Skip to main content

Privacy & GDPR (EN)

Agreement and Appointment as Data Processor for Personal Data Processing (GDPR)Standard Version)

1. Role of the Partiesparties

The CustomerClient  acts as Data Controller of the Datapersonal Controller. data.
The Provider  acts as the Data Processor pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), limited to the data processed asin partthe context of the service provision.delivery.

1.1 Data Processor Details

details

Forma Farm S.r.l. Address: via Savona 10 – 20144 Milan
Referent Name, Title and Contact: Alberto Pastorelli, CEO
Administration Email: amministrazione@formafarm.com

1.2 Data Protection Officer (DPO)

Forma Farm is not subject to the obligation to appoint a Data Protection Officer (DPO) pursuant to Art. 37 of Regulation (EU) 2016/679 (GDPR) and has not appointed one.

1.3 Organizational model and security governance

Forma Farm adopts an internal organizational structure for the management of information security and personal data protection. This structure includes the definition of roles, responsibilities, and operational processes aimed at ensuring compliance with Regulation (EU) 2016/679 (GDPR) and the secure delivery of services.

In particular, the Provider has implemented a structured set of procedures and organizational controls governing:

    access management to systems and data secure development and maintenance of platforms vulnerability management and security updates security incident and data breach management backup and business continuity processes

    These measures constitute the Provider’s internal security organizational framework and are documented in this DPA and in the technical documentation “Infrastructure & Security Standards”.

    1.4 Compliance with Arts. 40–42 GDPR

    Forma Farm does not currently adhere to any code of conduct pursuant to Art. 40 GDPR nor holds any certification pursuant to Art. 42.


    2. Personnel Authorizedauthorized to Processprocess Datadata

    The Provider uses internal staffpersonnel and external collaborators authorized to process personal data pursuant to Art. 29 of the GDPR.

    TheseSuch subjects:

    • Operateoperate under the direct authority of the Provider.Provider
    • Areare bound by contractual confidentiality obligations.obligations
    • Receivereceive documented instructions regardingon personal data protection.protection
    • Accessaccess data exclusively for technical purposes related to theservice provision,delivery, maintenance, and development of the service.

    Access to data is limitedrestricted to authorized subjectspersonnel only and followsis granted according to the principle of data minimization.

    An updated list of authorized subjectspersonnel is maintained internally by the Provider and ismade available to the Data Controller upon request.

    2.1 Assistance to the Data Controller

    The Processor shall provide the Controller, taking into account the nature of the processing and the information available to it, with reasonably necessary assistance to enable compliance with obligations under Articles 32 to 36 of the GDPR, as well as to handle data subject requests pursuant to Articles 15–22 of the GDPR.

    In particular, the Processor supports the Controller in managing:

      security of processing and technical and organizational measures (Art. 32) notification of personal data breaches to the supervisory authority (Art. 33) communication of data breaches to data subjects (Art. 34) data protection impact assessments (DPIA) (Art. 35) prior consultations with the supervisory authority (Art. 36) requests for the exercise of data subject rights

      3. Sub-processors

      For theservice provision of services,delivery, the Provider may engage sub-processors pursuant to Art. 28 GDPR.

      3.1 Main Sub-sub-processors

      • Cloud Provider:provider: Amazon Web Services (AWS)
        • Location:Location: European Union (Primaryprimary data center: Dublin, Ireland)
        • Service:Service: Cloudcloud infrastructure and application hosting
        • Processing:Processing: Storagestorage and management of data on infrastructure

      The Provider guaranteesensures that sub-processors:

      • Areare bound by agreements compliant with Art. 28 GDPR.GDPR
      • Adoptimplement appropriate technical and organizational measures appropriate for personal data protection.protection

      The Provider commitsundertakes to keepingkeep the list of sub-processors updated and communicatingto communicate any changes to the Data Controller upon request or through publication inwithin this documentation.


      4. Technical and Organizationalorganizational Measuresmeasures (Art. 32 GDPR)

      The Provider adopts appropriatea set of procedures and technical and organizational measures for information security and personal data protection management.

      These measures govern roles and responsibilities, access management, secure development, vulnerability management, incident response, backup, business continuity, and supplier control.

      In detail, the Provider implements appropriate measures to ensure a level of security appropriateproportional to the risk, including:

      • Access Controlcontrol and Authentication:authentication: Access to systems is allowedgranted onlyexclusively to authorized personnel viathrough individual credentials, with access profiling and, for administrative accounts, multi-factor authentication (MFA).authentication.
      • Tracking and Logging:logging: Logging and monitoring systems are implemented for access and system activities are implemented,activities, with logs keptretained for a defined period and protected from unauthorized access.
      • Data Encryption:encryption: Personal data is protected usingthrough encryption protocols during transmission (TLS) and, where applicable, through encryption of data at rest or backup systems.
      • Backup and Disasterdisaster Recovery:recovery: Periodical dataPeriodic backups are performed with restorationrestore verification procedures to ensure system availability and resilience.
      • Vulnerability Management and Updates:update management: Procedures are adoptedin place for periodicregular system updates and vulnerability management to ensure an adequate security level.
      • Infrastructure Protection:protection Viathrough firewalls and security controls.controls
      • Segregation of Environments:environments (Production,production, test,testing, development where applicable).

      For morefurther details on the implemented technical measures, please refer to the dedicated document: Infrastructure & Security Standards.


      5. Incident Management and Datadata Breachbreach management

      The Provider adopts internal procedures for managing security incidents and personal data breaches.

      In casethe event of a personal data breach, the Provider:

      • Notifiesnotifies the Data Controller without undue delay.delay
      • Providesprovides the information necessary information to allow the Controller to fulfillcomply with obligations under ArticlesArts. 33 and 34 of the GDPR.GDPR

      6. Data Transferstransfers

      Personal data isare processed within the European Economic Area (EEA).

      Any transfers to third countries takeare placecarried out in compliance with Chapter V of the GDPR and throughsubject adequateto appropriate safeguards (e.g., Standard Contractual Clauses), where applicable.


      7. Duration of Processingprocessing

      ThePersonal data processing of personal data is limited to the duration of the service provided by the Provider.

      AtUpon the endtermination of the contractual relationship, data will be deleted or returned to the Controller,Controller upon request or deleted according to the retention periods stated in the “Infrastructure & Security Standards” documentation, unless otherwise required by law.


      8. Description of Personalpersonal Datadata Processingprocessing

      8.1 Type of Serviceservice

      The service consists of providing an LMS (Learning Management System) platform in SaaS mode, including hosting, application maintenance, and technical support.


      8.2 Categories of Datadata Subjectssubjects

      The processed personal data processed may concern:relate to:

      • LMS platform users (Learners)learners)
      • Teachersteachers / Trainerstrainers
      • Platformplatform administrators on the CustomerClient side
      • CorporateClient referentscompany of the Customercontacts

      8.3 Categories of Personalpersonal Datadata

      Depending on the Customer'Client’s configuration, the following may be processed:

      • Biographicalpersonal data (name, surname)
      • Contactcontact detailsdata (email)
      • Accessaccess credentials (username, encrypted password)
      • Platformplatform usage data (access logs, activitiesperformed performed)activities)
      • Training-training-related data (courses attended, results, progress)

      8.4 SensitiveSpecial Datacategories of data (if present)any)

      The service is not designed forto processingprocess special categories of personal data (sensitive data).data.

      However, the CustomerClient may upload content thatincluding includesspecial suchcategories of data. In thissuch case:cases:

      • Processingprocessing takesis placecarried out under the Customer'Client’s responsibility.responsibility
      • Thethe Provider applies appropriate technical measures appropriate for data protection.protection

      8.5 Nature of the Processingprocessing

      Processing consists of:

      • Data collection and registrationrecording of data
      • Organizationorganization and storage
      • Consultationconsultation and use
      • Eventualpossible deletion or anonymization

      Processing is carried out exclusively for technical and operational purposes related to the service provision.delivery.


      8.6 PurposePurposes of Processingprocessing

      Personal data isare processed for:

      • Deliveryprovision and management of the LMS platform.platform
      • Authenticationuser authentication and user management.management
      • Trackingtracking of training activities.activities
      • Technicaltechnical assistance and support.support
      • Systemsystem security and monitoring.monitoring

      8.7 Data Retentionretention and Deletiondeletion

      Data isare processed for the entire duration of the contractual relationship with the Customer.Client.

      Upon termination of the service:

      • Datadata isare deleted or returned upon request.request
      • Datathey may be temporarily storedretained in backup systems according to the Provider'Provider’s technical policies.policies

      8.8 Scope of Processingprocessing by Sub-sub-processors

      Sub-processors process data exclusively to:for:

      • Hosthosting the infrastructure.infrastructure
      • Ensureensuring system availability and security.security

      They do not carry out processing for their own purposes.


      9. Audit and Verificationsverification

      The Provider makes available to the Data Controller the information necessary to demonstrate compliance with GDPR obligations.

      The Controller may request verificationsaudits or auditverification activities, which willshall be agreed upon in advance between the parties and carried out in such a mannerway that doesas not to compromise system security orand the confidentiality of other customers.clients.

      Specifically:In particular:

      • Auditsaudits must be notified with reasonable notice.advance notice
      • Theythey must be limited to aspects relevant to personal data processing.processing
      • Theythey canmay be carried outconducted directly by the Controller or throughby appointed third parties.parties
      • Theythey must not involve direct access to production systems, unless otherwise agreed.agreed

      The Provider commitsundertakes to cooperatingcooperate in good faith and providingto provide documentary evidence of the technical and organizational measures adopted.implemented.