ENIT

Terms

Last updated: 21 June 2026 — v1.1

AI Notice

The data controller is Juvant Srls, an Italian limited-liability company with registered office at Via Albert Bruce Sabin 2, 72100 Brindisi (BR), Italy, VAT number IT02807050741, REA BR-260986, represented by its legal representative Antonio Gatti.

Data-protection contact: privacy@juvant.io.

Given the nature, scope and purposes of the processing as of the date of this notice, Juvant Srls has not designated a Data Protection Officer (DPO) under Art. 37 GDPR, as the mandatory conditions are not met. This assessment is reviewed periodically.

Processing Purposes and Legal Bases.

Personal data are processed for the following purposes, each on the legal basis indicated:

  • AI conversational session. The messages you exchange with Vant and the technical session metadata strictly required to generate the response (e.g. an ephemeral session identifier, IP address handled in transit) are transmitted to the underlying language model so that Vant can reply to you.
  • Legal basis: consent of the data subject under Art. 6(1)(a) GDPR, given through the consent dialog shown before the interaction begins. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal, by ending or not starting the session.
  • Consent log (vantConsentLog). A minimal record of your consent action (timestamp, consent version, scope of the consent granted, and an opaque session reference) is stored to evidence that consent was freely given, specific, informed and unambiguous, as required by Art. 7(1) GDPR.
  • Legal basis: compliance with a legal obligationto which the controller is subject under Art. 6(1)(c) GDPR — specifically, the controller's obligation under Art. 7(1) GDPR to be able to demonstrate that the data subject has consented to the processing of his or her personal data. The consent log is the demonstrative record required by Art. 7(1) GDPR and is necessary to make the right of withdrawal effective.
  • Because the legal basis for this purpose is Art. 6(1)(c), the right to object under Art. 21 GDPR does not apply to the processing of the consent log itself (Art. 21 applies only to processing based on Art. 6(1)(e) or (f)). The data subject's other rights (access, rectification, erasure within the limits of Art. 17(3)(b), restriction) remain available, and consent for other purposes may be withdrawn at any time as described elsewhere in this notice.
  • Safety and rate-limit logging. When an interaction is flagged by an internal safety mechanism, or when rate-limit and abuse-prevention controls are triggered, Juvant Srls retains the data strictly necessary for review and to prevent misuse of the service (including denial-of-service, automated abuse, and content-policy violations).
  • Legal basis: legitimate interest of the controller under Art. 6(1)(f) GDPR, consisting in the need to ensure the security and availability of the service, to prevent unlawful use, and to protect users and the integrity of the platform. The balancing assessment is documented in the Legitimate Interest Assessment (LIA) maintained by the controller. You have the right to object to this processing under Art. 21 GDPR, or to contest any moderation outcome (including a session block), by writing to privacy@juvant.io; the controller will respond within the time limits set by Art. 12(3) GDPR.
  • Optional lead capture. If you choose to leave your contact details through the dedicated form, those details (e.g. name, email address, and any message you provide) are stored to enable Juvant Srls to reply to you and to follow up on the conversation you initiated.
  • Legal basis: consent of the data subject under Art. 6(1)(a) GDPR, given by submitting the lead-capture form. Providing your contact details is entirely optional; Vant remains usable without lead capture.
  • Conversation summary email. When you submit the lead-capture form, Juvant Srls sends you a single transactional email to the address you provided, containing an AI-generated summary of your conversation with Vant. The email is strictly informational and contains no promotional or marketing content.
  • Legal basis: performance of pre-contractual measures taken at the data subject's request under Art. 6(1)(b) GDPR. By submitting the lead-capture form and providing your email address, you request Juvant Srls to process your enquiry; the summary email is the direct response to that request.
  • Safety-layer signal detection (self-harm). A dedicated safety-classifier layer inspects the text of your input, transiently and within the live session only, for indicators of self-harm or acute distress. Where such an indicator is detected, Juvant Srls displays a plain-language, non-stigmatising on-screen response signposting to external mental-health helplines appropriate to your locale. Because the inference of distress is, by its nature, a datum that may reveal information about your mental-health state, the operation is treated as processing of data concerning health within the meaning of Art. 9(1) GDPR and recital 35. The classifier is operated through the Azure AI Content Safety service provided by Microsoft Ireland Operations Ltd. within the Microsoft EU Data Boundary. The self-harm safety-pathway is strictly non-punitive: it does not trigger a rate-limit hit, an abuse-prevention flag, a session block, a follow-up contact, an emergency-services dispatch, or any transmission to a third party — the on-screen signposting response is the only effect. No diagnosis is made and no demographic, behavioural or mental-health profile of you is constructed.
  • Legal basis (Art. 6): legitimate interest of the controller under Art. 6(1)(f) GDPR in the protection of users of the service, in the prevention of foreseeable harm, and in the responsible deployment of AI (recitals 47 and 49 GDPR). The balancing assessment is documented in the Legitimate Interest Assessment (LIA-VANT-001).
  • Legal basis (Art. 9): substantial public interestunder Art. 9(2)(g) GDPR, namely the public interest in the safe deployment of AI systems addressed to the public, as articulated in Regulation (EU) 2024/1689 (AI Act) Arts. 13-15 and the duty of care under Regulation (EU) 2022/2065 (Digital Services Act) Arts. 14 and 28. The processing is proportionate to the aim pursued, respects the essence of the right to data protection, and is subject to specific safeguarding measures documented in the controller's Art. 30 register, including the non-punitive pathway described above, a shortened 7-day retention of the minimised "safety-pathway fired" flag, and a fast-track erasure pathway for affected sessions. You have the right to object to this processing under Art. 21 GDPR, by writing to privacy@juvant.io.
  • Safety-layer signal detection (demographic / vulnerability calibration). The same safety-classifier layer may, transiently and within the live session only, infer indicators of demographic or vulnerability context in your input where this is necessary to calibrate the safety response and to avoid biased, discriminatory or harmful model output. Because such indicators may incidentally reveal information within the scope of Art. 9(1) GDPR (in particular: racial or ethnic origin, religious or philosophical beliefs, data concerning sex life or sexual orientation), the operation is treated as processing of special categories of personal data under Art. 9 GDPR. The classifier is operated through the Azure AI Content Safety service provided by Microsoft Ireland Operations Ltd. within the Microsoft EU Data Boundary. The inference is notused for ad-targeting, commercial profiling, model training, persistent profile construction, or any decision producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR; it is consumed entirely within the controller's own pipeline, is not transmitted to the Azure OpenAI processor as a separate datum, and is not persisted beyond the live session save for a minimised "safety classifier fired" flag that does not record which demographic category was inferred.
  • Legal basis (Art. 6): legitimate interest of the controller under Art. 6(1)(f) GDPR in delivering a non-discriminatory service and in complying with bias-mitigation obligations under the AI Act. The balancing assessment is documented in LIA-VANT-001.
  • Legal basis (Art. 9): substantial public interest under Art. 9(2)(g) GDPR, namely the public interest in the non-discriminatory deployment of AI systems addressed to the public, as articulated in Regulation (EU) 2024/1689 (AI Act) — in particular the requirements on data governance and bias detection and mitigation for general-purpose AI systems addressed to the public — and in the duty of care under the Digital Services Act. The processing is proportionate, respects the essence of the right to data protection, and is subject to specific safeguarding measures including minimisation of inference output, no transmission to the language-model processor, no persistence of free-text beyond the redaction window, and a contestation pathway with human review for any moderation outcome that would adversely affect you. You have the right to object to this processing under Art. 21 GDPR, by writing to privacy@juvant.io.

Providing data for the AI conversational session is optional; absent consent, Vant cannot be used. Providing data for lead capture is optional; absent consent, you can still use Vant but Juvant Srls will not be able to contact you back. The safety-layer inferences described above are an integral component of the service and are operated under the safeguards set out above; on the substantial-public-interest basis recognised by Art. 9(2)(g) GDPR, they do not require your separate consent under Art. 9(2)(a). If you object to the safety-layer processing under Art. 21 GDPR, the consequence is that you will not be able to use Vant, because the safety layer cannot be turned off for individual users while the service continues to run. You may exercise this right at any time by writing to privacy@juvant.io.

Data Processors and Recipients.

Personal data are disclosed to the following processors, each appointed under Art. 28 GDPR through a data processing agreement:

  • Microsoft Ireland Operations Ltd., as provider of the Azure OpenAI Service used to process the messages you exchange with Vant. Processing takes place in the Sweden Central region, within the Microsoft EU Data Boundary.
  • Microsoft Ireland Operations Ltd., as provider of the Azure AI Content Safety service used to operate the safety-classifier layer described above (self-harm signal detection and demographic / vulnerability calibration). Processing takes place within the Microsoft EU Data Boundary.
  • Microsoft Corporation, as provider of the SharePoint / Microsoft Graph API services used to store the consent log and the optional lead-capture records on the Juvant Srls EU tenant.

No personal data is disclosed to third parties for marketing purposes, commercial profiling, sale, or any other purpose not described in this notice. The service does not use tracking cookies, third-party analytics, or profiling technologies.

Retention Periods.

Personal data are retained only for as long as necessary for the purposes set out above. The applicable retention periods are as follows:

  • AI conversational session — live messages. Message content exchanged during a live session is not retained beyond the duration of the current session. At the end of the session, no live message content persists in any production archive managed by Juvant Srls. An isolated backup copy may persist on encrypted, access-controlled, immutable storage for up to 365 days as part of disaster-recovery and continuity controls; backup copies are never restored back into the live system without tombstone-replay reconciliation. See "Backups (DR / continuity)" below for full detail.
  • Conversation summaries (conversation_summary). Where a conversation summary is generated and stored to support the optional lead-capture flow described in the purposes section, the summary record is nullified in the live production system (irreversibly emptied of conversational content) at most 90 days after the session ends, by a scheduled automated retention job operated by Juvant Srls. After production nullification, only the non-personal record skeleton required for referential integrity may persist in the live system; no conversational content remains in production. An isolated backup copy of the summary record may persist for up to 365 days under the disaster-recovery controls described in "Backups (DR / continuity)" below; that backup copy is never read in the ordinary course and is never restored back into the live system without tombstone-replay reconciliation.
  • Consent log (vantConsentLog). Retained for 24 months from the moment consent is recorded, to evidence the lawfulness of the processing under Art. 7(1) GDPR.
  • Lead capture (SharePoint Lists). Lead records are hard-deleted 24 months after the date of last contact between you and Juvant Srls, by a scheduled automated deletion job operated by Juvant Srls. After that period the records no longer exist, unless retention is required by law or to establish, exercise or defend a legal claim.
  • Conversation summary email. The email address and the associated summary are retained only for as long as strictly necessary to send the transactional email. For subsequent processing of lead-capture data (including any follow-up communications you initiate), the retention period set out for lead-capture records (24 months) applies.
  • Safety and rate-limit events (vantSafetyEvents). When an interaction is flagged by an internal safety mechanism or by rate-limit and abuse-prevention controls, a minimal record is retained as follows: (a) the salted hash of the offending input is retained in the live production system for 7 days to support short-window correlation of repeated abusive patterns; (b) the full event row (including hash, request metadata and moderation outcome) is hard-deleted from the live production system 23 days after creation. No safety-event data is retained in production beyond 23 days. An isolated backup copy of the safety-event row may persist for up to 365 days under the disaster-recovery controls described in "Backups (DR / continuity)" below, never read in the ordinary course and never restored back into the live system without tombstone-replay reconciliation. The 365-day hard cap is the absolute ceiling: by day 365, no copy of the safety-event row exists in any tier.
  • Operational logs (Azure Monitor / Log Analytics). Platform-level operational and security logs collected by the underlying Microsoft Azure observability layer (including request metadata, HTTP response codes, and security-relevant signals) are retained for 90 days at the workspace level, after which they are automatically deleted by the Azure Monitor Log Analytics workspace retention policy. These logs do not contain conversational content.
  • Backups (DR / continuity). We keep an isolated backup copy of your conversation record for up to 365 days, and we keep it only so we can recover from data loss, security incidents, or outages. Nobody reads it for any other purpose, and it is never restored back into the live system.

    The figure to remember is 365 days. Internally those 365 days break down into an immutable hot snapshot on a rolling 35-day horizon, an Azure Storage soft-delete tail of up to a further 30 days, and a hard ceiling at 365 days from the date the record was first written to the live system; the record cannot exist in any backup tier beyond day 365 under any circumstance. We do not edit backups after they are written; they expire automatically.

    If you ask us to erase your data under Article 17 GDPR, we erase it from our production systems within the statutory deadline. We do not modify existing backups, because doing so would compromise their integrity; we instead record your request in an internal tombstone register. If we ever have to restore a backup (for example after an incident or a data-loss event), your record is suppressed against the restored set before that set returns to production, so the erasure outcome is preserved.

    The lawful basis is our legitimate interest under Article 6(1)(f) GDPR in the security and continuity of the service and the defensibility of legal claims, balanced against your rights as recorded in our internal Legitimate Interest Assessment (LIA-VANT-002). You retain all your rights under Articles 15–22 GDPR, including the right to object to processing based on legitimate interest; contact us at privacy@juvant.io.

Your Rights.

Within the limits and conditions set out in Arts. 15-22 GDPR, you have the right to:

  • access your personal data (Art. 15);
  • obtain their rectification (Art. 16);
  • obtain their erasure (Art. 17);
  • obtain restriction of the processing (Art. 18);
  • receive your data in a structured, commonly used and machine-readable format and transmit them to another controller (data portability, Art. 20), where applicable;
  • object to processing based on legitimate interest (Art. 21);
  • not be subject to a decision based solely on automated processing producing legal or similarly significant effects on you (Art. 22), within the applicable limits.

You may withdraw your consent at any time, without prejudice to the lawfulness of processing carried out on the basis of consent before its withdrawal.

To exercise any of these rights, please write to privacy@juvant.io. Juvant Srls will respond within the time limits set by Art. 12(3) GDPR.

Safety-pathway sessions — specific commitments.

If your request concerns a session in which the self-harm safety-pathway was triggered (i.e. a session in which Vant displayed the on-screen helpline signposting response described above), Juvant Srls applies the following enhanced commitments:

  • Fast-track response window. Juvant Srls will respond to your request within 7 calendar days of receipt, rather than within the standard period of Art. 12(3) GDPR. This shortened window applies to requests for access, rectification, erasure, restriction and objection concerning the safety-pathway session.
  • Erasure as the default outcome.If you ask Juvant Srls to erase the minimised "safety-pathway fired" flag associated with such a session, erasure is the default outcome. You do not need to provide a session identifier or any other technical reference; a contemporaneous description of the interaction (approximate date and a short description of the exchange) is sufficient for Juvant Srls to act on the request.

Contact and Complaints.

For any question regarding this notice or the processing of your personal data, please contact:

privacy@juvant.io — single point of contact for data subjects.

You also have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), under Art. 77 GDPR, without prejudice to any other administrative or judicial remedy.

Terms of Use

1. Acceptance

By using vant.juvant.io ("the Service") you accept these Terms. If you do not accept them, do not use the Service.

2. The Service

The Service is provided free of charge by Juvant Srls, a company incorporated in Italy (VAT IT02807050741), as an informational and demonstrational AI assistant. We may modify, suspend, or discontinue the Service at any time without notice.

3. Acceptable use

You agree not to: (a) use the Service for unlawful purposes; (b) attempt to extract personal data about others; (c) probe, scan, or attack the infrastructure; (d) misrepresent Vant's output as human-authored where the distinction is material; (e) use the Service to generate content that infringes third-party rights or violates applicable law.

4. No warranties

The Service is provided "as is" and "as available", without warranties of any kind. Outputs are generated automatically and are not verified.

5. Intellectual property

The Service, including the Vant name, interface, and underlying software, is owned by Juvant Srls. You retain rights to the text you input. You may use Vant's outputs subject to the limits in Section 3.

6. Backups and continuity of service

Plain-English lead. We keep an isolated backup copy of your conversation record for up to 365 days, only to recover from data loss, security incidents, or outages. Nobody reads it for any other purpose. If you ask us to delete your data, we delete it from our live system immediately. Backup copies are never restored back into the live system, and are automatically destroyed within at most 365 days from when the record was first written.

Legal detail. We keep encrypted, immutable backup copies of the data Vant generates and receives, so that we can recover from accidents, outages, or security incidents and continue to meet our legal duties — in particular our duty to demonstrate that you consented to processing and to respond to your data-protection requests. These backups roll through three tiers governed by a single outer ceiling: an immutable hot snapshot on a rolling 35-day horizon; an Azure Storage soft-delete tail of up to a further 30 days for accidental-deletion recovery; and a hard cap of 365 days, beyond which the record cannot exist in any tier under any circumstance. We do not modify backups once written; they age out automatically. If you ask us to erase your data under Article 17 GDPR, we erase it from our live systems within the legal deadline and record your request in an internal tombstone register; if we ever have to restore a backup (for example after an incident), your record is suppressed against the restored set before it returns to production, so the erasure outcome is preserved. The lawful basis for retaining these backups is our legitimate interest in the security, continuity, and legal defensibility of the service, as documented in our Privacy Notice and in our internal Legitimate Interest Assessment (LIA-VANT-002).

7. Limitation of liability

To the maximum extent permitted by Italian law, Juvant Srls shall not be liable for any direct, indirect, incidental, or consequential damages arising from use of the Service.

8. Governing law

These Terms are governed by Italian law. Any dispute is subject to the exclusive jurisdiction of the Court of Brindisi, without prejudice to mandatory consumer protections.

9. Contact

Juvant Srls — Brindisi, Italy — privacy@juvant.io

juvant.io

© 2026 Juvant Srls