Skip to content

Data Processing Agreement (DPA)

Version 1 — in force since Sep 10, 2026

Courtesy translation: in case of divergence the Italian text prevails. Read the Italian version

(Art. 28 GDPR)

4.1 Who is who

When a studio uploads its own clients' data into Registro — names, addresses, phone numbers, photographs of the cards, correspondence — the controller is the studio. We process that data only on behalf of the studio, as processor.

This means something concrete: we decide nothing about that data. We do not use it for our own purposes, we do not analyse it, we do not use it to train automated systems, and we do not show it to other studios.

4.2 What we process, for whom, and for how long

  • Subject matter: provision of the Registro service.
  • Duration: as long as the contract lasts, plus the 30-day recovery period.
  • Nature and purpose: storage, organisation, consultation, production of documents, sending communications to the studio's clients on its behalf.
  • Types of data: identification and contact data, photographs of objects (the cards), financial content (quotes, payments), correspondence.
  • Data subjects: the studio's clients, and the collaborators the studio adds.
  • Special categories: not envisaged. The studio undertakes not to upload any.

4.3 Our obligations

We process the data only on documented instructions from the studio, which coincide with the normal use of the product's features. We bind those who have access to it to confidentiality. We apply the security measures described in section 2.6.

Assistance to the studio. If one of the studio's clients exercises their rights, we make tools available to the studio to respond: full export of a single client and erasure of their data, photographs included.

Breaches. If we become aware of a breach we notify the studio without undue delay, with what we know, because it is the studio that must notify the supervisory authority. We do not notify on its behalf.

4.4 Sub-processors

The studio authorises the use of the providers listed in section 2.4, under the same protection conditions. If we change or add a provider we give at least 30 days' notice, and the studio may object; in the event of objection it may withdraw without penalty, because we cannot provide the service without infrastructure.

4.5 At the end of the relationship

On termination, and in any case within the 30 days of section 1.8, we delete all personal data processed on behalf of the studio, except what the law requires us to retain. Before deletion the studio can export everything.

4.6 Audits

The studio may ask us for the information needed to demonstrate compliance with Article 28, and agree an audit with reasonable notice, at its own expense and without compromising the confidentiality of other studios.

Back to the home page