Last updated: 8 September 2026

How this document is used. The DPA is an integral part of the Terms of Service (art. 8) and is signed by the Customer when subscribing to the Service, before activation. The Customer is the Controller of the data it enters into the CRM; Data Driven Solutions S.r.l. is the Processor.

1. Parties and definitions

This Agreement is entered into between:

The terms “personal data”, “processing”, “data subject”, “personal data breach”, “controller”, “processor” and “sub-processor” have the meaning given to them by art. 4 of Regulation (EU) 2016/679 (the “GDPR”). “Service” means the Regya platform and the modules activated by the Controller.

2. Subject matter and duration

This Agreement governs the processing of personal data that the Processor carries out on behalf of the Controller in the provision of the Service. The Agreement takes effect on the date the Service is activated and remains in force for the whole duration of the subscription contract, as well as for the subsequent period needed to return or delete the data under art. 12.

The details of the processing (nature, purposes, types of data, categories of data subjects) are described in Annex A.

3. Documented instructions

The Processor processes personal data only on documented instructions from the Controller. The subscription contract, the Terms of Service, this Agreement and the configurations set by the Controller within the Service constitute documented instructions.

The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions. The Processor does not process the data for its own purposes and, in particular, does not use the Controller’s data to train artificial intelligence models.

4. Obligations of the Controller

The Controller warrants that it has collected the personal data entered into the Service on a suitable legal basis, that it has provided data subjects with the information required by arts. 13 and 14 GDPR and that it is entitled to disclose the data to the Processor for the purposes of the Service. The Controller is responsible for the accuracy and lawfulness of the data uploaded, imported or generated within its own instance.

5. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they receive adequate instructions and training. Access to the Controller’s data is limited to staff who actually need it to provide the Service and support.

6. Security measures

The Processor implements appropriate technical and organisational measures pursuant to art. 32 GDPR, described in Annex B. The Processor may update such measures over time, provided that the level of security is not reduced.

7. Sub-processors

The Controller gives the Processor general authorisation to engage the sub-processors listed in Annex C. The Processor informs the Controller, with at least 30 days’ notice by email, of any intended change concerning the addition or replacement of sub-processors; within that period the Controller may object on reasonable and documented grounds. If the objection cannot be resolved, either party may terminate the subscription contract without penalty.

The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those of this Agreement and remains fully liable to the Controller for the performance of the sub-processor’s obligations.

8. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures:

The Service provides the Controller with search, export, rectification and deletion functions that allow most data subject requests to be handled independently.

9. Personal data breaches

The Processor informs the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach concerning the data processed on behalf of the Controller, providing the available information on the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. It is for the Controller to assess notification to the supervisory authority and to data subjects.

10. Data location and transfers outside the EU

The Controller’s data is hosted on servers located in the European Union. The Processor does not transfer personal data to third countries unless necessary to provide features expressly activated by the Controller (for example payment, messaging or artificial intelligence services). In that case the transfer takes place on the basis of an adequacy decision of the European Commission or of Standard Contractual Clauses (SCC) supplemented by additional measures, as indicated in Annex C.

11. Audits and inspections

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or by another auditor mandated by the Controller. Audits are agreed with at least 30 days’ notice, take place during business hours, no more than once a year except in the event of established breaches or a request from an authority, and must not compromise the security of other customers. Costs exceeding the provision of standard documentation are borne by the Controller.

12. Deletion or return of data

Upon termination of the Service, for any reason, the Controller may export its data in the formats made available by the platform. 30 days after termination, the Processor deletes the instance and the related backups, unless otherwise requested in writing by the Controller or unless retention is required by Union or Member State law. On request, the Processor issues a certificate of deletion.

13. Liability, amendments and governing law

The liability of the parties is governed by art. 82 GDPR and, insofar as compatible, by the limits set out in the Terms of Service. This Agreement may be updated by the Processor with at least 30 days’ notice by email, to adapt it to regulatory changes or to the evolution of the Service. The Agreement is governed by Italian law; the Court of Bologna has exclusive jurisdiction over any dispute.

Signature

In the self-service Service the Agreement is signed by the Customer through the specific acceptance at the time of registration on regya.it; the date, time and IP address of the acceptance are recorded by the Processor and associated with the subscription contract. For contracts concluded outside the website, the Agreement is signed by the parties at the foot of the subscription contract.

Annex A — Details of the processing

Element Description
Subject matter Provision of the Regya CRM platform and of the modules activated by the Controller (management of contacts, deals, quotes, invoices, Regya Care ticketing, artificial intelligence features).
Nature of the processing Collection, recording, organisation, structuring, storage, consultation, use, retrieval, disclosure by transmission, erasure and destruction, by electronic means.
Purposes Enabling the Controller to manage its business relationships and its sales, administrative and support processes, according to the configurations it sets.
Duration For the whole duration of the subscription contract, plus the subsequent retention period provided for in art. 12.
Categories of data subjects Customers and prospective customers of the Controller, suppliers, partners, employees and collaborators of the Controller, users of the Service authorised by the Controller.
Types of personal data Identification and contact data (first name, last name, role, company, email, phone, address); data relating to the business relationship (deals, offers, orders, quotes, invoices, overdue payments); content of communications and notes; recordings and transcripts of voice notes, if the Voice module is activated; access data and usage logs.
Special categories of data The Service is not designed for the processing of special categories of data (art. 9 GDPR) or of data relating to criminal convictions and offences (art. 10 GDPR). Any entry of such data takes place under the sole responsibility of the Controller, which must first verify the legal basis and inform the Processor.

Annex B — Technical and organisational measures

Area Measures
Segregation Dedicated CRM instance for each Customer, with separation of data and credentials from other customers.
Location Servers and backups hosted in data centres located in the European Union.
Encryption Traffic encrypted in transit via TLS; encryption of storage media at rest according to the infrastructure provider’s measures.
Access control Individual user authentication, role-based profiles and permissions, least-privilege principle, administrative access limited to authorised technical staff.
Backup and continuity Periodic backups of the instance and databases, with restore verification; documented restore procedures.
Updates Maintenance and security updates of the platform and its components, with work announced in advance where possible.
Logging Access and administrative activity logs, kept for the time needed for security purposes: web server logs 30 days, history of logins and actions in the instance 13 months.
Organisation Confidentiality commitment of authorised staff and collaborators; operating instructions on processing; sub-processor appointment contracts with suppliers.
Incident management Internal procedure for detecting, assessing and communicating personal data breaches pursuant to art. 9 of this Agreement.

Annex C — Authorised sub-processors

Sub-processor Activity Location Basis for transfer
Proweb di Michele Tugnoli, Medicina (BO), Italy — technical partner Development, maintenance and technical support of the Regya instances Italy Not applicable (EU)
Hetzner Online GmbH, Gunzenhausen, Germany Hosting of instances, databases and local backups (Falkenstein data centre, Germany) European Union Not applicable (EU)
Cloudflare, Inc., San Francisco, United States Content delivery network, DNS and protection of web traffic to the instances and the website EU / United States EU-US Data Privacy Framework and Standard Contractual Clauses
Stripe Payments Europe, Ltd., Dublin, Ireland Management of recurring payments and subscription billing data EU / United States Standard Contractual Clauses and supplementary measures
Qboxmail S.r.l., Italy Sending of service and support communications (email) European Union Not applicable (EU)
Google Ireland Ltd., Dublin, Ireland (Google Drive) Storage of a daily backup copy of the instances, automatically deleted after 21 days EU / United States EU-US Data Privacy Framework and Standard Contractual Clauses
OpenAI Ireland Ltd. / OpenAI, L.L.C., United States Transcription of voice notes and analysis and suggestion features (Regya AI), if the modules are activated by the Controller EU / United States Standard Contractual Clauses; no use of the data for model training (API with contractual opt-out)
Meta Platforms Ireland Ltd., Dublin, Ireland (WhatsApp Business Platform) WhatsApp messaging integration, if activated by the Controller EU / United States EU-US Data Privacy Framework and Standard Contractual Clauses

This is an English translation provided for convenience. In the event of any discrepancy, the Italian version prevails.