Privacy & GDPR (EN)
Agreement and Appointment as Data Processor for Personal Data Processing (GDPR)Standard Version)
1. Role of the Partiesparties
The CustomerClient acts as Data Controller of the Datapersonal Controller.
data.
The Provider acts as the Data Processor pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), limited to the data processed asin partthe context of the service provision.delivery.
1.1 Data Processor Details
details
Forma Farm S.r.l. Address: via Savona 10 – 20144 Milan
Referent Name, Title and Contact: Alberto Pastorelli, CEO
Administration Email: amministrazione@formafarm.com
1.2 Data Protection Officer (DPO)
Forma Farm is not subject to the obligation to appoint a Data Protection Officer (DPO) pursuant to Art. 37 of Regulation (EU) 2016/679 (GDPR) and has not appointed one.
1.3 Organizational model and security governance
Forma Farm adopts an internal organizational structure for the management of information security and personal data protection. This structure includes the definition of roles, responsibilities, and operational processes aimed at ensuring compliance with Regulation (EU) 2016/679 (GDPR) and the secure delivery of services.
In particular, the Provider has implemented a structured set of procedures and organizational controls governing:
These measures constitute the Provider’s internal security organizational framework and are documented in this DPA and in the technical documentation “Infrastructure & Security Standards”.
1.4 Compliance with Arts. 40–42 GDPR
Forma Farm does not currently adhere to any code of conduct pursuant to Art. 40 GDPR nor holds any certification pursuant to Art. 42.
2. Personnel Authorizedauthorized to Processprocess Datadata
The Provider uses internal staffpersonnel and external collaborators authorized to process personal data pursuant to Art. 29 of the GDPR.
TheseSuch subjects:
Operateoperate under the direct authority of theProvider.ProviderAreare bound by contractual confidentialityobligations.obligationsReceivereceive documented instructionsregardingon personal dataprotection.protectionAccessaccess data exclusively for technical purposes related totheserviceprovision,delivery, maintenance, and developmentof the service.
Access to data is limitedrestricted to authorized subjectspersonnel only and followsis granted according to the principle of data minimization.
An updated list of authorized subjectspersonnel is maintained internally by the Provider and ismade available to the Data Controller upon request.
2.1 Assistance to the Data Controller
The Processor shall provide the Controller, taking into account the nature of the processing and the information available to it, with reasonably necessary assistance to enable compliance with obligations under Articles 32 to 36 of the GDPR, as well as to handle data subject requests pursuant to Articles 15–22 of the GDPR.
In particular, the Processor supports the Controller in managing:
3. Sub-processors
For theservice provision of services,delivery, the Provider may engage sub-processors pursuant to Art. 28 GDPR.
3.1 Main Sub-sub-processors
- Cloud
Provider:provider: Amazon Web Services (AWS)Location:Location: European Union (Primaryprimary data center: Dublin, Ireland)Service:Service:Cloudcloud infrastructure and application hostingProcessing:Processing:Storagestorage and management of data on infrastructure
The Provider guaranteesensures that sub-processors:
Areare bound by agreements compliant with Art. 28GDPR.GDPRAdoptimplement appropriate technical and organizational measuresappropriatefor personal dataprotection.protection
The Provider commitsundertakes to keepingkeep the list of sub-processors updated and communicatingto communicate any changes to the Data Controller upon request or through publication inwithin this documentation.
4. Technical and Organizationalorganizational Measuresmeasures (Art. 32 GDPR)
The Provider adopts appropriatea set of procedures and technical and organizational measures for information security and personal data protection management.
These measures govern roles and responsibilities, access management, secure development, vulnerability management, incident response, backup, business continuity, and supplier control.
In detail, the Provider implements appropriate measures to ensure a level of security appropriateproportional to the risk, including:
- Access
Controlcontrol andAuthentication:authentication: Access to systems isallowedgrantedonlyexclusively to authorized personnelviathrough individual credentials, with access profiling and, for administrative accounts, multi-factorauthentication (MFA).authentication. - Tracking and
Logging:logging: Logging and monitoring systems are implemented for access and systemactivities are implemented,activities, with logskeptretained for a defined period and protected from unauthorized access. - Data
Encryption:encryption: Personal data is protectedusingthrough encryption protocols during transmission (TLS) and, where applicable, through encryption of data at rest or backup systems. - Backup and
DisasterdisasterRecovery:recovery:Periodical dataPeriodic backups are performed withrestorationrestore verification procedures to ensure system availability and resilience. - Vulnerability
ManagementandUpdates:update management: Procedures areadoptedin place forperiodicregular system updates and vulnerability management to ensure an adequate security level. - Infrastructure
Protection:protectionViathrough firewalls and securitycontrols.controls - Segregation of
Environments:environments (Production,production,test,testing, development where applicable).
For morefurther details on the implemented technical measures, please refer to the dedicated document: Infrastructure & Security Standards.
5. Incident Management and Datadata Breachbreach management
The Provider adopts internal procedures for managing security incidents and personal data breaches.
In casethe event of a personal data breach, the Provider:
Notifiesnotifies the Data Controller without unduedelay.delayProvidesprovides the information necessaryinformationto allow the Controller tofulfillcomply with obligations underArticlesArts. 33 and 34of the GDPR.GDPR
6. Data Transferstransfers
Personal data isare processed within the European Economic Area (EEA).
Any transfers to third countries takeare placecarried out in compliance with Chapter V of the GDPR and throughsubject adequateto appropriate safeguards (e.g., Standard Contractual Clauses), where applicable.
7. Duration of Processingprocessing
ThePersonal data processing of personal data is limited to the duration of the service provided by the Provider.
AtUpon the endtermination of the contractual relationship, data will be deleted or returned to the Controller,Controller upon request or deleted according to the retention periods stated in the “Infrastructure & Security Standards” documentation, unless otherwise required by law.
8. Description of Personalpersonal Datadata Processingprocessing
8.1 Type of Serviceservice
The service consists of providing an LMS (Learning Management System) platform in SaaS mode, including hosting, application maintenance, and technical support.
8.2 Categories of Datadata Subjectssubjects
The processed personal data processed may concern:relate to:
- LMS platform users (
Learners)learners) Teachersteachers /TrainerstrainersPlatformplatform administrators on theCustomerClient sideCorporateClientreferentscompanyof the Customercontacts
8.3 Categories of Personalpersonal Datadata
Depending on the Customer'Client’s configuration, the following may be processed:
Biographicalpersonal data (name, surname)Contactcontactdetailsdata (email)Accessaccess credentials (username, encrypted password)Platformplatform usage data (access logs,activitiesperformedperformed)activities)Training-training-related data (courses attended, results, progress)
8.4 SensitiveSpecial Datacategories of data (if present)any)
The service is not designed forto processingprocess special categories of personal data (sensitive data).data.
However, the CustomerClient may upload content thatincluding includesspecial suchcategories of data. In thissuch case:cases:
Processingprocessingtakesisplacecarried out under theCustomer'Client’sresponsibility.responsibilityThethe Provider applies appropriate technical measuresappropriatefor dataprotection.protection
8.5 Nature of the Processingprocessing
Processing consists of:
Datacollection andregistrationrecording of dataOrganizationorganization and storageConsultationconsultation and useEventualpossible deletion or anonymization
Processing is carried out exclusively for technical and operational purposes related to the service provision.delivery.
8.6 PurposePurposes of Processingprocessing
Personal data isare processed for:
Deliveryprovision and management of the LMSplatform.platformAuthenticationuser authentication anduser management.managementTrackingtracking of trainingactivities.activitiesTechnicaltechnical assistance andsupport.supportSystemsystem security andmonitoring.monitoring
8.7 Data Retentionretention and Deletiondeletion
Data isare processed for the entire duration of the contractual relationship with the Customer.Client.
Upon termination of the service:
Datadataisare deleted or returned uponrequest.requestDatathey may be temporarilystoredretained in backup systems according to theProvider'Provider’s technicalpolicies.policies
8.8 Scope of Processingprocessing by Sub-sub-processors
Sub-processors process data exclusively to:for:
Hosthosting theinfrastructure.infrastructureEnsureensuring system availability andsecurity.security
They do not carry out processing for their own purposes.
9. Audit and Verificationsverification
The Provider makes available to the Data Controller the information necessary to demonstrate compliance with GDPR obligations.
The Controller may request verificationsaudits or auditverification activities, which willshall be agreed upon in advance between the parties and carried out in such a mannerway that doesas not to compromise system security orand the confidentiality of other customers.clients.
Specifically:In particular:
Auditsaudits must be notified with reasonablenotice.advance noticeTheythey must be limited to aspects relevant to personal dataprocessing.processingTheytheycanmay becarried outconducted directly by the Controller orthroughby appointed thirdparties.partiesTheythey must not involve direct access to production systems, unless otherwiseagreed.agreed
The Provider commitsundertakes to cooperatingcooperate in good faith and providingto provide documentary evidence of the technical and organizational measures adopted.implemented.