AI governance and risk reduction

Useful, controlled and data respectful artificial intelligence

Webita uses artificial intelligence tools to support design, software development, analysis, automation and content production. Their use follows principles of data minimization, environment separation, credential protection and human oversight.

Last updated:1 August 2026

How Webita uses AI while protecting data and projects

In this video Giorgio Sanna explains the method Webita uses to organize projects, minimize data, protect credentials and keep human oversight over AI tools.

Video coming soon

The video will be available soon.

Our approach

For Webita, AI is a support tool and not a replacement for professional responsibility. We adopt a concrete AI governance and risk reduction system, with procedures subject to review and updates.

Data minimization

We share only the context strictly necessary to perform the task.

Sanitized contexts

We prepare synthetic and relevant environments with as little unnecessary data as possible.

Environment separation

AI tools are not connected indiscriminately to full client archives.

Secret protection

Passwords, tokens and API keys stay in dedicated tools and outside AI conversations.

Human oversight

Code, analysis, automations and content are reviewed by a person before relevant decisions.

Vendor checks

We review documentation, privacy settings and operational limits of the services we use.

Continuous updates

Procedures and configurations are reviewed to reflect legal and technical changes.

Responsibility for the final result

The final result is approved and used under professional responsibility, not delegated to AI.

AI Safe project environments

Webita uses dedicated project folders prepared specifically for work with AI tools. Assistants are not connected indiscriminately to the main folders containing the full client archive.

  • For each project we prepare a synthetic and relevant working context.
  • Whenever possible we exclude unnecessary personal data, full confidential documents, historical archives, backups and database exports.
  • Files containing credentials and client material not relevant to the requested work are kept out.
  • Environment separation is a minimization and risk reduction measure, not an absolute guarantee of compliance.

This data minimization approach helps reduce the information surface exposed to AI tools and keeps the project boundary clearer.

Data we do not intentionally put into AI tools

To support responsible use we avoid entering data or materials that are not necessary for the task.

  • passwords
  • authentication tokens
  • API keys
  • production credentials
  • real .env files
  • identity documents
  • health data
  • special categories of personal data
  • full database copies
  • user or customer exports
  • unnecessary financial data
  • backups and logs containing personal information
  • contracts or confidential documents in their full form
  • any client data not necessary to perform the task

Any processing that requires personal data or confidential information should be assessed in advance based on purpose, necessity, legal basis, roles of the parties and applicable security measures.

Credential protection

Passwords, tokens and production keys are managed through dedicated tools and must not be copied into conversations with AI assistants.

  • environment variables
  • secret management on hosting platforms
  • development and production separation
  • exclusion of sensitive files from Git
  • .gitignore rules
  • least privilege principle
  • credential rotation when needed
  • checks against accidental secret publication

Tools such as Vercel and GitHub may be part of the infrastructure, but using them does not automatically remove risk: correct configurations, appropriate roles and periodic checks are still required.

Privacy controls currently adopted

In addition to upstream data minimization, Webita uses privacy options made available by vendors when useful in the operating context.

Privacy preferences on Webita accounts

  • On Webita accounts used with AI tools, when available, we keep enabled the preference intended to exclude content from model training, product improvement or non essential analytics.
  • These preferences are checked on the accounts actually used by Webita and reviewed again when interfaces, terms or vendors change.
  • We do not assume that a single setting covers every function or environment offered by a vendor, so periodic review remains necessary.

Limits of privacy settings

  • Enabling privacy options does not necessarily mean that no data is technically processed or transmitted to deliver the service.
  • For this reason Webita limits data and files in AI environments before they are used.
  • Technical and organizational measures therefore remain central even when Webita accounts use dedicated privacy preferences.

Technical exclusions and sensitive files

  • .env
  • .env.*
  • certificates and private keys
  • backups
  • SQL exports
  • logs
  • upload folders
  • files containing credentials
  • non necessary confidential materials

Settings are checked periodically because products, interfaces and vendor conditions may change.

Databases, hosting and application data

Personal data handled by websites or platforms built by Webita remains in the databases and infrastructure services defined by the specific project. It is not automatically transferred into AI conversations.

  • AI assistants do not automatically receive access to production databases
  • application data stays separate from AI conversations
  • possible integrations are assessed and limited to the purpose
  • access and permissions must be proportionate
  • using an external provider does not remove privacy responsibilities from Webita or the client
  • retention, roles, permissions and security measures depend on the project

Human oversight

Artificial intelligence outputs are not treated as automatically correct. The level of review depends on the nature of the task and the risk connected to the result.

  • code and configurations are reviewed before use in relevant environments
  • automations, analyses and content are checked before publication or execution
  • decisions relevant for people, clients, security, production or publication are not delegated automatically to AI
  • the professional remains responsible for the verification and use of the final result

AI Act and GDPR

The AI Act and the GDPR are not the same. They can apply together, but they operate on different levels and require case by case assessment.

Initial information note

The European Artificial Intelligence Regulation entered into force on 1 August 2024. Most of its provisions become applicable from 2 August 2026, with exceptions, transitional periods and different deadlines.

This page is for informational purposes, does not constitute legal advice and describes the operating procedures adopted by Webita as of the last update date.

Essential regulatory timeline

1 August 2024

Entry into force of the European Artificial Intelligence Regulation.

2 August 2026

Most provisions become applicable, with exceptions and differentiated timelines.

Continuous assessment

Classification, roles, legal bases and measures depend on purpose, users, data, sector and consequences.

  • the GDPR concerns personal data processing
  • the AI Act regulates development, provision and use of AI systems according to roles and risk levels
  • not every AI system is automatically high risk
  • classification must be assessed case by case
  • even when a use case is not high risk, transparency, competence, security and human oversight still matter

What we do and what we do not do

What we do

  • prepare synthetic and relevant project contexts
  • adopt data minimization and risk reduction measures
  • separate environments, credentials and application data from prompts
  • periodically review procedures, tools and settings
  • maintain consistent privacy preferences on the Webita accounts in use
  • review working contexts before more sensitive activities
  • document limits, checks and procedure updates
  • adapt tools and workflows when requirements or risk profiles change

What we do not do

  • we do not indiscriminately connect full client archives to AI assistants
  • we do not intentionally use production credentials as context
  • we do not put unnecessary personal data into prompts
  • we do not treat AI as a substitute for professional oversight
  • we do not automatically publish every AI generated result
  • we do not promise absolute security or compliance
  • we do not present AI content as reliable without proportionate review
  • we do not use client data for additional purposes without an appropriate assessment

Frequently asked questions

Clear and prudent answers about the measures adopted by Webita for responsible AI use.

Does Webita put client documents into AI tools?

Not indiscriminately. Webita prepares synthetic and relevant project contexts and aims to exclude full documents, historical archives and materials that are not necessary for the task.

Are passwords and API keys shared with artificial intelligence?

No. Passwords, tokens, API keys and production credentials are managed through dedicated tools and must stay outside AI conversations.

Can the AI tools used by Webita use content for training or improvement?

On the Webita accounts in use, when available, we keep enabled the preference intended to exclude content from model training, product improvement or non essential analytics. These settings are checked periodically.

What do the privacy preferences enabled on Webita accounts do?

When the vendor makes them available, these preferences are intended to limit the use of interactions for purposes beyond service delivery, such as training, product improvement or non essential analytics.

Do privacy preferences mean that no data is processed?

No. Enabling privacy options does not automatically mean that no data is technically processed or transmitted to deliver the service. For this reason Webita limits data and files before using AI environments.

Does artificial intelligence take decisions autonomously?

No. AI outputs are not treated as automatically correct and relevant decisions are not delegated automatically. Human oversight remains proportionate to risk.

Are the AI Act and the GDPR the same thing?

No. The GDPR concerns personal data processing, while the AI Act regulates development, provision and use of AI systems according to roles and risk levels. They can apply together.

Are all AI systems considered high risk?

No. Classification depends on the specific use case, purpose, data involved, sector, users and possible consequences.

How is project context prepared?

A synthetic and relevant working environment is prepared, trying to exclude unnecessary personal data, backups, full archives, database exports and sensitive files.

Is it possible to request that a project does not use AI tools?

Yes. The use of AI tools can be discussed within the project scope and, when requested, limited or excluded depending on the type of work.

How are vendors reviewed?

Webita checks documentation, available privacy settings, terms of use and relevant vendor changes, updating procedures and configurations when needed.

How can I raise a question about my data?

You can use the existing contact channel on the site and ask for clarification about the use of AI, data and organizational measures adopted for your project.

Updates and contacts

Tools, procedures and settings may change over time. If you want clarification about a project or prefer to limit the use of AI tools, you can contact Webita through the existing contact channel on the site.

Last updated: 1 August 2026

The procedures described on this page are part of a governance and risk reduction system and are reviewed periodically.

Useful links

Webita

Do you want to define how AI should be used in your project?

We can define together the operating scope, data minimization measures and human oversight level most suitable for the project.

Talk to Webita

Sources and references

These links help frame the legal context and some privacy settings declared by vendors. They do not replace a legal assessment of a specific project.

AI Governance and Data Protection | Webita