DPA — Data Processing Agreement (Art. 28 GDPR)
CONSOO S.R.L.S. — hice
Edition: English master (international)
Last updated: 3 July 2026
Recitals
This Data Processing Agreement (hereinafter the «DPA» or the «Agreement») is entered into pursuant to and for the purposes of Art. 28 of Regulation (EU) 2016/679 («GDPR») between:
- the Customer — the entity (company or self-employed professional holding a VAT number, or other professional) that subscribes to the Service, identified in the Order Form and in the Tenant registration data — in its capacity as Data Controller (hereinafter the «Controller»); and
- CONSOO S.R.L.S., a simplified limited liability company, with registered office at Piazzetta Umberto Giordano 2, 20122 Milan (MI), Italy, VAT/Tax Code IT13823860963, REA MI-2745733, PEC consoo@pec.it, which operates the Service under the hice brand (hereinafter «hice», the «Provider» or the «Processor») — in its capacity as Data Processor.
hereinafter jointly the «Parties» and each a «Party».
Whereas:
(a) hice makes available to the Controller a multi-tenant SaaS Professional
Services Automation platform with an AI assistant (the «Service»), under
the conditions of the General Terms of Service
(condizioni-generali-servizio.md, the «Terms»);
(b) in providing the Service, hice processes on behalf of the Controller the Customer Data that contain personal data of third parties (candidates, employees, consultants, contacts) and of the Users, as described in Annex A;
(c) the Parties intend to govern, through this Agreement, their respective obligations regarding the protection of personal data in compliance with Art. 28 GDPR and applicable law;
(d) this DPA constitutes an integral and essential part of the Terms and applies to all Customers, including those who use the Free Plan, without the need for separate signature.
Capitalized terms not defined in this DPA have the meaning attributed to them in the Terms and in the shared glossary; the terms «Personal Data», «Processing», «Data Controller», «Data Processor», «Sub-processor», «Data Subject» and «Personal Data Breach» have the meaning set out in Art. 4 GDPR.
This DPA governs exclusively the processing in which hice acts as Processor
on behalf of the Customer. For the processing in which hice is Controller
(registration data, billing, security logs, diagnostics, support, marketing),
reference is made to the Privacy Policy (informativa-privacy.md).
1. Definitions and scope of application
1.1 Definitions. In addition to the terms defined in the Recitals and in the shared glossary, for the purposes of this Agreement the definitions of Art. 4 GDPR apply. In particular:
- Customer Data: all data, content and information — including personal data of third parties — that the Customer or the Users enter, upload or generate in the Service, as detailed in Annex A. They do not include the data of which hice is Controller pursuant to the Privacy Policy.
- Applicable Data Protection Law: the GDPR, Legislative Decree 196/2003 («Privacy Code») as amended by Legislative Decree 101/2018, the measures of the Italian Data Protection Authority (Garante) and any other rule applicable to the Processing.
- SCC (Standard Contractual Clauses): the standard contractual clauses adopted by Implementing Decision (EU) 2021/914 of the European Commission for transfers to third countries.
- DPF: the EU-U.S. Data Privacy Framework and related adequacy mechanisms for transfers to participating U.S. operators.
1.2 Scope. This DPA applies to any Processing of Personal Data carried out by hice, in its capacity as Processor, on behalf of and on the instructions of the Controller, in connection with the provision of the Service.
1.3 Precedence. In the event of conflict between this DPA and the Terms, this DPA prevails to the extent of the subject matter of personal data protection. In the event of conflict between this DPA and the SCC, the SCC prevail for transfers outside the EEA.
1.4 Roles. The Parties acknowledge that, with respect to the Customer Data, the Customer is Controller and hice is Processor. Each Party is responsible for complying with the obligations incumbent upon it in such capacity under the Applicable Law.
2. Subject matter, duration, nature and purpose of the processing
2.1 Subject matter. The subject matter of the Processing is the performance, by hice, of the Processing operations necessary to provide the Service to the Controller, in accordance with the features described in the Terms and in the Documentation.
2.2 Duration. The Processing lasts for the duration of the contractual relationship under the Terms (for the entire term of the subscription or use of the Free Plan), and continues for the period strictly necessary for the deletion or return operations under Art. 11. This DPA remains effective for as long as hice processes Customer Data.
2.3 Nature and purpose. The nature and purposes of the Processing are the provision of the Service's features (registries, recruiting, projects, timesheets, expense reports, purchases, documents, calendar, mail in BYO mode, chat, KPIs, org chart, AI assistant, candidate matching, CV parsing, OCR) and the related hosting, storage, security, backup and technical support services. Details in Annex A.
2.4 Types of data and categories of Data Subjects. The types of Personal Data processed and the categories of Data Subjects are indicated in Annex A.
2.5 AI Features. The operations performed by the AI Features (chat,
candidate matching, CV parsing, OCR) constitute Processing on behalf of the
Controller and are subject to this DPA. hice does not use Customer Data to
train foundation AI models. The details of algorithmic transparency are in
the AI and Algorithmic Transparency Notice (informativa-ai-trasparenza.md).
3. Obligation to process on documented instructions of the Controller
3.1 Documented instructions. hice processes Customer Data solely on the documented instructions of the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which it is subject; in such a case, hice informs the Controller of that legal requirement before the Processing, unless the law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR).
3.2 Initial instructions. The following constitute documented instructions of the Controller: (i) the Terms; (ii) this DPA and its Annexes; (iii) the configurations, settings and commands that the Controller and the Users issue through the Service's features in ordinary use.
3.3 Further instructions. Any further, different or additional instructions beyond those in Art. 3.2 must be given in writing. If an instruction requires activities exceeding the normal use of the Service, hice and the Controller may agree on the relevant terms, including financial terms.
3.4 Lawfulness of instructions. hice immediately informs the Controller if, in its opinion, an instruction infringes the GDPR, the Privacy Code or other applicable data protection provisions (Art. 28(3), final paragraph, GDPR), without prejudice to the fact that hice has no general obligation to monitor the lawfulness of the Customer Data.
3.5 Controller's warranty. The Controller warrants that the instructions given and the upload of the Customer Data comply with the Applicable Law and that it has a suitable legal basis for the Processing of personal data of third parties (candidates, employees, consultants, contacts) and for entrusting its Processing to hice. The Controller indemnifies hice against third-party claims based on the lack of such legal basis, within the limits set out in Art. 13.
4. Confidentiality of persons authorized to process
4.1 Confidentiality undertaking. hice ensures that the persons authorized to process the Customer Data (employees, collaborators and staff) have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
4.2 Restriction of access. hice restricts access to the Customer Data to the staff who need to access it for the provision of the Service, in accordance with the least privilege principle, and ensures their training in data protection matters.
4.3 Persistence of the obligation. The confidentiality obligation persists even after the termination of the employment or collaboration relationship of the authorized persons.
5. Technical and organizational security measures (Art. 32)
5.1 Measures adopted. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the Processing, as well as the risk to the rights and freedoms of the Data Subjects, hice implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Art. 32 GDPR. The measures currently in place are described in Annex C.
5.2 Evolution of the measures. hice may update the security measures over time, provided that the level of protection is not, overall, reduced compared to that described in Annex C.
5.3 Cooperation. hice makes available to the Controller the information reasonably necessary to demonstrate compliance with the obligations under Art. 32, in accordance with the procedures of Arts. 8 and 10 of this DPA.
6. Sub-processors
6.1 General authorization. The Controller grants hice a general written authorization to engage other processors («Sub-processors») for the performance of specific Processing activities connected with the provision of the Service, pursuant to Art. 28(2), first part, and 28(4) GDPR.
6.2 List. The list of Sub-processors authorized at the time this DPA comes into effect is set out in Annex B. The Controller declares that it has taken note thereof and approves their engagement.
6.3 Equivalent contractual obligations. hice imposes on each Sub-processor, by means of a contract or other legal act, data protection obligations equivalent to those set out in this DPA, in particular the provision of sufficient guarantees to implement appropriate technical and organizational measures (Art. 28(4) GDPR). Where the Sub-processor fails to fulfil its data protection obligations, hice remains liable to the Controller for the performance of the Sub-processor's obligations.
6.4 Changes to Sub-processors and right to object. hice informs the Controller of any intended changes concerning the addition or replacement of Sub-processors, with at least 30 (thirty) days' notice, by means of a communication to the administrative email address associated with the Tenant and/or publication of the updated list on a dedicated page of the Service, so as to give the Controller the opportunity to object to such changes (Art. 28(2), second part, GDPR).
6.5 Exercise of the objection. The Controller may object, for reasonable and documented reasons relating to data protection, within the notice period, by giving written notice to info@hice.ai. In such a case the Parties cooperate in good faith to find a solution. Where it is not possible to reach an agreement and hice nonetheless intends to use the Sub-processor, the Controller has the right to terminate the Service limited to the affected features, or the entire relationship if the features are essential, without penalty and with refund of any Fees paid and not enjoyed.
6.6 Local processing. Certain operations (in particular optical character recognition and document compression, as well as a fallback AI processing component) are performed by means of software components executed locally on the Service's infrastructure and do not entail the engagement of external Sub-processors or transfers to third parties.
7. Assistance to the Controller for Data Subjects' rights (Arts. 12–23)
7.1 Support measures. Taking into account the nature of the Processing, hice assists the Controller with appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests for the exercise of the Data Subject's rights under Chapter III of the GDPR — access, rectification, erasure, restriction, portability, objection and the rights relating to automated decision-making (Arts. 12–23 GDPR) — Art. 28(3)(e) GDPR.
7.2 Self-service tools. The Service makes available to the Controller features that allow it, independently, to access, rectify, extract/export and delete the Customer Data, so as to handle directly most of the Data Subjects' requests.
7.3 Forwarding of requests. Where a Data Subject contacts hice directly to exercise their rights over Customer Data, hice does not act on the request on its own initiative (unless otherwise required by law) and transmits it to the Controller without undue delay, providing the information useful to identify the Controller, so that the Controller, as the party responsible for the response, may handle it.
7.4 Further assistance. Where the request cannot be handled with the self-service tools, hice provides reasonable assistance to the Controller. For activities exceeding normal support, the Parties may agree on proportionate remuneration.
8. Assistance to the Controller for the obligations under Arts. 32–36
Taking into account the nature of the Processing and the information available to hice, hice assists the Controller in ensuring compliance with the obligations under Arts. 32–36 GDPR (Art. 28(3)(f) GDPR), as follows.
8.1 Security of processing (Art. 32). By adopting and maintaining the measures set out in Annex C and making the related information available.
8.2 Notification of breaches to the Controller (Arts. 33–34). hice notifies the Controller of any Personal Data Breach concerning the Customer Data without undue delay after becoming aware of it (Art. 33(2) GDPR), so as to enable the Controller to fulfil its own obligations to notify the supervisory authority (within 72 hours, Art. 33(1)) and, where applicable, to communicate to the Data Subjects (Art. 34). hice's notification contains, to the extent available:
- the description of the nature of the breach, including, where possible, the categories and the approximate number of Data Subjects and of personal data records concerned;
- the contact point at hice where more information can be obtained;
- the description of the likely consequences of the breach;
- the description of the measures taken or proposed to be taken to address the breach and to mitigate its possible adverse effects.
Where the information is not available at the same time, it is provided, in a
proportionate manner, in subsequent phases without further undue delay. The
internal handling of breaches follows the Data Breach Procedure
(interno-procedura-data-breach.md), with which this article is coordinated.
8.3 Limits. hice's notification pursuant to Art. 8.2 does not constitute an admission of liability or fault. hice provides reasonable cooperation to the Controller in the investigation and remediation activities.
8.4 Impact assessment and prior consultation (Arts. 35–36). hice assists the Controller, upon request and within the limits of the available information, in carrying out the data protection impact assessment (DPIA) and in any prior consultation with the supervisory authority, in particular with reference to the AI Features and candidate matching, by making available the relevant information on the Processing operations and on the security measures.
9. Deletion and return of data at the end of the relationship
9.1 Controller's choice. Upon termination, for any reason, of the provision of the Service, hice, at the Controller's choice, deletes or returns all Customer Data and deletes the existing copies, unless Union or Member State law requires retention (Art. 28(3)(g) GDPR).
9.2 Export window. Before deletion, and for a reasonable period of 30 (thirty) days running from termination, the Controller may export independently the Customer Data through the Service's features or request its return in a structured, commonly used and machine-readable format.
9.3 Effective deletion. After the window under Art. 9.2 has elapsed, hice proceeds to delete the Customer Data from the production systems and, within the subsequent technical rotation cycles, from the backups, in accordance with the normal backup retention policy described in the Documentation.
9.4 Retention by legal obligation. Any data whose retention is required by law is retained for the strictly necessary time, with application of the security measures set out in Annex C, and is not further processed.
9.5 Attestation. Upon the Controller's written request, hice provides an attestation of the deletion having taken place.
10. Audits and inspections
10.1 Controller's right. hice makes available to the Controller all the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to reviews (audits) and inspections, including those conducted by a third party mandated by the Controller, in accordance with Art. 28(3)(h) GDPR.
10.2 Reasonable procedures. The exercise of the audit right takes place in accordance with reasonable procedures, aimed at not compromising the security of the Service, the data of other customers and the confidentiality of the other Tenants. In particular:
- the Controller sends hice a written request with at least 30 (thirty) days' notice, except in cases of urgency connected with a Breach or a binding request of a supervisory authority;
- audits take place during working hours, without unduly interfering with hice's business, as a rule no more than once a year, unless a further audit is required by a supervisory authority or prompted by a Breach;
- the third party possibly mandated must not be a competitor of hice and must enter into suitable confidentiality undertakings;
- the Controller bears the costs of its own audit; the ordinary cooperation costs remain with hice.
10.3 Substitute documentation. To satisfy, in whole or in part, the right
under Art. 10.1, hice may provide the Controller with documentation on its
security measures, reports or, where available in the future, third-party audit
reports or certifications. (As of now, hice does not hold third-party
certifications of the ISO 27001 or SOC 2 type — see _foundation.md §6 «no
untrue claims».)
11. Transfers of personal data outside the EEA
11.1 Principle. hice processes the Customer Data, as a matter of priority, within the European Economic Area (EEA). Any transfers to third countries take place only where one of the lawfulness conditions of Chapter V of the GDPR is present.
11.2 Safeguards. For transfers to third countries that do not benefit from an adequacy decision, hice ensures the adoption of appropriate safeguards pursuant to Art. 46 GDPR, in particular the Standard Contractual Clauses (SCC) under Implementing Decision (EU) 2021/914, or, for participating U.S. operators, the EU-U.S. Data Privacy Framework (DPF). The list of transfers and the related safeguards is set out in Annex D.
11.3 Supplementary measures. Where necessary, hice adopts supplementary measures (technical, contractual and organizational) to ensure a level of protection substantially equivalent to that guaranteed within the Union, taking into account the circumstances of the transfer.
11.4 BYO mode. For Calendar/Mail synchronizations in «Bring Your Own» (BYO) mode, in which the Controller connects its own environment at the mail and calendar services chosen by it with its own OAuth credentials, any transfer to such providers is a processing activated by the Controller on its own account at the provider; the Controller is responsible for the contractual conditions and safeguards applicable to the relationship with that provider. hice processes the related metadata within the limits of the Service.
12. Confidentiality
The Customer Data constitute confidential information of the Controller. hice treats them as such, does not disclose them to third parties except to the Sub-processors authorized pursuant to Art. 6 or in fulfilment of legal obligations, and uses them exclusively for the provision of the Service and within the limits of the Controller's instructions. This clause is coordinated with the confidentiality obligations provided for in the Terms.
13. Liability and coordination with Art. 82 GDPR
13.1 Allocation towards Data Subjects. The liability of the Parties towards Data Subjects for damage caused by the Processing remains governed by Art. 82 GDPR. The Processor is liable for damage caused by the Processing only where it has not complied with the GDPR obligations specifically directed to processors or has acted outside or contrary to the lawful instructions of the Controller (Art. 82(2) GDPR).
13.2 Internal recourse. In the internal relations between the Parties, where one Party has paid full compensation for the damage suffered by a Data Subject, it is entitled to claim back from the other Party that part of the compensation corresponding to the latter's part of responsibility, pursuant to Art. 82(5) GDPR.
13.3 Contractual limitation. Without prejudice to Art. 82 GDPR towards Data
Subjects (which cannot be compressed), in the relations between the Parties the
limitations of liability set out in the Terms apply (see _foundation.md §4.2
and the «Limitation of liability» clause of the Terms), including the
mandatory carve-outs for wilful misconduct and gross negligence, personal
injury and anything that cannot be excluded under mandatory law (Art. 1229 of the
Italian Civil Code).
13.4 Administrative fines. Each Party bears the administrative pecuniary fines that may be imposed for infringements attributable to it.
14. Final provisions
14.1 Duration and termination. This DPA is effective from the date of acceptance of the Terms and remains in force for the entire duration of the Processing of the Customer Data by hice. The clauses intended by their nature to survive (in particular Arts. 9, 12 and 13) remain effective even after termination.
14.2 Amendments. hice may update this DPA to adapt it to regulatory changes, to measures of the supervisory authorities or to the evolution of the Service, giving notice to the Controller in the manner provided for in the Terms; the amendments do not reduce the level of data protection nor the Controller's rights arising from Art. 28 GDPR.
14.3 Partial invalidity. The possible invalidity or ineffectiveness of a clause does not affect the validity of the remaining ones.
14.4 Governing law and jurisdiction. This DPA is governed by Italian law, excluding conflict-of-law rules. For disputes, the courts of Milan, Italy have exclusive jurisdiction, save, for the Consumer Customer, the mandatory jurisdiction of the Consumer's courts (place of residence or domicile) pursuant to the Consumer Code. For transfers governed by the SCC, the law and jurisdiction provided therein remain unaffected.
ANNEX A — Details of the processing
(Art. 28(3) GDPR — description of the Processing entrusted to the Processor)
A.1 Data Controller: the Customer, as identified in the Order Form and in the Tenant registration data.
A.2 Data Processor: CONSOO S.R.L.S. — hice (details in the Recitals).
A.3 Subject matter of the processing. Performance of the Processing operations necessary to provide the Service: collection, recording, organization, structuring, storage, consultation, use, extraction, communication to authorized Sub-processors, comparison, interconnection, restriction, deletion of the Customer Data.
A.4 Duration of the processing. For the entire duration of the contractual relationship (subscription or use of the Free Plan), in addition to the period necessary for the deletion/return operations under Art. 9 of the DPA.
A.5 Nature and purpose of the processing. Provision of the Service's features and of the related hosting, storage, security, backup and support services. The purposes include, by way of example:
- management of customer, contact and supplier registries;
- management of candidates and recruiting processes, including candidate↔opportunity matching (aid to human decision-making) and CV parsing;
- management of projects, timesheets, expense reports and purchases;
- management of documents and corporate archive;
- management of calendar and mail in BYO mode (upon the Controller's activation);
- team chat, KPIs, org chart;
- AI assistant in chat (with human confirmation on write actions — HITL);
- optical character recognition (OCR) on receipts and invoices.
A.6 Categories of Data Subjects. The natural persons whose data are processed within the Service include:
- Candidates (selection profiles managed by the Customer in the recruiting vertical / in the candidates function);
- Employees of the Customer;
- Consultants / collaborators of the Customer;
- Contacts (representatives of customers, suppliers and other parties managed in the Customer's registries / CRM);
- Authorized Users of the Customer (limited to the Customer Data concerning them that the Controller processes in the Service).
A.7 Types of Personal Data. The categories of data processed include:
- registry and identification data (e.g. first name, surname, date of birth, tax code where entered by the Customer);
- contact data (e.g. email, telephone, address);
- professional and career data (e.g. role, experience, skills, remuneration/compensation, CV and related content);
- communication data deriving from the Calendar and Mail functions in BYO mode (e.g. calendar events, metadata and content of synchronized emails, where activated by the Controller);
- data generated in the use of the Service (e.g. notes, evaluations, chat content, attachments and documents uploaded by the Customer).
A.8 Possible special categories of data (Art. 9 GDPR). The Service is neither designed nor intended for the systematic processing of special categories of data. However, where the Customer, on its own initiative, uploads into the free-text fields, documents, CVs or attachments data revealing racial or ethnic origin, opinions, health status, trade union membership or other special categories (or data relating to criminal convictions and offences, Art. 10 GDPR), the Controller is solely responsible for ensuring the relevant legal basis and the lawfulness conditions; such data will be processed by hice within the limits of the instructions and with the security measures of Annex C.
ANNEX B — Sub-processors
(Art. 28(4) GDPR — functional categories of Sub-processors authorized as at the effective date of the DPA)
In line with the vendor-agnostic approach adopted by hice, the Sub-processors are described by functional category and not by name. The data are processed in the reference region of this edition (European Union / European Economic Area); any transfers outside that region take place only on an exceptional basis, with the safeguards set out in Annex D.
| Category of Sub-processor | Function | Categories of data processed | Location | Safeguard for any transfers outside the EEA |
|---|---|---|---|---|
| Cloud infrastructure, hosting, database, authentication, storage | Provision and storage of the Service (web application and API, database, identity, file storage, backup) | All Customer Data, account data, files | European Union / EEA | Not envisaged on an ordinary basis; where necessary, safeguards under Chapter V GDPR |
| Payment processing | Management of subscriptions, payments and billing | Customer's payment and billing data | European Union / EEA or with appropriate safeguards | Safeguards under Chapter V GDPR (SCC / adequacy) where the flow is outside the EEA |
| Sending of transactional emails | Invitations, password resets, service notifications | Recipient's email and name, content of the transactional message | European Union / EEA | Not envisaged on an ordinary basis; where necessary, safeguards under Chapter V GDPR |
| Product analytics and diagnostics | Improvement, security and diagnostics of the Service | Usage events, technical identifiers, masked interaction data | European Union / EEA | Not envisaged on an ordinary basis; where necessary, safeguards under Chapter V GDPR |
| Push notifications (optional, opt-in) | Notifications on the mobile app | Device tokens, notification metadata | European Union / EEA or with appropriate safeguards | Safeguards under Chapter V GDPR (SCC / adequacy) where the flow is outside the EEA |
| Processing for the AI Features | Inference of the artificial intelligence models | Prompt text (may contain personal data: CV text, chat content) | European Union / EEA or with appropriate safeguards | Safeguards under Chapter V GDPR (SCC / adequacy) where the flow is outside the EEA |
Integrations chosen by the Customer (mail/calendar «BYO»). When the Controller activates Calendar/Mail synchronization by connecting, with its own OAuth credentials, the mail and calendar services chosen by it, the related processing (calendar events, email metadata) takes place on the Controller's environment at the provider chosen by it: this is a processing activated by the Controller, which is responsible for it as controller and whose locations and safeguards are determined by the chosen provider.
Local processing (not external Sub-processors). Certain operations — in particular optical character recognition and document compression, as well as a fallback AI processing component — are performed by means of software components executed locally on the Service's infrastructure and do not entail communication to third parties.
The updated list of Sub-processors is made available to the Controller pursuant to Art. 6.4 of the DPA.
ANNEX C — Technical and organizational measures (Art. 32)
(measures actually adopted by hice; the list may evolve pursuant to Art. 5.2 of the DPA, without an overall reduction of the level of protection)
C.1 Multi-tenant isolation. Logical separation of each Tenant's data at
the database level: each record is bound to the Tenant identifier (tenant_id)
and row-level security policies prevent access to the data of different Tenants.
Cross-tenant isolation is subject to automated tests.
C.2 Encryption of personal data at rest. Application-level encryption of sensitive personal data (PII) at rest with the AES-256-GCM algorithm and a key derived per individual Tenant, so as to cryptographically segregate the data of the different Customers.
C.3 Encryption of integration tokens. Application-level encryption of the integration OAuth tokens (e.g. Calendar/Mail BYO), stored in encrypted form and not in clear text.
C.4 Encryption in transit. Transmission of data protected via TLS/HTTPS between client, Service and backend components.
C.5 Access control. Role- and permission-based access control (RBAC) with an application-level permission engine and module gating; User authentication managed through the identity provider.
C.6 Least privilege principle. Access of staff and technical components granted on a least privilege basis, limited to what is necessary for the provision of the Service.
C.7 Change log (audit log). Recording of data modification operations (audit log) for security, traceability and verification purposes.
C.8 Backup. Performance of backups, kept on copies also stored on
separate infrastructure (off-site), for business continuity and recovery
purposes, in accordance with the RPO and RTO objectives set out in the
Service Level Agreement (sla-livelli-servizio.md).
C.9 Secrets management. Management of application keys and secrets (credentials, encryption keys, integration secrets) separate from the code, with restricted access.
C.10 Staff confidentiality. Confidentiality undertakings and training of authorized staff (Art. 4 of the DPA).
C.11 Sub-processor management. Selection of Sub-processors that offer appropriate safeguards and imposition of equivalent obligations (Art. 6 of the DPA).
C.12 Features protecting Data Subjects. Human confirmation of write actions suggested by the AI (HITL) and no training of foundation AI models on the Customer Data.
Note: hice does not, as of now, hold third-party certifications (e.g. ISO 27001, SOC 2). These measures describe the actual state of the implementation and do not constitute a certification.
ANNEX D — International transfers
(location of the Processing and safeguards for any transfers to third countries)
D.1 Location and principle. The cloud services and servers used to provide the Service are located in the reference region of this edition (European Union / European Economic Area). Where a processing exceptionally requires a transfer outside that region, it is carried out by adopting appropriate safeguards pursuant to the applicable law (for the EU edition: Chapter V of the GDPR — Standard Contractual Clauses or adequacy decision).
D.2 Categories potentially concerned. Among the functional categories of Sub-processors described in Annex B, those relating to payment processing, push notifications and processing for the AI Features may, depending on the solution adopted, entail a processing outside the EEA; in such a case the safeguards under Art. 46 GDPR (SCC) and/or an adequacy decision apply. The other categories are envisaged within the European Union / EEA.
D.3 BYO mode. For mail and calendar integrations in BYO mode, the clarifications of Art. 11.4 of the DPA apply: the transfer is activated by the Controller on the environment of the provider chosen by it; the Controller remains responsible for the conditions and safeguards of the relationship with that provider.