Data processing agreement
A readable summary of the agreement required by article 28 of the GDPR. The signed text is delivered as an annex to the contract, in Italian, at signup.
Courtesy translation. Only the Italian version of this document has legal value: if the two texts diverge, the Italian text prevails. Italian law applies to the relationship in any case.
The roles, without ambiguity
When you use Flarseo to work on your brand, you are the controller: you decide which content to upload, which data to enter, where to publish and for what purposes.
Collaborazioni Digitali Srl acts as processor: it handles the data on your behalf, within the limits of your instructions and in order to deliver the service you subscribed to.
We remain controller for the data we collect in our own right: account, billing, technical logs and support correspondence. That part is described in the privacy notice.
Subject matter and duration
| Element | Content |
|---|---|
| Subject matter | Processing of the content and materials the customer entrusts to the platform in order to plan, generate, review and publish editorial and social content, and to build the website. |
| Duration | For the whole term of the contract, plus the limited recovery period set out in the framework agreement after it ends. |
| Nature of the operations | Collection, recording, organisation, storage, retrieval, processing through language models, transmission to the publishing systems named by the customer, erasure. |
| Categories of data subjects | Customer contacts, authors and reviewers named by the customer, individuals who may be mentioned in the materials the customer uploads. |
| Categories of data | Identification and contact data, textual and visual brand content, documents uploaded by the customer. |
The customer undertakes not to upload special categories of data under article 9 of the GDPR, nor data on criminal convictions. The platform is not designed to receive them.
Instructions of the controller
We process data only on the documented instruction of the customer. Those instructions live in the contract, in the configuration of the workspace and in the requests the customer sends through the platform.
If an instruction appears to us to conflict with the GDPR or with other applicable law, we tell the customer before carrying it out.
If Union or member state law obliges us to process differently, we inform the customer before proceeding, unless that law forbids the notice on grounds of public interest.
Confidentiality
The people authorised to access the data are identified by name, instructed on the processing, and bound by a confidentiality duty that survives the end of their employment or engagement.
Our staff access customer data only where needed: support the customer asked for, diagnosis of a fault, compliance with a legal obligation. Those accesses are logged.
We do not use customer content for our own purposes. In particular we do not use it to train general purpose models.
Security measures
We apply technical and organisational measures appropriate to the risk, under article 32 of the GDPR.
- Encryption of data in transit and at rest.
- Encryption of secrets and of the credentials for connected services.
- Access control on a least privilege basis, with strong authentication.
- Logical separation between the workspaces of different customers.
- Regular backups and tested restore procedures.
- Logging of relevant events and error monitoring.
- A documented incident handling procedure.
Subprocessors
The customer gives general authorisation to the use of subprocessors for the categories of service needed to run the platform: cloud infrastructure, language models, payments, transactional email delivery, SEO data, error monitoring.
Every subprocessor is bound by contract to data protection obligations no less strict than the ones we owe the customer. We remain fully liable to the customer for their performance.
We give reasonable advance notice of any intention to add or replace a subprocessor, so that the customer can object on documented data protection grounds.
Subprocessor categories and the notification process
Assistance to the controller
We assist the customer, with appropriate technical and organisational measures and taking account of the nature of the processing, in the duties the GDPR places on them.
- Data subject requests: if one reaches us we forward it to the customer without delay and provide the tools needed to answer.
- Security of processing: we supply the information needed to document the measures in place.
- Impact assessment: we supply the technical information we hold when the customer has to carry one out.
- Prior consultation of the authority: we cooperate with the information within our remit.
We also make available to the customer the information needed to demonstrate compliance with the obligations of article 28.
Personal data breaches
If we become aware of a personal data breach affecting data processed on behalf of the customer, we inform the customer without undue delay, as required by article 33.2 of the GDPR.
The notice states, so far as available, the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences and the measures taken or proposed.
Where not all information is available at first notice, we provide it progressively without further delay. Notification to the supervisory authority and to data subjects remains the responsibility of the customer, as controller.
Transfers outside the European Economic Area
Where processing involves a transfer to a third country, we apply one of the safeguards in chapter V of the GDPR: an adequacy decision, or the standard contractual clauses with the supplementary measures required.
Information on the safeguards applied to each category of supplier is available on request.
Deletion or return at the end
When the relationship ends the customer chooses whether to have the data returned or deleted.
Export tools stay available for the recovery period set out in the framework agreement. Once that period has passed, we delete.
Copies we are legally required to keep are excluded from deletion; they stay protected by the same security measures and are no longer used for any other purpose.
Audit and verification
The customer has the right to verify compliance with the obligations of article 28.
Verification runs first through the documentation we make available on request: description of the security measures, current list of subprocessors, information on the safeguards used for transfers.
If the documentation is not enough, the customer may request an audit on reasonable notice, during working hours, without interfering with service availability for other customers and while respecting the confidentiality we owe them. The arrangements and limits are set out in the signed agreement.
The signed text
This page is an explanatory summary. The agreement that binds the parties is the signed one, delivered as an annex to the framework agreement at signup, in Italian.
If you need a copy before subscribing, ask for it: we will send it with no commitment.
If this summary and the signed agreement diverge, the signed agreement prevails. The English, French and German versions of this page are courtesy translations.
Need the DPA before you sign?
Write to us with your company name and VAT number: we will send the full text of the agreement and the current list of subprocessors.