Data Processing Agreement
GDPR Article 28 — Last updated: June 2026
This Data Processing Agreement ("DPA") is entered into between PII Protect S.r.l. ("Processor") and the customer ("Controller") and supplements the Terms of Service.
1. Subject matter and nature of processing
Processor provides PII anonymization services. Processing involves tokenizing and replacing personal data in text passed via the API. Processor does not persistently store original personal data — only anonymized tokens and mapping references scoped to the Controller's tenant.
2. Duration
Processing continues for the duration of the Terms of Service. Upon termination, mapping data is deleted within 30 days unless otherwise required by law.
3. Controller obligations
Controller warrants it has a lawful basis to process the personal data submitted to the API and to authorize Processor to process it on Controller's behalf.
4. Processor obligations
- Process data only on documented instructions from Controller.
- Ensure confidentiality obligations are binding on all authorized personnel.
- Implement appropriate technical and organizational security measures (Art. 32 GDPR).
- Notify Controller of any data breach without undue delay (within 72 h of becoming aware).
- Assist Controller in responding to data subject rights requests.
- Delete or return all personal data upon termination at Controller's choice.
- Provide all information necessary to demonstrate compliance and allow audits.
5. Sub-processors
Processor uses the sub-processors listed in the Privacy Policy. Controller grants general authorization. Processor will notify Controller of any changes with 30 days' notice.
6. International transfers
Data is processed within the EU/EEA. Any transfer outside the EU relies on Standard Contractual Clauses (EU Commission Decision 2021/914).
7. Signing this DPA
Enterprise customers requiring a signed DPA should contact [email protected]. For customers using the standard plan, acceptance of the Terms of Service constitutes agreement to this DPA.