Business
Accordo sul trattamento dei dati
Condizioni dell’articolo 28 per i dati personali trattati tramite Colver.
- Ultimo aggiornamento
- 5 settembre 2026
- Gestore
- Colver.im
1. Scope and roles
This Data Processing Addendum (DPA) applies when a customer subject to the GDPR or equivalent data-protection law uses Colver to process personal data on its behalf. It forms part of the agreement between that customer (Controller) and Colver.im (Processor).
The Controller determines the purposes and essential means of processing Customer Personal Data. Colver processes that data only to provide and secure the service, on the Controller's documented instructions, and as required by law.
2. Instructions and compliance
The agreement, agent configuration, approved tools, user actions, and support requests are documented instructions. Colver will notify the Controller if it believes an instruction violates applicable data-protection law, unless prohibited from doing so.
The Controller is responsible for lawful instructions, notices, legal bases, data accuracy, and the rights to provide data and connect accounts. The Controller must not configure Colver for prohibited high-risk processing without a separate written assessment and agreement.
3. Confidentiality and security
People authorised to process Customer Personal Data are bound by confidentiality. Colver applies measures appropriate to risk, including authenticated access, logical tenant and principal isolation, encrypted transport, private object storage, encrypted write-only secrets, scoped tools, approval controls, request limits, security logging, and recovery procedures.
The Controller remains responsible for its users, endpoint security, tool permissions, connected services, and review of agent actions.
4. Subprocessors
The Controller gives general authorisation for the subprocessors in the current Subprocessor List. Colver remains responsible for requiring materially equivalent data-protection duties from each subprocessor.
Colver will provide reasonable notice of a new subprocessor where required. The Controller may object on reasonable data-protection grounds. The parties will work in good faith on a practical solution; if none exists, the Controller may stop the affected feature or terminate the affected service.
5. Assistance
Taking into account the nature of processing, Colver will provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. Additional work outside normal product controls may be charged at an agreed rate where the law allows.
Colver will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide available information needed for the Controller's assessment and notices.
6. Restricted transfers
Colver uses EU regions where supported, but some subprocessors and configured destinations can process data outside the EEA. A restricted transfer will use an applicable adequacy decision, the EU Standard Contractual Clauses, or another valid mechanism. The parties incorporate the appropriate controller-to-processor clauses when required, with the Controller as data exporter and Colver as data importer.
7. Return and deletion
At the end of the service, Colver will delete or return Customer Personal Data on request, unless law requires retention. Deletion from backups follows the ordinary protected-backup cycle. Colver may retain billing, security, dispute, and legal records that are not Customer Personal Data processed solely on behalf of the Controller.
8. Information and audit
Colver will make information reasonably necessary to demonstrate Article 28 compliance available to the Controller. Audits should first use current documentation, questionnaires, and independent reports. An on-site or intrusive audit requires reasonable notice, confidentiality, minimal disruption, and agreement on scope and cost, unless a regulator or serious incident requires otherwise.
Annex: processing details
| Item | Description |
|---|---|
| Subject matter | Agent building and operation, chats, files, memory, approved tools and connectors, shared-agent sessions, support, security, and observability |
| Duration | For the agreement term and the limited deletion or legal-retention period described above |
| Nature and purpose | Collection, storage, organisation, retrieval, analysis, generation, transmission, display, restriction, and deletion to provide the configured service |
| Data subjects | Controller users, workers, customers, suppliers, contacts, shared-agent visitors, and other people represented in Customer Personal Data |
| Data types | Identity and contact data, communications, documents, account and connector data, business records, usage data, and other data selected by the Controller |
| Special categories | Not intended by default. The Controller must not submit them unless lawful, necessary, proportionate, and expressly supported by the configured workflow |