Data Processing Agreement
This agreement governs how we handle personal data on your behalf when you use the ELECTE platform. It forms part of the contract under which we provide the platform to you (the "Agreement") and, for personal data, it takes precedence over anything in the Agreement that says otherwise.
It is written to satisfy Article 28 of the GDPR. Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority carry the meanings the GDPR gives them.
This DPA applies to every platform customer. For self-serve customers it is incorporated by reference into the terms accepted at sign-up and takes effect without a separate signature. Enterprise customers can have it counter-signed as part of a master services agreement. A signed copy is available from privacy@electe.net.
Who we are, and who does what
We are ELECTE S.R.L., an Italian company with its registered office at Via Montenapoleone 8, 20121 Milano (MI), Italy. VAT number IT 12771670960. Milan Companies Register, REA MI-2682918. Share capital €211,000.00, fully paid. Our supervisory authority is the Garante per la protezione dei dati personali.
You are the controller of the personal data you put into the platform. You decide why it is processed and how. We are the processor: we act on your instructions and for no purpose of our own.
If you are yourself a processor acting for another organisation, then we are a sub-processor. Everywhere this agreement says "your instructions", read it as the instructions you have passed down from your own controller, and you confirm that you have the authority to pass them down.
We are established in the EU and we process your data in the EU. Your data does not need a transfer mechanism to reach us. The transfers that need one go out from us to service providers outside the EEA, and are dealt with under "Where your data is processed" below.
What this agreement covers
The ELECTE platform at platform.electe.net, and the personal data you and your users put into it.
It does not cover our public website, newsletter or other properties. There we are the controller in our own right and our privacy policy applies. Nothing in our privacy policy reduces what we owe you here.
Definitions
Customer data is anything you or your users submit to, store in, or generate through the platform. Where customer data identifies a person, it is personal data and this agreement applies to it.
Sub-processor is any third party we engage to process customer data in the course of running the platform.
EEA is the European Economic Area. Where this agreement gives the EEA a status, the United Kingdom and Switzerland have the same status unless we say otherwise.
The processing we carry out for you
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex A, which is part of this agreement.
We process customer data for as long as you hold an account, in order to run the platform for you and to meet our obligations under the Agreement. We do not process it for any other purpose.
We will not sell customer data, share it for advertising, or use it to build products or profiles of our own.
Your instructions
We process personal data only on your documented instructions, including on transfers of personal data to a country outside the EEA, unless EU or Italian law requires otherwise. If a law requires us to process without your instruction, we will tell you before we do it, unless that law forbids us from telling you.
Your instructions are: this agreement, the Agreement, your order form, your configuration of the platform, and any further written instruction you give us that is consistent with the Agreement.
If you ask for something outside the scope of the platform, or something that would require us to change the platform or do work the Agreement does not cover, we will agree it with you in writing first. We may charge for it.
If we think an instruction from you breaks the GDPR or another EU or member-state data protection law, we will tell you. We may pause the part of the processing the instruction concerns until we have resolved it with you.
What you are responsible for
You are responsible for having a lawful basis for the processing you instruct us to carry out, and for giving your users the information the GDPR requires them to have — Articles 12 to 14, and consents where consent is the basis you rely on.
You are responsible for how you use the platform: for the security of the credentials, systems and devices your people use to reach it, for the access rights you grant inside it, and for deciding what you put into it.
The platform is not built for special category data, so do not put it in. That means the categories in Articles 9 and 10 of the GDPR — health data, biometric data used to identify someone, data about racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, and criminal convictions or offences — as well as government identification numbers, payment card data, financial account credentials, and credentials for third-party accounts other than those created to use the platform. If you need to process any of it in the platform, ask us first and we will agree in writing what additional measures apply.
You have satisfied yourself that the platform and the measures in Annex B are appropriate to the risk of the processing you instruct. Tell us if that stops being true.
Confidentiality
Everyone we authorise to access customer data is bound in writing to keep it confidential before access is granted, and that obligation continues after they stop working with us. Access to production systems is limited to the people who operate them.
Confidentiality is one of the general principles of our Ethical Code, signed on 12 June 2024, which forms part of our organisational and control model under Italian Legislative Decree 231/01.
Security
We keep technical and organisational measures appropriate to the risk, as Article 32 requires. They are described in Annex B.
We hold no security certification or attestation today. Our status is SOC 2 Type II (audit in progress).
We do not own or run physical infrastructure. Physical security, environmental controls and hardware disposal are inherited from the providers whose data centres we use, and we hold them to those controls contractually.
We may change the measures in Annex B as the platform changes, provided the overall level of protection does not go down.
Sub-processors
You give us general authorisation to engage sub-processors, on the terms in this section.
What we require of them. Before a sub-processor receives customer data we put a written contract in place that imposes data protection obligations at least as protective as the ones in this agreement, so far as they are relevant to what that sub-processor does. We remain responsible to you for their performance, and we are liable for their acts and omissions as if they were our own.
Changes. We give at least 30 days' written notice, by email to the contact you nominate, before a new sub-processor begins processing or an existing one is replaced.
Your right to object. You may object within that period on reasonable data protection grounds. Tell us in writing and we will work with you to find a way forward — a different provider, a different configuration, or a way of running the service that keeps your data out of that provider's hands. If we cannot find one within a reasonable time, you may terminate the affected part of the Agreement, without penalty, on written notice. You pay for what you have used up to that date.
The current list of sub-processors, with the role and country of establishment of each, is available on request to privacy@electe.net, including before you sign.
Helping you answer your users
If one of your users asks us directly to exercise a right — access, correction, erasure, restriction, portability, objection — we will not answer on your behalf. We will tell you promptly, unless the law forbids it, and point the person back to you.
Taking into account the nature of the processing, we will help you meet those requests: through the functions built into the platform where they exist, and by acting on your written request where they do not. If a request requires work well beyond what the platform does, we will tell you what it involves and what it costs before we start.
Helping you with impact assessments and regulators
Taking into account the nature of the processing and what we know, we will give you reasonable help with data protection impact assessments and prior consultations with a supervisory authority under Articles 35 and 36, and with your obligations under Articles 32 to 36 generally. In practice this means answering your questions about how the platform processes data, in writing, within a reasonable time. For anything more involved, we will agree the scope and cost with you first.
Personal data breaches
If we become aware of a personal data breach affecting customer data, we will tell you within 72 hours of becoming aware of it.
Our notice will describe what we know at the time: what happened, which categories of data and roughly how many records are involved so far as we can tell, the likely consequences, what we have done and what we recommend you do. We do not hold it back waiting for a complete picture, and we will keep you updated as we learn more. Sending a notice is not an admission of fault.
You are responsible for deciding whether the breach must be reported to a supervisory authority or to the people affected, and for making those reports. If a report of yours names us or identifies us indirectly, tell us before you send it where you lawfully can, and give us a chance to correct anything about our own involvement. We will not delay your reporting deadline.
Failed login attempts, port scans, blocked traffic and other unsuccessful attempts that do not compromise personal data are not breaches and we will not notify them as such.
Deletion and return
When the Agreement ends, or when we otherwise stop providing the part of the platform that involves processing your personal data, we stop processing customer data for any purpose other than storing it and returning or deleting it.
You have 30 days from termination to export your data or ask us, in writing, to return it. If you ask for return, we provide it by a secure method in a commonly used machine-readable format, and then delete our copies. If you do not tell us what you want, we delete it.
After that window we delete it from live systems within 90 days. Deleted data persists in off-site backups for up to 30 further days on the rolling rotation, where it is not processed for any purpose and is overwritten in turn. We will confirm deletion in writing on request.
Financial and tax records are the exception: Italian law (Codice Civile art. 2220) requires us to keep them for 10 years, and no instruction can override that. We keep personal data past those points only where EU or Italian law requires it, for no longer than that law requires, protected the same way and processed only for the purpose the law specifies.
Audit and information rights
What we will do, without limit and at no charge: answer your security questionnaire, give you a written summary of our sixteen security policies, describe the design of any specific control you ask about, and give you the information you need to demonstrate our compliance under Article 28(3)(h).
When the SOC 2 Type II report is issued, we will make it available to you under a confidentiality agreement. Where the controls you want to examine are covered by that report and we confirm there has been no material change since it was issued, you agree to accept it in place of a separate audit of those controls.
Audits. Once in any twelve-month period — and additionally where a supervisory authority with jurisdiction over you requires it, or where we have notified you of a breach affecting your data — you or an auditor you appoint may audit our compliance with this agreement. Audits are remote: we operate no data centre for an inspection to visit. Give us at least four weeks' notice and an audit plan setting out scope, method and duration. Your auditor must not be a competitor of ours and must sign a confidentiality agreement. We may withhold information that would breach a duty of confidentiality we owe someone else, or that would itself weaken our security.
Audits are at your cost, including our reasonable time at our then-current rates. Tell us promptly about anything you find, and give us a copy of the report.
Where your data is processed, and transfers out of the EEA
The platform and its database run on servers in Nuremberg, Germany. Off-site backups are held in Milan, Italy. Both are in the EU.
Because we are established in Italy, sending us personal data is not a restricted transfer for a customer in the EEA. It is not one for a customer in the United Kingdom or Switzerland either: both recognise the EU as providing an adequate level of protection. If you are established outside those regions, your transfer to us is a transfer into the EU, which Chapter V does not restrict.
The transfers that need a safeguard are ours: the ones going out from us to service providers established outside the EEA. Where such a transfer happens, we put a valid Chapter V transfer mechanism in place before customer data moves, we carry out the assessment that mechanism requires, and we tell you which mechanism applies when you ask.
The mechanism is the European Commission's standard contractual clauses. As an EU processor exporting to a sub-processor, Module 3 (processor to processor) applies; Module 2 applies where we export as controller. The UK Addendum covers transfers out of the United Kingdom and the Swiss amendments cover transfers out of Switzerland. Where a recipient is certified under the EU–US Data Privacy Framework we rely on that certification in addition to the clauses. A copy of the safeguards is available on request.
If a mechanism we rely on is invalidated or replaced, we will move to a valid replacement without waiting to be asked, and we will not let the level of protection drop in the process.
AI and automated decisions
We will not use your personal data to train, fine-tune or improve any AI model, ours or anyone else's, unless it is necessary to provide the platform on your documented instructions or you have authorised it in writing. We require the same of any AI provider we engage.
Where you use a feature that calls for it, content is processed by an external AI provider under terms that prohibit training on your data. Customer personal data is not sent to an AI provider for any other purpose.
The platform does not make automated decisions producing legal or similarly significant effects on your users. If that changes, we will tell you, describe the logic involved so far as we can without giving away confidential technical detail, and help you meet your obligations under Article 22.
Other data protection laws
This agreement is drafted against the GDPR. If you are subject to a data protection law that requires specific contractual terms we have not included, tell us before you sign and we will agree an addendum.
Liability, changes and notices
Liability under this agreement is subject to the limits and exclusions in the Agreement, which apply to the two documents together rather than to each separately. Nothing here limits anyone's rights against us under the GDPR itself.
We may vary this agreement where a change in data protection law makes it necessary, on written notice, provided the change does not reduce the protection your data gets or materially increase your obligations. Anything else needs your agreement.
Notices to you may go to the data protection contact in Annex A, to the contact details in the Agreement, or to the address you have given us for service communications. Keep it current. Notices to us go to the contact in Annex A.
This agreement is governed by the law that governs the Agreement, and disputes go to the courts the Agreement names.
Signature
Signed for and on behalf of the customer:
Name: _______________ Title: _______________ Date: _______________
Signed for and on behalf of ELECTE S.R.L.:
Name: _______________ Title: _______________ Date: _______________
Annex A — Details of the processing
Processor. ELECTE S.R.L., Via Montenapoleone 8, 20121 Milano (MI), Italy.
Contact for data protection matters. privacy@electe.net.
Controller. The customer that is party to the Agreement, at the address and with the data protection contact given in the Agreement or the order form.
Subject matter. Our provision of the ELECTE platform to you under the Agreement, and the processing of customer data that this involves.
Duration. For as long as the Agreement is in force, plus the wind-down period described under "Deletion and return".
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, backup, erasure and destruction, by automated means, as required to operate the platform.
Purpose of the processing. To provide the platform to you, to support you in using it, to keep it secure and available, and to meet our obligations under the Agreement. No other purpose.
Categories of data subjects. Determined by you, since you decide what goes into the platform. In the ordinary case: your personnel and contractors who use the platform, your customers and end users, and other individuals whose data you choose to process in it.
Categories of personal data. Determined by you. In the ordinary case:
- identification and contact details — name, email address, job title, organisation, telephone number
- technical data generated by use of the platform — IP addresses, device and browser information, timestamps, log entries and audit records
- the content you place in the platform, which may contain personal data of any kind you choose to put there, subject to the special category restriction below
Account and authentication data — user identifiers, hashed credentials, authentication tokens, roles and permissions — is processed by us as controller under our privacy policy, not as your processor, and is outside this agreement.
Special categories of personal data. None. As set out under "What you are responsible for", special category data must not be submitted to the platform without our prior written agreement.
Frequency of transfer. Continuous, for as long as you use the platform.
Retention. Customer data is retained for the life of the account. On termination: a 30-day export window, deletion from live systems within 90 days, and up to 30 further days in off-site backups before they are overwritten. Invoices and tax records are retained for 10 years under Codice Civile art. 2220.
Place of processing. Nuremberg, Germany (application and database). Milan, Italy (off-site backups).
Annex B — Technical and organisational measures
These are the measures in place at the date of this agreement. Controls we inherit from our infrastructure providers are marked as inherited.
Where the data sits
The platform, its database and the supporting services run on infrastructure in Nuremberg, Germany. Off-site backups are held in Milan, Italy. Under normal operation customer data does not leave the EU.
What we run ourselves
Analytics, search, workflow automation, the operational database and identity all run on software we operate on our own servers in the same estate. No third party receives that data, so none of it involves a sub-processor. Our web analytics is cookieless and sets no identifier.
Two lanes for automation
Automation is split into two lanes. The self-hosted lane handles anything residency-sensitive, end to end, on our own servers in Germany. The external lane uses a third-party automation platform and carries only non-sensitive flows; it holds no credentials for the self-hosted database and has no network path to it.
Access control
Access to production systems is limited to the people who operate them. Identity is handled by software we host ourselves. Administrative and internal operational interfaces are not exposed on the open internet: they sit behind an access gateway that authenticates every request before it reaches the application.
Multi-factor authentication is enforced on every administrative account. Administrative actions inside the application are written to an audit log; infrastructure and application logs are retained for 30 days, and access to them is limited to the people who operate the systems.
Network and edge protection
Traffic reaches the platform through a CDN and edge network that provides TLS termination and DDoS mitigation ahead of the origin. The origin is in the EU.
Encryption
Customer data is encrypted in transit with TLS, on the public edge and between our own services. It is encrypted at rest on the database volume and in the off-site backups. Encryption keys are held and rotated by the infrastructure providers that hold the storage, under their own key-management schedules. We do not offer customer-managed keys.
Resilience and backups
The database is backed up off-site to a separate provider in a different EU country from the primary hosting. Backups run automatically on a 30-day rolling rotation; restores are exercised when a restore is needed rather than to a published schedule.
Operating-system security updates are applied automatically as the vendor releases them. Application and dependency updates go out in scheduled maintenance rounds, with security releases prioritised and applied out of band. Dependencies and container images are scanned continuously by automated tooling, on every change. No third-party penetration test has been carried out.
Change management
Every change reaches production through a pull request that a second person reviews before it merges, with automated static analysis and dependency scanning as gates on the merge. Database schema changes ship as reviewed migrations applied automatically when the new release starts. Nobody edits a live database by hand.
Written policies and governance
Sixteen security policies are in place. We will give you a summary on request.
Independent assurance: SOC 2 Type II (audit in progress).
Inherited controls
We do not operate physical infrastructure. The following are performed by our infrastructure providers under their contracts with us:
- physical access control to data centres, and the monitoring and logging of entry to them
- environmental controls — power, cooling, fire suppression
- secure disposal and sanitisation of storage media and decommissioned hardware
- physical network infrastructure and its maintenance
There is no ELECTE office that houses production infrastructure, and no self-managed physical server anywhere in the estate.