Data Controller (Art. 4(7) GDPR): Customer
Data Processor (Art. 4(8) GDPR): D-One Software House di Sbreviglieri Davide – Registered Office: Via Genova, 12 – 41012 Carpi (MO), Italy – VAT No.: IT02211990367 – The Nios4 Platform is the exclusive property of D-One di Sbreviglieri Davide.
Version: 1.1
Last Updated: January 15, 2026
This Data Processing Agreement ("DPA") governs the processing of personal data carried out by the Data Processor on behalf of the Data Controller in connection with the provision of the Nios4 Cloud Software-as-a-Service (SaaS) platform and the related services.
This DPA constitutes the formal appointment of the Data Processor pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR") and sets out the rights and obligations of the Parties with respect to the processing of personal data carried out in connection with the provision of the Nios4 Cloud service.
D-One provides and licenses the Nios4 Software-as-a-Service (SaaS) platform. In accordance with the GDPR, the Parties acknowledge and agree that:
-------------------------------------------------------------------------------------------------------------------------
1.1. This Data Processing Agreement ("DPA") governs the processing of personal data carried out by the Data Processor on behalf of the Data Controller in connection with the provision of the Nios4 Cloud service.
1.2. This DPA constitutes the formal appointment of the Data Processor pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and includes all mandatory contractual clauses required under Article 28(3) GDPR.
1.3. This DPA is published as an online document and is expressly referenced during the purchase, registration, and/or activation process of the Nios4 Cloud free trial. Online acceptance of this DPA constitutes a legally binding agreement between the parties.
1.4. This DPA forms an integral part of the Nios4 Cloud Contractual Documents, including the Terms of Service and the Software License Terms.
2.1. Within the scope of the Nios4 Cloud service:
the Customer acts as the Data Controller pursuant to Article 4(7) GDPR;
D-One Software House / Nios4 acts as the Data Processor pursuant to Article 4(8) GDPR.
2.2. The Data Processor shall process personal data solely on behalf of the Data Controller and exclusively for the purposes strictly necessary to provide the Nios4 Cloud service.
3.1. This DPA governs the processing of personal data carried out by the Data Processor for the purpose of providing the Nios4 Cloud service to the Data Controller, including, but not limited to, the following activities:
application hosting and infrastructure management;
technical data storage and retention;
data processing necessary for the operation of the service;
technical support, maintenance, and customer assistance;
backup and disaster recovery operations;
security monitoring and incident prevention.
4.1. The processing of personal data shall continue for the entire duration of the contractual relationship, including any free trial period.
4.2. Upon termination of the service, the Data Processor shall continue processing personal data solely for the purposes of:
enabling the Data Controller to export its data;
securely deleting personal data;
maintaining technical backup copies for limited retention periods;
complying with applicable legal obligations.
5.1. The nature of the processing may include, without limitation, the following operations:
collection, recording, and organization;
storage, consultation, and retrieval;
processing and modification;
deletion or destruction;
access through web and mobile applications.
5.2. The sole purpose of the processing is to enable the Data Controller to use the Nios4 Cloud service.
6.1. The service may involve the processing of the following categories of personal data, by way of example:
identification and personal data;
contact information (such as email addresses, telephone numbers, and postal addresses);
business, administrative, and commercial data (such as orders, customer information, and business documents);
data relating to the Data Controller's employees, agents, or contractors;
technical and security data (including logs, IP addresses, timestamps, and session identifiers).
6.2. The Data Controller acknowledges that the Nios4 Platform is a general-purpose software platform and that the categories of personal data processed depend entirely on the information entered into the system by the Data Controller and its authorized users.
The categories of data subjects may include:
the Data Controller's customers and prospective customers;
employees and contractors;
agents and consultants;
suppliers and business contacts.
8.1. The Data Processor shall process personal data exclusively on the documented instructions of the Data Controller.
8.2. The Data Controller's documented instructions consist of:
this Data Processing Agreement (DPA);
the configuration and use of the Nios4 Cloud service by the Data Controller;
requests submitted through the official support channels.
8.3. If the Data Processor considers that any instruction infringes the GDPR or any other applicable data protection law, it shall promptly inform the Data Controller without undue delay.
9.1. The Data Processor shall ensure that all personnel authorized to process personal data:
are bound by appropriate confidentiality obligations;
access personal data solely where necessary for technical support and service delivery purposes;
operate in accordance with the Data Processor's internal security policies and procedures.
10.1. The Data Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
10.2. Such measures include, by way of example:
authentication using individual user credentials;
user role and permission management;
application of the principle of least privilege.
use of Amazon Web Services (AWS) cloud infrastructure with data centers located within the European Union (Ireland);
segregation of production environments;
infrastructure hardening and regular security updates.
encryption of data in transit using TLS/HTTPS;
protection of APIs and user sessions.
regular backup procedures;
data recovery procedures;
data integrity verification controls.
technical logging for audit and security purposes;
monitoring of anomalous events and unauthorized access attempts.
internal incident response procedures;
vulnerability management and mitigation processes.
10.3. The Data Controller acknowledges that the overall security of the service also depends on the security measures implemented by the Data Controller, including, without limitation, password management, user administration, endpoint security, and device protection.
11.1. The Data Controller hereby grants the Data Processor general authorization to engage sub-processors where necessary for the provision of the Nios4 Cloud service.
11.2. In particular, the Data Processor uses the following infrastructure sub-processor:
Amazon Web Services (AWS) – cloud hosting and infrastructure services
Processing Region: European Union (Ireland)
11.3. The Data Processor shall ensure that all sub-processors are bound by written agreements compliant with Article 28(4) GDPR and subject to data protection obligations that are no less protective than those set out in this Data Processing Agreement.
11.4. An up-to-date list of sub-processors may be published in a dedicated section of the Nios4 website or provided to the Data Controller upon request.
12.1. The Data Processor declares that, for the standard provision of the Nios4 Cloud service, personal data is processed within the European Economic Area (EEA), with the primary infrastructure hosted on Amazon Web Services (AWS) in Ireland.
12.2. Should it become necessary, for technical, maintenance, or specific ancillary service purposes, to transfer personal data outside the EEA, the Data Processor shall ensure that such transfers are carried out in compliance with Articles 44 et seq. of the GDPR by relying on:
the Standard Contractual Clauses (SCCs) approved by the European Commission; and/or
any other valid transfer mechanism recognized under the GDPR.
12.3. Unless required for technical or contractual reasons, the Data Processor shall not transfer personal data outside the EEA.
13.1. Taking into account the nature of the processing, the Data Processor shall assist the Data Controller in fulfilling its obligations to respond to requests for the exercise of data subjects' rights under Articles 12–22 GDPR.
13.2. If the Data Processor receives a request directly from a data subject, it shall promptly inform the Data Controller and shall not respond directly unless required to do so by applicable law.
14.1. Taking into account the nature of the processing and the information available to it, the Data Processor shall assist the Data Controller in ensuring compliance with the obligations set out in Articles 32–36 GDPR, including, where applicable, the performance of Data Protection Impact Assessments (DPIAs) and prior consultations with the competent supervisory authority.
15.1. In the event of a personal data breach affecting personal data processed on behalf of the Data Controller, the Data Processor shall notify the Data Controller without undue delay and, where feasible, no later than 48 hours after becoming aware of the breach.
15.2. Where available, the notification shall include:
a description of the nature of the personal data breach;
the categories and approximate volume of personal data affected;
the categories and approximate number of data subjects concerned;
the measures taken or proposed to mitigate the effects of the incident;
the contact details of the technical point of contact for follow-up communications.
15.3. The Data Processor shall cooperate with the Data Controller to enable the Data Controller to comply with its notification obligations towards the competent supervisory authority and, where applicable, the affected data subjects, pursuant to Articles 33 and 34 GDPR.
16.1. Upon termination of the service, the Data Controller may:
export its data using the functionalities made available within the service; or
request that the Data Processor provide a data export, where technically feasible.
16.2. Unless otherwise required by applicable law or necessary for technical backup purposes, the Data Processor shall delete all personal data from its production systems within 30 days following termination of the service.
16.3. Residual copies of personal data contained in backup systems may be retained only for the period strictly necessary in accordance with the applicable technical retention cycles and, in any event, for no longer than 90 days, after which they shall be automatically overwritten or permanently deleted.
16.4. Following termination of the service, the Data Processor shall not process or otherwise use the personal data, except as expressly permitted under this Article or where required by applicable law.
17.1. The Data Processor shall make available to the Data Controller all information reasonably necessary to demonstrate compliance with this Data Processing Agreement and with the obligations set out in Article 28 GDPR.
17.2. Audits and inspections may be requested by the Data Controller on a reasonable and proportionate basis, taking into account:
the nature of the multi-tenant cloud service;
the security of the service;
the confidentiality and protection of other customers' information.
17.3. Where appropriate, the Data Processor may provide technical documentation, security policies, certifications, or compliance reports as an alternative to on-site audits.
18.1. The Data Processor shall not use personal data processed on behalf of the Data Controller for its own purposes, including, without limitation, marketing, profiling, or commercial sale.
18.2. This limitation does not apply to processing activities carried out by the Data Processor acting as an independent Data Controller for its own legal and business purposes, including:
invoicing;
administrative management;
compliance with legal, accounting, and tax obligations.
19.1. The Data Controller represents and warrants that:
the processing of personal data is lawful and based on an appropriate legal basis;
data subjects have been provided with the required privacy notices in accordance with the GDPR;
requests from data subjects are managed in compliance with applicable data protection legislation.
19.2. The Data Controller undertakes to:
properly manage users, access permissions, and authentication credentials;
refrain from entering personal data that is unnecessary for the intended purposes;
use the Nios4 Cloud service in compliance with applicable laws and regulations.
20.1. This Data Processing Agreement is published as an online document and is expressly referenced during the following processes:
purchase of the Nios4 Cloud service;
account registration;
activation of the free trial.
20.2. Acceptance is provided through electronic mechanisms (such as a checkbox) and constitutes a valid appointment of the Data Processor pursuant to Article 28 GDPR, producing full legal effect between the parties.
This Data Processing Agreement shall be governed by the laws of the European Union and, to the extent not regulated by EU law, by the laws of the Republic of Italy.
For any questions relating to this Data Processing Agreement or the processing of personal data within the Nios4 Cloud service, the Data Controller may contact the support team through the communication channels indicated in the Nios4 Cloud Terms of Service.
| Item | Description |
|---|---|
| Service | Nios4 Cloud |
| Data Controller | Customer (Article 4(7) GDPR) |
| Data Processor | D-One / Nios4 (Article 4(8) GDPR) |
| Primary Sub-processor | Amazon Web Services (AWS) – European Union Region (Ireland) |
| Subject Matter | Cloud hosting, Software-as-a-Service (SaaS) platform, and technical support services |
| Duration | Annual SaaS subscription, including integrated functionalities allowing the complete export of the database, together with all stored data and customized database structure. If the Customer permanently deletes the owner account, all Cloud databases associated with that account are automatically and permanently deleted. |
| Personal Data Breach Notification | Where feasible, within 48 hours after becoming aware of the breach. |
| Deletion upon Cloud Service Expiration | Personal data stored in production systems is deleted within 30 days following expiration or termination of the Cloud service. Residual backup copies may be retained for a maximum of 90 days before being automatically overwritten or permanently deleted. |
| Transfers Outside the EEA | The Nios4 Cloud service is hosted on Amazon Web Services (AWS) infrastructure located in the European Union (Ireland). Under normal operating conditions, all personal data remains within the European Economic Area (EEA). Transfers outside the EEA are carried out only where technically or contractually necessary and exclusively in compliance with Articles 44 et seq. GDPR, using the Standard Contractual Clauses (SCCs) approved by the European Commission or another valid transfer mechanism recognized under the GDPR. |
D-One may use Artificial Intelligence (AI) systems to support software development, technical documentation, customer support, and the delivery of application features.
AI-generated outputs provided to the Customer are subject to human oversight or validation procedures appropriate to their intended purpose. The Customer agrees to use AI-powered features in accordance with the instructions provided by D-One and shall refrain from using such features for unauthorized purposes, including automated evaluation of individuals, disciplinary decision-making, profiling, or the processing of data that is not relevant to the intended purpose.
Where the Customer requests AI-based configurations or functionalities that may have a significant impact on natural persons, the Parties shall carry out a separate assessment of the proposed use in accordance with the requirements of the EU AI Act, the General Data Protection Regulation (GDPR), and any other applicable laws and regulations.