Data minimization
We share only the context strictly necessary to perform the task.
AI governance and risk reduction
Webita uses artificial intelligence tools to support design, software development, analysis, automation and content production. Their use follows principles of data minimization, environment separation, credential protection and human oversight.
Last updated:1 August 2026
In this video Giorgio Sanna explains the method Webita uses to organize projects, minimize data, protect credentials and keep human oversight over AI tools.
The video will be available soon.
For Webita, AI is a support tool and not a replacement for professional responsibility. We adopt a concrete AI governance and risk reduction system, with procedures subject to review and updates.
We share only the context strictly necessary to perform the task.
We prepare synthetic and relevant environments with as little unnecessary data as possible.
AI tools are not connected indiscriminately to full client archives.
Passwords, tokens and API keys stay in dedicated tools and outside AI conversations.
Code, analysis, automations and content are reviewed by a person before relevant decisions.
We review documentation, privacy settings and operational limits of the services we use.
Procedures and configurations are reviewed to reflect legal and technical changes.
The final result is approved and used under professional responsibility, not delegated to AI.
Webita uses dedicated project folders prepared specifically for work with AI tools. Assistants are not connected indiscriminately to the main folders containing the full client archive.
This data minimization approach helps reduce the information surface exposed to AI tools and keeps the project boundary clearer.
To support responsible use we avoid entering data or materials that are not necessary for the task.
Any processing that requires personal data or confidential information should be assessed in advance based on purpose, necessity, legal basis, roles of the parties and applicable security measures.
Passwords, tokens and production keys are managed through dedicated tools and must not be copied into conversations with AI assistants.
Tools such as Vercel and GitHub may be part of the infrastructure, but using them does not automatically remove risk: correct configurations, appropriate roles and periodic checks are still required.
In addition to upstream data minimization, Webita uses privacy options made available by vendors when useful in the operating context.
Settings are checked periodically because products, interfaces and vendor conditions may change.
Personal data handled by websites or platforms built by Webita remains in the databases and infrastructure services defined by the specific project. It is not automatically transferred into AI conversations.
Artificial intelligence outputs are not treated as automatically correct. The level of review depends on the nature of the task and the risk connected to the result.
The AI Act and the GDPR are not the same. They can apply together, but they operate on different levels and require case by case assessment.
Initial information note
The European Artificial Intelligence Regulation entered into force on 1 August 2024. Most of its provisions become applicable from 2 August 2026, with exceptions, transitional periods and different deadlines.
This page is for informational purposes, does not constitute legal advice and describes the operating procedures adopted by Webita as of the last update date.
1 August 2024
Entry into force of the European Artificial Intelligence Regulation.
2 August 2026
Most provisions become applicable, with exceptions and differentiated timelines.
Continuous assessment
Classification, roles, legal bases and measures depend on purpose, users, data, sector and consequences.
Clear and prudent answers about the measures adopted by Webita for responsible AI use.
Not indiscriminately. Webita prepares synthetic and relevant project contexts and aims to exclude full documents, historical archives and materials that are not necessary for the task.
No. Passwords, tokens, API keys and production credentials are managed through dedicated tools and must stay outside AI conversations.
On the Webita accounts in use, when available, we keep enabled the preference intended to exclude content from model training, product improvement or non essential analytics. These settings are checked periodically.
When the vendor makes them available, these preferences are intended to limit the use of interactions for purposes beyond service delivery, such as training, product improvement or non essential analytics.
No. Enabling privacy options does not automatically mean that no data is technically processed or transmitted to deliver the service. For this reason Webita limits data and files before using AI environments.
No. AI outputs are not treated as automatically correct and relevant decisions are not delegated automatically. Human oversight remains proportionate to risk.
No. The GDPR concerns personal data processing, while the AI Act regulates development, provision and use of AI systems according to roles and risk levels. They can apply together.
No. Classification depends on the specific use case, purpose, data involved, sector, users and possible consequences.
A synthetic and relevant working environment is prepared, trying to exclude unnecessary personal data, backups, full archives, database exports and sensitive files.
Yes. The use of AI tools can be discussed within the project scope and, when requested, limited or excluded depending on the type of work.
Webita checks documentation, available privacy settings, terms of use and relevant vendor changes, updating procedures and configurations when needed.
You can use the existing contact channel on the site and ask for clarification about the use of AI, data and organizational measures adopted for your project.
Tools, procedures and settings may change over time. If you want clarification about a project or prefer to limit the use of AI tools, you can contact Webita through the existing contact channel on the site.
Last updated: 1 August 2026
The procedures described on this page are part of a governance and risk reduction system and are reviewed periodically.
Webita
We can define together the operating scope, data minimization measures and human oversight level most suitable for the project.
Talk to WebitaThese links help frame the legal context and some privacy settings declared by vendors. They do not replace a legal assessment of a specific project.