Passa al contenuto

Data Processing Agreement

Dolcefy S.R.L.S. Data Processing Agreement


Last updated 7.6.2026

This Data Processing Agreement ("DPA") was last updated on [publication date] and forms part of, and is incorporated by reference into, the Dolcefy Terms and Conditions (the "Agreement") between Dolcefy and the Customer. It applies whenever Dolcefy processes personal data on behalf of the Customer in connection with the Services.

In the event of any conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Applicable Data Protection Law" means the GDPR and any Italian and EU laws governing the processing of personal data that apply to the parties.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given to them in the GDPR.

"Customer Personal Data" means personal data contained in the Customer Content that Dolcefy processes on behalf of the Customer in providing the Services.

"Sub-processor" means any third party engaged by Dolcefy to process Customer Personal Data.

Terms defined in the Agreement and not defined here have the meaning given to them in the Agreement.

2. Roles of the Parties

In respect of Customer Personal Data, the Customer acts as the Controller and Dolcefy acts as the Processor. Where the Customer is itself a processor acting on behalf of a third party, the Customer warrants that it is authorised to engage Dolcefy as a sub-processor and that its instructions reflect those of the relevant controller.

Dolcefy acts as an independent Controller in respect of personal data it processes for its own purposes, such as account administration, billing, security, and improvement of the Services. That processing is described in the Dolcefy Privacy Policy and is outside the scope of this DPA.

The details of the processing carried out by Dolcefy as Processor (subject matter, duration, nature, purpose, types of personal data, and categories of data subjects) are set out in Annex A.

3. Processing on Documented Instructions

Dolcefy shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by EU or Italian law, in which case Dolcefy shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Agreement, this DPA, and the Customer's use and configuration of the Services constitute the Customer's complete and documented instructions. If Dolcefy considers that an instruction infringes Applicable Data Protection Law, it shall inform the Customer without undue delay.

4. Customer Obligations

The Customer is responsible for the lawfulness of the Customer Personal Data and of the instructions it gives. In particular, the Customer warrants that it has a valid lawful basis for the processing, that it has provided all required information to data subjects, that it has obtained and can demonstrate any required consent, and that it is entitled to transfer the Customer Personal Data to Dolcefy for processing under this DPA.

The Customer shall not load into the Services any special categories of personal data within the meaning of Article 9 GDPR unless strictly necessary, and accepts that it does so under its own responsibility and lawful basis.

5. Confidentiality

Dolcefy shall ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory, and process the data only as necessary to provide the Services.

6. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, Dolcefy shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. A description of these measures is set out in Annex B. Dolcefy takes data protection by design and by default into account in the development and operation of the Platform, in accordance with Article 25 GDPR. Dolcefy may update its measures from time to time, provided the level of protection is not reduced.

7. Sub-processors

The Customer grants Dolcefy general authorisation to engage Sub-processors to process Customer Personal Data, subject to this Section. The current Sub-processors are listed in Annex C.

Dolcefy shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, and Dolcefy remains fully liable to the Customer for the performance of each Sub-processor's obligations.

Dolcefy shall inform the Customer in advance of any intended addition or replacement of a Sub-processor, giving the Customer a reasonable period to object on reasonable data protection grounds. If the Customer objects and the parties cannot agree on a resolution, the Customer may terminate the affected Services as its sole remedy.

8. International Transfers

Dolcefy processes Customer Personal Data within the European Union and the European Economic Area and does not transfer it to the United States.

Dolcefy shall not transfer Customer Personal Data to a country outside the EEA unless that country is covered by an adequacy decision of the European Commission, or unless appropriate safeguards within the meaning of Article 46 GDPR, such as the Standard Contractual Clauses, are in place. Where any Sub-processor is located in a third country, the basis for the transfer is identified in Annex C.

This commitment covers Dolcefy's own processing and the Sub-processors listed in Annex C. It does not cover third-party services that you choose to connect to or use within the Platform, such as an external payment provider, analytics tool, or other integration. Those services are not Dolcefy Sub-processors. In respect of them you act as the controller or contracting party, and you are responsible for the lawfulness of any transfer of personal data to them, including any transfer outside the EEA. If you wish to keep all processing within the EEA, you should connect only providers that process personal data within the EEA.

Card and wallet payments involve independent providers. Our payment provider is European, but where a payer chooses to pay using an international card scheme or a mobile wallet, for example a Visa or Mastercard card or Apple Pay or Google Pay, that scheme or wallet operator processes the payment data as an independent controller and may be established outside the EEA. This is inherent to accepting those payment methods and is not a transfer made by Dolcefy.

9. Assistance with Data Subject Rights

Taking into account the nature of the processing, Dolcefy shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests by data subjects exercising their rights under Chapter III GDPR. Where a data subject contacts Dolcefy directly in relation to Customer Personal Data, Dolcefy shall, where lawful, refer the data subject to the Customer.

10. Assistance with Compliance

Taking into account the nature of the processing and the information available to it, Dolcefy shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, namely security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation with a Supervisory Authority.

11. Personal Data Breach Notification

Dolcefy shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Dolcefy shall provide further information as it becomes available. It is the Customer's responsibility, as Controller, to notify the Supervisory Authority and affected data subjects where required.

12. Deletion or Return of Data

On termination or expiry of the Services, Dolcefy shall, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless EU or Italian law requires storage. The Customer may export Customer Personal Data during the retrieval period described in the Agreement. After that period, Dolcefy may delete Customer Personal Data from active systems, subject to deletion from backups in the ordinary course of Dolcefy's backup cycle.

13. Audits and Information

Dolcefy shall make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

The Customer shall give reasonable prior notice, audits shall take place during normal business hours and not more than once per year unless required by a Supervisory Authority or following a Personal Data Breach, and the parties shall conduct them in a manner that does not disrupt Dolcefy's operations or compromise the confidentiality or security of other customers' data. Dolcefy may satisfy this obligation by providing a relevant certification or third-party report where available.

14. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

15. Duration

This DPA takes effect when the Customer accepts the Agreement and continues for as long as Dolcefy processes Customer Personal Data on behalf of the Customer. The obligations that by their nature should survive, including those relating to deletion, confidentiality, and audit, continue after termination.

16. General

This DPA is governed by the laws of Italy, and any dispute is subject to the dispute resolution and jurisdiction provisions of the Agreement. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full effect.

Annex A: Details of the Processing

Subject matter. The provision of the Dolcefy software-as-a-service platform and its features to the Customer.

Duration. For the term of the Customer's subscription and any retrieval and deletion period that follows, as set out in the Agreement and this DPA.

Nature and purpose. Hosting, storage, organisation, retrieval, transmission, and other processing of Customer Personal Data as necessary to provide the Services, which may include website and funnel hosting, content and course delivery, contact and customer management, marketing automation, email sending through Dolcefy Email, facilitation of payments, and assistant and generative features.

Types of personal data. The personal data the Customer chooses to process through the Services, which may include: identification and contact data such as names, email addresses, postal addresses, and telephone numbers; account and profile data of the Customer's contacts; communication content and engagement data such as message activity, opens, and clicks; transaction and order data; and any other data the Customer loads into the Services.

Categories of data subjects. The Customer's own customers, clients, subscribers, students, prospects, contacts, and other individuals whose data the Customer processes through the Services.


Annex B: Technical and Organisational Measures

Dolcefy is the sole developer and operator of the Platform and maintains technical and organisational measures appropriate to the risk. The measures currently in place include:

  • Hosting location. The Platform is hosted in the European Union, in Hetzner's data centre in Helsinki, Finland. Hetzner is an ISO 27001 certified provider.
  • Network firewall. A cloud firewall is applied to the server, restricting inbound traffic to permitted ports.
  • Encryption in transit. All traffic between users and the Platform is protected with TLS, using certificates that are renewed automatically, across all domains and subdomains.
  • Backups. Automated daily server backups are maintained through Hetzner Cloud Backups, with seven days of retention, supporting restoration of availability.
  • Automatic security updates. The operating system applies security updates automatically.
  • Access control. Administrative access uses SSH public-key authentication and is restricted to authorised personnel.
  • Tenant separation. Each Customer operates within a logically separated tenant database.


Annex C: Sub-processors

The following Sub-processors may process Customer Personal Data in providing the Services. All are located within the EU or EEA.

Sub-processorRoleLocation
Hetzner Online GmbHHosting and infrastructureGermany / Finland
Mistral AI SA (15 rue des Halles, 75001 Paris)Assistant and generative features (Dolce Intelligence)France
Mollie B.V.Payment processingNetherlands
Nexi S.p.A. (planned, not yet active)Payment processingItaly

Contact

Questions about this DPA or about data protection at Dolcefy may be sent to ciao@dolcefy.com.

Dolcefy S.R.L.S., Via di Luiano 26, 50026 San Casciano in Val di Pesa (FI), Italy. 
VAT number IT07543460484.


© 2026 Dolcefy S.R.L.S. All rights reserved.