Data Processing Agreement
Agreement for the processing of personal data under Art. 28 GDPR, between the data Controller (DPO Workspace user) and the data Processor (Studio Cravero Consulting).
Version 1.0 - in force from 14 maggio 2026
1.Parties
This DPA is entered into between:
- "Controller": the User registered on the DPO Workspace platform, identified through their account and billing data. The Controller is the party that determines the purposes and means of processing the personal data uploaded to their workspace.
- "Processor": Studio Cravero Consulting, VAT IT03059830905, based in Sassari (SS), certified email info.studiocravero@pec.it, as operator of the DPO Workspace platform.
Note on roles: where the User is an external DPO or privacy consultant acting on behalf of their own End Client, the User is normally the "Processor" towards the actual controller (End Client). In such cases Studio Cravero Consulting takes on the role of sub-processor, and this DPA applies with the appropriate role adjustments. The User warrants that they have obtained written authorisation from their End Client Controller to appoint Studio Cravero as sub-processor.
2.Subject matter and duration of processing
The Processor processes personal data on behalf of the Controller solely to provide the DPO Workspace platform services, as described in the Terms of Service.
Duration: this DPA is effective for the entire duration of the contractual relationship between the parties, and extends for the time needed to return or delete the data at the end of the relationship.
3.Nature and purpose of processing
Processing takes place by electronic means, on cloud infrastructure, for the following purposes:
- Storage of documents uploaded by the Controller, classified by GDPR regulatory area;
- Storage of the Controller's End Client records and related compliance activities;
- Management of document deadlines, alerts and notifications;
- Collection of privacy-relevant event reports through public links generated by the Controller for their End Clients;
- Execution of structured event-handling workflows;
- Recording of an append-only audit trail of the Controller's and its collaborators' activities;
- Generation of reports and document exports at the Controller's request;
- Optional OCR of uploaded documents (if the Controller has subscribed to a Pro or Studio plan).
4.Categories of data subjects
The personal data processed may concern the following categories of data subjects:
- Legal representatives and operational contacts of the Controller's client companies;
- Employees, collaborators and professionals of the Controller's client companies, appointed as authorised persons;
- Data subjects exercising rights under Art. 15-22 GDPR with the Controller or its clients;
- Individuals involved in data breach events reported by the Controller or its clients;
- Suppliers and processors of the Controller's clients;
- People completing the public event-reporting form (privacy/HR/compliance contacts of the Controller's End Clients).
5.Types of personal data processed
The personal data processed may include:
- Identity data: first name, last name, role, professional qualification;
- Contact data: email address, phone, postal address;
- Company data: company name, VAT number, tax code, sector, registered office;
- GDPR documentation: contents of uploaded documents (notices, appointments, Art. 28 contracts, DPIAs, Art. 30 registers, etc.) that may contain third-party personal data;
- Breach-related data: descriptions and history of reported and handled data breaches;
- Data subject request data: content and history of requests under Art. 15-22 GDPR;
Special categories of data (Art. 9 GDPR): the Platform may contain, under the Controller's sole responsibility, data concerning health, sexual orientation, political, religious or trade-union opinions, biometric and genetic data. The Controller is responsible for having a suitable legal basis for such processing and for not uploading such data where this exceeds their operational powers.
Data relating to convictions and offences (Art. 10 GDPR): uploading such data is limited to cases permitted by applicable law and under the Controller's sole responsibility.
6.Obligations of the Processor
The Processor, pursuant to Art. 28(3) GDPR, undertakes to:
- Lawfulness of processing: process data only on the Controller's documented instructions (acceptance of these Terms and of the DPA constitutes a general instruction), including for non-EU transfers, save for legal obligations to which the Processor is subject;
- Confidentiality: ensure that persons authorised to process (employees, collaborators) have committed to confidentiality or are under an appropriate statutory confidentiality obligation;
- Security measures: adopt all technical and organisational measures required by Art. 32 GDPR, detailed in Annex A "Technical and organisational measures";
- Sub-processors: not engage further sub-processors without the Controller's prior (general or specific) authorisation. The Controller authorises the list published at /sub-processors, with a right to object within 30 days of notice of new sub-processors;
- Assistance to the Controller: assist the Controller with appropriate technical and organisational measures to meet the obligation to respond to data subject requests (Art. 15-22) and the Controller's other obligations;
- Breach notification: notify the Controller of any personal data breach it becomes aware of, without undue delay and in any case within 48 hours of discovery, providing all information required under Art. 33;
- DPIA: assist the Controller in carrying out impact assessments (DPIAs) where necessary, providing relevant technical information about its systems;
- Return/deletion: at the end of the service, at the Controller's choice, return or delete the personal data, save for statutory retention obligations. See Section 11;
- Audit: make available to the Controller all information needed to demonstrate compliance and allow audits, including by third parties appointed by the Controller, with reasonable notice (at least 14 days) and arrangements to be agreed to reduce operational impact.
7.Obligations of the Controller
The Controller undertakes to:
- Process personal data in compliance with the GDPR and applicable law, ensuring the lawfulness of the purposes for which it uploads data to the Platform;
- Provide data subjects with the privacy notices required under Art. 13-14 GDPR, including where relevant the presence of the Processor and its sub-processors;
- Obtain the appropriate legal bases (consent, contract, legal obligation, legitimate interest) before uploading data;
- Not upload personal data exceeding the purposes (minimisation principle);
- Correctly configure the permissions of its workspace (collaborator users, roles);
- Safeguard credentials and revoke access that is no longer needed;
- Hold a mandate and contractual authorisation to manage its End Clients' data via the Platform, and to appoint Studio Cravero as sub-processor;
- Immediately notify the Processor of any security compromise of its accounts.
8.Authorised sub-processors
The Controller generally authorises the Processor to use the sub-processors listed on the public page /sub-processors to deliver the service. The main ones are:
- Google Ireland Limited (Google Cloud / Firebase services) - hosting, authentication, database, storage. Location: Dublin, Ireland. Data region: europe-west1 (Belgium).
- Stripe Payments Europe Ltd - payment processing. Location: Dublin, Ireland. PCI-DSS Level 1 certification.
- Sendinblue SAS (Brevo) - transactional email sending. Location: Paris, France.
- Cloudflare Inc. - DNS, CDN and DDoS protection. Main location: USA. Non-EU transfer with SCC.
The Processor will give the Controller prior notice of the addition or replacement of sub-processors, with at least 30 days' notice. The Controller has the right to object to the change, giving rise to termination of the contract without penalty.
9.Non-EU transfers
Data is physically stored in europe-west1 (Belgium) at Google Cloud data centres. Any transfers to third countries take place exclusively:
- To countries covered by a European Commission adequacy decision under Art. 45 GDPR;
- On the basis of Standard Contractual Clauses (SCC) approved by the EU Commission under Art. 46 GDPR (EU Decision 2021/914);
- With appropriate supplementary measures (Transfer Impact Assessment) in line with the Schrems II ruling (CJEU C-311/18).
In particular, the use of Cloudflare services (DNS/CDN) involves non-EU transfers covered by SCC and TIA. Documentation available on request.
10.Security measures (see Annex A)
The technical and organisational measures adopted by the Processor are described in Annex A "Technical and organisational measures", available at /security, an integral part of this DPA. The main ones include:
- Encryption at rest (AES-256) and in transit (TLS 1.3);
- User authentication with password hashing and Google OAuth support;
- Database access rules (Firestore Security Rules) for workspace separation;
- Append-only audit trail of every relevant action;
- Cryptographic public access tokens (32 URL-safe characters, ~191 bits entropy);
- Daily automatic backups and versioning;
- Data breach management procedures with notification to the Controller within 48 hours;
- Restriction of internal access to the need-to-know principle;
- Periodic security testing.
11.Retention, return and deletion of data
On termination of the contractual relationship, the Processor:
- Keeps the data accessible for 90 days for export by the Controller;
- On the Controller's request, provides a full export of the data in structured format (CSV/JSON) and of uploaded documents (zip);
- After 90 days from termination, permanently deletes the data from production systems;
- Deletes the data from backup systems within 12 months of termination, according to backup rotation cycles;
- Retains only data whose retention is required by legal obligations (invoices, accounting data: 10 years; security logs: 5 years);
- Provides, on written request, a certificate of deletion.
12.Cooperation with supervisory authorities
The Processor will cooperate, on reasoned request, with the Italian Data Protection Authority and other competent EU supervisory authorities, providing all information needed to exercise their functions.
The Processor will promptly inform the Controller of any formal requests received from supervisory authorities concerning the Controller's data, unless the law prohibits such communication.
13.Limitation of liability
The limitations of liability set out in the Terms of Service also apply to this DPA, without prejudice to mandatory data protection rules.
Each party is responsible for its own breaches of GDPR and DPA obligations. In particular, the Processor is not liable for breaches resulting from the Controller's failure to comply with its obligations (Section 7).
13-bis.Business continuity and emergency channel
The Controller (DPO User) acknowledges and accepts that the DPO Workspace Platform is a supporting operational tool and not a certified notification system. In particular:
- The 'Event reporting link' channel does not replace the formal notifications under Art. 33 and 34 GDPR, which remain the Controller's responsibility;
- The Processor does not guarantee instant push notifications to the DPO about incoming reports;
- In case of Platform unavailability (force majeure events, maintenance, sub-processor malfunctions), the Controller remains solely responsible for GDPR obligations;
- The Controller undertakes to maintain business continuity procedures independent of Platform availability for short-deadline obligations (72h breach notification, data subject responses);
- The Controller undertakes to inform its End Clients, in writing, of the existence of alternative DPO communication channels for urgent events;
- The Controller will maintain its own internal breach register independent of the Platform, pursuant to Art. 33(5) GDPR.
Emergency procedure in case of disruption: where the Platform is unavailable and critical GDPR deadlines are running (e.g. the 72h breach notification deadline), the Controller must:
- Proceed with notification to the supervisory authority anyway via the official portal https://servizi.gpdp.it/databreach/s/;
- Make any communications to data subjects using the fastest channels available (certified email, email, registered post, public communication);
- Document the event and the actions taken in an internal paper register or other system, to be entered on the Platform when the service is restored;
- Notify the Processor (info@studiocravero.eu) of the disruption found if not already reported, for SLA documentation.
The Processor will maintain an emergency communication channel (email info@studiocravero.eu and certified email info.studiocravero@pec.it) for critical disruptions, with a target response time of 4 working hours.
14.Changes to the DPA
This DPA may be amended for regulatory alignment (new EDPB decisions, CJEU rulings, GDPR changes) or service developments. Substantial changes are communicated by email with at least 30 days' notice. The Controller may terminate the contract if it does not accept the changes.
15.Final provisions
This DPA is an integral part of the DPO Workspace Terms of Service and is interpreted together with them.
In case of conflict between this DPA and other contractual clauses, the provisions of this DPA prevail as regards the processing of personal data.
To obtain a digitally signed copy of this DPA, contact info@studiocravero.eu or certified email info.studiocravero@pec.it.
Annex B - Sub-processor list: see page /sub-processors.