Andrea AI · Trust Center

Security and compliance, documented with evidence.

Twenty-four public instruments govern corporate, contractual, privacy, security and artificial-intelligence matters, distinguishing responsibilities, duties and evidence.

Edition dated 29 July 2026 Effective from 2026-07-29 Italian text prevails

Public library

Documents in force

Each PDF carries an effective date, document code and SHA-256 digest. Confidential evidence is disclosed only through a controlled procedure.

01 Governance

Legal notice and company information

Publisher identity, digital scope and reliance conditions.

02 Privacy

Website and contact-form privacy notice

Processing of data on the commercial site and in contact forms.

03 Privacy

Product privacy notice and GDPR roles

Roles, data categories and GDPR responsibilities in the service.

04 Privacy

Extended notice on cookies and other tracking technologies

Storage technologies and the distinction between website and application.

05 Contracts

General terms of service and acceptable use policy

Public rules for access, responsibility and permitted use.

06 Product

Legal and functional description of the service

Intended use, audience, capabilities, dependencies and limitations.

07 Privacy

Personal Data Processing Addendum — DPA

Framework processing terms on behalf of the customer.

08 Suppliers

Subprocessor, location and transfer register

Material suppliers, functions and controls before engagement.

09 Security

Security, architecture and technical-organisational measures overview

Architecture, shared responsibility and verifiable measures.

10 Security

Infrastructure and hosting statement

Hosting scopes and separation of provider capabilities from Niltech controls.

11 Privacy

Retention, deletion, rights and complaints

Retention, deletion and rights-management criteria.

12 Security

Incident response and vulnerability disclosure summary

Channels, triage, communication and responsible disclosure.

13 AI

Responsible artificial intelligence policy and AI Act transparency

Intended use, transparency, literacy and governance of AI outputs.

14 AI

AI system card and legal-operational risk assessment

System, hazards, controls, residual risk and review criteria.

15 AI

Human oversight statement

Actual review, override, escalation and suspension points.

16 Privacy

Data protection impact assessment summary

Structured assessment of necessity, proportionality, risks and mitigations.

17 Data

Portability, export, deletion and exit

Formats, exit assistance, deletion and dependencies.

18 Resilience

DORA-oriented ICT supplier information sheet

Information for ICT due diligence by DORA-regulated customers.

19 Resilience

Business continuity, backup and disaster recovery

Continuity governance without unproven targets or capabilities.

20 Security

Software lifecycle security, vulnerabilities and updates

Development lifecycle, dependency management and vulnerability remediation.

21 Accessibility

Accessibility statement

Commitment, status, feedback channel and known limitations.

22 ESG

ESG statement and methodology

Evidence-based ESG approach with stated boundaries and methodology.

23 Service

Service levels, support and maintenance terms

Channels, maintenance, dependencies and conditions for agreed levels.

24 Governance

Regulatory applicability and compliance-controls matrix

Dated matrix of applicability, responsibilities and required evidence.

+Controlled evidence

Request the security pack

Full DPIA and ROPA, data flow, AI registers, TOMs, suppliers, incidents, backup, DSAR, SBOM, access review and ESG evidence are shared only with authorised parties.