Protezione dei dati personali

DPA - Data Processing Agreement

DPA CoreTech: accordo sul trattamento dei dati personali tra CoreTech e il cliente, misure di sicurezza, responsabilità condivisa e tutela dei diritti degli interessati.

General provisions

  • art. 1 - Premises
    1.01As integral parts of this agreement, CORETECH and the CLIENT agree on the following factual premises:
    (a) as indicated in the service contract, CORETECH provides IT services as described therein (IaaS, SaaS, related maintenance services) which involve the need to potentially access CLIENT data, as a technical prerequisite for providing the services or provide related assistance;
    (b) this implies that CORETECH carries out treatments on the personal data managed by the CLIENT through the Services provided, operating these treatments exclusively on behalf of the latter;
    (c) the personal data managed by the CLIENT through the Services in question can be of any type, common, particular, or even related to criminal convictions or crimes, being only the CLIENT to decide how to use the Services and which personal data to enter and which processing, CORETECH limiting itself to providing only IT Services;
    (d) the CLIENT can also carry out the processing of personal data by deciding the purposes and means of processing or he can in turn process the data on behalf of another subject, from which he receives instructions on the processing of such personal data;
    (e) the CLIENT can therefore be either directly a data controller (or co-owner) or a data processor or sub-manager depending on the type of service that the CLIENT provides to third parties;
    (f) given these premises, it is necessary to regulate how CORETECH manages the processing of personal data on behalf of the CLIENT, in order to ensure that the processing respects the privacy regulations and guarantees the protection of the rights and freedoms of the data subjects;
    (g) this agreement intends to regulate the obligations and rights of the parties, CORETECH and the CLIENT, concerning compliance with the requirements of the privacy legislation, in particular the regulation (EU) 2016/679 (hereinafter GDPR) and the privacy code referred to in Legislative Decree 06/30/2003 n. 196, as amended by Legislative Decree. 10.08.2018 n. 101 and any subsequent amendments or additions as well as the related regulatory discipline deriving from it;
    (h) CORETECH has adopted the technical and organizational measures to ensure that the services offered to its customers have adequate protection, according to technical market standards, to ensure efficient protection of the rights and freedoms of the data subjects in relation to their personal data.
    1.02 This agreement must be understood as an integral part of the CORETECH Service supply contract, having as its object the discipline of the consequent obligations under art 28 GDPR, sharing them between CORETECH and the CLIENT according to the principle of shared responsibility as specified below.

  • art. 2 - Definitions
    2.01 For the purpose of the application and interpretation of this agreement, the terms and expressions used must be understood as indicated below:
    (a) The definitions that have been indicated in the service contract concluded between CORETECH and the CLIENT will be taken into account;
    (b) It will also be held against the regulatory definitions provided for by the privacy regulations, including in the first place the provisions of art. 4 § 1 GDPR as well as what is consolidated by the application practice proposed by the competent European bodies on the subject and by the Italian Data Protection Authority, in addition to the relevant European and Italian jurisprudence;
    (c) For the sake of clarity, the person who processes data on direct behalf of the data holder is considered "data controller", while the person who processes data on behalf of a data controller or of a sub-processor for the treatment is referred to as "sub-processor;
    (d) In the course of this agreement for simple display convenience, CORETECH is indicated as the data processor, even if it qualifies as a sub-manager concerning the role played by the CLIENT.

  • art. 3 - Election of CORETECH as data processor
    3.01 The CLIENT appoints CORETECH as responsible for the processing of personal data which are processed through the IT services, subject of the supply contract concluded with the second, authorizing the latter to process, on behalf of the first, the related personal data and only insofar as necessary for the provision of the IT services themselves, in compliance with the contractual terms of supply and as established in this agreement.
    3.02 Concerning the election, it is agreed that:
    (a) The purposes of the processing of personal data transmitted by the CLIENT are exclusively those of providing the IT services referred to in the previous paragraph and are carried out on behalf of the CLIENT by CORETECH, as the data processor, according to the indications of this agreement or also upon the specific written instruction of the latter, always if it complies with the privacy regulations and in compliance with the contractual terms of the service;
    (b) As part of the processing allowed to the data controller referred to in the previous letter, the technical assistance, updating and maintenance of the IT systems requested by the CLIENT is also included, if necessary also in the "on-premise ", and may consist of all related support operations and therefore by way of example: - data migration activities aimed at installing and testing software or IT services; - assistance and updating services that involve (albeit occasionally) remote access to CLIENT data (eg. via remote access tools, eg. TeamViewer, VPN, etc.); - data analysis (DB, screens, data exports, etc.) of the CLIENT to verify technical problems and carry out maintenance or technical support activities;
    (c) The data controller may carry out the treatments in an automated and/or paper way, always as necessary for the purposes indicated above;
    (d) The CLIENT decides the type of personal data to be processed through the IT services provided by the data controller, which may be common personal data, of a particular category or relating to convictions or crimes;
    (e) The category of data subjects refers to natural persons such as customers, suppliers or employees of the CLIENT, depending on the type of activity or services offered in turn by the latter to third parties, directly or indirectly;
    (f) The duration of the processing is limited to the duration of the service as described in the general conditions of supply and at the end the personal data will be deleted according to what is contractually established, unless otherwise instructed in writing by the CLIENT, always if in compliance with the privacy regulations and in compliance of the contractual terms of the service. The hypothesis provided for by art. 28 § 3 lett. g) GDPR relating to the case in which European Union law or Italian law provides for data retention;
    g) The CLIENT declares and guarantees that it has all the necessary powers to appoint the manager in relation to the personal data that the latter will process on his behalf, in compliance with the privacy legislation.

  • art. 4 - Position of the CUSTOMER with respect to the personal data being processed
    4.01 The parties acknowledge that the CLIENT can take different positions concerning the privacy policy, being the owner (or co-owner) of the processing for personal data for which he decides the purposes and means of treatment or if he processes the data personal on instruction and on behalf of others, processor or sub-processor as the case may be.
    4.02 In the event that the CLIENT carries out the processing operations on behalf of a data controller or processor or a sub-processor, the CLIENT guarantees that this agreement complies with the instructions received and the powers conferred, having verified the regularity of his position before signing the CORETECH supply conditions and this agreement.
    4.03 In the case envisaged by the preceding paragraphs, CORETECH will assume the role of data processor or sub-processor depending on the role played by the CLIENT.
    4.04 Upon signing the contract for the supply of the services offered by CORETECH, the CLIENT must specify in the order form his role concerning the personal data that will be processed with the services ordered and in the absence of indication it will be understood that the latter assumes the role of data holder.
    4.05 If during the course of the supply contract, the CLIENT's role changes, he is required to communicate it to the data controller, in the manner specified therein.
    4.06 CORETECH will compile the register of the data controller according to art. 30 co. 2 GDPR, indicating the role of the CLIENT, with respect to the personal data covered by the supply contract, as stated by the latter as indicated above.

  • art. 5 - CLIENT instructions and limits
    5.01 As part of the execution of this agreement, CORETECH, as data processor, will comply with the instructions of the CLIENT, in relation to the personal data being processed, unless the operations requested with the instructions are not provided for in this agreement changes in IT and organizational resources not included in the service supply contract.
    5.02 In the latter case, CORETECH will evaluate the feasibility of the instructions and, if feasible, will agree with the CLIENT the aforementioned changes and related costs. In the absence of an agreement, the instructions will not be implemented, as dictated by this agreement.
    5.03It is understood that the CLIENT's instructions also falling within this agreement and in any case the treatments carried out as data controller, will be carried out as long as they do not involve, in the opinion of CORETECH, a violation of the privacy legislation or an order imposed by a public authority.
    5.04 In the latter case, CORETECH will send written reasons to the CLIENT without delay, without prejudice to the prohibitions established by law.

  • art. 6 - CORETECH's selection of other sub-processors
    6.01 THE CLIENT generally authorizes CORETCH, as the data processor, to appoint sub-processors for the performance of part of their duties as long as in compliance with the supply contract and this agreement.
    6.02 The aforementioned authorization entails the power to add new sub-processors or replace them, and to modify the related contractual agreements.
    6.03The general authorization granted is governed as follows:
    (a) The appointed person must present adequate guarantees of adequacy both in relation to the safety of processing and concerning the protection of the rights and freedoms of the interested parties and in any case respectful of the market standards of the sector;
    (b) The processing of personal data carried out by the sub-manager will be limited only to what is necessary for the provision of subcontracted services and as relevant and useful for the performance of a part of the services covered by the CORETECH supply contract;
    (c) The appointment of the sub-manager will be made in writing, imposing protection obligations no less than those provided for by this agreement and by art. 28 GDPR;
    (d) The CLIENT will be notified in advance in writing of the appointment within a term of 30 (thirty) days, which within the aforementioned term may oppose in writing. In case of opposition by the CLIENT, CORETECH may withdraw from the supply contract with 30 days notice, without proceeding with the appointment of the sub-manager in relation to the Services to be supplied with the CLIENT;
    (e) The list of sub-processors appointed by CORETECH can be found in the CLIENT's reserved area, in the "contractual communications" section.

  • art. 7 - Constraints on the transfer of personal data outside the European Economic Area (EEA
    7.01 Always in compliance with the privacy legislation, the person in charge may transfer the CLIENT's personal data, if possible technically through encryption systems according to internationally recognized technical standards, even outside the European Economic Area (EEA) or from a country that does not have of an adequacy decision by the European Commission according to art.45 of the GDPR, exclusively if it appoints a sub-manager under the previous art.6 and respecting one of the following conditions:
    (a) the standard contractual clauses provided for in the European Commission Decision 2010/87 / EU, of 5 February 2010, are stipulated with the sub-processor appointed by CORETECH, who is authorized as of now by the CLIENT to sign them;
    (b) or if the sub-processor is located in the United States, also through the application of the "Privacy Shield", www.privacyshield.govreferred to in the European Commission Decision 2016/1250 / EU of 12 July 2016;
    or, if the sub-processor is part of a corporate group concerning intra-group transfers, the latter has obtained the approval of the BCR (binding corporate rules).
    7.02 The data controller provides the CUSTOMER with information and suitable documentation concerning the above.
    7.03 In the order form, the CUSTOMER can choose not to apply this clause, by ticking the relevant option and in this case, the personal data will be processed by CORETECH exclusively within the European Economic Area (EEA).
    7.04 A different agreement between the parties remains.

  • art. 8 - Shared responsibility and the obligation of mutual collaboration regarding privacy
    8.01 The parties acknowledge that the efficiency, security, and compliance with the privacy regulations of the cloud services provided by CORETECH are the subject of shared responsibility between the latter and the CLIENT, which obliges both parties to take due action diligence for the management of the IT area of ​​its competence and under its responsibility.
    8.02 By way of example, to understand the concept of shared responsibility, it is summarized in the web page gdpr.php, of which the relevant pdf file was extracted and sent to the imprint parties
    sha256: 5c548cea59adc7229b8b3e9d7 c85a63b13ae7fc998562dbcb84ce58c7199bbf6) the division of tasks with the CUSTOMER, relating to the services offered by CORETECH. The contents of the aforementioned page may be updated over time concerning the technological development of the services offered.
    8.03 Each party also undertakes to comply with its obligations under the privacy regulations and to cooperate in good faith in the context of the application of this agreement to guarantee the rights and freedoms of the interested parties.

  • art. 9 - Methods of communication between the parties
    9.01 The method of communication takes place with the same forms provided for in the general conditions of supply.

  • art. 10 - Applicable law, applicable language, Disputes and exclusive court
    10.01 As regards the applicable law, the applicable language and the applicable forum, reference is made to the general conditions of supply.

Security measures

  • art. 11 - Adequate security measures of the data controller
    11.01 CORETECH, as the data processor, undertakes in the context of the treatments provided for in this agreement, relating to the supply of the IT services described above, to adopt the appropriate technical and organizational measures, according to technical market standards, in order to allow the protection of the lawfulness of the processing of personal data, their confidentiality, integrity, availability, and resilience of the services provided.
    11.02CORETECH declares to have prepared an information security and privacy compliance management plan, which summarizes the protection measures to manage its services in compliance with the previous paragraph.
    11.03 A summary of the protection measures adopted are contained in the technical sheet A) attached to this agreement.
    11.04 CORETECH may update the protection measures to maintain or increase the security levels of the services and for this purpose, the service contract regarding the operating procedures will apply.
    11.05 In any case, it is understood that CORETCH, to protect the personal data entrusted to it with this agreement, may take all the measures, including extraordinary ones, provided for in the supply contract, including the suspension of services.
    11.06 If the CLIENT requests to adopt further technical and organizational measures, CORETECH reserves the right to verify the feasibility of the request and to agree, if necessary, the relative methods and costs.
    11.07 The CLIENT, before accepting this agreement, has checked the security measures indicated above, finding them suitable for the data processing carried out.

  • art. 12 - Checks and controls
    12.01 The data controller periodically audits his information management system and privacy compliance plan, of which he draws up a written report. If deemed appropriate, he will also carry out third-party audits according to international standards and best practices.
    12.02 In order to demonstrate compliance with this agreement, the data processor may also show the CLIENT, at its headquarters, the documentation referred to in the previous paragraph, without extracting a copy and the verification and the results will be recorded.
    12.03 The CUSTOMER has the right to carry out, at its own expense, third-party audits in order to verify compliance with this agreement, through its own specialized staff or professionals with proven experience, in any case, bound in writing to confidentiality obligations. CORETECH may oppose the appointment of professionals who conflict with interest, not sufficiently qualified or not independent and in this case, the CLIENT must propose a different name or carry out the audit directly. The audit report will be made available to the person in charge of the procedure free of charge.
    12.04 The methods of conducting the audit referred to in the previous point will be agreed by the parties, and CORETECH will communicate the hourly cost of its staff appointed to assist you, in any case not less than the hourly rate for technical assistance.
    12.05 The verification activities involving any sub-managers appointed by CORETECH will be carried out in the manner agreed with the latter, in compliance with their privacy compliance policies.

  • art. 13 - CLIENT security measures

    13.01 The CLIENT is aware that the use and safety of the services purchased by CORETECH requires a suitable configuration of the services, which is decided autonomously by the CLIENT according to the general conditions of supply.
    13.02 The CLIENT undertakes to configure, to the extent of its competence, the aforementioned services in order to guarantee an adequate level of protection concerning its personal data processing area in compliance with the privacy legislation.
    13.03 In any case, the CLIENT will promptly inform CORETECH in the event of suspicion or findings of security violations of the services purchased, providing appropriate documentation in this regard.

  • art. 14 - Third party products
    4.01 It is understood between the parties that if the CLIENT uses components or third-party services on CORETECH services, the latter will not be responsible for their management also in relation to the protection measures for compliance with privacy legislation.

  • art. 15 - Breaches of personal data (Data Breach)
    15.01 In the event CORETECH becomes aware of an event that is giving rise or may have given rise to a violation of personal data referred to in this agreement, it will inform the CLIENT as soon as possible, in the manner provided for in the assistance contract, transferring the information at your disposal.
    In any case, CORETECH will send the CLIENT, without delay and as far as reasonably possible, a written report describing the possible damage caused and the causes if known, the protection measures adopted to avoid or mitigate potential risks, and suggesting the appropriate measures to the CLIENT to protect the personal data processed. However, the latter will always be kept constantly updated.
    15.02 It is understood that the above communication does not constitute acknowledgment of a non-fulfillment or responsibility of the data controller, in relation to the violation reported therein.
    15.03 The parties agree that in compliance with art. 33 and 34 of the GDPR, it is up to the CLIENT to make the communications provided therein to the Guarantor Authority under its sole responsibility.

  • art. 16 - Assistance to the CLIENT for compliance with privacy legislation
    16.01 The data controller undertakes to assist the CLIENT in ensuring compliance with the obligations established by the privacy legislation concerning the services provided, in particular also with regard to the obligations relating to the principles of minimization of the processing of personal data (privacy by design & privacy by default), as well as the data protection impact assessment (DPIA) and prior consultation.

    16.02 About the previous point, the data controller will only be required to provide information relating to the services provided that may be useful to the CLIENT and which represent the standard methods with which they are configured and provided.

    16.03 If the CLIENT requires personalized assistance concerning the type of service that it intends to configure within its autonomy, CORETECH will be entitled to a fee that will be agreed with the CLIENT together with the relative procedures for carrying out the assistance requested.

Interested parties Rights' Protection

  • art. 17 - Requests from interested parties to the data controller and obligations of the parties
    17.01 In the event that the data controller receives requests for the exercise of rights from interested parties in relation to personal data that it processes on behalf of the CLIENT, under this agreement, he will be required to send them without delay to the CLIENT, who will handle the aforementioned requests, directly or also through the data controller if different from the CLIENT himself.
    17.02 The data controller will assist the CLIENT by providing him with all the information concerning the services managed by CORETECH based on the provisions of this agreement and will invite the interested party to contact the CLIENT in order to exercise their rights, highlighting their position as manager of the treatment.
    17.03 The CLIENT, therefore, takes every fulfillment regarding the management of the rights of the interested parties, except as indicated in the two previous paragraphs relating to the data controller.

  • art. 18 - Requests of interested parties addressed to the CLIENT for personal data processed on his behalf by the data controller
    18.01 In the event that the CLIENT has to satisfy requests relating to interested parties for the exercise of their rights concerning personal data subject to this agreement, the data controller will provide the information requested by the CLIENT as regards this agreement, to the services purchased by the CLIENT.
    18.02 In any case, the CLIENT will process the aforementioned request directly, limiting the data controller to fulfill the above.

  • art. 19 - Portability of personal data
    19.01 In the event that it is necessary for the CLIENT to satisfy requests for portability of personal data, the data controller will provide, exclusively in relation to the services purchased by the CLIENT, only the useful information to extract them in a format compliant with the privacy legislation and provided this is reasonably possible.
    19.02 In the event that the CLIENT instead requests the technical assistance necessary to carry out the aforementioned extraction, CORETECH will evaluate the technical feasibility and agree with the first, if necessary, the relative procedures and costs to be borne by the CLIENT.

Final provisions

  • art. 20 - Faculty of modification of the agreement by the manager
    20.01 CORETECH has the right to modify the conditions envisaged for this agreement in compliance with the privacy legislation, according to the provisions of the general supply conditions, without prejudice to the CLIENT's right to withdraw.

  • art. 21 - CLIENT's obligation to indemnify
    21.01 For all activities carried out in violation of the privacy policy, negligently or maliciously committed by the CLIENT using the Services provided by CORETECH, from which any extra-judicial or judicial claim may arise against the latter, also related to the violation of these conditions by the CLIENT, he undertakes to take all responsibility and to indemnify and hold it harmless as soon as possible, freeing CORETECH from the aforementioned claims.
    21.02 The CLIENT will have to directly bear any type of cost, compensation for damages and charges, including any professional expenses, which may arise from such claims, in addition to any further damage suffered by CLIENT.
    21.03 The CLIENT has the right to prove CORETECH's liability for violation of this agreement.
    21.04 The CLIENT will inform CORETECH, as soon as possible, of any actions that may be brought against it.

  • art. 22 - Prevalence of this agreement
    22.01 This agreement replaces any other prior agreement or instruction relating to the management of personal data regarding the Services provided by CORETECH.

Data sheet

Protection measures adopted by the data controller

A) Organizational measures
A-1) Adoption of an information security management policy and a policy for the protection of personal data in compliance with the privacy policy, based on risk analysis, in order to guarantee the confidentiality, availability and integrity of the data personal to protect the rights and freedoms of the interested parties;
A-2) Procedures for accessing the physical structures, duly protected, only to authorized subjects subject to suitable recognition;
A-3) User Policy and Disciplinary: Detailed policies and regulations are applied, to which all users with access to IT services must comply to guarantee the security of the systems;
A-4) Logical access authorization - All computer systems are accessible only with access profiles for what is necessary for the task performed. The authorization profiles are identified and configured prior to access;
A-5) There is an accident management procedure connected to technical monitoring tools of the systems to which specialized personnel are proposed, with identification, in the event of an accident, of the interventions to be prepared in a logically determined order, to guarantee the service restoration in the shortest possible time, as well as verify the consequences, draw up a report, on the outcome of which additional protection measures depend, in any case without prejudice to the verification of the adequacy of the protection systems in place;
A-6) Assistance management procedure - Assistance interventions are managed through a procedure that verifies the authenticity of the request and delivers the support by minimizing the processing of personal data, through duly trained personnel and technical tools respecting the standards of safety. Also through a ticket system service made available to the CLIENT, it will always be possible to know the details of the intervention, duration, date and the operator (through a unique code assigned to him), as well as to verify, by the data controller, the authenticity of the request for support;
A-7) In any case, the levels of access to the CLIENT's systems to provide technical assistance will be assigned only to some specifically authorized employees with authentication credentials conforming to international standards;
A-8) Commitment to the confidentiality of all employees in writing prior to accessing the systems;
A-9) Each employee can only process the information for which he has been authorized concerning the duties performed and duly trained, through periodic updates, to process the data with the utmost confidentiality and security, in compliance with the privacy legislation;
A-10) Internal regulations for employees, regarding the use of IT tools and potential employer controls;
A-11) Procedures for protecting against attacks through social engineering with the related specific training of personnel;
A-12) Procedures for choosing suitable suppliers focused on checking the quality, safety and compliance with the current legislation of the goods or services offered;
A-13) Procedure for verifying the need for a DPIA, Data protection impact assessment concerning the IT systems used according to the privacy legislation;
A-14) Data Breach - There is a procedure for managing incidents that may affect personal data, based on the distribution of roles according to competence, verification of the potential prejudice (presumed or ascertained), management of countermeasures as well as the methods of sharing with the CLIENT of information relating to violations of personal data and for the adoption of the related obligations required by the privacy legislation;
A-15) Procedures for the disposal of analog documentation and IT systems potentially containing information, using suitable tools (such as document shredders and certified disposal companies);
A-16) Update of the organizational measures that will be verified every six months;
B) Technical measures
B-1) Authentication credentials - Access to systems is based exclusively on unique authentication credentials, based on a confidential PIN or access key and with security measures compliant with international standards;
B-2) Management of access passwords according to best practices, based on the length, complexity, expiration, robustness entrusted to subjects duly instructed on its use and storage;
B-3) System Administrators - For users with the role of System Administrators, whose duties are attributed with specific nominations and in writing, a non-alterable log management system is implemented, properly configured to track the activities carried out and allow subsequent monitoring to verify the regularity of transactions. A procedure is then activated for verifying the work of system administrators as part of the information security plan developed internally and for compliance with privacy legislation and also to improve protection measures;
B-4) Use of encryption systems based on computer algorithms and protocols compliant with international standards;
B-5) IDS / IPS Intrusion Detection System and Intrusion Prevention System as intrusion detection systems, to detect cyber attacks in advance;
B-6) Adoption of Firewall systems as perimeter defense components of computer networks and to protect communication lines;
B-7) Antivirus and Malware updated periodically against the risk of intrusion and illegal action of programs;
B-8) Logging systems for system monitoring, storage of events that have occurred and identification of accesses;
B-9) Backup & restore systems, with relative management procedure;
B-10) Business continuity for the resilience of systems in the event of an accident;
B-11) Vulnerability Assessment & Penetration Test - System vulnerability analysis activities are periodically performed both concerning infrastructural and application areas, as well as periodic Penetration Tests, assuming different attack scenarios, with the aim of verifying the security level of applications/systems/networks and therefore based on the relative reports, improve the security measures;
B-12) DATA CENTER choice with TIER 4 standard;
B-13) Constant updating of IT systems, technical measures, as technology changes and with constant verification according to pre-established times as well as constant verification, from reliable sources, of the security problems of the IT products and services in use for the relative update.
Document information
Document title:
DPA
Document version:
V.1.2
Date of last adjustment:
19/11/2024

Vuoi approfondire privacy e conformità?

Consulta il GDPR, l'informativa privacy e le condizioni generali per il quadro completo sulla protezione dei dati CoreTech.