1. Data Controller
The data controller for personal data is Monolait S.r.l. (fictitious), with registered office at Via Roma 1, 20121 Milan (MI). For any privacy-related question, you can contact us at: privacy@monolait.com.
2. Types of Data Collected
Monolait collects several types of data to provide the Service:
- Account Data: Name, email, encrypted password, user role, subscription plan, and billing information.
- Configuration Data: Documents, FAQs, and texts uploaded by the Customer to train the virtual assistant.
- Conversation Data: Texts entered by end users in chats handled by the Platform.
- Technical Data and Metrics: IP addresses, access logs, browser type, operating system, virtual assistant response times, and anonymous portal load-performance metrics.
3. Purposes and Legal Basis
Data is processed exclusively for the following purposes:
- Contract Performance (Art. 6.1.b GDPR): Providing Platform features, managing subscriptions, and technical support.
- Legitimate Interest (Art. 6.1.f GDPR): Optimizing virtual assistant performance, monitoring the technical stability and load performance of the portal, and preventing fraud or abuse.
- Legal Obligations (Art. 6.1.c GDPR): Tax and accounting obligations required by Italian law.
4. AI and Sub-Processors
For providing the Artificial Intelligence service, platform usage analytics and technical monitoring, Monolait relies on trusted sub-processors:
- AI Providers (OpenAI Ireland Ltd and Google Cloud Gemini API): Data transmitted (chat input) for response generation is NOT used to train their base models.
- Analytics and Events (PostHog Cloud EU): Used to analyze feature adoption and bot response speed. Data is hosted on servers within the European Union (Germany).
- Web Performance (Vercel Analytics): Used to monitor portal loading performance in a fully anonymous form.
- Error Monitoring (Sentry — servers in the European Union, Germany): Receives technical data about portal errors (error message, stack trace, the page where it occurred) so that we can fix them. It is configured not to transmit users' personal data and is not active on the public chatbot and agent pages.
5. Security and Retention
We adopt advanced technical measures to protect your data, including SSL/TLS encryption and database segregation.
- Account data is retained until account closure and for the time required by law (10 years for tax purposes).
- Conversation logs are retained for a predefined period (e.g., 12 months), unless otherwise configured by the Customer, to allow performance analysis.
- Assistant training documents are deleted immediately upon Customer request or account closure.
6. Rights of the Data Subject
Pursuant to articles 15-22 of the GDPR, you have the right to:
- Access your personal data and request a copy.
- Request correction of inaccurate data.
- Request erasure (right to be forgotten) or restriction of processing.
- Object to processing for legitimate reasons.
- Request data portability in a structured format.
To exercise these rights, write to privacy@monolait.com. You also have the right to lodge a complaint with the Italian Data Protection Authority.