Regolo.ai (Seeweb S.r.l.)
Seeweb S.r.l. · IT · Last reviewed: 2026-07-27
Data Protection Contracts
83/100Regolo.ai (Seeweb S.r.l.) has a Data Processing Agreement under Art. 28 GDPR that explicitly recognizes the processor chain.
jaSource: Regolo Terms and Conditions inkl. DPA (Agreement v01.01.2026), DPA §1 – erkennt Prozessor-Kette explizit an ('as a Data Processor on behalf of third-party clients') (reviewed 2026-01-28)
Regolo processes data exclusively within the EU; third-country transfers require the customer's prior written authorization, so SCCs are generally not required.
jaSource: Regolo DPA / Terms and Conditions, §6 – EU-Unternehmen (Seeweb S.r.l., Italien); Drittlandtransfer nur mit schriftlicher Controller-Autorisierung (reviewed 2026-01-28)
Regolo's DPA specifies a 48-hour notification deadline, but a drafting error in the clause weakens its literal effect.
teilweiseSource: Regolo DPA, §8 – 48h-Frist zugesagt, jedoch mit Redaktionsfehler (Meldepflicht an Kenntnis des Controllers statt Processor gekoppelt) (reviewed 2026-01-28)
Data Residency & Sovereignty
83/100Regolo contractually guarantees EU hosting (data centers in Frosinone and Milan).
jaSource: Regolo DPA, §6 – 'Personal Data are stored on servers located within the European Union'; RZ Frosinone + Mailand (Seeweb-eigen) (reviewed 2026-01-28)
Regolo contractually requires written authorization for new sub-processors but does not publish a sub-processor list.
teilweiseSource: Regolo Terms and Conditions / DPA, §5 – neue Sub-Prozessoren nur mit schriftlicher Autorisierung + Widerspruchsrecht, jedoch keine veröffentlichte Sub-Prozessorenliste (reviewed 2026-01-28)
Regolo is operated by Seeweb S.r.l., an Italian (EU-based) company.
jaSource: Regolo Terms and Conditions, Vertragspartner Seeweb S.r.l., Italien; italienisches Recht, Gerichtsstand Mailand (reviewed 2026-01-28)
Data Use
100/100Regolo contractually does not access, store, or analyze inputs or outputs (no-access/no-store).
jaSource: Regolo DPA, §3/§4 – 'does not access, store or analyze' Inputs und Outputs (e2e-verschlüsselt, reiner Technical Transit, §3.1) (reviewed 2026-01-28)
Regolo confirms in writing that customer prompts and outputs are never used to train, fine-tune or improve any model (its own or third parties'); a formal ZDR assessment document and a signed DPA have been offered.
jaSource: Schriftl. Bestätigung Regolo (Chiara Grande, privacy-Team, 28.07.2026) + regolo.ai/zero-data-retention, Antwort Punkt 1 ('We do confirm'); signiertes DPA + ZDR-Assessment angekündigt (reviewed 2026-07-28)
No separate opt-out is required: Regolo confirms the unconditional no-training commitment in writing, backed by the contractual no-access/no-store principle (DPA §3/§4).
jaSource: Regolo DPA §3/§4 + schriftl. Bestätigung (Chiara Grande, 28.07.2026), DPA §3/§4; Antwort Punkt 1 (reviewed 2026-07-28)
Certifications
25/100Certifications such as ISO 27001 exist at the parent company Seeweb level; a contractual scope confirmation for the Regolo product itself is still pending.
teilweiseSource: Seeweb-Zertifizierungsnachweise (Website), ISO 27001/17/18 u.a. auf Seeweb-Gruppenebene vorhanden; vertragliche Zusicherung bzw. Scope-Bestätigung für das Regolo-Produkt fehlt (nur Website-Angabe) (reviewed 2026-07-24)
No verifiable commitment
unbelegtAI Act Readiness
n/aPure inference/hosting provider: the AI Act's Article 53 documentation duty falls on the provider of the GPAI model, not on whoever runs the inference. This provider cannot discharge it for third-party models; the duty sits with the respective model provider.
nicht_anwendbarSource: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)
Pure inference/hosting provider: the GPAI Code of Practice is open to providers of general-purpose AI models. A provider that merely operates third-party models is not eligible to sign, so an absent signature is not a shortcoming.
nicht_anwendbarSource: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 — Pflichten des Anbieters eines GPAI-Modells. ERGÄNZUNG 2026-08-14: Regolo entwickelt mit 'Brick' ein EIGENES Modell (Open Source, github.com/regolo-ai/brick-SR1, arXiv-Veröffentlichung 06/2026); der Komplexitätsklassifikator basiert auf Qwen3.5-0.8B mit LoRA-Adapter. Regolo ist damit nicht ausschliesslich Inferenzanbieter. Am Ergebnis ändert das nichts: Ein 0,8-Mrd.-Parameter-Klassifikator, der drei Schwierigkeitsstufen ausgibt, ist kein Modell mit allgemeinem Verwendungszweck nach Art. 3 Nr. 63 (keine erhebliche allgemeine Verwendbarkeit, kein breites Aufgabenspektrum). Art. 53 bleibt nicht einschlägig, die Signaturberechtigung besteht weiterhin nicht. (reviewed 2026-08-04)
Contract Quality & Transparency
33/100Regolo's contract documents (including the DPA) are publicly available, with access via self-service signup.
jaSource: Regolo Terms and Conditions (regolo.ai/terms-and-conditions), Agreement v01.01.2026 inkl. DPA öffentlich abrufbar; Self-Service-Signup (PayPal prepaid) (reviewed 2026-01-28)
Regolo does not offer a contractual SLA for standard plans; an SLA is only available under custom enterprise agreements.
neinSource: Regolo FAQ ZDR und SLA (2026-07-25), Standard-Tarife ohne vertragliches SLA; SLA nur für Enterprise-Custom-Verträge verfügbar (reviewed 2026-07-25)
Regolo's liability is contractually capped at one month's fee – a very low cap compared to market standards.
neinSource: Regolo Terms and Conditions, §8.2 – Haftungsdeckel auf eine Monatsgebühr begrenzt (nur Vorsatz/grobe Fahrlässigkeit ausgenommen) (reviewed 2026-01-28)
Do you represent Regolo.ai (Seeweb S.r.l.) and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.
Report error