Data Processing Agreement (DPA) — Statuo

Annex to the Terms and Conditions of Service — Rev. 3 — Last updated: 9 July 2026

Courtesy translation. In case of any discrepancy, the Italian version prevails (statuo.io/dpa).

1. Parties and roles

This agreement (the "DPA") is entered into between the Customer (as defined in the Terms of Service), acting as data controller, and Apdsoftware of Carlo Zuffetti (apdsoftware.it), VAT IT03835250162 (the "Provider"), acting as data processor under art. 28 GDPR.

The DPA applies only to personal data the Provider processes on behalf of the Customer in supplying the Statuo Service. For the Customer's account data the Provider acts as an independent controller (see the Privacy Notice).

2. Subject matter, duration, nature and purpose of processing

3. Categories of data subjects and data (Annex 1)

Data subjects: employees and collaborators of the Customer; the Customer's end users whose contact details are added as notification channels; persons whose data appears in the URLs or names of the Monitored Sites.

Categories of data: contact data (e-mail addresses, Telegram identifiers); names and URLs attributable to natural persons; technical check data (results, latencies, timestamps). No special-category data (art. 9 GDPR) is required or envisaged by the Service; the Customer undertakes not to enter any.

4. Obligations of the Processor

The Provider undertakes to:

a) process data only on the Customer's documented instructions — instructions are deemed given through the configuration of the Service in the panel — save for legal obligations, in which case it will inform the Customer where permitted;

b) ensure that persons authorized to process the data are bound by confidentiality;

c) adopt the security measures under art. 32 GDPR, as described in Annex 2;

d) assist the Customer, taking into account the nature of the processing, in responding to data subjects' requests (arts. 15-22 GDPR) and with the obligations under arts. 32-36 GDPR, including — where requested — the information needed for impact assessments (DPIA) and prior consultations;

e) notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach, providing the information useful for notification under art. 33 GDPR;

f) make available the information necessary to demonstrate compliance and allow, with reasonable notice of at least 30 days and at the Customer's expense, documentary verifications; any on-site audits are limited to once a year and conducted so as not to compromise the security of other customers.

4-bis. Obligations and warranties of the Controller

The Customer, as controller, warrants: (a) that it has an appropriate legal basis for the processing entrusted to the Provider; (b) that it has provided data subjects (including its own End Users) with the notices required by arts. 13-14 GDPR; (c) that the instructions given — including through the configuration of the Service — are lawful and do not place the Provider in breach of the GDPR or other rules. The Customer shall hold the Provider harmless from the consequences of any breach of these warranties.

5. Sub-processors

5.1. The Customer gives general authorization to the sub-processors listed in Annex 2. The Provider will give at least 15 days' notice of any addition or replacement; in case of reasoned objection, the Customer may withdraw from the Service without penalty.

5.2. The Provider imposes on each sub-processor, by contract, obligations equivalent to those of this DPA and remains liable towards the Customer for the sub-processors' performance.

6. Transfers outside the EU

Data is processed predominantly on infrastructure within the European Economic Area (Hetzner in Germany for core and database, with continuous backups and a disaster-recovery standby on Google Cloud, always within the EU — Belgium). Exceptions: notification delivery via Telegram (enabled only at the Customer's choice); and execution of monitoring checks from Google Cloud's US location, which processes the URL and check outcome in memory only — even when a check includes a keyword match against the page, the content is read only for the comparison and never written to disk or logs — with no data storage on the non-EEA system. In both cases the transfer is based on adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or Standard Contractual Clauses.

7. Assistance and costs

Ordinary assistance under art. 4.d is included in the fee. Extraordinary, disproportionate or repetitive requests may be billed at an hourly rate communicated to the Customer in advance.

8. Termination and deletion

Upon termination of the Service, the Provider retains the data for 30 days to allow export from the panel, after which it permanently deletes it from active systems; backup copies are overwritten according to the rotation cycle within a further 30 days. Upon request, the Provider certifies deletion in writing.

9. Liability

Claims based on this DPA are subject to the limitation of liability under art. 9 of the Terms of Service, to the maximum extent permitted by law. Each party's liability towards data subjects under art. 82 GDPR, and the recourse regime provided therein, remain unaffected and cannot be contractually derogated.

10. Final provisions

For anything not provided herein, the Terms of Service apply. In case of conflict between the DPA and the Terms, the DPA prevails for data-protection matters. Italian law; Court of Bergamo.


Annex 1 — Details of processing

As per art. 3 of this DPA.

Annex 2 — Security measures and sub-processors

Technical and organizational measures (art. 32 GDPR):

Authorized sub-processors:

Sub-processor Activity Region
Hetzner Online GmbH Hosting and delivery (core/database) EU
Google Cloud Continuous backup and disaster-recovery standby of the database; execution of monitoring checks (probe) EU (Belgium, Milan) + USA (Iowa; in-memory execution only, no data storage)
Resend, Inc. Notification e-mail delivery EU
Telegram FZ-LLC (only if enabled by the Customer) Notification delivery Non-EU

(Paddle is not a sub-processor: for payments it acts as an independent controller in its capacity as merchant of record.)


Execution: the DPA is deemed accepted by the Customer upon acceptance of the Terms of Service at registration.