 5 for extra-EU transfer safeguards

2.5 Live chat with human operator

Data collectedName (optional), email (optional), message text
PurposeProvide direct assistance through a human operator
Legal basisLegitimate interest (Art. 6.1.f GDPR)
RetentionUp to 12 months after session closure
Third partiesNone — operator messages are handled internally

2.6 Client portal

Data collectedEmail, password (bcrypt hash), project data, invoices, quotes, messages, reviews
PurposeContract management, project progress monitoring, billing
Legal basisPerformance of a contract (Art. 6.1.b GDPR)
RetentionFor the duration of the contractual relationship and for 10 years thereafter for tax obligations
Third partiesResend (invitation emails, password reset), Anthropic (portal AI chat — see section 5)

Portal access uses a session cookie (wgb-portal-session) containing a signed JWT with the minimum data necessary for authentication (client ID, account ID). The cookie lasts 7 days and is HttpOnly, Secure, and SameSite Strict.

When a client accepts or declines a quote, their IP address is recorded as proof of contractual acceptance under Art. 6(1)(b) GDPR (contract performance). This data is retained for the duration of the contractual relationship and for 10 subsequent years for tax and evidentiary obligations.

2.7 AI-powered quote generation (admin area)

Data transmittedProject description, project type
PurposeAutomatically generate quote line items
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
Third partiesAnthropic (Claude API) — description text is transmitted to Anthropic's servers in the USA

2.8 Rate limiting and security

Data collectedIP address (SHA-256 hashed with a cryptographic salt before storage)
PurposeAbuse prevention, protection against automated attacks
Legal basisLegitimate interest (Art. 6.1.f GDPR) — website security
RetentionRate limit records expire automatically at the end of the configured time window

2.9 IMAP email client (admin area)

Data collectedContent of emails sent to info@webglobalbuild.it (sender, subject, body, attachments)
PurposeManaging correspondence with clients and prospects through the admin panel
Legal basisLegitimate interest (Art. 6.1.f GDPR) — operational management of communications
RetentionEmails are stored on the Aruba IMAP server and accessible only by the administrator through the admin panel
Third partiesAruba S.p.A. (IMAP email hosting) — data is not shared with any other third parties

2.9bis — AI email reply suggestions (admin area)

Data transmittedEmail subject, sender, message body
PurposeGenerate AI-powered reply suggestions for received emails
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
Third partiesAnthropic (Claude API) — email content is transmitted to Anthropic's servers in the USA for suggestion generation

2.10 Push notifications (Web Push API)

Data collectedPush subscription endpoint, browser encryption keys
PurposeSend push notifications to the site administrator for relevant events (new tickets, messages, etc.)
Legal basisLegitimate interest (Art. 6.1.f GDPR) — internal operational efficiency
RetentionSubscription endpoints are stored in Supabase until revocation or deactivation
Third partiesNo public user data is involved — push notifications are intended exclusively for the administrator

2.11 Demo account

The website provides a demo account (demo@webglobalbuild.it) with entirely fictitious data to allow evaluation of the client portal features. No real data is associated with this account.

2.12 Google Analytics 4

Data collectedAnonymous browsing data (pages visited, session duration, scroll depth, UI interactions), IP address (automatically anonymized)
PurposeStatistical analysis of traffic and user behavior on the website
Legal basisConsent (Art. 6.1.a GDPR) — activated only after explicit acceptance via cookie banner
RetentionAccording to Google Analytics retention policies (default 14 months)
Third partiesGoogle LLC (Google Analytics 4) — data is transferred to Google servers in the USA. Google Signals and ad personalization are disabled. See section 5

2.13 Vercel Analytics and Speed Insights

Data collectedPages visited, referrer, browser, operating system, device type, Core Web Vitals metrics (LCP, FID, CLS, TTFB)
PurposeWebsite performance monitoring and aggregate traffic analysis
Legal basisConsent (Art. 6.1.a GDPR) — activated only after explicit acceptance via cookie banner
RetentionAccording to Vercel retention policies
Third partiesVercel, Inc. — see section 5

2.14 Public reviews

Data collectedName, email, company name (optional), role (optional), review text (max 500 characters), rating (1-5 stars)
PurposeCollect and publish testimonials on the website. Reviews are moderated by the administrator before publication
Legal basisConsent (Art. 6.1.a GDPR) — voluntary form submission
RetentionUntil the user requests deletion
Third partiesNone — data is not shared with third parties

The name and optional company name are published on the website once the review is approved.

2.15 Google Indexing API (admin area)

Data transmittedURLs of published, updated, or removed site pages (blog posts, portfolio projects)
PurposeNotify Google for timely content indexing
Legal basisLegitimate interest (Art. 6.1.f GDPR) — search engine visibility
Third partiesGoogle LLC (Indexing API) — only public URLs are transmitted, no personal data

2.16 — AI content generation and translation (admin area)

Data transmittedPortfolio project descriptions, blog article content
PurposeGenerate portfolio case studies and translate content from Italian to English
Legal basisLegitimate interest (Art. 6.1.f GDPR) — operational efficiency, multilingual publishing
Third partiesAnthropic (Claude API) — texts are transmitted to Anthropic's servers in the USA for processing and translation

2.17 — AI usage logging and transparency

All interactions with AI systems are logged internally (ai_usage_log) tracking: feature name, token count, and estimated cost.

The log contains no personal data — it only records the feature identifier and a truncated prompt preview (maximum 100 characters). The purpose is cost monitoring, transparency, and compliance with EU Regulation 2024/1689 (AI Act).

2.18 Sentry (error monitoring)

Data collectedJavaScript error messages, stack traces, page URL, user agent, anonymized IP address
PurposeDetection and resolution of technical errors to improve website stability
Legal basisConsent (Art. 6.1.a GDPR) — "Functional" category in the cookie banner
Retention90 days (Sentry default policy)
Third partiesFunctional Software, Inc. (Sentry) — San Francisco, USA

2.19 Cloudflare Turnstile (anti-bot protection)

Data collectedVerification token, IP address, user agent, widget interaction data
PurposeProtection of login pages from automated access and bot attacks
Legal basisLegitimate interest (Art. 6.1.f GDPR) — service security
RetentionThe cf_clearance cookie lasts 30 minutes. Cloudflare does not retain personal data beyond the time necessary for verification
Third partiesCloudflare, Inc. — San Francisco, USA

3. Cookies

This website uses technical cookies necessary for its operation and, with user consent, analytics cookies (Google Analytics 4) and performance monitoring tools (Vercel Analytics, Speed Insights). No profiling or advertising cookies are used. For detailed information, please see our Cookie Policy.

4. Third parties

ServiceData receivedPrivacy policyDPA
ResendEmail, name, message content for transactional email deliveryresend.com/legal/privacy-policyDPA
AnthropicChat conversation text, project descriptions for AI response and quote generationanthropic.com/privacyDPA
SupabaseAll stored personal data (database and file storage)supabase.com/privacyDPA
Google LLCAnonymous browsing data for traffic analysis (Google Analytics 4), public URLs for indexing (Indexing API)policies.google.com/privacyDPA
VercelIP address, user agent, HTTP request logs (hosting and CDN), performance metrics and anonymous browsing data (Vercel Analytics and Speed Insights)vercel.com/legal/privacy-policyDPA
ArubaInbound and outbound emails (IMAP server for info@webglobalbuild.it mailbox)aruba.it/informativa-privacy—
Functional Software, Inc. (Sentry)Error messages, stack traces, URL, user agent, anonymized IP for error monitoringsentry.io/privacyDPA
Cloudflare, Inc.Verification token, IP address, user agent for anti-bot protection (Turnstile)cloudflare.com/privacypolicyDPA

5. Extra-EU data transfers

Some personal data is transferred to the United States to the following providers:

  • Anthropic, PBC (San Francisco, USA) — receives chat conversation text and project descriptions for response generation via the Claude API. The transfer is based on the Standard Contractual Clauses (SCC) adopted by the European Commission (Decision 2021/914). Anthropic does not use data submitted via API to train its models. (DPA)
  • Vercel, Inc. (San Francisco, USA) — website hosting and distribution. The transfer is covered by SCCs and Vercel's Data Processing Agreement. (DPA)
  • Resend, Inc. (USA) — transactional email delivery. The transfer is covered by SCCs. (DPA)
  • Google LLC (Mountain View, USA) — receives anonymous browsing data via Google Analytics 4 and public URLs via the Indexing API. The transfer is based on SCCs and Google's Data Processing Terms. (DPA)
  • Functional Software, Inc. (Sentry) (San Francisco, USA) — receives technical error data (stack traces, URLs, user agent) for website stability monitoring, subject to user consent. The transfer is based on SCCs. (DPA)
  • Cloudflare, Inc. (San Francisco, USA) — receives anti-bot verification data (token, IP, user agent) via the Turnstile service on login pages. The transfer is based on SCCs and Cloudflare's DPA. (DPA)

Data stored in Supabase (database and file storage) is hosted in the EU region (AWS eu-west-1, Ireland). No extra-EU transfer occurs for data stored in the database.

6. Data subject rights

Under Articles 15-22 of the GDPR, users have the right to:

  • Access — obtain confirmation of the existence of their personal data and access its content
  • Rectification — update or correct inaccurate or incomplete data
  • Erasure — request deletion of data, within the limits provided by law
  • Restriction — request restriction of processing in certain cases
  • Portability — receive their data in a structured, commonly used, and machine-readable format
  • Objection — object to processing on legitimate grounds
  • Withdrawal of consent — withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal

To exercise your rights, please contact:

  • Email: info@webglobalbuild.it
  • Certified email (PEC): salvatoreguccione6@pec.it

7. Right to lodge a complaint

Users have the right to lodge a complaint with the competent supervisory authority:

  • Garante per la protezione dei dati personali (Italian Data Protection Authority)
  • Piazza Venezia 11, 00187 Rome, Italy
  • Email: garante@gpdp.it
  • PEC: protocollo@pec.gpdp.it
  • Website: www.garanteprivacy.it

7bis. Artificial intelligence systems — AI Act compliance

This website uses artificial intelligence systems in compliance with EU Regulation 2024/1689 (AI Act). All systems used are classified as minimal or limited risk under the regulation.

AI systems used include: public chatbot for visitor assistance, client portal chat, quote line item generation, email reply suggestions, portfolio content generation, and article translation. All are based on Anthropic's Claude model.

The chatbot is clearly identified as AI in the interface. All AI-generated content is reviewed by a human operator before publication.

For detailed information, see our dedicated AI Disclosure page.

7ter. Data Protection Officer (DPO)

The Data Controller has not appointed a Data Protection Officer (DPO) as it does not fall within the cases required by Art. 37 of the GDPR. The data protection contact is the company's legal representative, Ivo Guccione, reachable at:

  • Email: info@webglobalbuild.it
  • Certified email (PEC): salvatoreguccione6@pec.it

7quater. Automated decision-making (Art. 22)

This website uses artificial intelligence systems (chatbot, content generation, quote assistant) that do not produce decisions with legal effects or that significantly affect the data subject. AI-generated responses are informational and non-binding in nature. Every commercial decision (quotes, invoices, project management) is always subject to human review and approval.

7quinquies. Special categories of data (Art. 9)

The Data Controller does not collect or process special categories of personal data as referred to in Art. 9 GDPR (data concerning health, racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data). Should users voluntarily include such information in contact messages, chat, or tickets, the Data Controller will proceed with their deletion.

8. Changes to this policy

The data controller reserves the right to modify this policy at any time. Changes will be published on this page with an updated date shown at the top. Continued use of the website after the publication of changes constitutes acceptance thereof.

WGB

Web development, e-commerce and AI solutions. Crafted quality for ambitious digital projects.

Quick links

ServicesPortfolioAboutContact
Blog

Legal

Privacy Policy
Cookie Policy
Terms and Conditions
AI Disclosure

WebGlobalBuild is a brand of Global Svapo S.r.l.s.

VAT / Tax ID: 02717040816 — REA: TP-191921

Registered office: Via Dino Buzzati 3, 91026 Mazara del Vallo (TP)

Share capital: €500.00 fully paid

© 2026 WebGlobalBuild. All rights reserved.