DATA PROCESSING AGREEMENT
Personal Data Processing Agreement (Article 28 GDPR)
BETWEEN THE PARTIES
This Data Processing Agreement ("DPA") is entered into between:
The party that electronically signs this DPA upon confirmation of the order for Invoicetronic services (the "Controller"), whose identifying data (company name, registered office, and VAT/tax code) are those resulting from the order form and the related order confirmation, which form an integral and substantial part of this DPA;
and
CIR 2000 snc, with registered office at via Trieste 90/A, 48122 Ravenna (RA), Italy, VAT number IT01180680397 (the "Processor").
The Controller and the Processor are hereinafter jointly referred to as the "Parties" and individually as a "Party".
RECITALS
- The Controller uses the services of the Invoicetronic platform to transmit and receive electronic invoices through the Exchange System (SdI).
- Within the scope of that service, the Processor processes personal data on behalf of the Controller.
- The Parties intend to govern such processing pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").
- This DPA supplements and forms an inseparable part of the service contract between the Parties (the "Terms of Service").
1. DEFINITIONS
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meaning attributed to them by Article 4 of the GDPR. In the event of a conflict between this DPA and the Terms of Service on matters of data protection, this DPA shall prevail.
2. SUBJECT MATTER, NATURE, AND PURPOSE OF THE PROCESSING
The Processor processes personal data solely for the purpose of providing the services of transmission, receipt, validation, technical storage, and notification of electronic invoices through the SdI, in accordance with the documented instructions of the Controller. The details of the processing are specified in Annex A.
3. DURATION
This DPA takes effect from the date of its electronic acceptance, concurrent with the confirmation of the order for Invoicetronic services, and remains in force for the entire duration of the processing of personal data carried out by the Processor on behalf of the Controller, i.e., for the entire duration of the Terms of Service.
4. OBLIGATIONS OF THE PROCESSOR
The Processor undertakes to:
- process personal data only on documented instructions from the Controller, including in the case of transfers to third countries, unless required to do so by law, in which case the Processor shall inform the Controller before processing;
- ensure that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement all security measures required by Article 32 of the GDPR (see Annex B);
- comply with the conditions for engaging another processor (sub-processor) referred to in Article 5 of this DPA;
- assist the Controller, taking into account the nature of the processing, by appropriate technical and organizational measures, in responding to requests to exercise data subjects' rights (Articles 12–23 GDPR);
- assist the Controller in ensuring compliance with the obligations under Articles 32–36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the information available to the Processor;
- at the choice of the Controller, delete or return all personal data at the end of the provision of the services, and delete existing copies unless retention is required by law;
- make available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow for audits and inspections pursuant to Article 7 of this DPA;
- immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
5. SUB-PROCESSORS
The Controller authorizes the Processor to engage the sub-processors listed in Annex C. The Processor shall inform the Controller of any changes concerning the addition or replacement of sub-processors with 10 days' prior notice, giving the Controller the opportunity to object. The Processor imposes on each sub-processor, by contract, the same data protection obligations set out in this DPA ("flow-down") and remains fully liable to the Controller for the sub-processor's performance.
6. TRANSFERS TO THIRD COUNTRIES
All data remains within countries belonging to the EU.
7. PERSONAL DATA BREACH
The Processor shall notify the Controller, without undue delay and in any event within 24 working hours of becoming aware, of any personal data breach, providing the information necessary for the Controller to fulfill its notification obligations under Articles 33 and 34 GDPR.
8. LIABILITY AND MISCELLANEOUS
The liability of the Parties is governed by Article 82 GDPR and by the Terms of Service. This DPA is governed by Italian law and any dispute shall be referred to the court of Ravenna. Amendments to this DPA must be made in writing.
ANNEX A — DETAILS OF THE PROCESSING
Categories of data subjects Customers and suppliers of the Controller, their representatives, and third parties indicated in the invoices.
Types of personal data Identification and contact data (company name, first name, last name), VAT number/tax code, address, and data contained in the invoices.
Nature of the processing Transmission, receipt, validation, temporary technical storage, and notification of electronic invoices through the SdI.
Purpose Provision of the electronic invoicing service requested by the Controller.
Retention period In accordance with the retention policy described in the documentation: a maximum of 2 years in the live environment for invoices; a maximum of 15 days for invoices in the Sandbox environment.
ANNEX B — TECHNICAL AND ORGANIZATIONAL MEASURES (ARTICLE 32)
Technical and organizational measures actually implemented by the Processor:
Encryption
- Encryption of data at rest (invoice payloads are encrypted in storage) using the AES-256 algorithm. Encryption keys are generated and managed internally by the Processor, stored in a protected configuration file, with access restricted to platform administrators.
- Encryption of data in transit via TLS, minimum version 1.3.
Access control
- Authentication via API key. Access to data is restricted to platform administrators. Credential rotation is at the customer's discretion and is not mandatory. Multi-factor authentication (MFA) for administrative access is not currently provided.
Resilience and continuity
- Point-in-time backups, retained for 5 days. A disaster recovery plan is in place.
Logging and monitoring
- Logging of API operations, with event logs retained for 7 days.
Incident management
- Incident management is handled by the platform administration team. A written incident response procedure is not currently formalized; notification to the Controller under the terms of Article 7 of this DPA remains in place.
Personnel and development security
- Personnel who process the data are bound by confidentiality obligations. Secure development practices are adopted, including code review and active vulnerability management.
ANNEX C — LIST OF SUB-PROCESSORS
| Sub-processor | Service provided | Processing location | Safeguards (if extra-EU) |
|---|---|---|---|
| OVH SRL | Infrastructure, mail, and backup | EU | — |
| Hetzner Online GmbH | Backup | EU | — |