CronoVentA REC Eventi project
EN

English translation of the Italian document. This translation does not change the service conditions.

SERVICE DOCUMENTS · VERSION 2026-09-12

Data processing agreement

Version dated 12 September 2026 · agreement under Article 28 GDPR, linked to the CronoVent terms.

1. Parties and scope

The customer is the organisation identified in the account and any order, represented by the authorised user accepting the agreement. The processor is REC Eventi di Andrea Matteo Bassi · Via Dumas 12, 42123 Reggio Emilia, Italy · VAT no. 02472790357, contact info@cronovent.it. If the customer acts as processor for an organiser, it warrants authorisation to appoint REC Eventi as sub-processor and provides applicable instructions.

Processing covers hosting, organising, displaying, updating, exporting, backing up and deleting production schedules and documents uploaded by the customer. It lasts for the service relationship and final return/deletion. It concerns technicians, speakers, artists, contacts and collaborators; ordinary data includes names, roles, professional contact details, timings and operational documents. Uploading special categories of data or criminal records is not authorised.

2. Instructions and confidentiality

The processor handles data only to provide the service and under the customer’s documented instructions, including transfer instructions. It does not use it for advertising, data sales or model training. If a legal obligation requires other processing, it informs the customer beforehand unless prohibited by law. It immediately informs the customer if it considers an instruction to breach the law.

Authorised persons must be bound by confidentiality and act according to instructions and the principle of minimum necessary access.

3. Technical and organisational measures

Applied measures: HTTPS; passwords stored as salted PBKDF2 derivatives, not plain text; limited and revocable sessions; server checks on customer ownership of schedules; attachment protection; login-attempt limits; random single-use email tokens; separation of viewing and editing; contact details not shared by default; operational backups with restricted access and limited retention; updates and recovery procedures.

Shared event passwords do not identify individual users: the customer must distribute them to authorised recipients and rotate them when the crew changes. Future individual-role features are not treated as already available. Measures must be reassessed according to risks and service developments.

4. Sub-processors

The customer authorises Hetzner Online GmbH for app infrastructure and operational backups in the Falkenstein area, Germany. The provider’s appointment must be governed by an Article 28-compliant agreement; REC Eventi remains responsible to the customer for obligations entrusted to the sub-processor.

New sub-processors will be communicated at least 15 days in advance, stating their role and location. The customer may object on documented data-protection grounds; the parties will seek an alternative and, if impossible, arrange termination of the affected processing. Account emails are sent through Aruba’s email service; they do not contain event schedules or attachments.

5. Assistance and breaches

The processor assists the customer with rights requests, impact assessments and obligations under Articles 32–36, taking account of the nature of processing and available information. Requests received directly concerning customer data are forwarded without delay; data is not disclosed or deleted beyond authorised instructions.

In a personal data breach, the processor informs the customer without undue delay after becoming aware, providing available information on its nature, data/person categories, likely consequences and measures taken, with updates as available. The controller assesses notifications to authorities and individuals, assisted by the processor.

6. Audits and information

The processor provides information needed to demonstrate compliance and allows audits and inspections by the customer or an appointed auditor, in a proportionate manner respecting security and other customers’ data. Any extraordinary activity costs are agreed without preventing exercise of GDPR audit rights.

7. Return and deletion

On termination, at the customer’s choice, the processor returns or deletes data and copies, subject to legal obligations. The procedure starts after instruction verification, normally within 30 days. Backup copies are not used for ordinary processing and expire under the privacy policy timeframes; deletions are reapplied on restoration. Temporary working copies must be included. The processor documents fulfilment of the request.

8. Transfers and precedence

No new transfer outside the EEA is activated without documenting the instructions and safeguards required by Chapter V GDPR. For data-protection obligations, this agreement takes precedence over conflicting service terms. The privacy policy does not replace this agreement.