Call · 15 min
·AI transparency

How Itria uses artificial intelligence.

This page explains how we build AI into the systems we make, what technology we use, how we protect our clients' data and which documents you can ask for. Last updated: September 2026.

1Principles

AI doesn't replace human judgement. The systems we build automate what's repetitive and make suggestions. Decisions that matter, about a customer, an offer or any message that commits the business, stay with a person. This is built into the design, not just a promise: no Itria system sends a message to a real customer unless it has been approved, either in advance on the content or at the time, message by message. The owner decides which, channel by channel, and can change the setting whenever they like.

Our clients' data stays theirs. We never use a client's data to train models, and we don't share it with any third party that isn't under contract. Where we use a third-party model (Anthropic Claude), the data processing agreement rules out using the data for training.

No secrets in the code. Credentials and API keys live in environment variables, never in version-controlled files, prompts or logs.

2The technology we use
TechnologyWhat it doesHow it's governed
Claude API
Anthropic
Reasoning over content: reading a website, drafting in several languages, qualifying enquiries. Data Processing Agreement with Anthropic; data excluded from training.
n8n Orchestrating the automated processes: the layer that ties together enquiries, reminders and reporting. Self-hosted on Itria's own infrastructure, not a third-party SaaS.
Google Sheets Holds the operational data (contacts, appointments, logs). The client can look at it at any time. Standard Google Workspace DPA.
Next.js · Vercel
the Plancia
The control panel the client sees, and the APIs behind it. Standard Vercel DPA, with a choice of hosting region.
Hetzner
EU server
The infrastructure that runs n8n. Servers in the European Union, Hetzner DPA.
WhatsApp Business API The channel that systems use, where relevant, to send reminders, confirmations and replies to end customers, always behind the human approval step described above. Meta platform, Business API terms, data kept to what the conversation needs.
Google Drive Where the nightly backup of the client's operational data (contacts, bookings, logs) is stored, separately from the server backup. Standard Google Workspace DPA, same scope as Google Sheets.
Cheerio · Puppeteer The engine that reads a real website line by line for the Quadro: structure, content, technical signals. Runs on Itria's own infrastructure and reads only public pages the user points it to.
Resend Sends periodic reports and transactional messages (confirmations, notifications) to the client. Provider's standard DPA, with every send logged.
3Reliability and continuity

What happens if a system stops overnight, or data goes missing?

Motori Watchdog

An internal system that monitors every automated run. If a run doesn't report back within its expected window, or finishes with an unusual result, the operator is alerted straight away. We don't wait for the client to notice.

UptimeRobot

External, independent monitoring of the Plancia and the public APIs, around the clock.

Client data backup

A dated nightly copy of the operational data, kept on rotation, separate from the server backup.

Infrastructure backup

A nightly copy of the server that runs the orchestration.

Cloudflare Turnstile

Bot protection on public forms and self-service tools, with a cap on requests per address.

4Data protection

Every kind of processing has a legal basis, set out in writing in the agreement with the client. We never process data without knowing exactly on what grounds: performance of the contract, legitimate interest or consent. This is documented before the system goes live, not after.

Sensitive data never goes into the AI systems. Where a process handles end customers' information (names, contact details, order history), the data is minimised and pseudonymised down to what the model needs to do its job. No health, financial or special-category data (Art. 9 GDPR) is ever passed to a third-party model.

A local setup is always an option. For clients with stricter compliance requirements, the steps that currently use the Claude API can be switched to a model running on local or dedicated infrastructure, at the cost of weaker language reasoning. It's an explicit technical choice, discussed case by case, never something quietly set up by default.

Technical measures include dedicated authentication, per-client data separation, secrets kept out of the code, encryption in transit and a log of every run. If there's a data breach, the client is told without undue delay.

5Sub-processors

Every provider that touches data, what it does with it, and on what basis. The same providers as in section 2, grouped for compliance purposes.

ProviderWhat it processesContractual basis
Anthropic (Claude API) Content it reads to produce drafts, classifications and suggested replies. Never used to train models. Data Processing Agreement, data excluded from training.
Google (Workspace) Live operational data (Sheets: contacts, appointments, logs) and the nightly backup (Drive). Standard Google Workspace DPA.
Vercel The data shown in the control panel (the Plancia) and the requests to the APIs behind it. Standard Vercel DPA, with a choice of hosting region.
Hetzner No content data: it only hosts the server that runs n8n. Servers in the European Union, Hetzner DPA.
Meta (WhatsApp Business API) Messages to end customers (reminders, confirmations), always behind the human approval step. Business API terms, data kept to what the conversation needs.
Resend Email addresses used to send periodic reports and transactional messages. Provider's standard DPA, with every send logged.
6Data retention

How long we keep data, and what happens to it afterwards. The same rules for every client, written down before any system goes live.

DataKept forWhat happens next
Data from a client relationship that has ended 30 days Deleted, or returned if the client asks.
Motori run logs 6 months Deleted automatically on rotation.
Leads collected through the website (Diagnostico, Quadro, contact) 24 months from the last contact Deleted if no business relationship follows, unless consent is withdrawn sooner.
Backups (client data and infrastructure) 30 days on rotation The oldest copy is overwritten by the next.
7AI Act compliance

Our role. Itria is both a deployer of third-party models and the provider of the systems it builds and sells under its own name. So the transparency obligations in the EU Artificial Intelligence Act apply to Itria, not just to the companies that make the models.

The risk level. The systems we build fall under minimal risk plus the transparency obligations. They don't touch access to employment, education, credit, essential services, biometric data or the administration of justice, so they are not high-risk systems under Annex III.

What this means in practice. Anyone dealing with an automated Itria system is told they're dealing with an automated system. No generated content carrying a client's name goes out without explicit human approval. No special-category data goes into the systems.

From 2 August 2026

The Art. 50 transparency obligations apply: these are the ones that directly affect the systems we build.

From February 2025

The AI literacy obligation (Art. 4) applies: anyone working with the systems must know enough to understand and oversee them.

2 December 2027 · 2 August 2028

The Digital Omnibus, in force since 27 July 2026, pushed the high-risk obligations back to these dates (Annex III and Annex I respectively).

These dates apply to us, because we build the systems and put them into service. For a business that simply uses AI, the picture is different: a distinction of role cuts the obligations down to four things, explained in the AI Act for a small business.

A full map of the AI systems we use, with their purpose, the model behind them and the level of human oversight, is available on request and comes attached to the contract for clients.

8Documentation
This page (AI transparency)Available
Data processing agreement (Art. 28 GDPR)Available on request
Standard service contractAvailable on request
Map of AI systemsAvailable on request
AI literacy note (Art. 4)Available on request

To request a document, email info@itria.io and tell us which one you need. We reply within 5 working days.