Privacy & GDPR (EN)
Ecco la traduzione in inglese della pagina "Privacy & GDPR (IT)" di Forma Cloud, formattata in Markdown:
Privacy & GDPR
Personal Data Processing (GDPR)
1. Role of the Parties
The Customer acts as the Data Controller. The Provider acts as the Data Processor pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), limited to the data processed as part of the service provision.
1.1 Data Processor Details
Forma Farm S.r.l. Address: via Savona 10 – 20144 Milan
Referent Name, Title and Contact: Alberto Pastorelli, CEO
Administration Email: amministrazione@formafarm.com
2. Personnel Authorized to Process Data
The Provider uses internal staff and external collaborators authorized to process personal data pursuant to Art. 29 of the GDPR.
These subjects:
- Operate under the direct authority of the Provider.
- Are bound by contractual confidentiality obligations.
- Receive documented instructions regarding personal data protection.
- Access data exclusively for technical purposes related to the provision, maintenance, and development of the service.
Access to data is limited to authorized subjects only and follows the principle of data minimization. An updated list of authorized subjects is maintained internally by the Provider and is available to the Controller upon request.
3. Sub-processors
For the provision of services, the Provider may engage sub-processors pursuant to Art. 28 GDPR.
Main Sub-processors
- Cloud Provider: Amazon Web Services (AWS)
- Location: European Union (Primary data center: Dublin, Ireland)
- Service: Cloud infrastructure and application hosting
- Processing: Storage and management of data on infrastructure
The Provider guarantees that sub-processors:
- Are bound by agreements compliant with Art. 28 GDPR.
- Adopt technical and organizational measures appropriate for personal data protection.
The Provider commits to keeping the list of sub-processors updated and communicating any changes to the Controller upon request or through publication in this documentation.
4. Technical and Organizational Measures
The Provider adopts appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Access Control and Authentication: Access to systems is allowed only to authorized personnel via individual credentials, with access profiling and, for administrative accounts, multi-factor authentication (MFA).
- Tracking and Logging: Logging and monitoring systems for access and system activities are implemented, with logs kept for a defined period and protected from unauthorized access.
- Data Encryption: Personal data is protected using encryption protocols during transmission (TLS) and, where applicable, through encryption of data at rest or backup systems.
- Backup and Disaster Recovery: Periodical data backups are performed with restoration verification procedures to ensure system availability and resilience.
- Vulnerability Management and Updates: Procedures are adopted for periodic system updates and vulnerability management to ensure an adequate security level.
- Infrastructure Protection: Via firewalls and security controls.
- Segregation of Environments: (Production, test, development where applicable).
For more details on the implemented technical measures, refer to the document: Infrastructure & Security Standards.
5. Incident Management and Data Breach
The Provider adopts internal procedures for managing security incidents and personal data breaches.
In case of a personal data breach, the Provider:
- Notifies the Controller without undue delay.
- Provides the necessary information to allow the Controller to fulfill obligations under Articles 33 and 34 of the GDPR.
6. Data Transfers
Personal data is processed within the European Economic Area (EEA).
Any transfers to third countries take place in compliance with Chapter V of the GDPR and through adequate safeguards (e.g., Standard Contractual Clauses), where applicable.
7. Duration of Processing
The processing of personal data is limited to the duration of the service provided by the Provider.
At the end of the contractual relationship, data will be deleted or returned to the Controller, unless required by law.
8. Description of Personal Data Processing
8.1 Type of Service
The service consists of providing an LMS (Learning Management System) platform in SaaS mode, including hosting, application maintenance, and technical support.
8.2 Categories of Data Subjects
The processed personal data may concern:
- LMS platform users (Learners)
- Teachers / Trainers
- Platform administrators on the Customer side
- Corporate referents of the Customer
8.3 Categories of Personal Data
Depending on the Customer's configuration, the following may be processed:
- Biographical data (name, surname)
- Contact details (email)
- Access credentials (username, encrypted password)
- Platform usage data (access logs, activities performed)
- Training-related data (courses attended, results, progress)
8.4 Sensitive Data (if present)
The service is not designed for processing special categories of personal data (sensitive data).
However, the Customer may upload content that includes such data. In this case:
- Processing takes place under the Customer's responsibility.
- The Provider applies technical measures appropriate for data protection.
8.5 Nature of the Processing
Processing consists of:
- Data collection and registration
- Organization and storage
- Consultation and use
- Eventual deletion or anonymization
Processing is carried out exclusively for technical and operational purposes related to the service provision.
8.6 Purpose of Processing
Personal data is processed for:
- Delivery and management of the LMS platform.
- Authentication and user management.
- Tracking of training activities.
- Technical assistance and support.
- System security and monitoring.
8.7 Data Retention and Deletion
Data is processed for the entire duration of the contractual relationship with the Customer.
Upon termination of the service:
- Data is deleted or returned upon request.
- Data may be temporarily stored in backup systems according to the Provider's technical policies.
8.8 Scope of Processing by Sub-processors
Sub-processors process data exclusively to:
- Host the infrastructure.
- Ensure system availability and security.
They do not carry out processing for their own purposes.
9. Audit and Verifications
The Provider makes available to the Controller the information necessary to demonstrate compliance with GDPR obligations.
The Controller may request verifications or audit activities, which will be agreed upon in advance between the parties and carried out in a manner that does not compromise system security or the confidentiality of other customers.
Specifically:
- Audits must be notified with reasonable notice.
- They must be limited to aspects relevant to personal data processing.
- They can be carried out directly by the Controller or through appointed third parties.
- They must not involve direct access to production systems, unless otherwise agreed.
The Provider commits to cooperating in good faith and providing documentary evidence of the technical and organizational measures adopted.