Status: In force Effective date: 6 September 2026 Version: 1.0
This Data Processing Addendum ("DPA") applies when a business uses OVIO and OVIO processes personal data on behalf of that business as processor. It supplements the OVIO Business Terms.
1. Parties
Business controller: the business that accepts this DPA.
Processor: ovioapp S.r.l., with registered address at Corso Piemonte, Settimo Torinese (TO), Italy.
2. When This DPA Applies
This DPA applies only where OVIO processes personal data on the business's documented instructions as processor.
OVIO remains an independent controller for platform operations such as account management, marketplace integrity, security, billing, business identity, legal compliance, payment metadata, fraud prevention, analytics consent, support, and policy enforcement.
Businesses may be independent controllers for service delivery, customer relationships, business marketing, tax, accounting, legal obligations, and professional obligations.
OVIO and the business are not joint controllers. Each is an independent controller for the purposes described above, and OVIO acts as processor only for the processing described in section 3.
3. Processing Details
Subject matter: OVIO's provision of marketplace, booking, communication, business-operation, customer-management, notification, and payment-support tools to the business.
Duration: for the term of the business's use of OVIO and any post-termination period needed for deletion, return, backup expiry, legal retention, support, security, or dispute handling.
Nature and purpose:
- Hosting and displaying business customer records.
- Managing bookings, orders, queues, events, messages, reminders, receipts, and support records.
- Supporting customer communications.
- Supporting business staff access.
- Supporting data export, correction, deletion, and retention workflows.
- Supporting security, fraud prevention, and operational reliability.
Categories of data subjects:
- Customers and prospective customers.
- Business staff and representatives.
- Invited contacts or message recipients.
- Support requesters.
Categories of personal data:
- Name, email, phone, account identifiers, and contact details.
- Booking, order, queue, event, service, product, staff, location, and message data.
- Preferences, marketing choices, consent records, and unsubscribe records.
- Payment metadata, receipt references, refund/dispute metadata, and subscription status where relevant.
- Support, report, moderation, and audit records.
- Device, log, and security data where needed to operate the service.
Sensitive data:
The business must not use OVIO to process special-category data as defined in Article 9 of the GDPR unless OVIO has agreed to that category in writing and the parties have put the additional terms and safeguards in place. OVIO's services are not designed for medical or other special-category processing.
4. Business Instructions
OVIO will process personal data under this DPA only on documented business instructions, including the Business Terms, this DPA, product configuration, and lawful written instructions from the business.
OVIO may refuse or pause an instruction if OVIO reasonably believes it violates law, OVIO's terms, payment provider rules, security requirements, or the rights of another person.
5. Business Obligations
The business is responsible for:
- Having a lawful basis for processing personal data.
- Providing required notices to customers and staff.
- Handling consent and opt-out requirements for business-controlled marketing.
- Ensuring staff have appropriate access.
- Responding to data rights requests where the business is controller.
- Ensuring its instructions to OVIO are lawful.
- Not uploading unnecessary sensitive data.
6. OVIO Processor Obligations
Where OVIO acts as processor, OVIO will:
- Process personal data only on documented instructions.
- Ensure people authorized to process personal data are bound by confidentiality obligations.
- Use technical and organizational measures designed to protect personal data.
- Assist the business with data rights requests, security, breach response, and data protection impact assessments where required and reasonably possible.
- Use subprocessors under written terms that provide appropriate data-protection obligations.
- Provide information reasonably necessary to demonstrate compliance with this DPA.
- Delete or return personal data at the end of service, subject to legal retention, backup expiry, security, dispute, and legitimate controller obligations.
7. Security Measures
OVIO's baseline measures may include:
- Authentication and role-based access controls.
- Separation of customer, business, and administrative access.
- Encryption in transit.
- Managed database and hosting controls.
- Service-role restrictions for privileged operations.
- Logging and monitoring for operational and security events.
- Webhook signature verification where applicable.
- Vendor access controls.
- Environment separation for development and production.
- Incident response procedures.
No service can guarantee absolute security.
8. Subprocessors
The business authorizes OVIO to use subprocessors listed in the Subprocessors & Security document, subject to this DPA.
OVIO will make available the current subprocessor list and will provide notice of material new subprocessors where required. If the business objects on reasonable data-protection grounds, OVIO and the business will work in good faith to address the concern. If the concern cannot be resolved, the business may stop using the affected feature or terminate the affected service as allowed by the Business Terms.
9. International Transfers
Where personal data is transferred internationally and transfer safeguards are required, OVIO will use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, Data Privacy Framework certifications where applicable, or another lawful transfer mechanism.
Where OVIO transfers personal data processed on the business's behalf outside the European Economic Area, the parties incorporate the Standard Contractual Clauses approved by Implementing Decision (EU) 2021/914, Module Three (processor to processor), with Italian law as the governing law and the courts of Italy as the forum, and OVIO carries out a transfer risk assessment for each such transfer. Where the business is established outside the European Economic Area and OVIO transfers personal data to it, Module Four applies instead.
10. Personal Data Breach
OVIO will notify the business without undue delay after becoming aware of a personal data breach affecting personal data processed by OVIO as processor for the business.
The notice will include information reasonably available to OVIO to help the business meet its obligations. OVIO may provide information in phases as it investigates.
The business is responsible for determining whether it must notify authorities or affected individuals, unless law requires OVIO to notify directly.
11. Data Rights Requests
OVIO will provide reasonable assistance to the business for access, correction, deletion, portability, objection, restriction, and other data rights requests where OVIO acts as processor and the business cannot reasonably fulfill the request without OVIO.
If OVIO receives a request relating to business-controlled data, OVIO may direct the requester to the business or notify the business where appropriate.
12. Audit and Compliance Information
OVIO will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, limited to data processed under this DPA, protect OVIO systems and other users' data, and avoid unnecessary disruption.
The business may request an audit no more than once in any twelve-month period, on at least 30 days' written notice, at its own cost, subject to confidentiality, and carried out by the business or by an independent auditor who is not a competitor of OVIO. OVIO may satisfy an audit request by providing current certifications, security documentation, or a completed security questionnaire. OVIO will cooperate with an additional audit where a supervisory authority requires one, or where OVIO has notified the business of a personal data breach affecting the business's data.
13. Deletion and Return
At termination, OVIO will delete or return personal data processed as processor as described in the product, Business Terms, or written instructions, subject to legal retention, backup expiry, security, fraud, tax, accounting, dispute, support, and OVIO controller obligations.
14. Order of Precedence
If this DPA conflicts with the Business Terms, this DPA controls only for processor obligations relating to personal data processed on the business's instructions. The Business Terms control for commercial and platform matters.
15. Contact
- Privacy/DPA contact: support@ovioapp.com
- Legal notices: support@ovioapp.com