DATA PROCESSING AGREEMENT
This Data Processing Agreement (“DPA”) forms an integral part of the agreement governing the use of the Twproject hosted service (the “Agreement”) between:
the Customer, as identified in the applicable order, registration or commercial agreement (“Customer” or “Controller”),
and
Twproject S.r.l., with registered office at Via Don Giulio Facibeni 8/A, 50141 Florence (FI), Italy (“Twproject” or “Processor”).
This DPA governs the processing of Personal Data by Twproject on behalf of the Customer in connection with the provision of the Twproject hosted service.
1. Definitions
For the purposes of this DPA:
“Applicable Data Protection Law” means Regulation (EU) 2016/679 (“GDPR”) and any other applicable European Union or Member State data protection legislation.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given to them under the GDPR.
“Customer Data” means information, data, documents, files and other content uploaded, entered, transmitted or otherwise processed through the Service by or on behalf of the Customer or its Users.
“Service” means the Twproject hosted service provided to the Customer under the Agreement.
“Sub-processor” means a third party engaged by Twproject to process Personal Data on behalf of the Customer in connection with the provision of the Service.
“Third-Party Integration” means an optional integration between the Service and a third-party service enabled by the Customer or its Users.
2. Roles and Instructions
Where Personal Data contained in Customer Data is processed by Twproject on behalf of the Customer, the Customer acts as Controller and Twproject acts as Processor.
The Customer determines the purposes and means of the processing and is responsible for ensuring that its processing activities comply with Applicable Data Protection Law.
Twproject will process Personal Data only on documented instructions from the Customer. The Agreement, this DPA and the Customer’s use and configuration of the Service constitute documented instructions for the purposes of this DPA.
Twproject may also process Personal Data where required by applicable European Union or Member State law. In such case, Twproject will inform the Customer of that legal requirement before processing, unless prohibited by law.
If Twproject reasonably believes that an instruction infringes Applicable Data Protection Law, Twproject will inform the Customer without undue delay.
3. Subject Matter, Nature and Purpose of Processing
Twproject processes Personal Data as necessary to provide, operate, maintain, secure and support the Service.
Processing may include:
– hosting and storage;
– organization and retrieval;
– transmission;
– backup and recovery;
– technical maintenance;
– security and operational monitoring;
– troubleshooting and technical support;
– deletion and destruction in accordance with the Agreement and this DPA.
Twproject does not determine the substantive content of Customer Data and does not routinely inspect Customer Data.
Twproject personnel may access Customer Data only where reasonably necessary to provide support requested or authorized by the Customer, operate or secure the Service, perform maintenance, investigate technical or security issues, or comply with applicable law or requests from competent authorities.
4. Duration of Processing
Processing will continue for the duration of the Agreement and for any additional period necessary to complete the deletion and backup retention procedures described in Section 14.
5. Categories of Personal Data
Depending on the Customer’s use of the Service, Personal Data may include:
– names and surnames;
– business contact information, including email addresses and telephone numbers;
– usernames and account identifiers;
– professional and organizational information;
– information relating to projects, tasks, assignments, activities, calendars and work organization;
– documents, communications and other information entered or uploaded by the Customer or its Users;
– technical and usage information associated with operation of the Service;
– any other Personal Data that the Customer or its Users choose to enter or upload into the Service.
The Customer determines which Personal Data is processed through the Service.
The Service is not specifically designed to require the processing of special categories of Personal Data under Article 9 GDPR or Personal Data relating to criminal convictions and offences under Article 10 GDPR.
Where the Customer chooses to process such data through the Service, the Customer is responsible for ensuring that the processing is lawful and that any additional safeguards required by Applicable Data Protection Law are implemented.
6. Categories of Data Subjects
Depending on the Customer’s use of the Service, Data Subjects may include Customer employees, collaborators, contractors, consultants and Users; customers and prospective customers; suppliers and business partners; and other individuals whose Personal Data is entered into the Service by or on behalf of the Customer.
7. Confidentiality and Authorized Personnel
Twproject will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations and receive appropriate information and instructions concerning information security and data protection.
Access to Personal Data will be limited according to role, authorization and operational necessity.
8. Security of Processing
Twproject will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing.
Such measures include, where appropriate:
– logical separation of Customer environments;
– access control and authentication;
– management of privileged access;
– encryption of data in transit using appropriate cryptographic protocols;
– backup and recovery procedures;
– logging and security monitoring;
– vulnerability and security management;
– information security incident management;
– business continuity and recovery procedures;
– organizational measures relating to confidentiality, authorization and information security awareness.
Twproject will review and update its technical and organizational measures as appropriate, taking into account identified risks, technological developments and changes to the Service, provided that such changes do not materially reduce the overall level of protection afforded to Personal Data.
9. Sub-processors
The Customer grants Twproject general written authorization to engage Sub-processors where reasonably necessary to provide, operate, maintain, secure or support the Service.
Twproject will maintain an up-to-date list of the Sub-processors used in connection with the Service and will make such information available to the Customer through an appropriate information channel maintained by Twproject or upon request.
Twproject will inform the Customer in advance of material intended changes concerning the addition or replacement of Sub-processors, giving the Customer a reasonable opportunity to object on legitimate and substantiated data protection grounds.
An objection does not require Twproject to continue using an existing Sub-processor or to refrain from changes reasonably necessary for the provision, security, continuity or operation of the Service.
Twproject ensures that each Sub-processor is subject to contractual data protection obligations appropriate to the processing carried out and consistent with the obligations applicable to Twproject under this DPA.
Twproject remains responsible for the performance of its Sub-processors’ data protection obligations to the extent required by Applicable Data Protection Law.
The current list of Sub-processors is maintained separately from this DPA so that it may be updated without requiring amendment of the DPA and can be reqested by email at support@twproject.com.
10. Third-Party Integrations
The Service may allow the Customer or its Users to enable integrations with third-party services, including external identity, authentication and calendar services.
Where a Third-Party Integration is enabled, Customer Data may be transmitted to or received from the relevant third-party service to the extent necessary to provide the requested integration.
The Customer is responsible for determining whether to enable such integrations and for ensuring that their use is appropriate and lawful for its processing activities.
A third-party service independently selected and enabled by the Customer or its Users will not be considered a Sub-processor appointed by Twproject solely as a result of such integration, unless Twproject independently engages that provider to process Personal Data on its behalf for the provision of the Service.
11. Data Location and International Transfers
Customer Data will be hosted in the data hosting location applicable to the Customer Account, including the region selected or agreed upon by the Customer where such choice is available.
Where the processing of Personal Data involves a transfer outside the European Economic Area (“EEA”), Twproject will ensure that such transfer is carried out in accordance with Chapter V of the GDPR.
Where required, an appropriate transfer mechanism will be used, including, as applicable, an adequacy decision of the European Commission, Standard Contractual Clauses or another lawful safeguard recognized under Applicable Data Protection Law.
Where a Sub-processor processes Personal Data outside the EEA, Twproject will ensure that the engagement of that Sub-processor complies with the applicable international transfer requirements.
12. Data Subject Rights and Assistance
Taking into account the nature of processing and insofar as reasonably possible, Twproject will assist the Customer through appropriate technical and organizational measures in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
Where Twproject receives a request directly from a Data Subject concerning Personal Data processed on behalf of a Customer, Twproject will, where the relevant Customer can reasonably be identified, direct the Data Subject to the Customer or inform the Customer of the request, unless Twproject is legally required to respond directly.
Taking into account the nature of processing and the information available to Twproject, Twproject will also provide reasonable assistance concerning the Customer’s obligations relating to security of processing, Personal Data Breaches, data protection impact assessments and prior consultations with Supervisory Authorities.
13. Personal Data Breaches
Twproject will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer.
To the extent reasonably available, the notification will include information necessary to assist the Customer in complying with Applicable Data Protection Law, including, as applicable:
-the nature of the Personal Data Breach;
– the categories of Personal Data and Data Subjects affected;
– the likely consequences;
– the measures taken or proposed to address and mitigate the breach.
Where complete information is not immediately available, Twproject may provide the information progressively as it becomes available.
Twproject will document Personal Data Breaches in accordance with Applicable Data Protection Law and its internal incident management procedures.
Notification of a Personal Data Breach does not constitute an acknowledgement of fault or liability by Twproject.
14. Return, Deactivation and Deletion of Personal Data
During the term of the Service, the Customer may use the functionality provided by Twproject to export or download Customer Data.
The Customer is responsible for exporting any Customer Data it wishes to retain before the applicable deletion occurs.
Upon expiration or non-renewal of the Customer Account:
– the related Twproject Instance will be deactivated after 7 days;
– after 15 days from the expiration date, on the first business day thereafter, the Instance and associated active Customer Data will be permanently deleted;
– Backup copies of Customer Data are retained in Twproject’s backup systems for 60 days following the deletion of the Instance, after which they are permanently deleted in accordance with Twproject’s backup retention procedures.
During the backup retention period, backup copies remain subject to the security and confidentiality obligations of this DPA and will not be restored or otherwise processed except where necessary for backup recovery, security, legal compliance or legitimate technical operation of the backup systems.
Where applicable law requires Twproject to retain specific Personal Data for a longer period, such data may be retained only to the extent and for the period required by law.
15. Audits and Demonstration of Compliance
Twproject will make available to the Customer, to the extent required by Applicable Data Protection Law, information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this DPA.
Compliance may initially be demonstrated through relevant documentation, security policies, certifications, audit reports or other information reasonably available to Twproject.
Where such information is not reasonably sufficient, the Customer may request an audit concerning the processing of Personal Data performed by Twproject on its behalf.
Any audit will be conducted on reasonable prior written notice, normally during regular business hours, and will be limited to information, systems and processing activities relevant to the Customer’s Personal Data.
Audits must not unreasonably interfere with Twproject’s operations or compromise the security, confidentiality, Personal Data or commercially sensitive information of Twproject or other customers.
The Customer may conduct the audit itself or appoint an independent auditor who is not a competitor of Twproject and is subject to appropriate confidentiality obligations.
Nothing in this Section limits the powers of a competent Supervisory Authority.
16. Records and Cooperation
Twproject will maintain records of processing activities to the extent required by Applicable Data Protection Law for processing performed on behalf of Customers.
Twproject will cooperate with competent Supervisory Authorities where required by Applicable Data Protection Law.
17. Customer Responsibilities
The Customer is responsible for ensuring that it has an appropriate lawful basis for processing Personal Data through the Service and for providing required information to Data Subjects.
The Customer is also responsible for ensuring that its instructions comply with Applicable Data Protection Law, appropriately managing its Users, permissions and access rights, and determining whether the Service and the technical and organizational measures made available by Twproject are appropriate for its intended processing.
Twproject does not determine which Personal Data the Customer chooses to enter or upload into the Service.
18. Liability
Each Party is responsible for its own acts and omissions in accordance with Applicable Data Protection Law.
Nothing in this DPA limits the rights of Data Subjects or the powers of Supervisory Authorities under Applicable Data Protection Law.
As between the Customer and Twproject, liability arising under or in connection with this DPA is subject to the applicable limitations and exclusions of liability contained in the Agreement, to the extent permitted by Applicable Data Protection Law.
19. Order of Precedence
This DPA forms an integral part of the Agreement.
In the event of a conflict between this DPA and the Agreement concerning the processing of Personal Data by Twproject on behalf of the Customer, this DPA will prevail to the extent of that conflict.
All other provisions of the Agreement remain unaffected.
20. Governing Law and Jurisdiction
This DPA is governed by Italian law.
Unless otherwise required by mandatory applicable law, disputes arising out of or relating to this DPA are subject to the exclusive jurisdiction of the Court of Florence, Italy.
21. Entry into Force and Duration
This DPA becomes effective when the Customer enters into the Agreement or otherwise accepts this DPA.
It remains in force for as long as Twproject processes Personal Data on behalf of the Customer, including any applicable backup retention period following termination or expiration of the Service.
Last update: 04/09/2026
