Your data, and what we do with it
The demo uses synthetic payment data. Do not submit customer data, payment credentials or private keys.
Last updated 19 September 2026. This page describes the free demo at api.trustedpai.com/demo. It is written to be read, not to be survived; if anything here is unclear, ask and it will be explained or corrected.
Who is responsible
The controller of this data is Enrico Lorenzo De Vito, trading as TrustedPAI.
Address: COMPLETARE — indirizzo postale
VAT / tax number: COMPLETARE — partita IVA
Email: info@trustedpai.com
There is no data protection officer. Questions about your data are answered by the controller at the address above, and there is nobody else in between.
If you write to us
The contact form asks for your name, work email, company, role and a description of what you are trying to solve. Those details exist so that a person can read your request, judge whether this service fits it, and answer you — which is the pre-contractual step under Art. 6(1)(b), not marketing.
They are held for as long as the conversation is useful and for as long as any contract that follows requires. They are never sold, never passed to a third party for their own purposes, and never used to send you anything you did not ask for. Ask, and they are deleted.
Writing to us does not create a demo account, and creating a demo account does not put you on any list.
What the demo holds, and why
Registration stores your sign-in provider identifier, verified email, registration time and a bounded referral label (for example, LinkedIn). The demo stores run counts, selected scenario identifiers, outcomes and timestamps to provide access and enforce the free allowance.
Before your first test you are asked for your company, your role, what your work involves, what brought you here and, optionally, an estimated monthly transaction volume and a company website. These answers are used to decide whether we can help with your integration and to reply to you.
The demo asks nothing about you personally — no name, no telephone number, no address. If you later request a proposal or an engagement, the contact form asks for the name, work email and company details needed to agree and invoice a contract. That is a separate step you choose to take, and running the demo does not require it.
Sign-in uses the configured identity provider. Essential, secure session cookies support sign-in and expire after one hour. Creating an account does not subscribe you to marketing emails, and the site sets no analytics or advertising cookies.
On what legal basis
- Performance of a contract (Art. 6(1)(b)). Your sign-in identity, email and run counts exist to give you the account you asked for and to enforce the free allowance. Without them the demo cannot be provided.
- Legitimate interest (Art. 6(1)(f)). The answers about your company and your work are used to judge whether this service fits your situation and to reply to you. You can object at any time, and the account keeps working.
- Legal obligation (Art. 6(1)(c)). If an engagement follows, the invoicing records that result are kept for the period Italian law requires, regardless of anything on this page.
Where the data is
The demo is not hosted in the European Union. These are the providers involved and what each one holds:
- Render — the service itself, in the United States (Oregon). Processes every request while it is being answered.
- Neon — the PostgreSQL database, on AWS in the United States (Ohio). Holds your registration, your answers and your run records.
- Auth0, an Okta company — the sign-in. Holds your email and the credentials you registered with. TrustedPAI never sees your password.
- Cloudflare — sits in front of the API. Sees requests in transit; stores nothing of your account.
- GitHub Pages — serves the public pages, including this one. Receives the request that loaded it, and nothing more.
Transfers outside the EU rely on the standard contractual clauses these providers publish, and on their own transfer frameworks. If where the data sits matters for your situation, say so before you register: an engagement can be scoped to run in the European Union.
How long it is kept
Demo registrations and their run records are deleted automatically 180 days after registration, by the same scheduled job that applies retention to the rest of the service. Nobody has to remember to do it.
An email you send to the address above is kept as long as the conversation is useful, and deleted on request.
What you can ask for
You can ask for a copy of what is held about you, for it to be corrected, for it to be deleted, for it to be sent to you in a portable form, and you can object to the use described under legitimate interest above. Write to info@trustedpai.com and you get an answer within thirty days, usually sooner.
Deletion on request is carried out against the identity your sign-in provider proved, not against an email address — an address can be shared or guessed, while the sign-in is what was actually verified. Deleting a demo account also deletes its run records.
If you think your data has been handled wrongly you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to the authority where you live.
Automated decisions
The demo evaluates synthetic payment scenarios and returns a recommendation. Those decisions are about test data you generated, never about you, and they produce no legal or similarly significant effect on anyone. No profiling of demo visitors takes place.