This document supplements the main service contract. Download the PDF to keep it on file or share it with your DPO.
1. Parties
Data Controller: the Customer, tenant registered on the Aegis platform.
Data Processor: Aegis Software Solutions, provider of the Aegis platform, with registered office available on request and reachable at info@aegissystem.net.
2. Subject matter and duration
This agreement (the "DPA") governs the processing of personal data carried out by the Processor on behalf of the Controller in the context of the SaaS platform services. Its duration matches that of the main service contract and continues until full return or deletion of the data.
3. Nature and purpose of processing
- SaaS service delivery (authentication, dashboard, application modules).
- Billing, accounting and administrative management.
- Technical support, monitoring and operational security.
- Transactional and service communications.
4. Categories of data and data subjects
Identification data (name, email, phone), contractual and profile data, service usage data, technical and security logs, payment data processed via Stripe and not stored directly. Data subjects: Customer's users, employees and collaborators, and Customer's end clients.
5. Processor's obligations
- Process data only on documented instructions from the Controller.
- Ensure confidentiality through contractual commitments of authorised personnel.
- Implement appropriate technical and organisational security measures (Art. 32 GDPR).
- Assist the Controller in responding to data subject requests (Arts. 12-23 GDPR).
- Assist with data protection impact assessments (Art. 35) and prior consultation (Art. 36).
- Notify the Controller of any personal data breach without undue delay and in any case within 72 hours.
- Return or delete the data at the end of the contract, save for statutory retention obligations.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Multi-factor authentication available for all administrative accounts.
- Row-Level Security applied to every customer data record.
- Audit logging of accesses and privileged actions.
- Encrypted daily backups with 30-day retention.
- Periodic penetration testing and security reviews.
- Formal vulnerability and incident management process.
7. Sub-processors
The Customer authorises the use of the sub-processors listed below; any changes will be communicated with 30 days' notice, granting the Customer the right to object.
- Supabase Inc. (USA/EU) - database hosting, authentication, storage.
- Cloudflare, Inc. (EU) - CDN, edge runtime, DDoS mitigation.
- Stripe, Inc. (USA/EU) - payment processing.
- Transactional email provider (EU) - service email delivery.
8. International transfers
Transfers of personal data outside the EU occur exclusively to countries covered by a European Commission adequacy decision or, failing that, through Standard Contractual Clauses (SCCs) supplemented by the technical and organisational measures necessary.
9. Data subject rights
The Customer can exercise GDPR rights (access, rectification, erasure, portability, restriction, objection) directly from the Privacy & GDPR panel of the platform, or by writing to info@aegissystem.net. The Processor provides timely assistance within statutory deadlines.
10. Retention and deletion
Data is retained for the entire duration of the contract. On termination a 30-day grace period applies; after that, data is automatically deleted or anonymised. Invoices and fiscal documents are retained for the period required by applicable tax law.
11. Audit and inspections
The Controller is entitled to request, with reasonable notice and subject to the confidentiality of the Processor's information, documentary evidence of the security measures in place (audit reports, certifications, summary results of penetration tests).
12. Governing law and jurisdiction
This DPA is governed by Italian law. Any dispute shall be subject to the exclusive jurisdiction of the Courts of Rome, without prejudice to mandatory consumer protection rules.