Clean Studio Control
Data Processing Agreement for Clean Studio Control
Agreement pursuant to Article 28 of Regulation (EU) 2016/679
This is a courtesy translation. The binding text is the Italian version of the agreement: in case of any discrepancy, the Italian version prevails. Read the binding Italian version
- Version
- 1.0-2026-09-25
- Effective date
- 25 September 2026
This agreement is entered into between Clean Studio di Samuele Castaldo, with registered office at Circumvallazione Ovest 6, scala 4, interno 9, 80023 Caivano (NA), VAT no. 11026611217, reachable at cleanstudio.lab@gmail.com (the “Processor”), and the natural or legal person holding the Partner account who accepts this agreement electronically (the “Controller”).
This agreement supplements the Clean Studio Terms and Conditions and governs exclusively the personal data that the Controller enters and manages in its own Control workspace for purposes determined by the Controller.
1. Subject matter, duration and roles
The Controller determines the purposes and essential means of the processing of the data of its customers, contacts and recipients. The Processor processes such data on behalf of the Controller solely to provide, protect, maintain and support the Control service.
Processing begins upon acceptance of this agreement and continues for the duration of access to Control, including the activities necessary to return or delete the data at the end of the service.
2. Nature, purpose and documented instructions
Operations may include collection, recording, organisation, storage, consultation, alteration, retrieval, technical transmission, making available, erasure and destruction of data, to the extent necessary for the operation of Control.
The features used by the Controller, the account settings and the requests sent through the support channels constitute documented instructions. The Processor does not use the data for incompatible purposes of its own and informs the Controller if it considers that an instruction infringes applicable law, unless prohibited by law.
3. Data subjects and categories of data
Data subjects may include customers, prospective customers, contacts, recipients, suppliers and other persons whose data are entered by the Controller into its workspace.
- identification and contact data, such as name, email and telephone number;
- addresses and information necessary for delivery;
- information relating to orders, products, requests, manually recorded payments, shipments and returns;
- operational notes entered by the Controller and technical identifiers necessary for the service.
- Control is not intended for special categories of data under Article 9 GDPR, data relating to criminal convictions and offences, credentials, identity documents or full payment card data. The Controller undertakes not to enter them.
4. Obligations of the Controller
- to process the data on an appropriate legal basis and provide data subjects with the information required by law;
- to collect only data that are adequate, relevant and necessary, keep them accurate and define appropriate retention periods;
- to use Control in compliance with the law and not to give unlawful instructions;
- to protect credentials and devices, manage access properly and promptly inform Clean Studio of any suspected incident;
- to handle data subject requests and indicate to the Processor the operations required when its assistance is needed.
5. Obligations of the Processor
- to process the data only on documented instructions from the Controller or where required by law;
- to bind the persons authorised to process the data to confidentiality and limit access to what is necessary;
- to adopt technical and organisational measures appropriate to the risk and maintain the logical separation of workspaces;
- to reasonably assist the Controller in the exercise of data subjects’ rights, in the handling of incidents and in the other obligations under Articles 32–36 GDPR;
- to make available the information necessary to demonstrate compliance with this agreement.
6. Security and personal data breaches
The main security measures are described in Annex B. The Processor may update them while maintaining an overall level of protection that is not lower.
The Processor informs the Controller without undue delay after becoming aware of a personal data breach relating to the Control workspace and provides the information reasonably available to enable the Controller to fulfil its obligations.
7. Sub-processors
The Controller grants general authorisation for the use of the sub-processors listed in Annex A. The Processor imposes on them data protection obligations that are substantially equivalent for the activities entrusted to them.
Material changes to the list of sub-processors are communicated by email, in the reserved area or through a clearly flagged update. The Controller may raise a reasoned objection before the new processing begins; the parties cooperate in good faith to find a reasonable solution.
8. International transfers
Where a provider entails a transfer of data outside the European Economic Area, the Processor relies on the mechanisms provided for in Articles 44 et seq. GDPR, including adequacy decisions or standard contractual clauses, in accordance with the applicable terms of the provider.
9. Data subject requests
If the Processor directly receives a request concerning data in the workspace, it forwards it to the Controller without responding on the merits, unless required by law. Upon an authenticated request from the Controller, the Processor provides reasonable assistance in searching, accessing, rectifying, exporting or erasing the data concerned.
10. Return and deletion
Upon termination of the service or on authenticated instruction from the Controller, the Processor returns a copy of the data in a reasonably available structured format and deletes the workspace data, according to the Controller’s choice and instructions, unless there are legal retention obligations.
Residual copies in continuity and backup systems are isolated from ordinary use and overwritten according to the providers’ normal technical cycles, remaining protected by this agreement in the meantime.
11. Verification and audits
Upon reasonable request, the Processor provides the information useful to verify compliance with Article 28 GDPR. Any further verification must be agreed with reasonable notice, respect confidentiality and not compromise the security or continuity of the services and of other customers.
12. Precedence, updates and contacts
For the matters governed by this agreement, it prevails over any incompatible provisions of the general Terms. Privacy requests and operational instructions must be sent from a verified account or to cleanstudio.lab@gmail.com.
A material change that requires new instructions or affects the obligations of the parties entails the publication of a new version and a new acceptance. Purely formal updates, or updates necessary to reflect equivalent providers, are communicated as provided for in this agreement.
Annex A — Main sub-processors
- Google Cloud Platform / Firebase: authentication, Firestore database, storage and security of the data infrastructure;
- Vercel: application hosting, API execution, delivery and technical logs necessary for security and operation.
Annex B — Main technical and organisational measures
- Firebase authentication and server-side token verification;
- authorisation and separation of workspaces by UID, with server-side ownership checks;
- direct access to Control documents denied by the Firestore rules, with operations performed through controlled APIs;
- encryption in transit and encryption-at-rest measures offered by the infrastructure providers;
- limitation of administrative access to the needs of support, security and legal compliance;
- dependency updates, validation checks, incident management procedures and continuity offered by the cloud providers.